Human auth

Sign-in for the humans who own agents

Each method is a plugin you opt into. Use passkeys, OAuth, magic links or SSO for people, and keep agent identity separate.

Methods
14
OAuth providers
17
Adapters
11
Databases
4

Methods

All 14 methods

  1. 01Email and passwordTS: PBKDF2-SHA256, optional HIBP check
  2. 02Username and passwordHandles instead of email
  3. 03Magic linkSigned, single-use email link
  4. 04Email OTPSix-digit code by email
  5. 05Phone SMSCode through any SMS provider
  6. 06Passkey / WebAuthnTouch ID, Face ID, security keys
  7. 07TOTP 2FAAny RFC 6238 authenticator, backup codes
  8. 08AnonymousSessions without an account
  9. 09Google One TapGoogle sign-in prompt
  10. 10Sign In With EthereumEIP-4361 wallet sign-in
  11. 11Device authorizationFor TVs and CLIs
  12. 12CaptchaBot checks on auth endpoints
  13. 13Password resetToken-based reset flow
  14. 14Session freshnessRequire a recent sign-in for sensitive actions

OAuth

17 providers, plus generic OIDC

Every provider is configured the same way through the oauth() plugin. The ids below are the first-class providers in the source. Apple is the exception to the pattern: it needs a signed ES256 JWT client secret that you generate yourself and pass in.

  • Appleapple
  • Atlassianatlassian
  • Discorddiscord
  • Dropboxdropbox
  • Figmafigma
  • GitHubgithub
  • GitLabgitlab
  • Googlegoogle
  • LinkedInlinkedin
  • Microsoftmicrosoft
  • Notionnotion
  • Redditreddit
  • Slackslack
  • Spotifyspotify
  • Twitchtwitch
  • Twitter/Xtwitter
  • Zoomzoom
  • Any other OIDC providergenericOIDC()

Details

Passkeys, TOTP, SSO, organizations

  • Passkeys. WebAuthn with Touch ID, Face ID, Windows Hello or hardware keys, through the passkey() plugin. Passkey docs.
  • TOTP. The twoFactor() plugin adds QR enrollment, six-digit codes and backup codes. Two-factor docs.
  • Magic link. Signed, single-use links with configurable expiry. Magic link docs.
  • SSO basics. SAML 2.0 and OIDC connections, such as Okta or Azure AD, with just-in-time provisioning. SSO docs.
  • Organizations. Create orgs, invite members, assign roles, cap membership. Organization docs.
  • Passwords. TypeScript hashes with PBKDF2-SHA256. Go uses Argon2id.
People sign in with the methods you enable, such as passkeys, magic links, OAuth providers and TOTP two-factor codes. theAuth turns a successful sign-in into one session that your app reads.
auth.ts
import { createTheAuth } from "@glinr/theauth";
import { emailPassword, passkey } from "@glinr/theauth/auth";

const auth = await createTheAuth({
  database: { provider: "postgres", url: process.env.DATABASE_URL },
  plugins: [emailPassword(), passkey()],
});

Frameworks

Adapters

Core databases: SQLite, PostgreSQL, MySQL and Cloudflare D1. Client packages exist for React, Vue, Svelte, Expo and Electron.

  • Next.js @glinr/theauth-nextjs
  • SvelteKit @glinr/theauth-sveltekit
  • Nuxt @glinr/theauth-nuxt
  • Hono @glinr/theauth-hono
  • Express @glinr/theauth-express
  • Fastify @glinr/theauth-fastify
  • Astro @glinr/theauth-astro
  • NestJS @glinr/theauth-nestjs
  • SolidStart @glinr/theauth-solidstart
  • TanStack Start @glinr/theauth-tanstack
  • Prisma @glinr/theauth-prisma

Get started

Give your first agent an identity.

Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.

  • npm install @glinr/theauth
  • go get github.com/glincker/theauth-go
Or skip hosting with theAuth Cloud