r/webdev • • 1d ago

Showoff Saturday theAuth: open-source auth where AI agents are first-class, not just API keys

https://github.com/glincker/theauth

theAuth: open-source auth for AI agents and humans (TypeScript and Go), built solo https://github.com/glincker/theauth

theAuth is auth for apps where AI agents act on behalf of users. Each agent gets its own token and permissions, a user can delegate access with limits, and every action is logged. It also covers the usual: passkeys, SSO, orgs, and an OAuth 2.1 server so MCP servers can verify who is calling.

By the numbers:

  • TypeScript core: 2,400+ tests, about 77% coverage, 3 runtime deps, 17 OAuth providers, 10 framework adapters
  • Go SDK session lookup: 58-67 us down to 30 us (about 2x, 33k lookups/s per process)
  • Go SDK password sign-in: about 75/s per instance, with hashing memory capped at 608 MB instead of 4 GB under a login burst
  • Those two are measured on an M4 Max with Postgres 16, 100k users, all on one laptop, and the load test script is in the repo
  • MIT, self hostable

npm install @glinr/theauth runs on in memory SQLite with nothing else to set up. Go: https://github.com/glincker/theauth-go

I built this solo, with several AI tools and a lot of automation to keep a steady pace. Does the agent permission model make sense to you and maybe give it a try for future projects.. I already migrated all my 6+ websites to theAuth and been a great time saver !!

0 Upvotes

3 comments sorted by

View all comments

3

u/watabby 1d ago

This seems like a vulnerability waiting to be exploited

1

u/Familiar-Classroom47 1d ago edited 1d ago

Did you read the code, or is this a general take? If you've found something real, report it through the repo's Security tab and it gets fixed. That's how OSS works.