npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@qavren/auth-next

v0.1.2

Published

Thin Auth.js v5 wrapper for Qavren (Keycloak) realms

Readme

@qavren/auth-next

Thin Auth.js v5 wrapper for Qavren (Keycloak) realms. One call wires the Keycloak provider for a realm as a public client (PKCE, no client secret) and surfaces the realm roles on the session.

Install

npm install @qavren/auth-next next-auth@beta

Use

// auth.ts
import { createAuth } from "@qavren/auth-next";

export const { handlers, auth, signIn, signOut } = createAuth({
  realm: "squarelog",
  // baseUrl defaults to QAVREN_AUTH_URL, then https://auth.qavrensolutions.com
});
// app/api/auth/[...nextauth]/route.ts
export { GET, POST } from "@/auth";
// anywhere server-side
const session = await auth();
session?.user.roles; // string[] from realm_access.roles

Convention (shared by all Qavren SDKs)

  • Base URL: baseUrl param, else QAVREN_AUTH_URL, else https://auth.qavrensolutions.com.
  • Issuer: {base}/realms/{realm}. Client ID: {realm}-web.
  • Public client: no client secret; token_endpoint_auth_method: "none". PKCE plus the realm's redirect-URI allow-list carry the security.
  • Roles: realm roles are read from the access token's realm_access.roles -- where Keycloak's default realm-roles mapper writes them -- unioned with any roles a custom ID-token mapper surfaces on the profile, then exposed as session.user.roles (typed via module augmentation this package ships). Reading the ID-token profile alone yields [] under the default Keycloak mapper config, so the access token is the source of truth.

Composition

createAuth accepts any NextAuthConfig override alongside realm/baseUrl (e.g. pages, extra callbacks). buildAuthConfig is also exported for callers who want the config object without instantiating NextAuth.

Scope of tests

This package's tests are unit-level: they assert the produced Auth.js config (issuer, public client id, no secret, PKCE, role callbacks). The end-to-end browser login flow against a live Keycloak is exercised by the demo app (Plan 03), not here.

Install

npm install @qavren/auth-next