| 🟠 reddit | theAuth: Auth for AI agents and humans. First-class agent identity, MCP OAuth 2.1, delegation, audit. TypeScript, edge-native, MIT. with Claude Code ClaudeAI Retrieved article excerptOpen article · Retrieved 2026-10-10T18:47:57.376551+00:00 [theAuth](https://camo.githubusercontent.com/3a09f0f982b019538470cad39ee4c0cd5f7a16f3cfc29dcd4610f4ee97703bb7/68747470733a2f2f746865617574682e6465762f6c6f676f2e737667)
# theAuth
**Open-source auth for AI agents and humans.**
Agent identity, delegation, MCP OAuth 2.1 server, DPoP, passkeys, device flow. A self-hostable Better Auth alternative for TypeScript.
[npm version](https://www.npmjs.com/package/@glinr/theauth)
[CI status](https://github.com/glincker/theauth/actions/workflows/ci.yml)
[License](https://github.com/glincker/theauth/blob/main/LICENSE)
[Discord](https://discord.gg/Ar5pcaZB99)
[Context7](https://context7.com/glincker/theauth)
[CodeQL](https://github.com/glincker/theauth/actions/workflows/codeql.yml)
[Code coverage](https://codecov.io/gh/glincker/theauth)
[**Website**](https://theauth.dev) ·
[**Quickstart**](https://docs.theauth.dev/quickstart) ·
[**Docs**](https://docs.theauth.dev) ·
[**Examples**](https://github.com/glincker/theauth/tree/main/examples) ·
[**Discussions**](https://github.com/glincker/theauth/discussions) ·
[**GLINR Discord**](https://discord.gg/Ar5pcaZB99)
[theAuth, open-source auth for AI agents and humans](https://theauth.dev)
---
## What it is
Most auth libraries stop at human sign-in. Once an AI agent needs its own identity, scoped permissions, delegation from a user, and an audit trail, you end up bolting a second system on. theAuth puts agents and humans in one library: sign-in methods, an OAuth 2.1 authorization server for MCP, and agent tokens with permissions you can check and audit.
It runs on Node, Bun, Deno and Cloudflare Workers with three runtime dependencies (`drizzle-orm`, `jose`, `zod`). MIT licensed. No hosted service required.
## 30 second quickstart
Runs as pasted with SQLite. Needs Node 20 or newer.
```
npm install @glinr/theauth
```
```
import { createTheAuth, users } from "@glinr/theauth";
const auth = await createTheAuth({ database: { provider: "sqlite", url: ":memory:" } });
// Agents need an owner row in theauth_users (human auth creates these for you).
auth.db.insert(users).values({
id: "user-123", email: "[email protected]", name: "Owner",
createdAt: new Date(), updatedAt: new Date(),
}).run();
const agent = await auth.agent.create({
ownerId: "user-123",
name: "github-reader",
type: "autonomous",
permissions: [{ resource: "mcp:github:*", actions: ["read"] }],
});
console.log(agent.token); // "kv_..." shown once
const { allowed } = await auth.authorize(agent.id, { action: "read", resource: "mcp:github:repos" });
console.log(allowed); // true
```
Agent tokens start with `kv_`. The prefix predates the rename from Kavach and stays so issued tokens keep working ([RENAME-MAP.md](https://github.com/glincker/theauth/blob/main/RENAME-MAP.md)).
To mount it over HTTP, pick an adapter such as `@glinr/theauth-hono` or `@glinr/theauth-nextjs` (framework snippets below). To add email and password, install `@glinr/theauth-email`. Full walkthrough: [docs.theauth.dev/quickstart](https://docs.theauth.dev/quickstart). Or scaffold an app: `npm create @glinr/theauth-app`.
## What is merged today
| Area | What you get | Docs |
| --- | --- | --- |
| Agent identity | `kv_` bearer tokens, wildcard permissions, delegation chains with depth limits, budget policies, denial-based trust score, CIBA-style approvals, audit trail per action | [Agents](https://docs.theauth.dev/agents) |
| MCP OAuth 2.1 server | Authorization code with PKCE S256, dynamic client registration, resource indicators, metadata (RFC 7591, 8707, 8414, 9728) | [MCP](https://docs.theauth.dev/mcp) |
| DPoP | Sender-constrained tokens for MCP resource servers | [DPoP](https://docs.theauth.dev/dpop) |
| Token vault | Encrypted third-party OAuth tokens for agents, refresh with a shared lock, key rotation | [Token vault](https://docs.theauth.dev/token-vault) |
| Human sign-in | Email and password (HIBP check), magic link, email OTP, phone OTP, passkeys, TOTP, anonymous, Google One Tap, SIWE, device flow, username, captcha | [Auth](https://docs.theauth.dev/auth) |
| Providers and presets | 17 first-class OAuth providers, a generic OIDC factory, and ready-made presets for more | [Providers](https://docs.theauth.dev/auth/more-providers) |
| Enterprise | Organizations with RBAC, SAML 2.0 and OIDC SSO, SCIM, admin controls, API keys, GDPR export and delete, compliance evidence export (not a certification) | [Docs](https://docs.theauth.dev) |
| CLI | `theauth doctor` checks your setup for common mistakes (`--json` for CI) | [CLI tools](https://docs.theauth.dev/cli-tools) |
The token policy, RFC 9396 rich authorization requests and ID-JAG pieces live in the Go SDK, not here. See [theauth-go](https://github.com/glincker/theauth-go).
17 providers: Apple, Atlassian, Discord, Dropbox, Figma, GitHub, GitLab, Google, LinkedIn, Microsoft, Notion, Reddit, Slack, Spotify, Twitch, Twitter/X, Zoom.
## Frameworks and adapters
Hono, Next.js, SvelteKit, Nuxt, Express, Fastify, Astro, NestJS, SolidStart, TanStack Start, plus clients for React, Vue, Svelte, Expo and Electron. Databases: SQLite, PostgreSQL, MySQL, Cloudflare D1, and Prisma through `@glinr/theauth-prisma`.
Next.js (App Router)
```
npm install @glinr/theauth @glinr/theauth-nextjs
```
```
// app/api/theauth/[...theauth]/route.ts
import { createTheAuth } from "@glinr/theauth";
import { theAuthNextjs } from "@glinr/theauth-nextjs";
const auth = await createTheAuth({
database: { provider: "postgres", url: process.env.DATABASE_URL! },
});
// `authenticate` resolves the caller from the request. See the adapter docs.
export const { GET, POST, PATCH, DELETE, OPTIONS } = theAuthNextjs(auth, { authenticate });
```
The adapter serves agent, authorization, delegation and audit routes under `/api/theauth`. Human sign-in is wired separately: see the docs for the methods you enable. Working example: [`examples/nextjs-app`](https://github.com/glincker/theauth/tree/main/examples/nextjs-app).
Hono (Workers, Bun, Node)
```
npm install @glinr/theauth @glinr/theauth-hono
```
```
import { Hono } from "hono";
import { createTheAuth } from "@glinr/theauth";
import { theAuthHono } from "@glinr/theauth-hono";
const auth = await createTheAuth({
database: { provider: "postgres", url: process.env.DATABASE_URL! },
});
const app = new Hono();
app.route("/api/theauth", theAuthHono(auth, { authenticate }));
export default app;
```
Examples: [`hono-server`](https://github.com/glincker/theauth/tree/main/examples/hono-server), [`cloudflare-workers`](https://github.com/glincker/theauth/tree/main/examples/cloudflare-workers).
Every adapter has the same shape. Per-framework docs: [docs.theauth.dev/adapters](https://docs.theauth.dev/adapters).
## How theAuth compares
Checked against each vendor's public docs on 2026-10-07. Vendors change fast, so verify against their docs. Write-ups with sources: [theauth.dev/compare](https://theauth.dev/compare/).
| Capability | Auth0 | Clerk | Better Auth | **theAuth** |
| --- | --- | --- | --- | --- |
| Source license | Proprietary | Proprietary | MIT | **MIT** |
| Self-hostable | Managed private cloud only | No | Yes | **Yes** |
| OAuth 2.1 server for MCP | Yes | Yes | Yes | **Yes** |
| Agent identity as its own model | Add-on: Token Vault, CIBA | Not found in docs | Plugin, not yet stable | **Yes, core** |
| Enterprise SSO | Yes | Yes | Plugin | **SAML 2.0, OIDC, SCIM** |
Where theAuth is the weaker choice: Better Auth has a larger community, more tutorials and a bigger plugin catalog. Auth0 and Clerk are managed products with hosted UIs and support contracts, which we do not match. Pick theAuth when agents are first-class users of your system and you want to run the whole thing yourself. Migration guides: [`migrate-from-auth0`](https://github.com/glincker/theauth/tree/main/examples/migrate-from-auth0), [`migrate-from-better-auth-agent-plugin`](https://github.com/glincker/theauth/tree/main/examples/migrate-from-better-auth-agent-plugin).
## Packages
All packages live in this monorepo and publish under `@glinr/`.
| Group | Packages |
| --- | --- |
| Core | [`theauth`](https://github.com/glincker/theauth/blob/main/packages/core), [`theauth-email`](https://github.com/glincker/theauth/blob/main/packages/auth/email), [`theauth-plugin-discovery`](https://github.com/glincker/theauth/blob/main/packages/plugins/discovery), [`theauth-plugin-telemetry`](https://github.com/glincker/theauth/blob/main/packages/plugins/telemetry) |
| Clients and UI | [`theauth-client`](https://github.com/glincker/theauth/blob/main/packages/client), [`theauth-react`](https://github.com/glincker/theauth/blob/main/packages/react), [`theauth-vue`](https://github.com/glincker/theauth/blob/main/packages/vue), [`theauth-svelte`](https://github.com/glincker/theauth/blob/main/packages/svelte), [`theauth-expo`](https://github.com/glincker/theauth/blob/main/packages/expo), [`theauth-electron`](https://github.com/glincker/theauth/blob/main/packages/electron), [`theauth-ui`](https://github.com/glincker/theauth/blob/main/packages/ui), [`theauth-ui-headless`](https://github.com/glincker/theauth/blob/main/packages/ui-headless), [`theauth-dashboard`](https://github.com/glincker/theauth/blob/main/packages/dashboard) |
| Framework adapters | [`theauth-hono`](https://github.com/glincker/theauth/blob/main/packages/adapters/hono), [`theauth-nextjs`](https://github.com/glincker/theauth/blob/main/packages/adapters/nextjs), [`theauth-nextjs-auth`](https://github.com/glincker/theauth/blob/main/packages/adapters/nextjs-auth), [`theauth-sveltekit`](https://github.com/glincker/theauth/blob/main/packages/adapters/sveltekit), [`theauth-nuxt`](https://github.com/glincker/theauth/blob/main/packages/adapters/nuxt), [`theauth-express`](https://github.com/glincker/theauth/blob/main/packages/adapters/express), [`theauth-fastify`](https://github.com/glincker/theauth/blob/main/packages/adapters/fastify), [`theauth-astro`](https://github.com/glincker/theauth/blob/main/packages/adapters/astro), [`theauth-nestjs`](https://github.com/glincker/theauth/blob/main/packages/adapters/nestjs), [`theauth-solidstart`](https://github.com/glincker/theauth/blob/main/packages/adapters/solidstart), [`theauth-tanstack`](https://github.com/glincker/theauth/blob/main/packages/adapters/tanstack) |
| Database | [`theauth-prisma`](https://github.com/glincker/theauth/blob/main/packages/adapters/prisma) |
| Tooling | [`create-theauth-app`](https://github.com/glincker/theauth/blob/main/packages/create-theauth-app), [`theauth-cli`](https://github.com/glincker/theauth/blob/main/packages/cli), [`theauth-gateway`](https://github.com/glincker/theauth/blob/main/packages/gateway), [`theauth-test-utils`](https://github.com/glincker/theauth/blob/main/packages/test-utils) |
| Other languages | [Go](https://github.com/glincker/theauth-go) ([pkg.go.dev](https://pkg.go.dev/github.com/glincker/theauth-go/v2)), [Python](https://pypi.org/project/theauth/) ([source](https://github.com/glincker/theauth/blob/main/sdks/python)), [Terraform provider](https://registry.terraform.io/providers/glincker/theauth) ([source](https://github.com/glincker/theauth/blob/main/sdks/terraform)) |
## Example apps
[`nextjs-app`](https://github.com/glincker/theauth/blob/main/examples/nextjs-app), [`nextjs-demo`](https://github.com/glincker/theauth/blob/main/examples/nextjs-demo), [`hono-server`](https://github.com/glincker/theauth/blob/main/examples/hono-server), [`cloudflare-workers`](https://github.com/glincker/theauth/blob/main/examples/cloudflare-workers), [`mcp-server`](https://github.com/glincker/theauth/blob/main/examples/mcp-server), [`scim-okta`](https://github.com/glincker/theauth/blob/main/examples/scim-okta), [`basic-agent`](https://github.com/glincker/theauth/blob/main/examples/basic-agent), [`migrate-from-auth0`](https://github.com/glincker/theauth/blob/main/examples/migrate-from-auth0), [`migrate-from-better-auth-agent-plugin`](https://github.com/glincker/theauth/blob/main/examples/migrate-f | Familiar-Classroom47 | 2 | 1 |