Skip to main content
theAuthExpress(theauth, options?) returns an Express Router with all theAuth routes pre-mounted. Use app.use to attach it at your chosen path.

Install

Setup

1

Create the theauth instance

2

Mount the adapter

Call express.json() and express.urlencoded() before mounting the adapter. The adapter reads req.body which requires those parsers to be in place.

MCP endpoints

Pass mcp to enable the MCP OAuth 2.1 authorization server. All MCP endpoints are registered on the same router alongside the REST API:

Management routes and client IP

With the default session guard, a signed-in user only acts on their own agents, delegations and audit rows. A custom authenticate resolver is a trust decision and sees everything. The adapter does not read forwarded headers for the client IP. Behind a proxy, set trustedProxy with trustedProxyCount or trustedHeader, or ipAllowlist constraints cannot match.
On Cloudflare use trustedHeader: 'cf-connecting-ip'. Only trust a header your edge overwrites. Without trustedProxy the adapter uses req.ip, which is the socket peer unless your server framework is configured to trust the proxy.

Endpoint reference

Full example

Adapters overview

Compare all available framework adapters and their mount patterns.

Fastify

High-performance alternative with async plugin architecture.

NestJS

Module-based setup for NestJS apps using Express under the hood.

MCP

OAuth 2.1 authorization server endpoints mounted by the adapter.
Last modified on October 9, 2026