Skip to main content
theAuthSvelteKit(theauth, options?) returns named route handlers { GET, POST, PATCH, DELETE, OPTIONS }. Mount them in a catch-all server route file so all theAuth paths are handled.

Install

Setup

1

Create the theauth instance

2

Create the catch-all route

Create src/routes/api/theauth/[...path]/+server.ts. The [...path] segment catches every sub-path under /api/theauth/.
SvelteKit passes a standard Web API Request to route handlers, so the adapter delegates directly to the theAuth dispatcher without any conversion.

Options

MCP endpoints

When mcp is passed, the MCP OAuth 2.1 endpoints are available at:

Management routes and client IP

With the default session guard, a signed-in user only acts on their own agents, delegations and audit rows. A custom authenticate resolver is a trust decision and sees everything. The adapter does not read forwarded headers for the client IP. Behind a proxy, set trustedProxy with trustedProxyCount or trustedHeader, or ipAllowlist constraints cannot match.
On Cloudflare use trustedHeader: 'cf-connecting-ip'. Only trust a header your edge overwrites.

Endpoint reference

Full example

Adapters overview

Compare all available framework adapters and their mount patterns.

Next.js

App Router catch-all with MCP OAuth 2.1 support.

Hono

Lightweight edge-compatible adapter for Hono apps.

MCP

OAuth 2.1 authorization server endpoints mounted by the adapter.
Last modified on October 9, 2026