@adcp/sdk API Reference - v14.3.0
    Preparing search index...

    Interface DerivedRosterAccountStoreOptions<TCtxMeta>

    Shape D options for a credential-scoped roster — the upstream exposes many accounts to one credential (Meta / Snap business managers, an agency seat).

    interface DerivedRosterAccountStoreOptions<TCtxMeta = Record<string, unknown>> {
        skipAuthCheck?: boolean;
        listAccounts: (
            ctx: ResolveContext | undefined,
        ) => readonly Account<TCtxMeta>[] | Promise<readonly Account<TCtxMeta>[]>;
        lookupAccount?: (
            accountId: string,
            ctx: ResolveContext | undefined,
        ) =>
            | Account<TCtxMeta>
            | Promise<Account<TCtxMeta> | null | undefined>
            | null
            | undefined;
        toAccount?: undefined;
    }

    Type Parameters

    • TCtxMeta = Record<string, unknown>

    Hierarchy (View Summary)

    Index
    skipAuthCheck?: boolean

    Skip the AUTH_REQUIRED precheck. Defaults to false — the factory throws AdcpError('AUTH_REQUIRED') when ctx.authInfo is absent or carries no credential, matching the canonical Shape D pattern (every call must authenticate, because the credential is what scopes the reachable roster).

    Set to true for genuinely unauthenticated agents (rare — public format catalogs, signed-request-only agents that authenticate out-of-band). When true, the account callbacks run unconditionally.

    If you're tempted to set this because tests don't carry authInfo, fix the tests instead — serve({ authenticate }) should populate ctx.authInfo from your test harness (or use dispatchTestRequest which threads a synthetic principal). The escape hatch is for production agents that legitimately accept unauthenticated traffic, not for working around fixture gaps.

    false
    
    listAccounts: (
        ctx: ResolveContext | undefined,
    ) => readonly Account<TCtxMeta>[] | Promise<readonly Account<TCtxMeta>[]>

    Enumerate every account the caller's credential can reach. Backs list_accounts and, unless lookupAccount is supplied, the verification of buyer-supplied account_id references.

    This is the tenant-isolation boundary for the whole namespace: scope the query by ctx.authInfo (OAuth client_id, API-key key_id, the upstream token you exchange for it). Returning the full upstream roster regardless of caller is a cross-tenant enumeration and authorization bug — every id returned here becomes an id that caller can transact on.

    lookupAccount?: (
        accountId: string,
        ctx: ResolveContext | undefined,
    ) =>
        | Account<TCtxMeta>
        | Promise<Account<TCtxMeta> | null | undefined>
        | null
        | undefined

    Optional point-lookup for large rosters — avoids materializing the full list on every resolve(). Return the account for accountId, or null when the caller's credential cannot reach it.

    Must be credential-scoped. The accountId is a buyer-supplied claim; an unscoped SELECT ... WHERE id = $1 here is a tenant-isolation bypass. The factory defends what it can — a returned account whose id differs from the requested one is discarded — but it cannot tell whether your query filtered on the caller.

    Omit it and the factory verifies against listAccounts(ctx) instead, which is safe by construction.

    toAccount?: undefined

    Mutually exclusive with listAccounts — supply the singleton option instead.