SkillAgentSearch skills...

theauth

Auth for AI agents and humans. First-class agent identity, MCP OAuth 2.1, delegation, audit. TypeScript, edge-native, MIT.

Install / Use

claude mcp add glincker -- npx -y github:glincker/theauth

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

84/100

Category

Security

Supported Platforms

Claude Code
Claude Desktop

Our assessment of theauth

theauth scores 84/100 on our quality scale, 724th of 1,000 Security skills we index.

Its MCP Server is 18 KB long, well organised into 34 sections with 13 code examples: a thorough specification that gives an agent plenty to work with.

It has 10 GitHub stars, so there is little community track record yet; judge it on its content.

Substance
30/30
Structure
20/20
Description
15/15
Adoption
4/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated today, so theauth is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 97/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.

Automated pattern scan on 2026-10-01. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

theauth compared with similar skills

All 4 of these similar skills score higher than theauth; compare them before choosing.

SkillScoreStarsUpdatedFormat
theauth (this skill)by glincker8410todayMCP Server
Agent-Reachby Panniantong10087.2k16d agoCLAUDE.md
headroomby headroomlabs-ai10074.2ktodayCLAUDE.md
rufloby ruvnet10073.6ktodayCLAUDE.md
CowAgentby zhayujie10047.2ktodayCLAUDE.md

Frequently asked questions

How do I install theauth?
Run claude mcp add glincker -- npx -y github:glincker/theauth. The install tabs above show the steps for each supported agent.
Which AI agents does theauth work with?
It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
Is theauth safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 97/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is theauth still maintained?
The repository was last updated today, so theauth is actively maintained.
<p align="center"> <img src="https://theauth.dev/logo.svg" height="64" alt="TheAuth" /> </p> <h2 align="center"><em>Type-safe authentication for TypeScript. OAuth 2.1, MCP, passkeys, agents.</em></h2> <p align="center"> by <a href="https://glincker.com"><strong>GLINR STUDIOS</strong></a> &middot; a <a href="https://glincker.com">GLINCKER LLC</a> project </p> <p align="center"> <a href="https://www.npmjs.com/package/@glinr/theauth"><img src="https://img.shields.io/npm/v/@glinr/theauth?style=flat&colorA=000000&colorB=000000&label=npm" alt="npm version" /></a> <a href="https://www.npmjs.com/package/@glinr/theauth"><img src="https://img.shields.io/npm/dm/@glinr/theauth?style=flat&colorA=000000&colorB=000000&label=downloads" alt="monthly downloads" /></a> <a href="https://github.com/glincker/theauth/blob/main/LICENSE"><img src="https://img.shields.io/github/license/glincker/theauth?style=flat&colorA=000000&colorB=000000&label=license" alt="License" /></a> <a href="https://github.com/glincker/theauth/actions/workflows/ci.yml"><img src="https://img.shields.io/github/actions/workflow/status/glincker/theauth/ci.yml?branch=main&style=flat&colorA=000000&colorB=000000&label=CI" alt="CI status" /></a> <a href="https://bundlephobia.com/package/@glinr/theauth"><img src="https://img.shields.io/bundlephobia/minzip/@glinr/theauth?style=flat&colorA=000000&colorB=000000&label=bundle" alt="bundle size" /></a> <a href="https://www.typescriptlang.org/"><img src="https://img.shields.io/badge/TypeScript-strict-blue?style=flat&colorA=000000&colorB=3178c6&logo=typescript&logoColor=white" alt="TypeScript strict" /></a> <a href="https://github.com/glincker/theauth/discussions"><img src="https://img.shields.io/github/discussions/glincker/theauth?style=flat&colorA=000000&colorB=000000&label=discussions" alt="GitHub Discussions" /></a> <a href="https://discord.gg/Ar5pcaZB99"><img src="https://img.shields.io/discord/829168897080557579?style=flat-square&logo=discord&logoColor=white&label=discord&color=5865F2" alt="Discord" /></a> </p> <p align="center"> <a href="https://docs.theauth.dev/docs/quickstart"><strong>Quickstart</strong></a> &middot; <a href="https://docs.theauth.dev/docs"><strong>Docs</strong></a> &middot; <a href="https://github.com/glincker/theauth/tree/main/examples"><strong>Examples</strong></a> &middot; <a href="https://github.com/glincker/theauth/discussions"><strong>Discussions</strong></a> &middot; <a href="https://app.theauth.dev"><strong>TheAuth Cloud</strong></a> </p> <p align="center"> <a href="https://theauth.dev"> <img src="https://theauth.dev/theauth-og-img.png" alt="TheAuth, auth OS for AI agents and humans" width="960" /> </a> </p>

Why TheAuth

Most auth libraries stop at human sign-in. That leaves you stitching together separate systems when your AI agents need identity, scoped permissions, delegation, and audit trails. TheAuth handles both in one place.

How it differs

Ask yourself about the auth library you're using or evaluating:

  • Does it model AI agents as first-class identities, with their own scoped permissions and an audit trail you can export, not just human users with API keys?
  • Does it ship an MCP OAuth 2.1 authorization server that complies with the published RFC stack (9728, 8707, 8414, 7591), so your agents can talk to MCP servers without you writing the spec?
  • Does it run on Cloudflare Workers, Bun, and Deno without Node-only APIs in the core?
  • Does it give you delegation chains with depth limits, budget policies per agent, and CIBA-style approval flows for sensitive tool calls?

If any of those is a no, that gap is why theauth exists.

Agent identity

Cryptographic bearer tokens (kv_...), wildcard permission matching, delegation chains with depth limits, budget policies, anomaly detection, and CIBA approval flows.

Human auth

14 methods: email/password, magic link, email OTP, phone SMS, passkey/WebAuthn, TOTP 2FA, anonymous, Google One-tap, Sign In With Ethereum, device authorization, username/password, captcha, password reset, session freshness.

OAuth

17 first-class providers: Apple, Atlassian, Discord, Dropbox, Figma, GitHub, GitLab, Google, LinkedIn, Microsoft, Notion, Reddit, Slack, Spotify, Twitch, Twitter/X, Zoom. Plus a generic OIDC factory for anything else.

MCP OAuth 2.1

Authorization server for the Model Context Protocol. PKCE S256, RFC 9728 / 8707 / 8414 / 7591.

Enterprise

Organizations with RBAC, SAML 2.0 and OIDC SSO, admin controls (ban/impersonate), API key management, SCIM directory sync, multi-tenant isolation, GDPR export/delete/anonymize, compliance reports for EU AI Act, NIST, SOC 2, ISO 42001.

Runs on the edge

Works on Cloudflare Workers, Deno, and Bun without code changes. Three runtime dependencies: drizzle-orm, jose, zod.

Security

Rate limiting per agent and per IP, HIBP password breach checking, CSRF protection, httpOnly secure cookies, email enumeration prevention, trusted device windows, signed expiring reset tokens, session freshness enforcement.

Performance

The policy engine hits 2.6M warm-cache evals/sec with a p99 of 500ns. Cold paths stay under 0.3ms p99 on direct permissions, RBAC role expansion, and ReBAC graph lookups. Numbers from pnpm bench on the policy-engine suite in packages/core/bench/, reproducible locally.


Install

npm install @glinr/theauth
# or
pnpm add @glinr/theauth
# or
yarn add @glinr/theauth
import { createTheAuth } from "@glinr/theauth";
import { emailPassword, passkey } from "@glinr/theauth/auth";
import { createHonoAdapter } from "@glinr/theauth-hono";

const auth = await createTheAuth({
  database: { provider: "postgres", url: process.env.DATABASE_URL },
  plugins: [emailPassword(), passkey()],
});

const app = new Hono();
app.route("/api/auth", createHonoAdapter(auth));

// Create an AI agent with scoped MCP permissions
const agent = await auth.agent.create({
  ownerId: "user-123",
  name: "github-reader",
  type: "autonomous",
  permissions: [{ resource: "mcp:github:*", actions: ["read"] }],
});

const result = await auth.authorize(agent.id, {
  action: "read",
  resource: "mcp:github:repos",
});
// { allowed: true, auditId: "aud_..." }

How TheAuth compares

| Capability | Auth0 | Clerk | Better-Auth | NextAuth | Lucia | TheAuth | |---|---|---|---|---|---|---| | License | Proprietary | Proprietary | MIT | ISC | MIT | MIT | | Self-hosted | Partial | No | Yes | Yes | Yes | Yes | | OAuth 2.1 server | Yes | Yes | Partial | No | No | Yes | | MCP OAuth 2.1 | No | No | No | No | No | Yes | | Passkeys / WebAuthn | Yes | Yes | Plugin | Plugin | No | Yes | | Multi-tenant / orgs | Yes | Yes | Plugin | No | No | Yes | | Audit log | Yes (paid) | Yes (paid) | No | No | No | Yes | | AI agent identity | No | No | No | No | No | Yes | | Edge runtimes | Partial | No | Yes | Partial | Yes | Yes |


Features

<details> <summary><strong>Full feature checklist (click to expand)</strong></summary>

Authentication

  • Email and password with HIBP breach checking
  • Magic link
  • Email OTP
  • Phone SMS OTP
  • Passkeys / WebAuthn
  • TOTP 2FA (authenticator apps)
  • SAML 2.0 and OIDC SSO
  • Anonymous sessions
  • Google One Tap
  • Sign In With Ethereum
  • Device Authorization (TV / CLI flows)
  • Username and password
  • Captcha integration
  • Session freshness enforcement

OAuth 2.1

  • Authorization Code + PKCE
  • Client Credentials
  • Device Authorization Grant
  • Refresh Token rotation
  • Token introspection
  • Dynamic Client Registration (RFC 7591)
  • Server metadata (RFC 8414)
  • Resource indicators (RFC 8707)
  • Authorization Server Issuer Identification (RFC 9728)

MCP Support

  • Full OAuth 2.1 authorization server for the Model Context Protocol
  • PKCE S256 mandatory
  • RFC 9728 / 8707 / 8414 / 7591 compliant
  • Agent token issuance and validation

AI Agent Identity

  • Cryptographic bearer tokens (kv_...)
  • Wildcard permission matching
  • Delegation chains with configurable depth limits
  • Budget policies per agent
  • Anomaly detection
  • CIBA-style approval flows for sensitive tool calls
  • Full audit trail per agent action

Framework Adapters

  • Next.js 15 (App Router, Route Handlers, Middleware)
  • SvelteKit
  • Nuxt / Vue
  • Hono (Cloudflare Workers, Bun, Deno)
  • Express
  • Fastify
  • Astro
  • NestJS
  • SolidStart
  • TanStack Start
  • React Native / Expo
  • Electron

Database Adapters

Built-in: SQLite, PostgreSQL, MySQL, Cloudflare D1

Plugin: Prisma (share an existing PrismaClient)

Enterprise

  • Organizations with RBAC
  • SCIM directory sync
  • Admin controls (ban, impersonate)
  • API key management
  • Multi-tenant isolation
  • GDPR: export, delete, anonymize
  • Compliance reports: EU AI Act, NIST, SOC 2, ISO 42001

Edge Runtimes

  • Cloudflare Workers (D1, KV)
  • Vercel Edge Functions
  • Deno Deploy
  • Bun
  • Three runtime dependencies: drizzle-orm, jose, zod
</details>

Quick start by framework

<details> <summary><strong>Next.js (App Router)</strong></summary>
npm install @glinr/theauth @glinr/theauth-nextjs
// app/api/auth/[...theauth]/route.ts
import { createTheAuth } from "@glinr/theauth";
import { emailPassword } from "@glinr/theauth/auth";
import { createNextAuthHandler } from "@glinr/theauth-nextjs";

const auth = await createTheAuth({
  database: { provider: "postgres", url: process.env.DATABASE_URL },
  plugins: [emailPassword()],
});

const handler = createNextAuthHandler(auth);
export { handler as GET, handler as POST };
// app/dashboard/page.tsx (Server Component)
import { getServerSession } from "@glinr/theauth-nextjs";

export default async function Dashboard() {
  const session = await getServerSession();
  if (!session) redirect("/sign-in");
  return <h1>Hello, {session.user.email}</h1>;
}

See examples/nextjs-app for a full working example.

</details> <details> <summary><strong>SvelteKit</strong></summary>
npm install @glinr/theauth @glinr/theauth-sveltekit
// src/hooks.server.ts
import { createTheAuth } from "@glinr/theauth";
import { emailPassword } from "@glinr/theauth/auth";
import { createSvelteKitHandler } from "@glinr/theauth-sveltekit";

const auth = await createTheAuth({
  database: { provider: "sqlite", url: "theauth.db" },
  plugins: [emailPassword()],
});

export const handle = createSvelteKitHandler(auth);
// src/routes/+layout.server.ts
import { getSession } from "@glinr/theauth-sveltekit";

export async function load(event) {
  const session = await getSession(event);
  return { session };
}
</details> <details> <summary><strong>Vue / Nuxt</strong></summary>
npm install @glinr/theauth @glinr/theauth-nuxt
// server/plugins/theauth.ts
import { createTheAuth } from "@glinr/theauth";
import { emailPassword } from "@glinr/theauth/auth";

export const auth = await createTheAuth({
  database: { provider: "postgres", url: process.env.DATABASE_URL },
  plugins: [emailPassword()],
});
// nuxt.config.ts
export default defineNuxtConfig({
  modules: ["@glinr/theauth-nuxt"],
});
</details> <details> <summary><strong>Hono (Cloudflare Workers / Express / Bun)</strong></summary>
npm install @glinr/theauth @glinr/theauth-hono
import { Hono } from "hono";
import { createTheAuth } from "@glinr/theauth";
import { emailPassword } from "@glinr/theauth/auth";
import { createHonoAdapter } from "@glinr/theauth-hono";

type Env = { DATABASE_URL: string };
const app = new Hono<{ Bindings: Env }>();

app.use("/api/auth/*", async (c, next) => {
  const auth = await createTheAuth({
    database: { provider: "postgres", url: c.env.DATABASE_URL },
    plugins: [emailPassword()],
  });
  return createHonoAdapter(auth)(c, next);
});

export default app;
``

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars10
CategorySecurity
Updated16h ago
Forks3

Languages

TypeScript

Trust signals

97/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 info
theauth — MCP Server: Install & Safety Check | SkillAgent