Human auth
Sign-in for the humans who own agents
Each method is a plugin you opt into. Use passkeys, OAuth, magic links or SSO for people, and keep agent identity separate.
- Methods
- 14
- OAuth providers
- 17
- Adapters
- 11
- Databases
- 4
Methods
All 14 methods
- 01Email and passwordTS: PBKDF2-SHA256, optional HIBP check
- 02Username and passwordHandles instead of email
- 03Magic linkSigned, single-use email link
- 04Email OTPSix-digit code by email
- 05Phone SMSCode through any SMS provider
- 06Passkey / WebAuthnTouch ID, Face ID, security keys
- 07TOTP 2FAAny RFC 6238 authenticator, backup codes
- 08AnonymousSessions without an account
- 09Google One TapGoogle sign-in prompt
- 10Sign In With EthereumEIP-4361 wallet sign-in
- 11Device authorizationFor TVs and CLIs
- 12CaptchaBot checks on auth endpoints
- 13Password resetToken-based reset flow
- 14Session freshnessRequire a recent sign-in for sensitive actions
OAuth
17 providers, plus generic OIDC
Every provider is configured the same way through the oauth() plugin. The ids below are the first-class providers in the source. Apple is the exception to the pattern: it needs a signed ES256 JWT client secret that you generate yourself and pass in.
- Appleapple
- Atlassianatlassian
- Discorddiscord
- Dropboxdropbox
- Figmafigma
- GitHubgithub
- GitLabgitlab
- Googlegoogle
- LinkedInlinkedin
- Microsoftmicrosoft
- Notionnotion
- Redditreddit
- Slackslack
- Spotifyspotify
- Twitchtwitch
- Twitter/Xtwitter
- Zoomzoom
- Any other OIDC providergenericOIDC()
Details
Passkeys, TOTP, SSO, organizations
- Passkeys. WebAuthn with Touch ID, Face ID, Windows Hello or hardware keys, through the passkey() plugin. Passkey docs.
- TOTP. The twoFactor() plugin adds QR enrollment, six-digit codes and backup codes. Two-factor docs.
- Magic link. Signed, single-use links with configurable expiry. Magic link docs.
- SSO basics. SAML 2.0 and OIDC connections, such as Okta or Azure AD, with just-in-time provisioning. SSO docs.
- Organizations. Create orgs, invite members, assign roles, cap membership. Organization docs.
- Passwords. TypeScript hashes with PBKDF2-SHA256. Go uses Argon2id.
import { createTheAuth } from "@glinr/theauth";
import { emailPassword, passkey } from "@glinr/theauth/auth";
const auth = await createTheAuth({
database: { provider: "postgres", url: process.env.DATABASE_URL },
plugins: [emailPassword(), passkey()],
});
Frameworks
Adapters
Core databases: SQLite, PostgreSQL, MySQL and Cloudflare D1. Client packages exist for React, Vue, Svelte, Expo and Electron.
- Next.js
@glinr/theauth-nextjs - SvelteKit
@glinr/theauth-sveltekit - Nuxt
@glinr/theauth-nuxt - Hono
@glinr/theauth-hono - Express
@glinr/theauth-express - Fastify
@glinr/theauth-fastify - Astro
@glinr/theauth-astro - NestJS
@glinr/theauth-nestjs - SolidStart
@glinr/theauth-solidstart - TanStack Start
@glinr/theauth-tanstack - Prisma
@glinr/theauth-prisma
Get started
Give your first agent an identity.
Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.
npm install @glinr/theauthgo get github.com/glincker/theauth-go