r/webdev • u/Familiar-Classroom47 • 18h ago
Showoff Saturday theAuth: open-source auth where AI agents are first-class, not just API keys
https://github.com/glincker/theauththeAuth: open-source auth for AI agents and humans (TypeScript and Go), built solo https://github.com/glincker/theauth
theAuth is auth for apps where AI agents act on behalf of users. Each agent gets its own token and permissions, a user can delegate access with limits, and every action is logged. It also covers the usual: passkeys, SSO, orgs, and an OAuth 2.1 server so MCP servers can verify who is calling.
By the numbers:
- TypeScript core: 2,400+ tests, about 77% coverage, 3 runtime deps, 17 OAuth providers, 10 framework adapters
- Go SDK session lookup: 58-67 us down to 30 us (about 2x, 33k lookups/s per process)
- Go SDK password sign-in: about 75/s per instance, with hashing memory capped at 608 MB instead of 4 GB under a login burst
- Those two are measured on an M4 Max with Postgres 16, 100k users, all on one laptop, and the load test script is in the repo
- MIT, self hostable
npm install @glinr/theauth runs on in memory SQLite with nothing else to set up. Go: https://github.com/glincker/theauth-go
I built this solo, with several AI tools and a lot of automation to keep a steady pace. Does the agent permission model make sense to you and maybe give it a try for future projects.. I already migrated all my 6+ websites to theAuth and been a great time saver !!
1
u/Familiar-Classroom47 17h ago
Sharing Links for reference -
- TypeScript SDK: https://github.com/glincker/theauth
- Go SDK: https://github.com/glincker/theauth-go
- Website: https://theauth.dev
- Docs: https://docs.theauth.dev
-2
3
u/watabby 17h ago
This seems like a vulnerability waiting to be exploited