Features

What the TypeScript and Go libraries do today

One row per capability, a status for each library, and a link to the code. This is an index. The explainer pages go deeper. Last verified 2026-10-06 against the main branch of both repositories.

Reading the tables

How statuses work

Each cell shows an icon and a word, so the status never depends on color. The small source link in a cell goes to the code in that library.

Stable
Go only. The package or API is named in the stable lists of the Go stability policy, so it carries Semantic Versioning guarantees.
Beta
Shipped and working in the repository, with no stability promise. Every TypeScript row is beta: the core package is at version 0.5.0 and no TypeScript stability policy has been published, so we do not call any TypeScript surface stable. A Go row is beta when the policy marks it experimental or does not name it. Release process rows are not API surface, so the policy does not cover them and they show as beta.
Planned
Named in the Go roadmap or an open issue. We found no TypeScript roadmap or open issue to cite, so no TypeScript row is planned.
Unverified
We could not confirm it from code, so we claim nothing either way. The cell says what we looked for.
Not available
Not found in that library at the commit we checked.

How rows are counted. TypeScript has 17 OAuth providers: one source file per provider under core/src/auth/oauth/providers, not counting generic, index, presets and tests. Go has 12: one package per provider under provider/, not counting internal and oidc. Facebook and Bitbucket exist in TypeScript as presets over the generic provider, so those cells carry a note. The 11 framework adapters are every package in packages/adapters except prisma, a database adapter (12 packages in all). Go has 3 audit sinks.

Compliance rows list control mapping docs only. They map library features to framework controls and are reference documents, not an audit result.

Last verified 2026-10-06 at sdk commit 28635bf and go commit eb5c178. Counts are checked by npm run features:check.

Human sign-in

Ways a person proves who they are.

Human sign-in: status in the TypeScript and Go libraries
CapabilityWhat it doesTypeScriptGoRead more
Email and passwordSign-up and sign-in with hashed passwords.TypeScript: BetasourceGo: StablesourceHuman auth
Breach check on passwordsRejects passwords found in the Have I Been Pwned range API.TypeScript: BetasourceGo: StablesourceHuman auth
Magic linkPasswordless sign-in by emailed single-use link.TypeScript: BetasourceGo: StablesourceHuman auth
Email one-time codeSign-in by a one-time code sent to an email address.TypeScript: BetasourceGo: Not availableHuman auth
Phone and SMS codeSign-in by a one-time code sent to a phone number.TypeScript: BetasourceGo: Not availableHuman auth
Passkeys (WebAuthn)Register and sign in with discoverable passkeys.TypeScript: BetasourceGo: StablesourcePasskey docs
TOTP second factorAuthenticator app codes with recovery codes.TypeScript: BetasourceGo: StablesourceTwo-factor docs
Session freshness and step-upRequire a recent sign-in before a sensitive action.TypeScript: BetasourceGo: StableRequireRecentAuthsourceSessions docs
Session list and revokeShow a user their sessions and end any of them.TypeScript: BetasourceGo: BetaOptional storage capability, listed as experimentalsourceSessions docs
Password resetEmailed single-use reset token with expiry.TypeScript: BetasourceGo: StablesourceHuman auth
Username sign-inSign in with a username instead of an email address.TypeScript: BetasourceGo: Not availableHuman auth
Anonymous sessionsCreate a session before the visitor has an identity.TypeScript: BetasourceGo: Not availableHuman auth
Captcha on auth routesVerify a captcha token before sign-in and sign-up.TypeScript: BetasourceGo: Not availableHuman auth
Google One TapOne Tap sign-in with a Google identity token.TypeScript: BetasourceGo: Not availableHuman auth
Sign In With EthereumWallet sign-in using the SIWE message format.TypeScript: BetasourceGo: Not availableHuman auth
Device authorization (RFC 8628)Sign in on a TV or CLI through a code entered on another device.TypeScript: BetasourceGo: StableServer side of the device grantsourceCLI login guide
CLI login client helperGo package that runs the device login from a command-line program.TypeScript: Not availableGo: BetaExperimental packagesourceCLI login guide

OAuth providers

Social and enterprise login providers.

OAuth providers: status in the TypeScript and Go libraries
CapabilityWhat it doesTypeScriptGoRead more
AppleSign in with Apple.TypeScript: BetasourceGo: StablesourceHuman auth
DiscordSign in with Discord.TypeScript: BetasourceGo: StablesourceHuman auth
GitHubSign in with GitHub.TypeScript: BetasourceGo: StablesourceHuman auth
GitLabSign in with GitLab.TypeScript: BetasourceGo: StablesourceHuman auth
GoogleSign in with Google.TypeScript: BetasourceGo: StablesourceHuman auth
LinkedInSign in with LinkedIn.TypeScript: BetasourceGo: StablesourceHuman auth
MicrosoftSign in with Microsoft.TypeScript: BetasourceGo: StablesourceHuman auth
SlackSign in with Slack.TypeScript: BetasourceGo: StablesourceHuman auth
TwitchSign in with Twitch.TypeScript: BetasourceGo: StablesourceHuman auth
X (Twitter)Sign in with X (Twitter).TypeScript: BetasourceGo: StablePKCE requiredsourceHuman auth
AtlassianSign in with Atlassian.TypeScript: BetasourceGo: Not availableHuman auth
DropboxSign in with Dropbox.TypeScript: BetasourceGo: Not availableHuman auth
FigmaSign in with Figma.TypeScript: BetasourceGo: Not availableHuman auth
NotionSign in with Notion.TypeScript: BetasourceGo: Not availableHuman auth
RedditSign in with Reddit.TypeScript: BetasourceGo: Not availableHuman auth
SpotifySign in with Spotify.TypeScript: BetasourceGo: Not availableHuman auth
ZoomSign in with Zoom.TypeScript: BetasourceGo: Not availableHuman auth
FacebookSign in with Facebook.TypeScript: BetaPreset over the generic OAuth provider, not a dedicated provider modulesourceGo: StablesourceHuman auth
BitbucketSign in with Bitbucket.TypeScript: BetaPreset over the generic OAuth provider, not a dedicated provider modulesourceGo: StablesourceHuman auth
Generic OIDC and OAuth 2.0Add any other OIDC or OAuth 2.0 provider from its discovery URL or endpoints.TypeScript: BetasourceGo: BetaPackage not named in the stable listsourceHuman auth

Agent identity

Identity, authority and oversight for AI agents.

Agent identity: status in the TypeScript and Go libraries
CapabilityWhat it doesTypeScriptGoRead more
Agent identitiesCreate, suspend, rotate and revoke agents owned by a user.TypeScript: BetasourceGo: StableAgent token minting and revocation helpers are experimentalsourceAgent identity
Delegation chains with depth limitA user grants an agent authority, and agents can pass a narrower grant on.TypeScript: BetasourceGo: StablesourceDelegation docs
Policy engineEvaluate resource and action permissions for an agent or user.TypeScript: BetasourceGo: BetaExperimental packagesourcePolicy engine docs
Budget policiesCap an agent by spend or call volume.TypeScript: BetasourceGo: Not availableBudget docs
Trust scoring and anomaly signalsScore an agent from age, volume and privilege escalation attempts.TypeScript: BetasourceGo: Not availableAgent identity
Human approval for sensitive actionsHold a tool call until a person approves it.TypeScript: BetaCIBA style approval module, not the CIBA grantsourceGo: BetaCIBA backchannel grant, see the MCP tablesourceApproval docs
Agent to agent protocol (A2A)Publish an agent card and call other agents.TypeScript: BetasourceGo: Not availableA2A docs
Decentralized identifiers (DID)did:key and did:web identifiers for agents, with signing.TypeScript: BetasourceGo: Not availableDID docs
Verifiable credentialsIssue and verify credentials, including audit exports as credentials.TypeScript: BetasourceGo: Not availableCompliance docs

MCP and OAuth server

The authorization server and resource server pieces that MCP clients rely on.

MCP and OAuth server: status in the TypeScript and Go libraries
CapabilityWhat it doesTypeScriptGoRead more
OAuth 2.1 authorization serverAuthorization code with PKCE S256 for MCP clients.TypeScript: BetasourceGo: StablesourceMCP OAuth 2.1
Server metadata (RFC 8414, RFC 9728)Authorization server and protected resource discovery documents.TypeScript: BetasourceGo: StablesourceMCP OAuth 2.1
Dynamic client registration (RFC 7591)Clients register themselves at a registration endpoint.TypeScript: BetasourceGo: StablesourceMCP OAuth 2.1
Resource indicators (RFC 8707)Bind a token to the resource it was requested for.TypeScript: BetasourceGo: StablesourceMCP OAuth 2.1
Refresh token rotation and reuse detectionEach refresh issues a new token and a replayed one revokes the family.TypeScript: BetasourceGo: StablesourceMCP OAuth 2.1
Resource server token validationValidate access tokens inside an MCP server.TypeScript: BetasourceGo: StableSeparate zero dependency modulesourceMCP OAuth 2.1
Client credentials grantMachine to machine tokens for a registered client.TypeScript: Not availableThe MCP token endpoint handles the authorization code and refresh token grantsGo: StablesourceMCP OAuth 2.1
Token exchange (RFC 8693)Swap one token for another, used for delegation.TypeScript: UnverifiedOnly RFC 8693 actor claims found, no exchange endpointGo: StablesourceMCP OAuth 2.1
Client ID metadata documents (CIMD)Use an HTTPS URL as a client identifier, per the MCP specification.TypeScript: Not availableNo CIMD code found in the TypeScript coreGo: BetaOptions such as CIMDConfig.DenyHost are experimentalsourceMCP OAuth 2.1
DPoP (RFC 9449)Sender constrained access tokens.TypeScript: UnverifiedNo implementation found in coreGo: BetaNot named in the stable listsourceMCP OAuth 2.1
Pushed authorization requests (RFC 9126)Send authorization parameters to the server before the redirect.TypeScript: UnverifiedNo implementation found in coreGo: BetaNot named in the stable listsourcePAR and JAR guide
JWT secured authorization requests (RFC 9101)Signed request objects for authorization requests.TypeScript: UnverifiedNo implementation found in coreGo: BetaNot named in the stable listsourcePAR and JAR guide
CIBA backchannel authenticationStart a sign-in on a user's own device and poll for the result.TypeScript: UnverifiedAn approval module exists, no CIBA grant foundGo: BetaNot named in the stable listsourceMCP OAuth 2.1

Enterprise

Organizations, directory sync, audit and compliance documents.

Enterprise: status in the TypeScript and Go libraries
CapabilityWhat it doesTypeScriptGoRead more
Organizations and RBACOrganizations, members, roles and permission checks.TypeScript: BetasourceGo: StablesourceOrganizations docs
SAML 2.0 single sign-onFederate sign-in with an enterprise identity provider.TypeScript: BetasourceGo: StablesourceSSO docs
OIDC single sign-onPer organization OIDC connections.TypeScript: BetasourceGo: UnverifiedNot checked in the Go codeSSO docs
SCIM 2.0 provisioningCreate, update and deactivate users from an identity provider.TypeScript: BetasourceGo: StablesourceSCIM docs
Admin controlsBan a user and impersonate a user for support.TypeScript: BetasourceGo: Not availableGo has an admin API and password reset, not ban or impersonateAdmin docs
API keys and scoped tokensLong lived keys and scoped tokens with abilities.TypeScript: BetasourceGo: StablesourceAuth docs
Multi-tenant isolationTenants with their own settings and status.TypeScript: BetasourceGo: BetaOpt-in TenancyConfig, not named in the stable listsourceMulti-tenant docs
Audit logEvery sign-in and agent action recorded with identity and result.TypeScript: BetasourceGo: StableAppend-only by contractsourceEnterprise
Audit streaming to Splunk HECForward audit events to Splunk over HTTP Event Collector.TypeScript: Not availableNo sink code found in the TypeScript coreGo: StablesourceSplunk guide
Audit streaming by signed webhookPOST CloudEvents with an HMAC-SHA256 signature.TypeScript: Not availableNo audit sink code found in the TypeScript coreGo: StablesourceAudit streaming guide
Audit streaming over OTLPSend audit events as OpenTelemetry logs.TypeScript: Not availableNo sink code found in the TypeScript coreGo: StableSeparate Go modulesourceAudit streaming guide
Signed event webhooksDeliver auth events to your endpoint with a signature.TypeScript: BetasourceGo: Not availableGo streams audit events through sinks insteadWebhooks docs
GDPR export, delete and anonymizePer user data export, erasure and anonymization.TypeScript: BetasourceGo: Not availableGo ships a GDPR handling reference, no export or erase API foundGDPR docs
Control mapping docs: EU AI Act, NIST, ISO 42001Documents mapping library features to framework controls. Not a certification.TypeScript: BetasourceGo: Not availableCompliance docs
Control mapping docs: SOC 2Documents mapping library features to SOC 2 criteria. Not a certification.TypeScript: BetasourceGo: BetaPublished at docs.theauth.dev/go/securitysourceSOC 2 mapping

Storage

Where users, sessions and audit events are kept.

Storage: status in the TypeScript and Go libraries
CapabilityWhat it doesTypeScriptGoRead more
PostgreSQLProduction database backend.TypeScript: BetasourceGo: StablesourceAdapters docs
MySQLMySQL 8 backend.TypeScript: BetasourceGo: BetaPackage not named in the stable listsourceAdapters docs
SQLiteSingle file or embedded database.TypeScript: BetasourceGo: BetaExperimental module, no organizations, SAML, SCIM or RBACsourceAdapters docs
Cloudflare D1D1 binding for Workers.TypeScript: BetasourceGo: Not availableAdapters docs
Prisma adapterUse a PrismaClient as the database.TypeScript: BetasourceGo: Not availableAdapters docs
In-memory storeProcess local storage for tests and demos.TypeScript: UnverifiedNot checked, the SQLite provider can run in memoryGo: StablesourceCapability interfaces
Storage contract test suitePublic tests to verify a custom storage backend.TypeScript: Not availableNo equivalent suite foundGo: BetaNot named in the stable listsourceCapability interfaces
Storage contract gate in CI for Postgres and MySQLTurn the older shared contract tests on by default for both adapters.TypeScript: Not availableGo: PlannedListed under stability hardeningsourceCapability interfaces

Frameworks and clients

Server adapters, client libraries and tools.

Frameworks and clients: status in the TypeScript and Go libraries
CapabilityWhat it doesTypeScriptGoRead more
Next.jsNext.js App Router adapter exposing auth as HTTP REST endpoints.TypeScript: BetasourceGo: Not availableGo mounts on any net/http router insteadAdapters docs
Next.js with an external backendNext.js adapter for an external auth backend: cookies, refresh, CSRF, getServerSession and middleware.TypeScript: BetasourceGo: Not availableGo mounts on any net/http router insteadAdapters docs
SvelteKitSvelteKit adapter exposing auth as HTTP REST endpoints.TypeScript: BetasourceGo: Not availableGo mounts on any net/http router insteadAdapters docs
NuxtNuxt adapter exposing auth as HTTP REST endpoints through H3.TypeScript: BetasourceGo: Not availableGo mounts on any net/http router insteadAdapters docs
HonoHono adapter exposing auth as HTTP REST endpoints.TypeScript: BetasourceGo: Not availableGo mounts on any net/http router insteadAdapters docs
ExpressExpress adapter exposing auth as HTTP REST endpoints.TypeScript: BetasourceGo: Not availableGo mounts on any net/http router insteadAdapters docs
FastifyFastify adapter exposing auth as HTTP REST endpoints.TypeScript: BetasourceGo: Not availableGo mounts on any net/http router insteadAdapters docs
AstroAstro adapter exposing auth as HTTP REST endpoints.TypeScript: BetasourceGo: Not availableGo mounts on any net/http router insteadAdapters docs
NestJSNestJS adapter.TypeScript: BetasourceGo: Not availableGo mounts on any net/http router insteadAdapters docs
SolidStartSolidStart adapter.TypeScript: BetasourceGo: Not availableGo mounts on any net/http router insteadAdapters docs
TanStack StartTanStack Start adapter.TypeScript: BetasourceGo: Not availableGo mounts on any net/http router insteadAdapters docs
net/http handlerMount the auth routes on net/http, chi, gin or echo.TypeScript: Not availableTypeScript uses the framework adapters aboveGo: StableHandler and MountsourceGo docs
Browser clientTypeScript client for the REST API.TypeScript: BetasourceGo: Not availableQuickstart
ReactReact hooks, with session rotation.TypeScript: BetasourceGo: Not availableQuickstart
VueVue 3 composables.TypeScript: BetasourceGo: Not availableQuickstart
SvelteSvelte stores.TypeScript: BetasourceGo: Not availableQuickstart
ExpoReact Native and Expo client.TypeScript: BetasourceGo: Not availableQuickstart
ElectronAuth client for Electron desktop apps.TypeScript: BetasourceGo: Not availableQuickstart
DashboardReact admin UI for agents, permissions and audit logs.TypeScript: BetasourceGo: Not availableQuickstart
Gateway proxyStandalone proxy that enforces auth, authorization and audit in front of an API or MCP server.TypeScript: BetasourceGo: Not availableMCP docs
Command line toolsTypeScript setup wizard and dev tools. Go ships theauth-doctor and theauth-migrate.TypeScript: BetasourceGo: BetaDoctor is listed as experimentalsourceQuickstart
Selective re-exports for deep customizationExport chosen internal symbols so integrators can extend more.TypeScript: Not availableGo: PlannedOpen issue 79, also on the roadmapsourceGo docs

Observability and supply chain

What you can monitor, and what you can verify about a release.

Observability and supply chain: status in the TypeScript and Go libraries
CapabilityWhat it doesTypeScriptGoRead more
OpenTelemetry spansTrace auth operations.TypeScript: BetaSpan shapes handed to your callback, no OpenTelemetry dependencysourceGo: BetaNot named in the stable listsourceTracing guide
Prometheus metricsCounters and hooks for a metrics endpoint.TypeScript: Not availableNo Prometheus code foundGo: BetaHooks plus an example, not named in the stable listsourceMetrics reference
Reproducible benchmarksBenchmarks you can rerun on your own machine.TypeScript: BetasourceGo: BetaGates releases against regressionssourceBenchmarks
Signed release artifacts (Sigstore)Release files signed with keyless cosign.TypeScript: Not availableNo signing step found in the release workflowGo: BetasourceReleases and verification
SBOM for releasesA software bill of materials generated with syft.TypeScript: Not availableNo SBOM step found in the release workflowGo: BetasourceReleases and verification
SLSA provenance attestationBuild provenance for release artifacts.TypeScript: Not availableNo attestation step found in the release workflowGo: BetasourceReleases and verification
npm provenancePackages published with npm provenance.TypeScript: BetasourceGo: Not availableNot applicable, Go modules are not published to npmSecurity

Get started

Give your first agent an identity.

Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.

  • npm install @glinr/theauth
  • go get github.com/glincker/theauth-go
Or skip hosting with theAuth Cloud