Open

What we publish, and where

theAuth is MIT licensed and developed in public. This hub summarizes the documents that describe how it is maintained, versioned, released and threat-modeled, and links each summary to the full text on GitHub. Latest Go release: v2.7.0. TypeScript core: 0.5.0, pre-1.0.

Sources and review date

SourceLast reviewed 2026-10-06
Source
The documents named in each section below, in theauth-go and theauth.
Last reviewed
2026-10-06. Summaries on this page are written by hand and checked against the linked documents on that date. The documents themselves are the record.
Versions shown
Go v2.7.0 (released 2026-10-05), TypeScript core 0.5.0. Data as of 2026-10-06.

Six documents

Read the summary, then the source

Each page is a short, hand-written summary with a visible source link and review date. None of them replaces the document it points to.

Transparency hubSix pages
Roadmap
What the Go roadmap lists as shipped and in flight, and the fact that the TypeScript repository has no roadmap file.
API stability
Strict SemVer for the Go module, which packages are stable or experimental, and why TypeScript has no guarantee yet.
Threat model
Trust boundaries, scope, what the operator owns, and how the Go threat catalog is organized.
Governance
Who maintains the project, how decisions are made, and who to contact.
Releases
How Go and TypeScript releases are cut and verified. No release schedule is promised.
Compliance
SOC 2 control mapping and a GDPR reference. Reports, not certifications.

How to read these pages

Summaries, not copies

Values that change, such as the latest release and the review dates, come from one data file in this site and carry an as-of date. If a summary and a source document ever differ, the document wins.

  • Go libraryDocuments live under docs/ in theauth-go, plus CHANGELOG.md, GOVERNANCE.md and MAINTAINERS.md at the root.
  • TypeScripttheauth publishes governance, maintainers, support, security and changelog files at the root. It has no roadmap or threat model file.
  • DisclosureReporting a vulnerability is covered on the security page and in each repository's SECURITY.md. This hub does not repeat it.

What this hub does not claim

  • No certifications. There is no SOC 2, ISO or other certificate, and no third-party audit is published.
  • No release schedule. The release process is documented. A cadence is not promised.
  • No TypeScript stability guarantee. The core package is pre-1.0, so minor versions can break.

Get started

Give your first agent an identity.

Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.

  • npm install @glinr/theauth
  • go get github.com/glincker/theauth-go
Or skip hosting with theAuth Cloud