Open
What we publish, and where
theAuth is MIT licensed and developed in public. This hub summarizes the documents that describe how it is maintained, versioned, released and threat-modeled, and links each summary to the full text on GitHub. Latest Go release: v2.7.0. TypeScript core: 0.5.0, pre-1.0.
Sources and review date
- Source
- The documents named in each section below, in theauth-go and theauth.
- Last reviewed
- 2026-10-06. Summaries on this page are written by hand and checked against the linked documents on that date. The documents themselves are the record.
- Versions shown
- Go v2.7.0 (released 2026-10-05), TypeScript core 0.5.0. Data as of 2026-10-06.
Six documents
Read the summary, then the source
Each page is a short, hand-written summary with a visible source link and review date. None of them replaces the document it points to.
- Roadmap
- What the Go roadmap lists as shipped and in flight, and the fact that the TypeScript repository has no roadmap file.
- API stability
- Strict SemVer for the Go module, which packages are stable or experimental, and why TypeScript has no guarantee yet.
- Threat model
- Trust boundaries, scope, what the operator owns, and how the Go threat catalog is organized.
- Governance
- Who maintains the project, how decisions are made, and who to contact.
- Releases
- How Go and TypeScript releases are cut and verified. No release schedule is promised.
- Compliance
- SOC 2 control mapping and a GDPR reference. Reports, not certifications.
How to read these pages
Summaries, not copies
Values that change, such as the latest release and the review dates, come from one data file in this site and carry an as-of date. If a summary and a source document ever differ, the document wins.
- Go libraryDocuments live under docs/ in theauth-go, plus CHANGELOG.md, GOVERNANCE.md and MAINTAINERS.md at the root.
- TypeScripttheauth publishes governance, maintainers, support, security and changelog files at the root. It has no roadmap or threat model file.
- DisclosureReporting a vulnerability is covered on the security page and in each repository's SECURITY.md. This hub does not repeat it.
What this hub does not claim
- No certifications. There is no SOC 2, ISO or other certificate, and no third-party audit is published.
- No release schedule. The release process is documented. A cadence is not promised.
- No TypeScript stability guarantee. The core package is pre-1.0, so minor versions can break.
Related pages
Get started
Give your first agent an identity.
Install the package, create an agent with scoped permissions, and read its first audit record. The core runs on Postgres, SQLite, MySQL or D1, and the Go module needs a single go get.
npm install @glinr/theauthgo get github.com/glincker/theauth-go