DEV Community

Cover image for go-dev-auth: own your authentication in Go
Bisrat Melak
Bisrat Melak

Posted on

go-dev-auth: own your authentication in Go

go-dev-auth is an authentication library for Go with zero external
dependencies. One import, one config struct, one http.Handler, and your app has a complete auth system running on your own database. No hosted service to deploy, no vendor, no per-user pricing. You own the users,the sessions, and every line of code that touches them.

We built it because Go doesn't have what TypeScript has with
better-auth. The existing options are an auth service to deploy next to your app, OAuth-only libraries, or abandoned projects. So we built the missing one.

What's inside:

  • Email and password, verification, reset, change-email
  • Social sign-on: 11 providers built in, PKCE, custom providers in one declaration
  • Sessions with signed cookies and list/revoke
  • Passkeys (WebAuthn), CBOR parsing and signature verification in-package
  • SSO (OIDC): each organization brings its own identity provider
  • Two-factor, magic links, organizations, admin, API keys, JWT
  • Postgres, MySQL, SQLite and in-memory adapters with migrations

Security claims are testable: a threat model where every claim maps to
a committed test, fuzzing and the race detector on every push, and the
storage suite runs against real databases in CI.

Pre-1.0, running in production ourselves. Tell us what's missing:

Repo: https://github.com/go-dev-auth/go-dev-auth
Docs: https://www.godevauth.com

Top comments (0)