go-dev-auth is an authentication library for Go with zero external
dependencies. One import, one config struct, one http.Handler, and your app has a complete auth system running on your own database. No hosted service to deploy, no vendor, no per-user pricing. You own the users,the sessions, and every line of code that touches them.
We built it because Go doesn't have what TypeScript has with
better-auth. The existing options are an auth service to deploy next to your app, OAuth-only libraries, or abandoned projects. So we built the missing one.
What's inside:
- Email and password, verification, reset, change-email
- Social sign-on: 11 providers built in, PKCE, custom providers in one declaration
- Sessions with signed cookies and list/revoke
- Passkeys (WebAuthn), CBOR parsing and signature verification in-package
- SSO (OIDC): each organization brings its own identity provider
- Two-factor, magic links, organizations, admin, API keys, JWT
- Postgres, MySQL, SQLite and in-memory adapters with migrations
Security claims are testable: a threat model where every claim maps to
a committed test, fuzzing and the race detector on every push, and the
storage suite runs against real databases in CI.
Pre-1.0, running in production ourselves. Tell us what's missing:
Repo: https://github.com/go-dev-auth/go-dev-auth
Docs: https://www.godevauth.com
Top comments (0)