@dmfaster/local-auth
v1.4.0
Published
Shared secure local authentication for DM Faster agent clients.
Readme
@dmfaster/local-auth
Secure local authentication shared by the official DM Faster CLI and MCP
server. It implements DM Faster's browser-approved device authorization flow,
stores issued credentials in the operating system's credential store, and
supports DMFASTER_TOKEN for non-interactive CI environments.
Distribution note: the registry command below works only after this exact release is published. Before then, maintainers use the built package from an authorized source checkout.
npm install @dmfaster/[email protected]Application integrations normally use @dmfaster/sdk directly. This package
is the lower-level authentication layer for DM Faster's official local clients.
It never stores an access token in the DM Faster config file.
Device authorization supports the read, plan, draft, and full access
profiles. beginDeviceAuthorization({ access: "plan" }) requests only the five
operational read scopes plus audiences:read; omitting access requests the
complete full Agent 1.0 scope set. The browser approval page remains the
authority for the workspace and permissions actually granted.
The supported runtime is Node.js 24. Browser sign-in defaults to
https://app.dmfaster.com; compatible loopback API endpoints are available for
local development and tests.
Direct campaign control (since 1.3.0)
An owner can grant campaigns:control once when connecting an agent with the
full profile. Explicit user instructions then suffice for launch or pause:
preflight returns ready and a version-bound authorization ID for immediate
execution. The normal action scope is still required. Existing credentials
retain per-action approval until the owner reconnects and grants this permission.
Planning or preparing a campaign never authorizes launch.
