Functional Weave
Code in TypeScript

auth.bearer-token

The token from an HTTP Authorization header of the form "Bearer <token>" (RFC 6750), or null if it has none.

1.0.0 · published 2026-10-03 by charlie · Anterra

Pinned by 18 tests, run in TypeScript, Python and Rust.

What it does

`parseBearerToken("Bearer eyJhbGciOi...")` is `"eyJhbGciOi..."`. An API calls it with the request's `Authorization` header (or null when there is none) and answers 401 when the result is null; it never throws, because a bad header is the client's mistake and gets an answer, not a crash.

It follows RFC 6750 section 2.1: the scheme `Bearer`, one or more spaces, then a `b64token`, which is letters, digits and `- . _ ~ + /`, optionally followed by `=` padding. The scheme is case-insensitive (`bearer`, `BEARER`), as HTTP authentication schemes are (RFC 9110 section 11.1). Spaces and tabs around the whole value are ignored, since HTTP strips them from field values anyway.

For example

  • parseBearerToken(Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxIn0.c2lnbmF0dXJl) → eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxIn0.c2lnbmF0dXJl a JWT after Bearer
  • parseBearerToken(Bearer mF_9.B5f-4.1JqM) → mF_9.B5f-4.1JqM RFC 6750 section 2.1's example token
  • parseBearerToken(bearer abc) → abc the scheme is case-insensitive

The function

The same function in TypeScript, Python and Rust, pinned by the same tests. Pick your language; the choice follows you around the registry.

export function parseBearerToken(authorization: string | null): string | null
authorizationstring?the Authorization header's value, or null when the request has none
returnsstring?the token, exactly as sent; null when the header is missing, another scheme or malformed

Your code names it in one line, in the file that uses it

import { parseBearerToken } from "#fune/auth.bearer-token@^1";
impl/typescript.ts · 26 lines · open · raw
function isTokenChar(ch: string): boolean {
  return (ch >= "A" && ch <= "Z") || (ch >= "a" && ch <= "z") || (ch >= "0" && ch <= "9") || ch === "-" || ch === "." || ch === "_" || ch === "~" || ch === "+" || ch === "/";
}

/**
 * The token from `Authorization: Bearer <token>` (RFC 6750 section 2.1), or
 * null. Never throws: a malformed header is an answer (401), not an error.
 */
export function parseBearerToken(authorization: string | null): string | null {
  if (typeof authorization !== "string") return null;
  let start = 0;
  let end = authorization.length;
  while (start < end && (authorization[start] === " " || authorization[start] === "\t")) start++;
  while (end > start && (authorization[end - 1] === " " || authorization[end - 1] === "\t")) end--;
  const value = authorization.slice(start, end);
  if (value.length < 7 || value.slice(0, 6).toLowerCase() !== "bearer" || value[6] !== " ") return null;
  let i = 6;
  while (i < value.length && value[i] === " ") i++;
  const token = value.slice(i);
  if (token.length === 0) return null;
  let j = 0;
  while (j < token.length && isTokenChar(token[j])) j++;
  if (j === 0) return null;
  while (j < token.length && token[j] === "=") j++;
  return j === token.length ? token : null;
}

Install

fune build

With that line in your source, in a TypeScript project (language typescript in fune.project), fune build resolves it and nothing else, pins them in fune.lock, downloads only the TypeScript package of each, and builds the code above into your project’s .fune/build, one readable file per capability with a header linking back here. Or pin a range in fune.project and build in one step:

fune add auth.bearer-token
Download for TypeScript auth.bearer-token-1.0.0-typescript.fune · 5,907 bytes sha256 5362858ea42a2a30eb3683d14ef53bbfd95665dad22afe49e392a29e205e9e60

The manifest, vectors and README with only the TypeScript implementation. Install it without the registry with fune add ./auth.bearer-token-1.0.0-typescript.fune, or fetch it from a terminal with fune pull auth.bearer-token@1.0.0:typescript.

The whole function, every language, is one file too: auth.bearer-token-1.0.0.fune, 8,426 bytes, sha256 087efd10d3dfaa6bd7fa838be29eaa2233f7a031d8bda534f66e615ae3a0a064. It installs into a project of any language.

Customise it in your app

The seams this capability offers. Put a marker directly above a function of your own and fune build wires it into the built code; the package on the registry is not changed, the built file’s header lists it under CUSTOMISED, and fune hooks lists every hook in the project. How hooks work.

before — your function gets the arguments and returns them, changed or not, or throws to refuse the call.

// fune: before auth.bearer-token

after — your function gets the result and the arguments, and returns the final result.

// fune: after auth.bearer-token

replace — it requires no other capability, so there is no dependency to replace.

step — your function runs at a numbered point inside the function’s body, receives the in-scope values it names as parameters, and may return replacements. List the points with fune show auth.bearer-token --steps.

// fune: step auth.bearer-token after <n|label>

Tests

A version published now needs at least 8 tests for every function, and one that expects the error for each function that throws; the registry refuses it otherwise. fune verify --all runs each case in TypeScript, Python and Rust, and a project runs them again with fune verify. This page lists the cases; it does not run them. The exact JSON is vectors.json.

CaseArgumentsExpected
a JWT after Bearer Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxIn0.c2lnbmF0dXJl → eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxIn0.c2lnbmF0dXJl
RFC 6750 section 2.1's example token Bearer mF_9.B5f-4.1JqM → mF_9.B5f-4.1JqM
the scheme is case-insensitive bearer abc → abc
upper-case scheme BEARER abc → abc
several spaces after the scheme (1*SP) Bearer abc → abc
spaces around the whole value are ignored Bearer abc → abc
trailing = padding and the + / ~ characters are allowed Bearer a+b/c~d== → a+b/c~d==
no header at all — → —
an empty header → —
the scheme with no token Bearer → —
Show the other 8 tests
CaseArgumentsExpected
the scheme and a space but no token Bearer → —
another scheme Basic dXNlcjpwYXNz → —
no space between scheme and token Bearerabc → —
a tab is not the space RFC 6750 requires after the scheme Bearer abc → —
a space inside the token Bearer abc def → —
= in the middle of the token Bearer ab=c → —
a token that is only padding Bearer == → —
a non-ASCII character in the token Bearer abcé → —

More from the author

Everything else is null: another scheme (`Basic ...`), `Bearer` with no token, a space or a tab inside the token, `=` anywhere but the end, non-ASCII characters, or `Bearerabc` with no separating space. A JWT (three base64url parts joined by dots) is always a valid `b64token`.

This only finds the token; checking it is `auth.jwt` (or `auth.access-token`, which does both).

Source: RFC 6750, The OAuth 2.0 Authorization Framework: Bearer Token Usage, section 2.1 (https://www.rfc-editor.org/rfc/rfc6750#section-2.1).

Files

PathBytes
README.md1,217
impl/python.py1,103
impl/rust.rs1,277
impl/typescript.ts1,252
vectors.json1,722