2026-10-11 16:38 UTC

glincker releases theAuth, an open-source TypeScript auth system with first-class agent identity, MCP OAuth 2.1 server, delegation, audit, and token vault — positioning it as a self-hostable reference for agent-first authentication.

state: seedheat: mediumuncertainty: mediumconvergesscott: highagent-identity mcp-oauth agent-authglincker

What is this?

theAuth is an open-source (MIT) TypeScript authentication library by GitHub user glincker that positions itself as a self-hostable reference implementation for agent-first authentication. It provides first-class agent identity as a core model (not an add-on), a full MCP OAuth 2.1 authorization server, delegation chains, audit logging, and a token vault — all edge-native. The project explicitly compares itself against Auth0, Clerk, Better Auth, and others on these agent-native capabilities. The snippets confirm the feature set and licensing; they do not reveal glincker's real-world identity or organizational backing beyond the GitHub handle.

Why it matters to Scott

theAuth is a concrete, MIT-licensed reference implementation that independently arrives at the exact agent-first auth architecture Scott's frameworks prescribe: first-class agent identity (Agent Addressability V4), MCP OAuth 2.1 server with delegation chains (Agent Provenance Stack's Identity→Intent→Artefact→Execution), capability-bound tokens (Capability Tokens), token vault with audit (agent-readable credential health), and self-hosted sovereign deployment (Sovereign Software Assurance). This is not merely an example of a pattern — it is a production-grade artifact that validates, extends, and could replace Scott's own Nango/OpenClaw auth layer, creating a dated-receipts publishing opportunity and a potential upstream dependency for LeverageAI client work.
ip:framework.agent-addressabilityip:framework.agent-provenance-stackip:concept.capability-tokensip:framework.sovereign-software-assurancedev:project.nangodev:project.openclawdev:concept.privacy-tokenized-agent-boundarydev:concept.agent-readable-credential-healthdev:technology.mcpradar:ac2-agent-security-protocolradar:aafp-commons-signed-agent-notebookradar:abyss-acp-agent-isolationradar:agentdrive-persistent-shared-storageradar:agentmeasure-token-accounting-audit
queries asked of Scott's wikis
  • agent identity as first-class primitive in auth systems
  • MCP OAuth 2.1 server implementations and agent delegation patterns
  • self-hosted open-source auth infrastructure for AI agents
  • token vault and delegation chain designs for agent-to-agent auth
  • edge-native TypeScript auth libraries Scott has evaluated or built

Measured heat

now 0 pts/hpeak 2 pts/hcomments 0/hpeers p33momentum: steady2 platformsage 4893h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

03-21 19:18⭐ origin echo-reconstructedThe origin is the project repository itself, not a report about it. Repo description: "Auth for AI agents and humans. First-class agent iden
GLINCKER (GDS K S, founder; GLINCKER LLC / GLINR STUDIOS) on github (echo) · attributed from reddit.post.1x2kuix
—
10-10 17:24first on r/ClaudeAI · published · +4870.1htheAuth: Auth for AI agents and humans. First-class agent identity, MCP OAuth 2.1, delegation, audit. TypeScript, edge-native, MIT. with Claude Code
Familiar-Classroom47
—
10-10 17:24amplified on r/ClaudeAI 👑reddit.post.1x2kuix
Familiar-Classroom47
peak 2 · 1 comments · 100% of case engagement
10-10 18:35our radar first saw it · +4871.3hdiscovery anchor: reddit.post.1x2kuix—

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟠 reddittheAuth: Auth for AI agents and humans. First-class agent identity, MCP OAuth 2.1, delegation, audit. TypeScript, edge-native, MIT. with Claude Code
ClaudeAI
Retrieved article excerpt

Open article · Retrieved 2026-10-10T18:47:57.376551+00:00

[theAuth](https://camo.githubusercontent.com/3a09f0f982b019538470cad39ee4c0cd5f7a16f3cfc29dcd4610f4ee97703bb7/68747470733a2f2f746865617574682e6465762f6c6f676f2e737667)

# theAuth

**Open-source auth for AI agents and humans.**  
Agent identity, delegation, MCP OAuth 2.1 server, DPoP, passkeys, device flow. A self-hostable Better Auth alternative for TypeScript.

[npm version](https://www.npmjs.com/package/@glinr/theauth)
[CI status](https://github.com/glincker/theauth/actions/workflows/ci.yml)
[License](https://github.com/glincker/theauth/blob/main/LICENSE)
[Discord](https://discord.gg/Ar5pcaZB99)
[Context7](https://context7.com/glincker/theauth)
[CodeQL](https://github.com/glincker/theauth/actions/workflows/codeql.yml)
[Code coverage](https://codecov.io/gh/glincker/theauth)

[**Website**](https://theauth.dev) ·
[**Quickstart**](https://docs.theauth.dev/quickstart) ·
[**Docs**](https://docs.theauth.dev) ·
[**Examples**](https://github.com/glincker/theauth/tree/main/examples) ·
[**Discussions**](https://github.com/glincker/theauth/discussions) ·
[**GLINR Discord**](https://discord.gg/Ar5pcaZB99)

[theAuth, open-source auth for AI agents and humans](https://theauth.dev)

---

## What it is

Most auth libraries stop at human sign-in. Once an AI agent needs its own identity, scoped permissions, delegation from a user, and an audit trail, you end up bolting a second system on. theAuth puts agents and humans in one library: sign-in methods, an OAuth 2.1 authorization server for MCP, and agent tokens with permissions you can check and audit.

It runs on Node, Bun, Deno and Cloudflare Workers with three runtime dependencies (`drizzle-orm`, `jose`, `zod`). MIT licensed. No hosted service required.

## 30 second quickstart

Runs as pasted with SQLite. Needs Node 20 or newer.

```
npm install @glinr/theauth
```

```
import { createTheAuth, users } from "@glinr/theauth";

const auth = await createTheAuth({ database: { provider: "sqlite", url: ":memory:" } });

// Agents need an owner row in theauth_users (human auth creates these for you).
auth.db.insert(users).values({
  id: "user-123", email: "[email protected]", name: "Owner",
  createdAt: new Date(), updatedAt: new Date(),
}).run();

const agent = await auth.agent.create({
  ownerId: "user-123",
  name: "github-reader",
  type: "autonomous",
  permissions: [{ resource: "mcp:github:*", actions: ["read"] }],
});
console.log(agent.token); // "kv_..." shown once

const { allowed } = await auth.authorize(agent.id, { action: "read", resource: "mcp:github:repos" });
console.log(allowed); // true
```

Agent tokens start with `kv_`. The prefix predates the rename from Kavach and stays so issued tokens keep working ([RENAME-MAP.md](https://github.com/glincker/theauth/blob/main/RENAME-MAP.md)).

To mount it over HTTP, pick an adapter such as `@glinr/theauth-hono` or `@glinr/theauth-nextjs` (framework snippets below). To add email and password, install `@glinr/theauth-email`. Full walkthrough: [docs.theauth.dev/quickstart](https://docs.theauth.dev/quickstart). Or scaffold an app: `npm create @glinr/theauth-app`.

## What is merged today

| Area | What you get | Docs |
| --- | --- | --- |
| Agent identity | `kv_` bearer tokens, wildcard permissions, delegation chains with depth limits, budget policies, denial-based trust score, CIBA-style approvals, audit trail per action | [Agents](https://docs.theauth.dev/agents) |
| MCP OAuth 2.1 server | Authorization code with PKCE S256, dynamic client registration, resource indicators, metadata (RFC 7591, 8707, 8414, 9728) | [MCP](https://docs.theauth.dev/mcp) |
| DPoP | Sender-constrained tokens for MCP resource servers | [DPoP](https://docs.theauth.dev/dpop) |
| Token vault | Encrypted third-party OAuth tokens for agents, refresh with a shared lock, key rotation | [Token vault](https://docs.theauth.dev/token-vault) |
| Human sign-in | Email and password (HIBP check), magic link, email OTP, phone OTP, passkeys, TOTP, anonymous, Google One Tap, SIWE, device flow, username, captcha | [Auth](https://docs.theauth.dev/auth) |
| Providers and presets | 17 first-class OAuth providers, a generic OIDC factory, and ready-made presets for more | [Providers](https://docs.theauth.dev/auth/more-providers) |
| Enterprise | Organizations with RBAC, SAML 2.0 and OIDC SSO, SCIM, admin controls, API keys, GDPR export and delete, compliance evidence export (not a certification) | [Docs](https://docs.theauth.dev) |
| CLI | `theauth doctor` checks your setup for common mistakes (`--json` for CI) | [CLI tools](https://docs.theauth.dev/cli-tools) |

The token policy, RFC 9396 rich authorization requests and ID-JAG pieces live in the Go SDK, not here. See [theauth-go](https://github.com/glincker/theauth-go).

17 providers: Apple, Atlassian, Discord, Dropbox, Figma, GitHub, GitLab, Google, LinkedIn, Microsoft, Notion, Reddit, Slack, Spotify, Twitch, Twitter/X, Zoom.

## Frameworks and adapters

Hono, Next.js, SvelteKit, Nuxt, Express, Fastify, Astro, NestJS, SolidStart, TanStack Start, plus clients for React, Vue, Svelte, Expo and Electron. Databases: SQLite, PostgreSQL, MySQL, Cloudflare D1, and Prisma through `@glinr/theauth-prisma`.

Next.js (App Router)

```
npm install @glinr/theauth @glinr/theauth-nextjs
```

```
// app/api/theauth/[...theauth]/route.ts
import { createTheAuth } from "@glinr/theauth";
import { theAuthNextjs } from "@glinr/theauth-nextjs";

const auth = await createTheAuth({
  database: { provider: "postgres", url: process.env.DATABASE_URL! },
});

// `authenticate` resolves the caller from the request. See the adapter docs.
export const { GET, POST, PATCH, DELETE, OPTIONS } = theAuthNextjs(auth, { authenticate });
```

The adapter serves agent, authorization, delegation and audit routes under `/api/theauth`. Human sign-in is wired separately: see the docs for the methods you enable. Working example: [`examples/nextjs-app`](https://github.com/glincker/theauth/tree/main/examples/nextjs-app).


Hono (Workers, Bun, Node)

```
npm install @glinr/theauth @glinr/theauth-hono
```

```
import { Hono } from "hono";
import { createTheAuth } from "@glinr/theauth";
import { theAuthHono } from "@glinr/theauth-hono";

const auth = await createTheAuth({
  database: { provider: "postgres", url: process.env.DATABASE_URL! },
});

const app = new Hono();
app.route("/api/theauth", theAuthHono(auth, { authenticate }));

export default app;
```

Examples: [`hono-server`](https://github.com/glincker/theauth/tree/main/examples/hono-server), [`cloudflare-workers`](https://github.com/glincker/theauth/tree/main/examples/cloudflare-workers).

Every adapter has the same shape. Per-framework docs: [docs.theauth.dev/adapters](https://docs.theauth.dev/adapters).

## How theAuth compares

Checked against each vendor's public docs on 2026-10-07. Vendors change fast, so verify against their docs. Write-ups with sources: [theauth.dev/compare](https://theauth.dev/compare/).

| Capability | Auth0 | Clerk | Better Auth | **theAuth** |
| --- | --- | --- | --- | --- |
| Source license | Proprietary | Proprietary | MIT | **MIT** |
| Self-hostable | Managed private cloud only | No | Yes | **Yes** |
| OAuth 2.1 server for MCP | Yes | Yes | Yes | **Yes** |
| Agent identity as its own model | Add-on: Token Vault, CIBA | Not found in docs | Plugin, not yet stable | **Yes, core** |
| Enterprise SSO | Yes | Yes | Plugin | **SAML 2.0, OIDC, SCIM** |

Where theAuth is the weaker choice: Better Auth has a larger community, more tutorials and a bigger plugin catalog. Auth0 and Clerk are managed products with hosted UIs and support contracts, which we do not match. Pick theAuth when agents are first-class users of your system and you want to run the whole thing yourself. Migration guides: [`migrate-from-auth0`](https://github.com/glincker/theauth/tree/main/examples/migrate-from-auth0), [`migrate-from-better-auth-agent-plugin`](https://github.com/glincker/theauth/tree/main/examples/migrate-from-better-auth-agent-plugin).

## Packages

All packages live in this monorepo and publish under `@glinr/`.

| Group | Packages |
| --- | --- |
| Core | [`theauth`](https://github.com/glincker/theauth/blob/main/packages/core), [`theauth-email`](https://github.com/glincker/theauth/blob/main/packages/auth/email), [`theauth-plugin-discovery`](https://github.com/glincker/theauth/blob/main/packages/plugins/discovery), [`theauth-plugin-telemetry`](https://github.com/glincker/theauth/blob/main/packages/plugins/telemetry) |
| Clients and UI | [`theauth-client`](https://github.com/glincker/theauth/blob/main/packages/client), [`theauth-react`](https://github.com/glincker/theauth/blob/main/packages/react), [`theauth-vue`](https://github.com/glincker/theauth/blob/main/packages/vue), [`theauth-svelte`](https://github.com/glincker/theauth/blob/main/packages/svelte), [`theauth-expo`](https://github.com/glincker/theauth/blob/main/packages/expo), [`theauth-electron`](https://github.com/glincker/theauth/blob/main/packages/electron), [`theauth-ui`](https://github.com/glincker/theauth/blob/main/packages/ui), [`theauth-ui-headless`](https://github.com/glincker/theauth/blob/main/packages/ui-headless), [`theauth-dashboard`](https://github.com/glincker/theauth/blob/main/packages/dashboard) |
| Framework adapters | [`theauth-hono`](https://github.com/glincker/theauth/blob/main/packages/adapters/hono), [`theauth-nextjs`](https://github.com/glincker/theauth/blob/main/packages/adapters/nextjs), [`theauth-nextjs-auth`](https://github.com/glincker/theauth/blob/main/packages/adapters/nextjs-auth), [`theauth-sveltekit`](https://github.com/glincker/theauth/blob/main/packages/adapters/sveltekit), [`theauth-nuxt`](https://github.com/glincker/theauth/blob/main/packages/adapters/nuxt), [`theauth-express`](https://github.com/glincker/theauth/blob/main/packages/adapters/express), [`theauth-fastify`](https://github.com/glincker/theauth/blob/main/packages/adapters/fastify), [`theauth-astro`](https://github.com/glincker/theauth/blob/main/packages/adapters/astro), [`theauth-nestjs`](https://github.com/glincker/theauth/blob/main/packages/adapters/nestjs), [`theauth-solidstart`](https://github.com/glincker/theauth/blob/main/packages/adapters/solidstart), [`theauth-tanstack`](https://github.com/glincker/theauth/blob/main/packages/adapters/tanstack) |
| Database | [`theauth-prisma`](https://github.com/glincker/theauth/blob/main/packages/adapters/prisma) |
| Tooling | [`create-theauth-app`](https://github.com/glincker/theauth/blob/main/packages/create-theauth-app), [`theauth-cli`](https://github.com/glincker/theauth/blob/main/packages/cli), [`theauth-gateway`](https://github.com/glincker/theauth/blob/main/packages/gateway), [`theauth-test-utils`](https://github.com/glincker/theauth/blob/main/packages/test-utils) |
| Other languages | [Go](https://github.com/glincker/theauth-go) ([pkg.go.dev](https://pkg.go.dev/github.com/glincker/theauth-go/v2)), [Python](https://pypi.org/project/theauth/) ([source](https://github.com/glincker/theauth/blob/main/sdks/python)), [Terraform provider](https://registry.terraform.io/providers/glincker/theauth) ([source](https://github.com/glincker/theauth/blob/main/sdks/terraform)) |

## Example apps

[`nextjs-app`](https://github.com/glincker/theauth/blob/main/examples/nextjs-app), [`nextjs-demo`](https://github.com/glincker/theauth/blob/main/examples/nextjs-demo), [`hono-server`](https://github.com/glincker/theauth/blob/main/examples/hono-server), [`cloudflare-workers`](https://github.com/glincker/theauth/blob/main/examples/cloudflare-workers), [`mcp-server`](https://github.com/glincker/theauth/blob/main/examples/mcp-server), [`scim-okta`](https://github.com/glincker/theauth/blob/main/examples/scim-okta), [`basic-agent`](https://github.com/glincker/theauth/blob/main/examples/basic-agent), [`migrate-from-auth0`](https://github.com/glincker/theauth/blob/main/examples/migrate-from-auth0), [`migrate-from-better-auth-agent-plugin`](https://github.com/glincker/theauth/blob/main/examples/migrate-f
Familiar-Classroom4721
🟧 echo.github ⭐The origin is the project repository itself, not a report about it. Repo description: "Auth for AI agents and humans. First-class agent idenGLINCKER (GDS K S, founder; GLINCKER LLC / GLINR STUDIOS)——

Interpretation history

Decision trace