theAuthSvelteKit(theauth, options?) returns named route handlers { GET, POST, PATCH, DELETE, OPTIONS }. Mount them in a catch-all server route file so all theAuth paths are handled.
Install
Setup
1
Create the theauth instance
2
Create the catch-all route
Create
src/routes/api/theauth/[...path]/+server.ts. The [...path] segment catches every sub-path under /api/theauth/.SvelteKit passes a standard Web API
Request to route handlers, so the adapter delegates directly to the theAuth dispatcher without any conversion.Options
MCP endpoints
Whenmcp is passed, the MCP OAuth 2.1 endpoints are available at:
Management routes and client IP
With the default session guard, a signed-in user only acts on their own agents, delegations and audit rows. A customauthenticate resolver is a trust decision and sees everything.
The adapter does not read forwarded headers for the client IP. Behind a proxy, set trustedProxy with trustedProxyCount or trustedHeader, or ipAllowlist constraints cannot match.
trustedHeader: 'cf-connecting-ip'. Only trust a header your edge overwrites.
Endpoint reference
Full example
Related
Adapters overview
Compare all available framework adapters and their mount patterns.
Next.js
App Router catch-all with MCP OAuth 2.1 support.
Hono
Lightweight edge-compatible adapter for Hono apps.
MCP
OAuth 2.1 authorization server endpoints mounted by the adapter.