@authmy/authjs
v0.1.1
Published
The auth.my provider for Auth.js (NextAuth). Optional: plain OIDC configuration works just as well.
Maintainers
Readme
@authmy/authjs
The auth.my provider for Auth.js — NextAuth, SvelteKit, Express.
This package is optional
auth.my is a plain OpenID Connect provider. Configuring it by hand takes fifteen lines and works exactly the same. This package gives you nothing you cannot get without it, and it is not meant to become required: a free choice of library is a promise made on the front page.
What it does give you is one thing — it pins down the defaults you would otherwise have to keep in your head, and could get wrong.
Install
npm install @authmy/authjsUse
// auth.ts
import NextAuth from 'next-auth'
import AuthMy from '@authmy/authjs'
export const { handlers, auth, signIn, signOut } = NextAuth({
providers: [AuthMy()],
})clientId and clientSecret are read from AUTHMY_CLIENT_ID and
AUTHMY_CLIENT_SECRET. Pass them explicitly and the environment is ignored.
The callback URL to register in the console:
https://your-site/api/auth/callback/authmyWhat is pinned
| Setting | Value | Why it is not left to you |
|---|---|---|
| issuer | https://auth.my | Every other endpoint comes from discovery |
| scope | openid profile email | offline_access is not requested: a refresh token is issued without it, and an extra scope is an extra line on the consent screen |
| checks | pkce, state | PKCE is required of every client, confidential ones included |
| id | authmy | It determines the callback URL, which is already registered on the auth.my side |
Without a clientSecret the client is declared public
(token_endpoint_auth_method: 'none'): a single-page or mobile app has
nowhere to keep a secret, and PKCE protects the code exchange instead. With a
clientSecret the client is declared confidential
(token_endpoint_auth_method: 'client_secret_basic'), set explicitly rather
than left to the library default — auth.my's token endpoint accepts only
client_secret_basic and none.
Options
AuthMy({
clientId: '...',
clientSecret: '...',
issuer: 'https://staging.example', // staging deployment or local work
scope: 'openid profile email phone',
})Profile
sub becomes id, plus name, email, image and emailVerified.
image is the avatar when the person has one, null otherwise. auth.my
serves the picture itself rather than linking to the provider the person
signed in with: the browser of your site never goes to Google for it, and
Google never learns which sites they visit.
emailVerified is true only for an explicit email_verified: true. Silence
from the provider is not a confirmation — account takeover by matching
addresses is built on reading it the other way.
