namespace PartnerBLL.Auth; public enum PartnerTokenResultStatus { Success, InvalidApiKey } public class PartnerTokenResult { public PartnerTokenResultStatus Status { get; set; } public string? AccessToken { get; set; } public DateTime? ExpiresOn { get; set; } } /// /// Issues short-lived M2M access tokens for a partner backend, exchanging its existing /// TPARTNERAPIKEY secret once for a signed JWT instead of presenting the raw secret on every /// call — closes the gap where Entitlement's public endpoints previously trusted a raw, /// unauthenticated PartnerProductId query parameter for anything beyond public read data. /// public interface IPartnerTokenBLL { Task IssueTokenAsync(string rawApiKey, CancellationToken ct); }