OptionalskipSkip the AUTH_REQUIRED precheck. Defaults to false — the factory
throws AdcpError('AUTH_REQUIRED') when ctx.authInfo is absent or
carries no credential, matching the canonical Shape D pattern (every
call must authenticate, because the credential is what scopes the
reachable roster).
Set to true for genuinely unauthenticated agents (rare — public format
catalogs, signed-request-only agents that authenticate out-of-band).
When true, the account callbacks run unconditionally.
If you're tempted to set this because tests don't carry authInfo,
fix the tests instead — serve({ authenticate }) should populate
ctx.authInfo from your test harness (or use dispatchTestRequest
which threads a synthetic principal). The escape hatch is for
production agents that legitimately accept unauthenticated traffic,
not for working around fixture gaps.
Build the one account this credential can reach. Called on every
resolve() and list() (no caching — the tenant is per-request because
the auth principal varies).
The factory verifies buyer-supplied references against the returned
id: a request carrying a different account_id resolves to null
(framework → ACCOUNT_NOT_FOUND) rather than being silently serviced
against this account. You do not implement that check yourself.
id must be the id the upstream namespace actually uses — it is what
list_accounts publishes and what buyers will send back. A placeholder
like '__singleton__' is fine only if that is genuinely the id you want
on the wire.
DO NOT put credentials in ctx_metadata. See
docs/guides/CTX-METADATA-SAFETY.md for the rationale. The wire-strip
protects buyer responses but does NOT protect server-side log lines,
error envelopes, or adopter-generated strings (e.g. JSON.stringify(account)
in an error message). Re-derive the bearer from ctx.authInfo per
request inside specialism methods instead.
Adopters MAY omit authInfo from the returned Account — the framework
auto-attaches the principal from ctx.authInfo when absent (matches
Shape A/B/C semantics).
OptionallistMutually exclusive with toAccount — supply the roster options instead.
OptionallookupApplies to listAccounts rosters only.
Shape D options for a credential-bound singleton — one upstream account per credential (AudioStack, flashtalking, a single-namespace retail-media proxy).