# SSOAuthSettings

**Kind**: interface | **Module**: [Insights](https://docs.interop.io/desktop/reference/javascript/insights/index.md)

**Source**: https://docs.interop.io/desktop/reference/javascript/insights/ssoauthsettings/index.html

Settings for injecting the io.Connect SSO login information into the headers of the
OpenTelemetry export requests.

The login is asked for on every export (and cached for a while - see `authInfoCacheMs`), so
it doesn't have to be there when io.Insights is initialized, and a refreshed token is picked
up. Exports that happen before anybody has logged in go out without it, unless `waitForLogin`
is set.

In io.Connect Desktop the login of the platform is used: by the platform itself, and by the
applications that are allowed to have it (`allowAuthInfo` set to `true` in the application
definition) - the rest export without it. It isn't available to Node.js applications. The
io.Connect Gateway gets the login as it is when the gateway is started, which is usually
before anybody has logged in.

Only applies to the OTLP exporters io.Insights creates itself (from `url`), and to custom
ones that are created from the exporter settings they are handed.

## Properties

- **`authInfoCacheMs`** (`number`, optional) default: `30000`
  For how long the login is reused before it is asked for again, in milliseconds. In an
  application of io.Connect Desktop asking means a round trip to the platform.
- **`authInfoTimeoutMs`** (`number`, optional) default: `5000`
  How long to wait for the login to be provided, in milliseconds. A login that doesn't come
  in time is treated like one that isn't available: the export goes out without it, and the
  login isn't asked for again until `authInfoCacheMs` has passed.
- **`enabled`** (`boolean`, optional) default: `false`
  If `true`, the io.Connect SSO token is sent as the `Authorization` header of the
  OpenTelemetry export requests, together with any headers the SSO login provides.
- **`getAuthInfo`** (`() => SSOAuthInfo | null | undefined | Promise<SSOAuthInfo | null | undefined>`, optional)
  Provides the login. By default the login of io.Connect Desktop is used, when running in it
  (`iodesktop.getAuth()`); hosts with a login of their own specify this. Called on every export
  that doesn't find the login in the cache; can return `null` while nobody has logged in.
- **`useAuthHeader`** (`boolean`, optional) default: `false`
  If `true`, will also use a custom `auth` header to send the entire io.Connect SSO
  authorization object as a JSON string, unless `headers` already specifies one.
- **`useRawToken`** (`boolean`, optional) default: `true`
  If `true`, will use the io.Connect SSO token as-is. If `false`, "Bearer " will be prepended
  to the token if it lacks the prefix.
- **`waitForLogin`** (`boolean`, optional) default: `false`
  If `true`, an export that happens before anybody has logged in waits for the login - for
  up to `waitForLoginTimeoutMs` - instead of going out without it (and most likely being
  rejected, and lost). Only until the first login, and only until the first time the wait
  times out: from then on exports don't wait.

  The wait is part of the export, so it counts against the export timeout of the batch
  processors (`processorSettings.exportTimeoutMillis`, 30 seconds by default), and whatever
  is published in the meantime queues up (`processorSettings.maxQueueSize`).
- **`waitForLoginTimeoutMs`** (`number`, optional) default: `5000`
  How long an export waits for the login when `waitForLogin` is set, in milliseconds.

## Related types

- [SSOAuthInfo](https://docs.interop.io/desktop/reference/javascript/insights/ssoauthinfo/index.md)
