Features
What the TypeScript and Go libraries do today
One row per capability, a status for each library, and a link to the code. This is an index. The explainer pages go deeper. Last verified 2026-10-06 against the main branch of both repositories.
Reading the tables
How statuses work
Each cell shows an icon and a word, so the status never depends on color. The small source link in a cell goes to the code in that library.
- Stable
- Go only. The package or API is named in the stable lists of the Go stability policy, so it carries Semantic Versioning guarantees.
- Beta
- Shipped and working in the repository, with no stability promise. Every TypeScript row is beta: the core package is at version 0.5.0 and no TypeScript stability policy has been published, so we do not call any TypeScript surface stable. A Go row is beta when the policy marks it experimental or does not name it. Release process rows are not API surface, so the policy does not cover them and they show as beta.
- Planned
- Named in the Go roadmap or an open issue. We found no TypeScript roadmap or open issue to cite, so no TypeScript row is planned.
- Unverified
- We could not confirm it from code, so we claim nothing either way. The cell says what we looked for.
- Not available
- Not found in that library at the commit we checked.
How rows are counted. TypeScript has 17 OAuth providers: one source file per provider under core/src/auth/oauth/providers, not counting generic, index, presets and tests. Go has 12: one package per provider under provider/, not counting internal and oidc. Facebook and Bitbucket exist in TypeScript as presets over the generic provider, so those cells carry a note. The 11 framework adapters are every package in packages/adapters except prisma, a database adapter (12 packages in all). Go has 3 audit sinks.
Compliance rows list control mapping docs only. They map library features to framework controls and are reference documents, not an audit result.
Last verified 2026-10-06 at sdk commit 28635bf and go commit eb5c178. Counts are checked by npm run features:check.
Human sign-in
Ways a person proves who they are.
| Capability | What it does | TypeScript | Go | Read more |
|---|---|---|---|---|
| Email and password | Sign-up and sign-in with hashed passwords. | TypeScript: Betasource | Go: Stablesource | Human auth |
| Breach check on passwords | Rejects passwords found in the Have I Been Pwned range API. | TypeScript: Betasource | Go: Stablesource | Human auth |
| Magic link | Passwordless sign-in by emailed single-use link. | TypeScript: Betasource | Go: Stablesource | Human auth |
| Email one-time code | Sign-in by a one-time code sent to an email address. | TypeScript: Betasource | Go: Not available | Human auth |
| Phone and SMS code | Sign-in by a one-time code sent to a phone number. | TypeScript: Betasource | Go: Not available | Human auth |
| Passkeys (WebAuthn) | Register and sign in with discoverable passkeys. | TypeScript: Betasource | Go: Stablesource | Passkey docs |
| TOTP second factor | Authenticator app codes with recovery codes. | TypeScript: Betasource | Go: Stablesource | Two-factor docs |
| Session freshness and step-up | Require a recent sign-in before a sensitive action. | TypeScript: Betasource | Go: StableRequireRecentAuthsource | Sessions docs |
| Session list and revoke | Show a user their sessions and end any of them. | TypeScript: Betasource | Go: BetaOptional storage capability, listed as experimentalsource | Sessions docs |
| Password reset | Emailed single-use reset token with expiry. | TypeScript: Betasource | Go: Stablesource | Human auth |
| Username sign-in | Sign in with a username instead of an email address. | TypeScript: Betasource | Go: Not available | Human auth |
| Anonymous sessions | Create a session before the visitor has an identity. | TypeScript: Betasource | Go: Not available | Human auth |
| Captcha on auth routes | Verify a captcha token before sign-in and sign-up. | TypeScript: Betasource | Go: Not available | Human auth |
| Google One Tap | One Tap sign-in with a Google identity token. | TypeScript: Betasource | Go: Not available | Human auth |
| Sign In With Ethereum | Wallet sign-in using the SIWE message format. | TypeScript: Betasource | Go: Not available | Human auth |
| Device authorization (RFC 8628) | Sign in on a TV or CLI through a code entered on another device. | TypeScript: Betasource | Go: StableServer side of the device grantsource | CLI login guide |
| CLI login client helper | Go package that runs the device login from a command-line program. | TypeScript: Not available | Go: BetaExperimental packagesource | CLI login guide |
OAuth providers
Social and enterprise login providers.
| Capability | What it does | TypeScript | Go | Read more |
|---|---|---|---|---|
| Apple | Sign in with Apple. | TypeScript: Betasource | Go: Stablesource | Human auth |
| Discord | Sign in with Discord. | TypeScript: Betasource | Go: Stablesource | Human auth |
| GitHub | Sign in with GitHub. | TypeScript: Betasource | Go: Stablesource | Human auth |
| GitLab | Sign in with GitLab. | TypeScript: Betasource | Go: Stablesource | Human auth |
| Sign in with Google. | TypeScript: Betasource | Go: Stablesource | Human auth | |
| Sign in with LinkedIn. | TypeScript: Betasource | Go: Stablesource | Human auth | |
| Microsoft | Sign in with Microsoft. | TypeScript: Betasource | Go: Stablesource | Human auth |
| Slack | Sign in with Slack. | TypeScript: Betasource | Go: Stablesource | Human auth |
| Twitch | Sign in with Twitch. | TypeScript: Betasource | Go: Stablesource | Human auth |
| X (Twitter) | Sign in with X (Twitter). | TypeScript: Betasource | Go: StablePKCE requiredsource | Human auth |
| Atlassian | Sign in with Atlassian. | TypeScript: Betasource | Go: Not available | Human auth |
| Dropbox | Sign in with Dropbox. | TypeScript: Betasource | Go: Not available | Human auth |
| Figma | Sign in with Figma. | TypeScript: Betasource | Go: Not available | Human auth |
| Notion | Sign in with Notion. | TypeScript: Betasource | Go: Not available | Human auth |
| Sign in with Reddit. | TypeScript: Betasource | Go: Not available | Human auth | |
| Spotify | Sign in with Spotify. | TypeScript: Betasource | Go: Not available | Human auth |
| Zoom | Sign in with Zoom. | TypeScript: Betasource | Go: Not available | Human auth |
| Sign in with Facebook. | TypeScript: BetaPreset over the generic OAuth provider, not a dedicated provider modulesource | Go: Stablesource | Human auth | |
| Bitbucket | Sign in with Bitbucket. | TypeScript: BetaPreset over the generic OAuth provider, not a dedicated provider modulesource | Go: Stablesource | Human auth |
| Generic OIDC and OAuth 2.0 | Add any other OIDC or OAuth 2.0 provider from its discovery URL or endpoints. | TypeScript: Betasource | Go: BetaPackage not named in the stable listsource | Human auth |
Agent identity
Identity, authority and oversight for AI agents.
| Capability | What it does | TypeScript | Go | Read more |
|---|---|---|---|---|
| Agent identities | Create, suspend, rotate and revoke agents owned by a user. | TypeScript: Betasource | Go: StableAgent token minting and revocation helpers are experimentalsource | Agent identity |
| Delegation chains with depth limit | A user grants an agent authority, and agents can pass a narrower grant on. | TypeScript: Betasource | Go: Stablesource | Delegation docs |
| Policy engine | Evaluate resource and action permissions for an agent or user. | TypeScript: Betasource | Go: BetaExperimental packagesource | Policy engine docs |
| Budget policies | Cap an agent by spend or call volume. | TypeScript: Betasource | Go: Not available | Budget docs |
| Trust scoring and anomaly signals | Score an agent from age, volume and privilege escalation attempts. | TypeScript: Betasource | Go: Not available | Agent identity |
| Human approval for sensitive actions | Hold a tool call until a person approves it. | TypeScript: BetaCIBA style approval module, not the CIBA grantsource | Go: BetaCIBA backchannel grant, see the MCP tablesource | Approval docs |
| Agent to agent protocol (A2A) | Publish an agent card and call other agents. | TypeScript: Betasource | Go: Not available | A2A docs |
| Decentralized identifiers (DID) | did:key and did:web identifiers for agents, with signing. | TypeScript: Betasource | Go: Not available | DID docs |
| Verifiable credentials | Issue and verify credentials, including audit exports as credentials. | TypeScript: Betasource | Go: Not available | Compliance docs |
MCP and OAuth server
The authorization server and resource server pieces that MCP clients rely on.
| Capability | What it does | TypeScript | Go | Read more |
|---|---|---|---|---|
| OAuth 2.1 authorization server | Authorization code with PKCE S256 for MCP clients. | TypeScript: Betasource | Go: Stablesource | MCP OAuth 2.1 |
| Server metadata (RFC 8414, RFC 9728) | Authorization server and protected resource discovery documents. | TypeScript: Betasource | Go: Stablesource | MCP OAuth 2.1 |
| Dynamic client registration (RFC 7591) | Clients register themselves at a registration endpoint. | TypeScript: Betasource | Go: Stablesource | MCP OAuth 2.1 |
| Resource indicators (RFC 8707) | Bind a token to the resource it was requested for. | TypeScript: Betasource | Go: Stablesource | MCP OAuth 2.1 |
| Refresh token rotation and reuse detection | Each refresh issues a new token and a replayed one revokes the family. | TypeScript: Betasource | Go: Stablesource | MCP OAuth 2.1 |
| Resource server token validation | Validate access tokens inside an MCP server. | TypeScript: Betasource | Go: StableSeparate zero dependency modulesource | MCP OAuth 2.1 |
| Client credentials grant | Machine to machine tokens for a registered client. | TypeScript: Not availableThe MCP token endpoint handles the authorization code and refresh token grants | Go: Stablesource | MCP OAuth 2.1 |
| Token exchange (RFC 8693) | Swap one token for another, used for delegation. | TypeScript: UnverifiedOnly RFC 8693 actor claims found, no exchange endpoint | Go: Stablesource | MCP OAuth 2.1 |
| Client ID metadata documents (CIMD) | Use an HTTPS URL as a client identifier, per the MCP specification. | TypeScript: Not availableNo CIMD code found in the TypeScript core | Go: BetaOptions such as CIMDConfig.DenyHost are experimentalsource | MCP OAuth 2.1 |
| DPoP (RFC 9449) | Sender constrained access tokens. | TypeScript: UnverifiedNo implementation found in core | Go: BetaNot named in the stable listsource | MCP OAuth 2.1 |
| Pushed authorization requests (RFC 9126) | Send authorization parameters to the server before the redirect. | TypeScript: UnverifiedNo implementation found in core | Go: BetaNot named in the stable listsource | PAR and JAR guide |
| JWT secured authorization requests (RFC 9101) | Signed request objects for authorization requests. | TypeScript: UnverifiedNo implementation found in core | Go: BetaNot named in the stable listsource | PAR and JAR guide |
| CIBA backchannel authentication | Start a sign-in on a user's own device and poll for the result. | TypeScript: UnverifiedAn approval module exists, no CIBA grant found | Go: BetaNot named in the stable listsource | MCP OAuth 2.1 |
Enterprise
Organizations, directory sync, audit and compliance documents.
| Capability | What it does | TypeScript | Go | Read more |
|---|---|---|---|---|
| Organizations and RBAC | Organizations, members, roles and permission checks. | TypeScript: Betasource | Go: Stablesource | Organizations docs |
| SAML 2.0 single sign-on | Federate sign-in with an enterprise identity provider. | TypeScript: Betasource | Go: Stablesource | SSO docs |
| OIDC single sign-on | Per organization OIDC connections. | TypeScript: Betasource | Go: UnverifiedNot checked in the Go code | SSO docs |
| SCIM 2.0 provisioning | Create, update and deactivate users from an identity provider. | TypeScript: Betasource | Go: Stablesource | SCIM docs |
| Admin controls | Ban a user and impersonate a user for support. | TypeScript: Betasource | Go: Not availableGo has an admin API and password reset, not ban or impersonate | Admin docs |
| API keys and scoped tokens | Long lived keys and scoped tokens with abilities. | TypeScript: Betasource | Go: Stablesource | Auth docs |
| Multi-tenant isolation | Tenants with their own settings and status. | TypeScript: Betasource | Go: BetaOpt-in TenancyConfig, not named in the stable listsource | Multi-tenant docs |
| Audit log | Every sign-in and agent action recorded with identity and result. | TypeScript: Betasource | Go: StableAppend-only by contractsource | Enterprise |
| Audit streaming to Splunk HEC | Forward audit events to Splunk over HTTP Event Collector. | TypeScript: Not availableNo sink code found in the TypeScript core | Go: Stablesource | Splunk guide |
| Audit streaming by signed webhook | POST CloudEvents with an HMAC-SHA256 signature. | TypeScript: Not availableNo audit sink code found in the TypeScript core | Go: Stablesource | Audit streaming guide |
| Audit streaming over OTLP | Send audit events as OpenTelemetry logs. | TypeScript: Not availableNo sink code found in the TypeScript core | Go: StableSeparate Go modulesource | Audit streaming guide |
| Signed event webhooks | Deliver auth events to your endpoint with a signature. | TypeScript: Betasource | Go: Not availableGo streams audit events through sinks instead | Webhooks docs |
| GDPR export, delete and anonymize | Per user data export, erasure and anonymization. | TypeScript: Betasource | Go: Not availableGo ships a GDPR handling reference, no export or erase API found | GDPR docs |
| Control mapping docs: EU AI Act, NIST, ISO 42001 | Documents mapping library features to framework controls. Not a certification. | TypeScript: Betasource | Go: Not available | Compliance docs |
| Control mapping docs: SOC 2 | Documents mapping library features to SOC 2 criteria. Not a certification. | TypeScript: Betasource | Go: BetaPublished at docs.theauth.dev/go/securitysource | SOC 2 mapping |
Storage
Where users, sessions and audit events are kept.
| Capability | What it does | TypeScript | Go | Read more |
|---|---|---|---|---|
| PostgreSQL | Production database backend. | TypeScript: Betasource | Go: Stablesource | Adapters docs |
| MySQL | MySQL 8 backend. | TypeScript: Betasource | Go: BetaPackage not named in the stable listsource | Adapters docs |
| SQLite | Single file or embedded database. | TypeScript: Betasource | Go: BetaExperimental module, no organizations, SAML, SCIM or RBACsource | Adapters docs |
| Cloudflare D1 | D1 binding for Workers. | TypeScript: Betasource | Go: Not available | Adapters docs |
| Prisma adapter | Use a PrismaClient as the database. | TypeScript: Betasource | Go: Not available | Adapters docs |
| In-memory store | Process local storage for tests and demos. | TypeScript: UnverifiedNot checked, the SQLite provider can run in memory | Go: Stablesource | Capability interfaces |
| Storage contract test suite | Public tests to verify a custom storage backend. | TypeScript: Not availableNo equivalent suite found | Go: BetaNot named in the stable listsource | Capability interfaces |
| Storage contract gate in CI for Postgres and MySQL | Turn the older shared contract tests on by default for both adapters. | TypeScript: Not available | Go: PlannedListed under stability hardeningsource | Capability interfaces |
Frameworks and clients
Server adapters, client libraries and tools.
| Capability | What it does | TypeScript | Go | Read more |
|---|---|---|---|---|
| Next.js | Next.js App Router adapter exposing auth as HTTP REST endpoints. | TypeScript: Betasource | Go: Not availableGo mounts on any net/http router instead | Adapters docs |
| Next.js with an external backend | Next.js adapter for an external auth backend: cookies, refresh, CSRF, getServerSession and middleware. | TypeScript: Betasource | Go: Not availableGo mounts on any net/http router instead | Adapters docs |
| SvelteKit | SvelteKit adapter exposing auth as HTTP REST endpoints. | TypeScript: Betasource | Go: Not availableGo mounts on any net/http router instead | Adapters docs |
| Nuxt | Nuxt adapter exposing auth as HTTP REST endpoints through H3. | TypeScript: Betasource | Go: Not availableGo mounts on any net/http router instead | Adapters docs |
| Hono | Hono adapter exposing auth as HTTP REST endpoints. | TypeScript: Betasource | Go: Not availableGo mounts on any net/http router instead | Adapters docs |
| Express | Express adapter exposing auth as HTTP REST endpoints. | TypeScript: Betasource | Go: Not availableGo mounts on any net/http router instead | Adapters docs |
| Fastify | Fastify adapter exposing auth as HTTP REST endpoints. | TypeScript: Betasource | Go: Not availableGo mounts on any net/http router instead | Adapters docs |
| Astro | Astro adapter exposing auth as HTTP REST endpoints. | TypeScript: Betasource | Go: Not availableGo mounts on any net/http router instead | Adapters docs |
| NestJS | NestJS adapter. | TypeScript: Betasource | Go: Not availableGo mounts on any net/http router instead | Adapters docs |
| SolidStart | SolidStart adapter. | TypeScript: Betasource | Go: Not availableGo mounts on any net/http router instead | Adapters docs |
| TanStack Start | TanStack Start adapter. | TypeScript: Betasource | Go: Not availableGo mounts on any net/http router instead | Adapters docs |
| net/http handler | Mount the auth routes on net/http, chi, gin or echo. | TypeScript: Not availableTypeScript uses the framework adapters above | Go: StableHandler and Mountsource | Go docs |
| Browser client | TypeScript client for the REST API. | TypeScript: Betasource | Go: Not available | Quickstart |
| React | React hooks, with session rotation. | TypeScript: Betasource | Go: Not available | Quickstart |
| Vue | Vue 3 composables. | TypeScript: Betasource | Go: Not available | Quickstart |
| Svelte | Svelte stores. | TypeScript: Betasource | Go: Not available | Quickstart |
| Expo | React Native and Expo client. | TypeScript: Betasource | Go: Not available | Quickstart |
| Electron | Auth client for Electron desktop apps. | TypeScript: Betasource | Go: Not available | Quickstart |
| Dashboard | React admin UI for agents, permissions and audit logs. | TypeScript: Betasource | Go: Not available | Quickstart |
| Gateway proxy | Standalone proxy that enforces auth, authorization and audit in front of an API or MCP server. | TypeScript: Betasource | Go: Not available | MCP docs |
| Command line tools | TypeScript setup wizard and dev tools. Go ships theauth-doctor and theauth-migrate. | TypeScript: Betasource | Go: BetaDoctor is listed as experimentalsource | Quickstart |
| Selective re-exports for deep customization | Export chosen internal symbols so integrators can extend more. | TypeScript: Not available | Go: PlannedOpen issue 79, also on the roadmapsource | Go docs |
Observability and supply chain
What you can monitor, and what you can verify about a release.
| Capability | What it does | TypeScript | Go | Read more |
|---|---|---|---|---|
| OpenTelemetry spans | Trace auth operations. | TypeScript: BetaSpan shapes handed to your callback, no OpenTelemetry dependencysource | Go: BetaNot named in the stable listsource | Tracing guide |
| Prometheus metrics | Counters and hooks for a metrics endpoint. | TypeScript: Not availableNo Prometheus code found | Go: BetaHooks plus an example, not named in the stable listsource | Metrics reference |
| Reproducible benchmarks | Benchmarks you can rerun on your own machine. | TypeScript: Betasource | Go: BetaGates releases against regressionssource | Benchmarks |
| Signed release artifacts (Sigstore) | Release files signed with keyless cosign. | TypeScript: Not availableNo signing step found in the release workflow | Go: Betasource | Releases and verification |
| SBOM for releases | A software bill of materials generated with syft. | TypeScript: Not availableNo SBOM step found in the release workflow | Go: Betasource | Releases and verification |
| SLSA provenance attestation | Build provenance for release artifacts. | TypeScript: Not availableNo attestation step found in the release workflow | Go: Betasource | Releases and verification |
| npm provenance | Packages published with npm provenance. | TypeScript: Betasource | Go: Not availableNot applicable, Go modules are not published to npm | Security |
Get started
Give your first agent an identity.
Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.
npm install @glinr/theauthgo get github.com/glincker/theauth-go