theAuthExpress(theauth, options?) returns an Express Router with all theAuth routes pre-mounted. Use app.use to attach it at your chosen path.
Install
Setup
1
Create the theauth instance
2
Mount the adapter
MCP endpoints
Passmcp to enable the MCP OAuth 2.1 authorization server. All MCP endpoints are registered on the same router alongside the REST API:
Management routes and client IP
With the default session guard, a signed-in user only acts on their own agents, delegations and audit rows. A customauthenticate resolver is a trust decision and sees everything.
The adapter does not read forwarded headers for the client IP. Behind a proxy, set trustedProxy with trustedProxyCount or trustedHeader, or ipAllowlist constraints cannot match.
trustedHeader: 'cf-connecting-ip'. Only trust a header your edge overwrites. Without trustedProxy the adapter uses req.ip, which is the socket peer unless your server framework is configured to trust the proxy.
Endpoint reference
Full example
Related
Adapters overview
Compare all available framework adapters and their mount patterns.
Fastify
High-performance alternative with async plugin architecture.
NestJS
Module-based setup for NestJS apps using Express under the hood.
MCP
OAuth 2.1 authorization server endpoints mounted by the adapter.