---
editLink: false
lastUpdated: false
---

[@salesforce/b2c-tooling-sdk](../../modules.md) / [auth](../index.md) / UserAuthStrategy

# Interface: UserAuthStrategy

Defined in: [packages/b2c-tooling-sdk/src/auth/types.ts:83](https://github.com/SalesforceCommerceCloud/b2c-developer-tooling/blob/2feab01f654eec77c6d702777ec2818472f131f1/packages/b2c-tooling-sdk/src/auth/types.ts#L83)

An interactive, token-bearing OAuth strategy — the "user" auth flow
(Authorization Code + PKCE, with the legacy implicit flow as fallback).

Unlike the base [AuthStrategy](AuthStrategy.md), these always expose the access token /
decoded JWT so callers like `auth token` can surface them. Implemented by
`PkceOAuthStrategy`, `ImplicitOAuthStrategy`, and the transitional
`PkceWithImplicitFallbackStrategy`.

## Extends

- [`AuthStrategy`](AuthStrategy.md)

## Properties

### authMethod

> `readonly` **authMethod**: `"user"` \| `"implicit"`

Defined in: [packages/b2c-tooling-sdk/src/auth/types.ts:85](https://github.com/SalesforceCommerceCloud/b2c-developer-tooling/blob/2feab01f654eec77c6d702777ec2818472f131f1/packages/b2c-tooling-sdk/src/auth/types.ts#L85)

Browser auth method represented by this strategy.

## Methods

### fetch()

> **fetch**(`url`, `init?`): `Promise`\<`Response`\>

Defined in: [packages/b2c-tooling-sdk/src/auth/types.ts:22](https://github.com/SalesforceCommerceCloud/b2c-developer-tooling/blob/2feab01f654eec77c6d702777ec2818472f131f1/packages/b2c-tooling-sdk/src/auth/types.ts#L22)

Performs a fetch request with authentication.
Implementations MUST handle header injection and 401 retries (token refresh) internally.

#### Parameters

##### url

`string`

##### init?

[`FetchInit`](../type-aliases/FetchInit.md)

#### Returns

`Promise`\<`Response`\>

#### Inherited from

[`AuthStrategy`](AuthStrategy.md).[`fetch`](AuthStrategy.md#fetch)

***

### getAccessTokenForCascade()?

> `optional` **getAccessTokenForCascade**(`candidates`): `Promise`\<`string`\>

Defined in: [packages/b2c-tooling-sdk/src/auth/types.ts:71](https://github.com/SalesforceCommerceCloud/b2c-developer-tooling/blob/2feab01f654eec77c6d702777ec2818472f131f1/packages/b2c-tooling-sdk/src/auth/types.ts#L71)

Optional: Resolves a scope cascade by trying each candidate scope set
in order and returning the first that AM accepts.

Implementations should:
  1. Return any cached token whose scopes ⊇ a candidate (no AM call).
  2. Otherwise, call AM with each candidate in order until one survives;
     cache the result keyed by what was requested.
  3. Throw the last `invalid_scope` error if all candidates fail.

Implementations MUST add any base scopes (e.g. tenant scope baked in
via [withAdditionalScopes](AuthStrategy.md#withadditionalscopes)) to each candidate before sending it
to AM.

Used by the SCAPI auth middleware to pick the right scope tier (rw vs
ro) per operation. Strategies without OAuth-style scope grants (basic,
api-key) should leave this unset; the middleware falls through to
[getAuthorizationHeader](AuthStrategy.md#getauthorizationheader) in that case.

#### Parameters

##### candidates

`string`[][]

Outer array is cascade order; inner arrays are the
  scopes for each token request attempt. e.g.
  `[['sfcc.jobs.rw'], ['sfcc.jobs']]`.

#### Returns

`Promise`\<`string`\>

The access token (Bearer value, no `Bearer ` prefix).

#### Inherited from

[`AuthStrategy`](AuthStrategy.md).[`getAccessTokenForCascade`](AuthStrategy.md#getaccesstokenforcascade)

***

### getAuthorizationHeader()

> **getAuthorizationHeader**(): `Promise`\<`string`\>

Defined in: [packages/b2c-tooling-sdk/src/auth/types.ts:86](https://github.com/SalesforceCommerceCloud/b2c-developer-tooling/blob/2feab01f654eec77c6d702777ec2818472f131f1/packages/b2c-tooling-sdk/src/auth/types.ts#L86)

Optional: Helper for legacy clients (like a strict WebDAV lib) that need the raw header.

#### Returns

`Promise`\<`string`\>

#### Overrides

[`AuthStrategy`](AuthStrategy.md).[`getAuthorizationHeader`](AuthStrategy.md#getauthorizationheader)

***

### getJWT()

> **getJWT**(): `Promise`\<[`DecodedJWT`](DecodedJWT.md)\>

Defined in: [packages/b2c-tooling-sdk/src/auth/types.ts:87](https://github.com/SalesforceCommerceCloud/b2c-developer-tooling/blob/2feab01f654eec77c6d702777ec2818472f131f1/packages/b2c-tooling-sdk/src/auth/types.ts#L87)

#### Returns

`Promise`\<[`DecodedJWT`](DecodedJWT.md)\>

***

### getTokenResponse()

> **getTokenResponse**(): `Promise`\<[`AccessTokenResponse`](AccessTokenResponse.md)\>

Defined in: [packages/b2c-tooling-sdk/src/auth/types.ts:88](https://github.com/SalesforceCommerceCloud/b2c-developer-tooling/blob/2feab01f654eec77c6d702777ec2818472f131f1/packages/b2c-tooling-sdk/src/auth/types.ts#L88)

#### Returns

`Promise`\<[`AccessTokenResponse`](AccessTokenResponse.md)\>

***

### invalidateToken()

> **invalidateToken**(): `void`

Defined in: [packages/b2c-tooling-sdk/src/auth/types.ts:89](https://github.com/SalesforceCommerceCloud/b2c-developer-tooling/blob/2feab01f654eec77c6d702777ec2818472f131f1/packages/b2c-tooling-sdk/src/auth/types.ts#L89)

Optional: Invalidates the cached token, forcing re-authentication on next request.
Used by middleware to retry requests after receiving a 401 response.

#### Returns

`void`

#### Overrides

[`AuthStrategy`](AuthStrategy.md).[`invalidateToken`](AuthStrategy.md#invalidatetoken)

***

### withAdditionalScopes()?

> `optional` **withAdditionalScopes**(`additionalScopes`): [`AuthStrategy`](AuthStrategy.md)

Defined in: [packages/b2c-tooling-sdk/src/auth/types.ts:45](https://github.com/SalesforceCommerceCloud/b2c-developer-tooling/blob/2feab01f654eec77c6d702777ec2818472f131f1/packages/b2c-tooling-sdk/src/auth/types.ts#L45)

Optional: Returns a copy of this strategy with the given scopes merged into
its requested scope set. SCAPI client factories use this to ensure the
tenant scope is present on every token request.

Implemented by `OAuthStrategy` and `JwtOAuthStrategy`. Strategies that
obtain tokens by other means (basic, api-key, implicit-via-stored-session)
may not implement this; callers should treat them as "scopes already
established at construction time."

#### Parameters

##### additionalScopes

`string`[]

#### Returns

[`AuthStrategy`](AuthStrategy.md)

#### Inherited from

[`AuthStrategy`](AuthStrategy.md).[`withAdditionalScopes`](AuthStrategy.md#withadditionalscopes)
