{"_id":"@aneeshgusain/next-gen-auth-server","_rev":"18-650f284ac08ac43ccce9b7d3a7536d79","name":"@aneeshgusain/next-gen-auth-server","dist-tags":{"latest":"0.1.13"},"versions":{"0.1.9":{"name":"@aneeshgusain/next-gen-auth-server","version":"0.1.9","keywords":["oauth","oidc","jwt","jwks","express","middleware","authentication"],"license":"MIT","_id":"@aneeshgusain/next-gen-auth-server@0.1.9","maintainers":[{"name":"aneeshgusain","email":"anishgusain432@gmail.com"}],"dist":{"shasum":"4171bbd842e55efb52968d0bda584bea00afbaeb","tarball":"https://registry.npmjs.org/@aneeshgusain/next-gen-auth-server/-/next-gen-auth-server-0.1.9.tgz","fileCount":8,"integrity":"sha512-926VxauXq5TZBD4zB2rKNaonSWb3e0Iyya3ZVv0LfKu2B7we4zSzj1zzo4xcYI739YTAOFR7pRiX0JP43rR2TA==","signatures":[{"sig":"MEUCIQCE4sTWQ3dO1VvI0p4XoZ8++kXLywbs6CEyTqyRG2dPBgIgJM/c0sSYeibca0uZ7TUQy/QZK0dPewc2S7rAt4DQMnU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":34840},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"dev":"tsup --watch","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"aneeshgusain","email":"anishgusain432@gmail.com"},"_npmVersion":"10.9.7","description":"Express middleware for verifying Next-Gen Auth (OIDC) access tokens — no manual JWT/JWKS handling required","directories":{},"_nodeVersion":"22.22.2","dependencies":{"jose":"^5.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","express":"^4.19.0","typescript":"^5.4.0","@types/express":"^4.17.0"},"peerDependencies":{"express":">=4"},"_npmOperationalInternal":{"tmp":"tmp/next-gen-auth-server_0.1.9_1783396116816_0.1062888004607081","host":"s3://npm-registry-packages-npm-production"}},"0.1.10":{"name":"@aneeshgusain/next-gen-auth-server","version":"0.1.10","keywords":["oauth","oidc","jwt","jwks","express","middleware","authentication"],"license":"MIT","_id":"@aneeshgusain/next-gen-auth-server@0.1.10","maintainers":[{"name":"aneeshgusain","email":"anishgusain432@gmail.com"}],"dist":{"shasum":"9b51d2d3662857a5391ff58e421f66bbe43f6cf3","tarball":"https://registry.npmjs.org/@aneeshgusain/next-gen-auth-server/-/next-gen-auth-server-0.1.10.tgz","fileCount":8,"integrity":"sha512-dFH6AdZ+/3pTZKfMEgXByefSpGx2U/bVElp6IpjLmYqTPeU/sgporwtwypLEuPT5oM+0kMLJqsqFYp6JaEGalQ==","signatures":[{"sig":"MEQCID3VMbkYWf/mr8AL5QFtsDp7o1T8jo+7LBpNW4X17sslAiBlNASWCfxuVnWB0AKPDYOmMlXRiwKTyJClArOtpISeew==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":35063},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"dev":"tsup --watch","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"aneeshgusain","email":"anishgusain432@gmail.com"},"_npmVersion":"10.9.7","description":"Express middleware for verifying Next-Gen Auth (OIDC) access tokens — no manual JWT/JWKS handling required","directories":{},"_nodeVersion":"22.22.2","dependencies":{"jose":"^5.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","express":"^4.19.0","typescript":"^5.4.0","@types/express":"^4.17.0"},"peerDependencies":{"express":">=4"},"_npmOperationalInternal":{"tmp":"tmp/next-gen-auth-server_0.1.10_1783397624421_0.13676738426153445","host":"s3://npm-registry-packages-npm-production"}},"0.1.11":{"name":"@aneeshgusain/next-gen-auth-server","version":"0.1.11","keywords":["oauth","oidc","jwt","jwks","express","middleware","authentication"],"license":"MIT","_id":"@aneeshgusain/next-gen-auth-server@0.1.11","maintainers":[{"name":"aneeshgusain","email":"anishgusain432@gmail.com"}],"dist":{"shasum":"d6ad1abfa0cab11b7b0830f821ab34168f7fb0fa","tarball":"https://registry.npmjs.org/@aneeshgusain/next-gen-auth-server/-/next-gen-auth-server-0.1.11.tgz","fileCount":8,"integrity":"sha512-nM6h2e0uDKLhOev8SYBQ34J8jckpKzVg30Gpn+NOSJpTcli3u/w7DIu/vLL6m1Ft7OzkRgRcKuBRj6DoAiZsng==","signatures":[{"sig":"MEUCIEVkvJJil8zSqU+sJcTzolq+EWUx3Ac4mwI49/eO2L6WAiEAhslnWEUp63ey2MpDudbhGI3F/Yfxy92WVEGkgHTCpq8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":37950},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"dev":"tsup --watch","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"aneeshgusain","email":"anishgusain432@gmail.com"},"_npmVersion":"10.9.7","description":"Express middleware for verifying Next-Gen Auth (OIDC) access tokens — no manual JWT/JWKS handling required","directories":{},"_nodeVersion":"22.22.2","dependencies":{"jose":"^5.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","express":"^4.19.0","typescript":"^5.4.0","@types/express":"^4.17.0"},"peerDependencies":{"express":">=4"},"_npmOperationalInternal":{"tmp":"tmp/next-gen-auth-server_0.1.11_1783398839461_0.25898456806023495","host":"s3://npm-registry-packages-npm-production"}},"0.1.12":{"name":"@aneeshgusain/next-gen-auth-server","version":"0.1.12","keywords":["oauth","oidc","jwt","jwks","express","middleware","authentication"],"license":"MIT","_id":"@aneeshgusain/next-gen-auth-server@0.1.12","maintainers":[{"name":"aneeshgusain","email":"anishgusain432@gmail.com"}],"dist":{"shasum":"f447e79984a4ed4db6e79b964b0aecb4f981dac4","tarball":"https://registry.npmjs.org/@aneeshgusain/next-gen-auth-server/-/next-gen-auth-server-0.1.12.tgz","fileCount":8,"integrity":"sha512-XThCHIGRrTBr0CG2oBmZXYfGuiB14ZgELb/s0GfAtyXJCcn9D2fjWAI9an7BsA+uZcfFbNYgigTKoDV/2waBHA==","signatures":[{"sig":"MEUCIE+M5rA5VumQg2otdpSS8HZcDSrsOb/Pk7jTV0AJ/tTZAiEAzOTkephxpdR20DtyGWO0fV9DTwLlxWzjbyUbPQMNMuI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":35063},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"dev":"tsup --watch","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"aneeshgusain","email":"anishgusain432@gmail.com"},"_npmVersion":"10.9.7","description":"Express middleware for verifying Next-Gen Auth (OIDC) access tokens — no manual JWT/JWKS handling required","directories":{},"_nodeVersion":"22.22.2","dependencies":{"jose":"^5.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","express":"^4.19.0","typescript":"^5.4.0","@types/express":"^4.17.0"},"peerDependencies":{"express":">=4"},"_npmOperationalInternal":{"tmp":"tmp/next-gen-auth-server_0.1.12_1783399456354_0.7870892944406078","host":"s3://npm-registry-packages-npm-production"}},"0.1.13":{"name":"@aneeshgusain/next-gen-auth-server","version":"0.1.13","description":"Express middleware for verifying Next-Gen Auth (OIDC) access tokens — no manual JWT/JWKS handling required","type":"module","main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"build":"tsup","dev":"tsup --watch","prepublishOnly":"npm run build"},"dependencies":{"jose":"^5.2.0"},"peerDependencies":{"express":">=4"},"devDependencies":{"tsup":"^8.0.0","typescript":"^5.4.0","@types/express":"^4.17.0","express":"^4.19.0"},"keywords":["oauth","oidc","jwt","jwks","express","middleware","authentication"],"license":"MIT","publishConfig":{"access":"public"},"_id":"@aneeshgusain/next-gen-auth-server@0.1.13","_nodeVersion":"22.22.2","_npmVersion":"10.9.7","dist":{"integrity":"sha512-/B+1iSda/7MeA2psWBoGVXv4as3Bvq4Xus02d2xwBhUjDKKLazNzvGyXWRIs6QxRWdic6gJk8QvkTyNaA42NXQ==","shasum":"37bea5b68119f9f7fcc7110fe16c509fccd44d9c","tarball":"https://registry.npmjs.org/@aneeshgusain/next-gen-auth-server/-/next-gen-auth-server-0.1.13.tgz","fileCount":8,"unpackedSize":37508,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDyEJx7293iypYBoRYYMDqxzgBoMxc+adI+AWhTx8neRQIhAK4t5HQvX+DZXx8RvqgNtAor1F8hw3dFXp4wqplr7RyR"}]},"_npmUser":{"name":"aneeshgusain","email":"anishgusain432@gmail.com"},"directories":{},"maintainers":[{"name":"aneeshgusain","email":"anishgusain432@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/next-gen-auth-server_0.1.13_1783401437694_0.9490796941816797"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-07T04:13:44.305Z","modified":"2026-07-07T05:17:17.938Z","0.1.0":"2026-07-06T04:41:18.037Z","0.1.1":"2026-07-06T04:44:57.809Z","0.1.2":"2026-07-06T04:55:17.364Z","0.1.3":"2026-07-06T06:32:08.184Z","0.1.4":"2026-07-06T14:47:11.958Z","0.1.5":"2026-07-06T14:52:04.232Z","0.1.9":"2026-07-07T03:48:36.934Z","0.1.10":"2026-07-07T04:13:44.599Z","0.1.11":"2026-07-07T04:33:59.593Z","0.1.12":"2026-07-07T04:44:16.513Z","0.1.13":"2026-07-07T05:17:17.833Z"},"license":"MIT","keywords":["oauth","oidc","jwt","jwks","express","middleware","authentication"],"description":"Express middleware for verifying Next-Gen Auth (OIDC) access tokens — no manual JWT/JWKS handling required","maintainers":[{"name":"aneeshgusain","email":"anishgusain432@gmail.com"}],"readme":"# @aneeshgusain/next-gen-auth-server\n\nExpress middleware for verifying **Next-Gen Auth** (OAuth 2.0 / OpenID Connect) access\ntokens. Handles JWKS fetching, key caching, key rotation, JWT verification, and\nfetching user profile data internally — no `jose`, manual JWT/JWKS code, or\nraw `fetch` calls required in your app.\n\n## Install\n\n```bash\nnpm install @aneeshgusain/next-gen-auth-server\n```\n\n## Usage\n\n```javascript\nimport express from \"express\";\nimport { createAuthMiddleware } from \"@aneeshgusain/next-gen-auth-server\";\n\nconst app = express();\n\nconst requireAuth = createAuthMiddleware({\n  provider: \"https://next-gen-auth.onrender.com\",\n});\n\napp.get(\"/protected\", requireAuth, (req, res) => {\n  res.json({ message: `Hello ${req.user.sub}` });\n});\n```\n\nThat's the entire integration. The middleware:\n\n- Fetches the provider's public keys from `/.well-known/jwks.json` on first use\n- Caches them, and automatically re-fetches if a token references an unrecognized `kid` (handles key rotation transparently)\n- Verifies the token's signature, issuer, and expiry\n- Attaches the decoded claims to `req.user`\n- Attaches a ready-to-use `req.getUserInfo()` function, already bound to the request's token\n- Responds with a `401` automatically on any failure — no try/catch needed in your route handlers\n\n## Getting the user's email, name, and other profile data\n\nAccess tokens only ever carry `sub`, `scope`, `iss`, `aud`, `exp`, and `iat` —\nnever the person's email or name. For that, call `req.getUserInfo()`, which\nis already wired up by the middleware with no setup:\n\n```javascript\napp.get(\"/profile\", requireAuth, async (req, res) => {\n  const token = req.headers.authorization.split(\" \")[1];\n  const user = await req.getUserInfo({provider: \"https://next-gen-auth.onrender.com\"}, token); // { sub, email, given_name, family_name, ... }\n  res.json(user);\n});\n```\n\nOnly call this on routes that actually need profile data — if all you need\nis the user's ID, `req.user.sub` alone is enough and avoids an extra network\ncall.\n\n## Optional authentication\n\nFor routes that behave differently for logged-in vs. anonymous users, without requiring auth:\n\n```javascript\nimport { createOptionalAuthMiddleware } from \"@aneeshgusain/next-gen-auth-server\";\n\nconst optionalAuth = createOptionalAuthMiddleware({\n  provider: \"https://next-gen-auth.onrender.com\",\n});\n\napp.get(\"/feed\", optionalAuth, (req, res) => {\n  if (req.user) {\n    res.json({ message: `Personalized feed for ${req.user.sub}` });\n  } else {\n    res.json({ message: \"Generic public feed\" });\n  }\n});\n```\n\nIf no token is present, `req.user` is left `undefined` and the request proceeds normally.\nIf a token *is* present but invalid, it's silently ignored (treated as anonymous)\nrather than rejected. `req.getUserInfo()` is also available here when `req.user` is set.\n\n## Using this outside Express\n\nIf there's no `req`/`res` to attach to (a WebSocket handler, a cron job, a\nscript, another framework), use the standalone functions instead.\n\n**Verifying a token:**\n\n```javascript\nimport { createTokenVerifier } from \"@aneeshgusain/next-gen-auth-server\";\n\nconst verifyAccessToken = createTokenVerifier({ provider: \"https://next-gen-auth.onrender.com\" });\n\nconst claims = await verifyAccessToken(someToken); // throws AuthVerificationError on failure\n```\n\n**Fetching user info, configured once and reused:**\n\n```javascript\nimport { createUserInfoFetcher } from \"@aneeshgusain/next-gen-auth-server\";\nconst token = req.headers.authorization.split(\" \")[1];\nconst getUserInfo = createUserInfoFetcher({ provider: \"https://next-gen-auth.onrender.com\" });\n\nconst user = await getUserInfo(token); // just the token, every call\n```\n\n**Fetching user info, one-off (provider passed every call):**\n\n```javascript\nimport { getUserInfo } from \"@aneeshgusain/next-gen-auth-server\";\n\nconst user = await getUserInfo({ provider: \"https://next-gen-auth.onrender.com\" }, token);\n```\n\nIf you're inside an Express route already wrapped in `requireAuth` or\n`createOptionalAuthMiddleware`, you never need any of these three — use\n`req.user` and `req.getUserInfo()` instead.\n\n## API\n\n### `createAuthMiddleware(config)`\n\n| Option       | Required | Description                                                                       |\n| ------------ | -------- | --------------------------------------------------------------------------------- |\n| `provider` | yes      | Base URL of your Next-Gen Auth provider                                           |\n| `audience` | no       | If set, rejects tokens whose`aud` claim doesn't match (pass your `client_id`) |\n\nReturns an Express middleware. On success, sets `req.user` to the decoded token\nclaims and `req.getUserInfo()` to a ready-to-call function bound to the\nrequest's token. On failure, responds `401` directly — the request never\nreaches your handler.\n\n### `createOptionalAuthMiddleware(config)`\n\nSame config shape. Never rejects a request — `req.user` and `req.getUserInfo`\nare set if a valid token was present, otherwise left `undefined`.\n\n### `requireScope(scope)`\n\nReturns a middleware that checks `req.user.scope` for the given value. Use it\n*after* `createAuthMiddleware` in your route's middleware chain. Responds `403`\nif the scope is missing.\n\n### `createTokenVerifier(config)`\n\nReturns a function `(token) => Promise<AuthClaims>` for verifying a token\noutside Express. Throws `AuthVerificationError` on failure.\n\n### `getUserInfo(config, token)`\n\nFetches user claims from the provider's `/userinfo` endpoint. Standalone —\nrequires `provider` on every call. Prefer `req.getUserInfo()` inside Express,\nor `createUserInfoFetcher` if calling this repeatedly outside Express.\n\n### `createUserInfoFetcher(config)`\n\nReturns a function `(token) => Promise<Record<string, unknown>>`, with\n`provider` configured once instead of on every call.\n\n## Error handling\n\nAll verification failures throw (or, in the middleware, respond with) one of\nthese messages: `\"access token expired\"`, `\"invalid token signature\"`,\n`\"invalid or malformed access token\"`, or `\"missing access token\"`. The\n`WWW-Authenticate` response header is set automatically per the Bearer token\nspec, so standard HTTP clients and tooling can introspect the failure reason.\n\n## Security notes\n\n- Token verification uses the provider's **public** key only — this package\n  never needs or accepts a private key or client secret.\n- The JWKS is fetched over HTTPS and cached in memory per process. If you run\n  multiple server instances, each will fetch and cache independently — this\n  is expected and fine, since JWKS responses are public, cacheable data.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}