@multiplatform.one/auth
v7.31.0
Published
Better Auth helpers for multiplatform.one apps with Keycloak
Readme
@multiplatform.one/auth
Better Auth helpers for Keycloak in One apps. createAuth() wires the Keycloak
OAuth provider, Expo, and a front-channel SSO plugin; the route handler and
session helpers sit on top of that instance.
Wallet connect (SIWE / SIWS / SIU) lives in @multiplatform.one/wallet. This
package lists it as an optional peer so wagmi, viem, and siwe stay out of the
auth bundle. Import wallet from @multiplatform.one/wallet in the app that
needs it.
What it provides
createAuth(options?)— Better Auth instance for Keycloak. ReadsBASE_URL,SECRET,KEYCLOAK_*,DATABASE_URL,ONE_PORT. Wallet-only Keycloak users (no email claim) get a stable{handle}@walletplaceholder.createAuthRouteHandler(auth)—{ GET, POST }for One+api.tsfiles. In dev, the request origin (including LAN /*.local) is stored so OAuth redirect URIs follow the host the visitor is actually on.createSessionHelpers(auth)—verifyAuth(throws 401) andgetSession(session or null).@multiplatform.one/auth/access-token— isomorphic refresh classifier (classifyAccessTokenResponse,retryWhileTransient,watchDocumentVisible) without Nodeasync_hooks.
SSO sign-out is GET {basePath}/sign-out/sso. Native clients pass ?mode=json
and ride the returned Keycloak end-session URL in the system browser.
Usage
import { createAuth, createAuthRouteHandler, createSessionHelpers } from "@multiplatform.one/auth";
export const auth = createAuth();
export const { GET, POST } = createAuthRouteHandler(auth);
export const { verifyAuth, getSession } = createSessionHelpers(auth);// lib/server/auth.ts
export const { GET, POST } = createAuthRouteHandler(auth);
// routes/api/auth/[route]+api.ts
export { GET, POST } from "../../../lib/server/auth";License
Apache-2.0
