theAuth is the open-source auth library that treats AI agents as first-class identities: scoped permissions, delegation chains with depth limits, an MCP OAuth 2.1 server, and an audit trail for every action. Passkeys, SSO and 14 human sign-in methods are included.
One auth layer for the people and the programs acting for them.
01
Agent identity
kv_...mcp:github:*
Every agent gets its own cryptographic bearer token and a set of permissions, instead of borrowing a human session. Each action is checked against those permissions and written to the audit trail, so you can answer who did what, and on whose behalf.
Cryptographic bearer tokens (kv_...) per agent
Wildcard permission matching, such as mcp:github:*
Delegation chains with configurable depth limits
CIBA-style approval flows for sensitive tool calls
An OAuth 2.1 authorization server for your MCP servers, built to the MCP authorization spec. Clients discover it, register, and authorize with PKCE S256 without you hand-rolling the flow.
The sign-in side is covered too: 14 methods and 17 OAuth providers, plus organizations, SSO and SCIM. Every agent is created with an owner (ownerId), so a human is always accountable for what it does.
Go ships the OAuth 2.1 and MCP authorization server as a library, so it mounts into your existing router.
{ allowed: true, auditId: "aud_..." }
Standards
Built on the specs, not around them
MCP authorization
RFC 9728
RFC 8707
RFC 8414
RFC 7591
CIMD
OAuth 2.1
PKCE S256
Refresh rotation, family revocation
RFC 8693 token exchange
RFC 9449 DPoP
RFC 9126 PAR
RFC 9101 JAR
RFC 9509 CIBA
Identity
WebAuthn / FIDO2 passkeys
SAML 2.0
SCIM 2.0
OIDC
Supply chain
SLSA level 3 provenance
Sigstore-signed SBOM
MIT
Token exchange, DPoP, PAR, JAR, CIBA, CIMD and the SLSA and SBOM items apply to the Go library, where releases carry the provenance.
Compliance reports map to the EU AI Act, NIST, SOC 2 and ISO 42001. They are reports, not certifications.
SDKs and adapters
One auth model, three languages and a Terraform provider
TypeScript is the reference implementation. The Go and Python SDKs talk to the same concepts: agents, permissions, delegation and audit. Versions below are pre-1.0 where noted.
TypeScript packages
Core is at 0.5.0 and the other packages are 0.x, so expect API movement before 1.0. Core runs on Node, Bun, Deno and Cloudflare Workers.
@glinr/theauthCore: agents, auth, MCP server
npm i @glinr/theauth
@glinr/theauth-clientBrowser and Node client
npm i @glinr/theauth-client
@glinr/theauth-reactReact hooks and components
npm i @glinr/theauth-react
@glinr/theauth-vueVue bindings
npm i @glinr/theauth-vue
@glinr/theauth-svelteSvelte bindings
npm i @glinr/theauth-svelte
@glinr/theauth-expoExpo and React Native
npm i @glinr/theauth-expo
@glinr/theauth-electronElectron apps
npm i @glinr/theauth-electron
@glinr/theauth-cliCommand line tool
npm i @glinr/theauth-cli
@glinr/theauth-gatewayAPI gateway
npm i @glinr/theauth-gateway
@glinr/create-theauth-appProject scaffolder
npx @glinr/create-theauth-app
Framework adapters
Next.js
SvelteKit
Nuxt
Hono
Express
Fastify
Astro
NestJS
SolidStart
TanStack Start
Databases: SQLite, PostgreSQL, MySQL and Cloudflare D1 are built into core. A Prisma adapter shares an existing PrismaClient.
Requires Go 1.25 or newer. Storage backends are Postgres, MySQL and in-memory. Observability is OpenTelemetry and Prometheus, and audit events can go to webhook or Splunk HEC sinks.
go get github.com/glincker/theauth-go
StoragePostgres, MySQL, in-memory
Go version1.25+
mcpresourceZero-dependency module for MCP resource servers
Manage agents, permissions, API keys and organizations as Terraform resources, so every grant goes through code review. Not published to a registry yet: the README at 0.1.0 describes building from source and using a dev override.
What ships in the library today. Compliance items are reports mapped to frameworks, not certifications.
Organizations and RBAC
Teams, roles and member management.
SAML 2.0 and OIDC SSO
Connect corporate identity providers.
SCIM 2.0
Directory sync for users and groups.
Admin controls
Ban and impersonate users.
API key management
Scoped keys for server-to-server access.
Tenant tagging
Tag agents with a tenantId and filter by it. Your app enforces the boundary.
Audit log export
Webhook and Splunk HEC sinks in Go.
GDPR tooling
Export, delete and anonymize user data.
Compliance reports
EU AI Act, NIST, SOC 2 and ISO 42001 mappings. Reports, not certifications.
How it compares
Feature comparison of Auth0, Clerk, Better Auth and theAuth
Feature
Auth0
Clerk
Better Auth
theAuth
Source license
No, Proprietary
No, Proprietary
Yes, MIT
Yes, MIT
Self-hostable
Partial or different, Managed private cloud only
No, No
Yes, Yes
Yes, Yes
OAuth 2.1 server for MCP
Yes, Yes
Yes, Yes
Yes, Yes
Yes, Yes
Agent identity as its own model
Partial or different, Add-on: Token Vault, CIBA
Partial or different, Not found in docs
Partial or different, Plugin, not yet stable
Yes, Yes, core
Enterprise SSO
Yes, Yes
Yes, Yes
Partial or different, Plugin
Yes, SAML 2.0, OIDC, SCIM
Checked against each vendor's public docs on 2026-10-07. Vendors change fast, so verify against their docs. Full comparisons
FAQ
Questions developers ask first
Short answers, taken from the repositories. Anything not covered is in the docs or GitHub Discussions.
What is theAuth?
theAuth is an open-source auth library for AI agents and humans, built by GLINR STUDIOS, a GLINCKER LLC project. It handles human sign-in (passkeys, OAuth, SSO) and gives each AI agent its own identity, scoped permissions and audit trail. It also ships an MCP OAuth 2.1 authorization server. SDKs exist for TypeScript, Go and Python.
Is theAuth an Auth0 alternative for AI agents?
It can be, if you want agent identity and delegation chains in the same library as human auth, MIT licensed and self-hostable. Auth0 is a mature hosted product that now has its own MCP authorization and AI agent features, so compare both against your requirements. The Auth0 comparison lists what each covers, with sources.
How do I secure an MCP server with theAuth?
Run theAuth as the OAuth 2.1 authorization server for your MCP server. It supports PKCE S256 and the RFCs MCP clients expect: 9728 protected resource metadata, 8707 resource indicators, 8414 server metadata and 7591 dynamic client registration. Your MCP server then validates the issued tokens, and in Go the zero-dependency theauth-go/mcpresource module covers that resource-server role. The MCP guide walks through setup.
How are AI agents modeled differently from API keys?
An API key is a shared secret for a service. A theAuth agent is an identity with an owner, a cryptographic bearer token, wildcard permissions such as mcp:github:*, and delegation chains with configurable depth limits. Agents can also carry budget policies and a trust score, sensitive tool calls can require CIBA-style approval, and every action lands in a per-agent audit trail. API keys still exist for server-to-server access, managed separately.
Can I self-host it and where does it run?
Yes. theAuth is MIT licensed and runs against your own database: SQLite, PostgreSQL, MySQL or Cloudflare D1 in TypeScript, and Postgres, MySQL or in-memory storage in Go. The TypeScript core runs on Cloudflare Workers, Deno and Bun without code changes, with three runtime dependencies: drizzle-orm, jose and zod. A hosted Cloud version is in early access.
Which languages and frameworks are supported?
TypeScript has the broadest coverage: core, client, React, Vue, Svelte, Expo and Electron packages, plus adapters for Next.js, SvelteKit, Nuxt, Hono, Express, Fastify, Astro, NestJS, SolidStart and TanStack Start. Go has theauth-go (Go 1.25+). Python has a pip package (Python 3.9+, httpx client) at version 0.1.0. A Terraform provider exists in the repository and is built from source.
What is the license and who maintains it?
theAuth is MIT licensed. It is maintained by GLINR STUDIOS, a GLINCKER LLC project, in the open on GitHub. Compliance reports map to the EU AI Act, NIST, SOC 2 and ISO 42001, but they are reports, not certifications.
Was this KavachOS?
Yes. theAuth was formerly named KavachOS. The old Kavach names remain exported as deprecated aliases that point at the theAuth implementation, and the rename map lists every old and new name.
Get started
Give your first agent an identity.
Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.