apps-script-utils 2.1.1 Help

requireValidToken

function requireValidToken( token: unknown, allowedKeys: string | string[] | Record<string, unknown>, message: string = "Invalid API key." ): string;

The allowed keys may be a single string, a list, or an object whose keys are the tokens. This is the check at the door of a web app: it returns the token so the call reads as one expression, and throws a named exception otherwise.

Parameters

Parameter

Type

Description

token

unknown

The token presented by the caller.

allowedKeys

string \| string[] \| Record<string, unknown>

One key, a list of keys, or an object keyed by them.

message (optional) = "Invalid API key."

string

The message of the exception. "Invalid API key." by default.

Returns

string — the token, unchanged.

Throws

Exception

Condition

AuthenticationException

the token is missing or matches none of the allowed keys.

Examples

In use

function doPost(event) { const key = requireValidToken( event.parameter.key, PropertiesService.getScriptProperties().getProperty("API_KEYS").split(","), "Unknown API key." ); // … the request is from someone we know }

See also

Source

src/appsscript/net/requireValidToken.ts

23 September 2026

This documentation was generated with AI (Claude) from the library's source code.