theAuthAstro(theauth, options?) returns named route handlers { GET, POST, PATCH, DELETE, OPTIONS, ALL }. Mount them in a catch-all API page so all theAuth paths are handled. Use individual named exports or the ALL catch-all handler.
Install
Setup
1
Create the theauth instance
2
Create the catch-all route
Create Or use the
src/pages/api/theauth/[...path].ts. The [...path] spread catches every sub-path under /api/theauth/.ALL handler to catch every HTTP method in one export:Options
MCP endpoints
Whenmcp is passed, the MCP OAuth 2.1 endpoints are available at:
Management routes and client IP
With the default session guard, a signed-in user only acts on their own agents, delegations and audit rows. A customauthenticate resolver is a trust decision and sees everything.
The adapter does not read forwarded headers for the client IP. Behind a proxy, set trustedProxy with trustedProxyCount or trustedHeader, or ipAllowlist constraints cannot match.
trustedHeader: 'cf-connecting-ip'. Only trust a header your edge overwrites.
Endpoint reference
Full example
Related
Adapters overview
Compare all available framework adapters and their mount patterns.
SvelteKit
Edge-compatible adapter using +server.ts catch-all routes.
Next.js
App Router catch-all handler with MCP OAuth 2.1 support.
MCP
OAuth 2.1 authorization server endpoints mounted by the adapter.