npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@next-nest-auth/nextauth

v0.3.0

Published

NextAuth is a frontend authentication package designed for Next.js applications, providing easy integration with NestJS-based backends. It supports login, session management, and token handling (including JWT and refresh tokens) to ensure secure user auth

Readme

@next-nest-auth/nextauth

Cookie-based JWT authentication for Next.js apps backed by a NestJS API.

npm version npm downloads license types

@next-nest-auth/nextauth is the frontend half of a matched authentication pair for full-stack TypeScript apps: this package handles login, session, and token refresh on the Next.js (App Router) side, and @next-nest-auth/nestauth handles issuing and validating JWTs on the NestJS side. Together they give you secure, httpOnly-cookie-based authentication with automatic access/refresh token handling, without wiring it up from scratch.

Not related to Auth.js / NextAuth.js. This is a lightweight, purpose-built package for pairing a Next.js frontend with a NestJS backend — it is not a fork of, or drop-in replacement for, the popular next-auth package.

Features

  • 🔐 httpOnly cookie sessions — access and refresh tokens never touch client-side JavaScript or localStorage.
  • 🔄 Built-in refresh flow — a middleware-ready refreshToken() helper for silently renewing expired sessions.
  • 🧩 Drop-in with @next-nest-auth/nestauth — matches its /nestauth/login and /nestauth/refresh-token endpoint contract out of the box.
  • 🪪 JWT claim decoding — read the logged-in user's claims with getUserInfo(), no extra API call required.
  • 📦 TypeScript-first — ships its own type declarations, no @types package needed.
  • 🌐 Authenticated fetch helpers — get/post wrappers that attach the bearer token automatically.

Requirements

  • Next.js 13.4+ using the App Router (this package uses next/headers and Next.js middleware APIs, which are not available in the Pages Router).
  • A backend implementing the @next-nest-auth/nestauth login/refresh contract (or a compatible API — see Prerequisites).

Installation

npm install @next-nest-auth/nextauth
# or
yarn add @next-nest-auth/nextauth
# or
pnpm add @next-nest-auth/nextauth

Prerequisites

This package is the client counterpart to @next-nest-auth/nestauth. Read that package's documentation first — it defines the backend endpoints (/nestauth/login, /nestauth/refresh-token) and token response shape this package expects.

Environment variables

Set the following in your Next.js app's .env:

| Variable | Required | Description | | --- | --- | --- | | NEXT_AUTH_API_URL or NEXT_PUBLIC_AUTH_API_URL | Yes (one of the two) | Base URL of your NestJS backend. | | NODE_ENV | Recommended | development or production. Controls whether auth cookies are marked secure (production only). | | AUTOEXPIRE_REFRESH_TOKEN | No | When set, the refresh-token cookie's expiry is not extended on each token refresh — it expires on its original schedule. Default: unset (sliding expiry). | | BASE_URL | No | Your Next.js frontend's own URL, for reference in redirect flows. |

NODE_ENV=development
BASE_URL=http://localhost:3000
NEXT_AUTH_API_URL=http://localhost:3001
# or
NEXT_PUBLIC_AUTH_API_URL=http://localhost:3001

Quick start

1. Log in and set session cookies

import { authenticate } from "@next-nest-auth/nextauth";

const response = await authenticate({
  username: "user",
  password: "password",
});

2. Protect routes in middleware

import { NextRequest, NextResponse } from "next/server";
import { checkAuth, refreshToken } from "@next-nest-auth/nextauth";

export async function middleware(req: NextRequest) {
  const protectedRoutes = ["/dashboard", "/profile", "/settings"];

  if (protectedRoutes.some((route) => req.nextUrl.pathname.startsWith(route))) {
    const authenticated = await checkAuth();
    if (!authenticated) {
      try {
        return await refreshToken(req);
      } catch (error) {
        return NextResponse.redirect(new URL("/", req.url));
      }
    }
  }
  return NextResponse.next();
}

export const config = {
  matcher: ["/dashboard/:path*", "/profile/:path*", "/settings/:path*"],
};

3. Read the current user and log out

import { getUserInfo, logout } from "@next-nest-auth/nextauth";

const user = await getUserInfo();
await logout();

API reference

authenticate(params)

Authenticates the user against your NestJS backend and stores the returned access and refresh tokens as httpOnly cookies.

import { authenticate } from "@next-nest-auth/nextauth";

const response = await authenticate({
  username: "user",
  password: "password",
});

refreshToken(req)

Renews the access token using the refresh token cookie. Designed for use in Next.js middleware (it reads from req.cookies and returns a NextResponse, since next/headers cookies() is not available there).

import { refreshToken } from "@next-nest-auth/nextauth";

const refreshedResponse = await refreshToken(req);

getUserInfo()

Decodes the current access token and returns its claims, or null if there is no valid token.

import { getUserInfo } from "@next-nest-auth/nextauth";

const userInfo = await getUserInfo();

This reads claims from the JWT locally and does not re-verify the token's signature. Treat it as a convenience read, not an authorization check — your NestJS backend remains the source of truth for whether a token is actually valid.

getAccessToken() / getRefreshToken()

Read the raw token values from cookies.

import { getAccessToken, getRefreshToken } from "@next-nest-auth/nextauth";

const accessToken = await getAccessToken();
const refreshToken = await getRefreshToken();

checkAuth()

Returns true if an access token cookie is present.

import { checkAuth } from "@next-nest-auth/nextauth";

const authenticated = await checkAuth();

logout()

Deletes the access and refresh token cookies.

import { logout } from "@next-nest-auth/nextauth";

await logout();

get(url, params?, headers?, secured?) / post(url, data?, headers?, secured?)

Axios-based helpers that automatically attach Authorization: Bearer <access_token> when secured is true (the default).

import { get, post } from "@next-nest-auth/nextauth";

const data = await get("/some-api-endpoint");
const postData = await post("/some-api-endpoint", { someData: "value" });

Security considerations

  • Tokens are stored as httpOnly cookies, never exposed to client-side JavaScript.
  • The secure cookie flag is enabled automatically when NODE_ENV is exactly production — make sure that's set correctly in your deployment environment, or cookies won't be marked secure there.
  • If your Next.js frontend and NestJS backend are on different origins, configure CORS on the backend to allow credentials (Access-Control-Allow-Credentials: true) from your frontend's specific origin — this package sends requests with withCredentials: true.
  • getUserInfo() decodes but does not verify the JWT signature; don't use it as your only authorization gate for sensitive actions.

Related

Contributing

Issues and pull requests are welcome at github.com/tanvir0604/nextauth.

License

This package is licensed under the MIT License.