requireValidToken
function requireValidToken(
token: unknown,
allowedKeys: string | string[] | Record<string, unknown>,
message: string = "Invalid API key."
): string;
The allowed keys may be a single string, a list, or an object whose keys are the tokens. This is the check at the door of a web app: it returns the token so the call reads as one expression, and throws a named exception otherwise.
Parameters
Parameter | Type | Description |
|---|---|---|
|
| The token presented by the caller. |
|
| One key, a list of keys, or an object keyed by them. |
|
| The message of the exception. |
Returns
string — the token, unchanged.
Throws
Exception | Condition |
|---|---|
| the token is missing or matches none of the allowed keys. |
Examples
In use
function doPost(event) {
const key = requireValidToken(
event.parameter.key,
PropertiesService.getScriptProperties().getProperty("API_KEYS").split(","),
"Unknown API key."
);
// … the request is from someone we know
}
See also
Source
23 September 2026
This documentation was generated with AI (Claude) from the library's source code.