---
title: "theAuth: open-source auth for AI agents and humans"
description: "Open-source auth for AI agents and humans: agent identity, delegation chains, MCP OAuth 2.1, passkeys and SSO for TypeScript, Go and Python. MIT licensed."
canonical: https://theauth.dev/
lastmod: 2026-10-10
---

[New: MCP OAuth 2.1 authorization server](https://docs.theauth.dev/mcp)

# Identity for humans, and the agents they send.

theAuth is the open-source auth library that treats AI agents as first-class identities: scoped permissions, delegation chains with depth limits, an MCP OAuth 2.1 server, and an audit trail for every action. Passkeys, SSO and 14 human sign-in methods are included.

[Read the quickstart](https://docs.theauth.dev/quickstart) [Star on GitHub](https://github.com/glincker/theauth)

`npm install @glinr/theauth`

`go get github.com/glincker/theauth-go/v2`

- MIT licensed
- 3 runtime deps
- 2.45M policy evals/sec, p99 625 ns
- Workers, Bun, Deno

Works where you ship

- TypeScript
- Go
- Python
- Next.js
- Hono
- Cloudflare Workers
- Bun
- Deno
- PostgreSQL
- Svelte
- Nuxt
- Express

What it is

## One auth layer for the people and the programs acting for them.

01

### Agent identity

kv_... mcp:github:*

Every agent gets its own cryptographic bearer token and a set of permissions, instead of borrowing a human session. Each action is checked against those permissions and written to the audit trail, so you can answer who did what, and on whose behalf.

- Cryptographic bearer tokens (kv_...) per agent
- Wildcard permission matching, such as mcp:github:*
- Delegation chains with configurable depth limits
- CIBA-style approval flows for sensitive tool calls

[Agent identity docs](https://docs.theauth.dev/agents)

02

### MCP OAuth 2.1

An MCP client starts with only the MCP server URL, discovers the authorization server from metadata, registers, and authorizes with PKCE S256. theAuth issues the token, and the MCP server validates its signature, audience, scope and expiry before it runs the tool.

An OAuth 2.1 authorization server for your MCP servers, built to the MCP authorization spec. Clients discover it, register, and authorize with PKCE S256 without you hand-rolling the flow.

- PKCE with S256 on every authorization code flow
- RFC 9728 and RFC 8414 metadata for discovery
- RFC 8707 resource indicators, RFC 7591 client registration
- Go: refresh token rotation with family revocation

[MCP docs](https://docs.theauth.dev/mcp)

03

### Human auth

People sign in with the methods you enable, such as passkeys, magic links, OAuth providers and TOTP two-factor codes. theAuth turns a successful sign-in into one session that your app reads.

The sign-in side is covered too: 14 methods and 17 OAuth providers, plus organizations, SSO and SCIM. Every agent is created with an owner (`ownerId`), so a human is always accountable for what it does.

- Passkeys (WebAuthn), TOTP 2FA, magic link, email OTP
- Email and password with HIBP breach check
- 17 OAuth providers plus a generic OIDC factory
- Organizations with RBAC, SAML 2.0 and OIDC SSO, SCIM 2.0

[Human auth docs](https://docs.theauth.dev/auth)

Agent lifecycle

## From first credential to instant revoke

Five moments in the life of one agent. Scroll to step through them, or use the list.

agent credentialactive

scopes

mcp:github:* [read]file:reports/* [read]

delegationmaxDepth 2

- plannermcp:github:* [read, comment]
- code-reviewermcp:github:pulls [read, comment]
- diff-fetchermcp:github:pulls [read]

Each hop can only narrow. A wider request is refused when the link is created.

approval neededpending

**github-reader** wants to delete file:prod-data/export.csv

Approve onceDeny

The agent waits. A denial or a timeout means no.

audit loggithub-reader

- allow read mcp:github:repos aud_71c2
- allow read mcp:github:pulls aud_71c3
- hold delete file:prod-data/* aud_71c4
- deny read mcp:slack:channels aud_71c5

agents1 revoked

**github-reader revoked**
authorize() => allowed: false

Links created downstream of this agent are revoked with it. It applies on the next call, not to work already run.

How it works

## How an agent call gets authorized

1

### Create the agent with scoped permissions

Give the agent an owner, a name and the resources and actions it may touch, such as read on mcp:github:*.

2

### Delegate to sub-agents with a depth limit

Agents can hand work to other agents through delegation chains, and the chain depth is capped by configuration.

3

### Authorize each action at the MCP server

Before a tool runs, ask the auth layer whether this agent may perform this action on this resource.

4

### Read the audit trail

Every decision is recorded per agent, so you can trace an action back to the agent and its owner. [Agents docs](https://docs.theauth.dev/agents)

agent.ts

```ts
const agent = await auth.agent.create({
  ownerId: "user-123",
  name: "github-reader",
  type: "autonomous",
  permissions: [{ resource: "mcp:github:*", actions: ["read"] }],
});

const result = await auth.authorize(agent.id, {
  action: "read",
  resource: "mcp:github:repos",
});
// { allowed: true, auditId: "aud_..." }
```

main.go

```go
a, _ := theauth.New(theauth.Config{
    Storage: memory.New(),
    BaseURL: "http://localhost:8080",
})
r := chi.NewRouter()
a.Mount(r) // /auth/* magic-link, email-password, OAuth, passkeys, TOTP, SAML
r.With(a.RequireAuth()).Get("/me", func(w http.ResponseWriter, r *http.Request) {
    user, _ := theauth.UserFromContext(r.Context())
    w.Write([]byte("hello " + user.Email))
})
http.ListenAndServe(":8080", r)
```

Go ships the OAuth 2.1 and MCP authorization server as a library, so it mounts into your existing router.

{ allowed: true, auditId: "aud_..." }

What travels with an agent

## Every call carries its limits

An agent identity is more than a key. Scope, spend, lifetime, trust and the key it is bound to are checked on every call, not once at login.

- read:calendar what it may touch
- $5.00 budget policy cap
- 15m credential lifetime
- 0.92 trust score from anomaly detection
- DPoP token bound to a client key (Go AS)
- 2/3 delegation depth used

Values are examples. Hover the hub to pause it.

Standards

## Built on the specs, not around them

### MCP authorization

- RFC 9728
- RFC 8707
- RFC 8414
- RFC 7591
- CIMD

### OAuth 2.1

- PKCE S256
- Refresh rotation, family revocation
- RFC 8693 token exchange
- RFC 9449 DPoP
- RFC 9126 PAR
- RFC 9101 JAR
- RFC 9509 CIBA

### Identity

- WebAuthn / FIDO2 passkeys
- SAML 2.0
- SCIM 2.0
- OIDC

### Supply chain

- SLSA level 3 provenance
- Sigstore-signed SBOM
- MIT

Token exchange, DPoP, PAR, JAR, CIBA, CIMD and the SLSA and SBOM items apply to the Go library, where releases carry the provenance. Row by row status for both libraries is on [the features index](https://theauth.dev/features/), and release and stability policy is under [open source and transparency](https://theauth.dev/open/).

2.45M

policy evaluations per second, warm cache, p99 625 ns

Reproducible: `pnpm bench` in `packages/core/bench`. [Method and full results](https://theauth.dev/benchmarks/)

Compliance reports map to the EU AI Act, NIST, SOC 2 and ISO 42001. They are reports, not certifications.

SDKs and adapters

## One auth model, three languages and a Terraform provider

TypeScript is the reference implementation. The Go and Python SDKs talk to the same concepts: agents, permissions, delegation and audit. Versions below are pre-1.0 where noted.

### TypeScript packages

Core is at 0.5.0 and the other packages are 0.x, so expect API movement before 1.0. Core runs on Node, Bun, Deno and Cloudflare Workers.

- @glinr/theauthCore: agents, auth, MCP server

  `npm i @glinr/theauth`
- @glinr/theauth-clientBrowser and Node client

  `npm i @glinr/theauth-client`
- @glinr/theauth-reactReact hooks and components

  `npm i @glinr/theauth-react`
- @glinr/theauth-vueVue bindings

  `npm i @glinr/theauth-vue`
- @glinr/theauth-svelteSvelte bindings

  `npm i @glinr/theauth-svelte`
- @glinr/theauth-expoExpo and React Native

  `npm i @glinr/theauth-expo`
- @glinr/theauth-electronElectron apps

  `npm i @glinr/theauth-electron`
- @glinr/theauth-cliCommand line tool

  `npm i @glinr/theauth-cli`
- @glinr/theauth-gatewayAPI gateway

  `npm i @glinr/theauth-gateway`
- @glinr/create-theauth-appProject scaffolder

  `npx @glinr/create-theauth-app`

#### Framework adapters

- Next.js
- SvelteKit
- Nuxt
- Hono
- Express
- Fastify
- Astro
- NestJS
- SolidStart
- TanStack Start

**Databases:** SQLite, PostgreSQL, MySQL and Cloudflare D1 are built into core. A Prisma adapter shares an existing PrismaClient.

[Adapter docs](https://docs.theauth.dev/adapters)

### Go: theauth-go

Requires Go 1.25 or newer. Storage backends are Postgres, MySQL and in-memory. Observability is OpenTelemetry and Prometheus, and audit events can go to webhook or Splunk HEC sinks.

`go get github.com/glincker/theauth-go/v2`

- StoragePostgres, MySQL, in-memory
- Go version1.25+
- mcpresourceZero-dependency module for MCP resource servers
- ReleasesSLSA level 3 provenance, Sigstore-signed SBOM

[Go docs](https://pkg.go.dev/github.com/glincker/theauth-go/v2) [pkg.go.dev](https://pkg.go.dev/github.com/glincker/theauth-go/v2) [GitHub](https://github.com/glincker/theauth-go)

### Python: theauth

An async-capable client built on httpx. Version 0.1.0, marked Beta, and not yet published to PyPI, so install it from the repository for now.

`pip install "git+https://github.com/glincker/theauth.git#subdirectory=sdks/python"`

- Python3.9+
- HTTPhttpx (the only runtime dependency)
- Version0.1.0, Beta
- LicenseMIT

[Source on GitHub](https://github.com/glincker/theauth/tree/main/sdks/python) [Quickstart](https://docs.theauth.dev/quickstart)

### Terraform provider

Manage agents, permissions, API keys and organizations as Terraform resources, so every grant goes through code review. **Not published to a registry yet:** the README at 0.1.0 describes building from source and using a dev override.

- Resourcestheauth_agent, theauth_permission, theauth_api_key, theauth_organization
- Data sourcestheauth_agent, theauth_agents
- RequiresTerraform 1.5+, Go 1.21+ to build, a running theAuth deployment
- Version0.1.0

[Source on GitHub](https://github.com/glincker/theauth) [Docs](https://docs.theauth.dev)

Self-host or Cloud

## Self-host it, or run it on our Cloud

The library is the product. Run it yourself under MIT, or let us host it. Cloud is in early access.

Self-hosted

### Your database, your infrastructure

- MIT licensed, so there is no license fee and no per-MAU charge from us.
- Runs against your own SQLite, PostgreSQL, MySQL or Cloudflare D1 database.
- Runs on Cloudflare Workers, Bun and Deno without code changes.
- Three runtime dependencies in the TypeScript core: drizzle-orm, jose and zod.
- You operate it: upgrades, backups and uptime are yours.

[Self-host quickstart](https://docs.theauth.dev/quickstart)

Cloud Early access

### Hosted theAuth

- Managed theAuth on Cloudflare Workers, so you skip running the server yourself.
- Dashboard for agents, API keys and audit logs.
- Same open-source library underneath, so you can move to self-hosting later.
- Early access: pricing is not published yet.

[Ask about early access](https://github.com/glincker/theauth/discussions)

### Enterprise capabilities

What ships in the library today. Compliance items are reports mapped to frameworks, not certifications.

### How it compares

Feature comparison of Auth0, Clerk, Better Auth and theAuth

| Feature | Auth0 | Clerk | Better Auth | theAuth |
| --- | --- | --- | --- | --- |
| Source license | No, Proprietary | No, Proprietary | Yes, MIT | Yes, MIT |
| Self-hostable | Partial or different, Managed private cloud only | No, No | Yes, Yes | Yes, Yes |
| OAuth 2.1 server for MCP | Yes, Yes | Yes, Yes | Yes, Yes | Yes, Yes |
| Agent identity as its own model | Partial or different, Add-on: Token Vault, CIBA | Partial or different, Not found in docs | Partial or different, Plugin, not yet stable | Yes, Yes, core |
| Enterprise SSO | Yes, Yes | Yes, Yes | Partial or different, Plugin | Yes, SAML 2.0, OIDC, SCIM |

Checked against each vendor's public docs on 2026-10-07. Vendors change fast, so verify against their docs. [Full comparisons](https://theauth.dev/compare/)

FAQ

## Questions developers ask first

Short answers, taken from the repositories. Anything not covered is in the [docs](https://docs.theauth.dev) or [GitHub Discussions](https://github.com/glincker/theauth/discussions).

**What is theAuth?**

theAuth is an open-source auth library for AI agents and humans, built by [GLINCKER](https://glincker.com), the open-source division of [GLINR STUDIOS](https://glinr.com). It handles human sign-in (passkeys, OAuth, SSO) and gives each AI agent its own identity, scoped permissions and audit trail. It also ships an MCP OAuth 2.1 authorization server. SDKs exist for TypeScript, Go and Python.

**Is theAuth an Auth0 alternative for AI agents?**

It can be, if you want agent identity and delegation chains in the same library as human auth, MIT licensed and self-hostable. Auth0 is a mature hosted product that now has its own MCP authorization and AI agent features, so compare both against your requirements. The [Auth0 comparison](https://theauth.dev/compare/auth0/) lists what each covers, with sources.

**How do I secure an MCP server with theAuth?**

Run theAuth as the OAuth 2.1 authorization server for your MCP server. It supports PKCE S256 and the RFCs MCP clients expect: 9728 protected resource metadata, 8707 resource indicators, 8414 server metadata and 7591 dynamic client registration. Your MCP server then validates the issued tokens, and in Go the zero-dependency [theauth-go/mcpresource](https://pkg.go.dev/github.com/glincker/theauth-go/v2) module covers that resource-server role. The [MCP guide](https://docs.theauth.dev/mcp) walks through setup.

**How are AI agents modeled differently from API keys?**

An API key is a shared secret for a service. A theAuth agent is an identity with an owner, a cryptographic bearer token, wildcard permissions such as mcp:github:*, and delegation chains with configurable depth limits. Agents can also carry budget policies and a trust score, sensitive tool calls can require CIBA-style approval, and every action lands in a per-agent audit trail. API keys still exist for server-to-server access, managed separately.

**Can I self-host it and where does it run?**

Yes. theAuth is MIT licensed and runs against your own database: SQLite, PostgreSQL, MySQL or Cloudflare D1 in TypeScript, and Postgres, MySQL or in-memory storage in Go. The TypeScript core runs on Cloudflare Workers, Deno and Bun without code changes, with three runtime dependencies: drizzle-orm, jose and zod. A hosted Cloud version is in early access.

**Which languages and frameworks are supported?**

TypeScript has the broadest coverage: core, client, React, Vue, Svelte, Expo and Electron packages, plus adapters for Next.js, SvelteKit, Nuxt, Hono, Express, Fastify, Astro, NestJS, SolidStart and TanStack Start. Go has [theauth-go](https://pkg.go.dev/github.com/glincker/theauth-go/v2) (Go 1.25+). Python has a pip package (Python 3.9+, httpx client) at version 0.1.0. A Terraform provider exists in the repository and is built from source.

**What is the license and who maintains it?**

theAuth is MIT licensed. It is maintained by [GLINCKER](https://glincker.com), the open-source division of [GLINR STUDIOS](https://glinr.com), in the open on [GitHub](https://github.com/glincker/theauth). Compliance reports map to the EU AI Act, NIST, SOC 2 and ISO 42001, but they are reports, not certifications.
