{"_id":"@credocentral/e-identity-nextjs","_rev":"3-5d926b545293ec3d58118959007bc3c0","name":"@credocentral/e-identity-nextjs","dist-tags":{"latest":"1.0.2"},"versions":{"1.0.0":{"name":"@credocentral/e-identity-nextjs","version":"1.0.0","keywords":["oauth2","oidc","nextjs","e-identity","etranzact"],"license":"MIT","_id":"@credocentral/e-identity-nextjs@1.0.0","maintainers":[{"name":"valenteeena","email":"toun.olayemi2@gmail.com"},{"name":"stephen.obi","email":"hello@credocentral.com"}],"dist":{"shasum":"e6479fb68bbbee62b268c6f2a5ebabf9253c0b7d","tarball":"https://registry.npmjs.org/@credocentral/e-identity-nextjs/-/e-identity-nextjs-1.0.0.tgz","fileCount":27,"integrity":"sha512-5Jm1kLLUjLh7G4jag7e5RJ5+AvI9Zvdg/eQMLEIRW2wLyBOUVnvntGMwOdm/YcA6YOTypCDqiR1ocwbjz/1Q1w==","signatures":[{"sig":"MEUCICxvLQB+yIgEcDuwZb0a2CFCPwyXht8hyQuG8/bjvATfAiEAq7voMHST1PomJGFgYUqc3W8WjqIwONZJfzRd7J1XSQc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":63473},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./server":{"types":"./dist/server.d.ts","import":"./dist/server.js","require":"./dist/server.cjs"},"./handler":{"types":"./dist/handler.d.ts","import":"./dist/handler.js","require":"./dist/handler.cjs"},"./middleware":{"types":"./dist/middleware.d.ts","import":"./dist/middleware.js","require":"./dist/middleware.cjs"}},"gitHead":"dddee3f3c6d07f72b8a94b9ac47a7dfde28eea82","scripts":{"build":"tsup","clean":"rm -rf dist","typecheck":"tsc --noEmit"},"_npmUser":{"name":"stephen.obi","email":"hello@credocentral.com"},"_npmVersion":"10.9.7","description":"Next.js SDK for e-identity OAuth2/OIDC authentication (App Router)","directories":{},"_nodeVersion":"22.22.2","dependencies":{"@credocentral/e-identity-core":"^1.0.0","@credocentral/e-identity-react":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"next":"^16.2.6","tsup":"*","typescript":"*","@types/react":"^19"},"peerDependencies":{"next":">=14.0.0","react":">=18.0.0"},"_npmOperationalInternal":{"tmp":"tmp/e-identity-nextjs_1.0.0_1779220449785_0.13993199802205192","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@credocentral/e-identity-nextjs","version":"1.0.1","keywords":["oauth2","oidc","nextjs","e-identity","etranzact"],"license":"MIT","_id":"@credocentral/e-identity-nextjs@1.0.1","maintainers":[{"name":"valenteeena","email":"toun.olayemi2@gmail.com"},{"name":"stephen.obi","email":"hello@credocentral.com"}],"dist":{"shasum":"499bdb1470e0758e5fb932ea28b9caf7ed7adb1c","tarball":"https://registry.npmjs.org/@credocentral/e-identity-nextjs/-/e-identity-nextjs-1.0.1.tgz","fileCount":32,"integrity":"sha512-XUJrY1/eSVIZ6jwl+t8KuBiHROtndysRQA3VHKJo3gdRuYfarfg/vqb+TxF+pcfBys+x+q3vq/WnYWTzGMgJpg==","signatures":[{"sig":"MEUCIQClfdQDDSpPNGxB+b0HeswVbeYgKsy8ATC5IOg1xEP7YAIgc/CEPDxMz9+R6Db4zq630Kgyg7u0ZEUPMKFcJl2d4J4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":264869},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./server":{"types":"./dist/server.d.ts","import":"./dist/server.js","require":"./dist/server.cjs"},"./handler":{"types":"./dist/handler.d.ts","import":"./dist/handler.js","require":"./dist/handler.cjs"},"./middleware":{"types":"./dist/middleware.d.ts","import":"./dist/middleware.js","require":"./dist/middleware.cjs"}},"gitHead":"f41bfb1f82279bd15dbff7af104d6b11124ee89f","scripts":{"build":"tsup","clean":"rm -rf dist","typecheck":"tsc --noEmit"},"_npmUser":{"name":"stephen.obi","email":"hello@credocentral.com"},"_npmVersion":"10.9.7","description":"Next.js SDK for e-identity OAuth2/OIDC authentication (App Router)","directories":{},"_nodeVersion":"22.22.2","dependencies":{"@credocentral/e-identity-core":"^1.0.0","@credocentral/e-identity-react":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"next":"^16.2.6","tsup":"*","typescript":"*","@types/react":"^19"},"peerDependencies":{"next":">=14.0.0","react":">=18.0.0"},"_npmOperationalInternal":{"tmp":"tmp/e-identity-nextjs_1.0.1_1779220867976_0.053293841324030256","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@credocentral/e-identity-nextjs","version":"1.0.2","description":"Next.js SDK for e-identity OAuth2/OIDC authentication (App Router)","keywords":["oauth2","oidc","nextjs","e-identity","etranzact"],"license":"MIT","type":"module","main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/index.js","require":"./dist/index.cjs","types":"./dist/index.d.ts"},"./server":{"import":"./dist/server.js","require":"./dist/server.cjs","types":"./dist/server.d.ts"},"./handler":{"import":"./dist/handler.js","require":"./dist/handler.cjs","types":"./dist/handler.d.ts"},"./middleware":{"import":"./dist/middleware.js","require":"./dist/middleware.cjs","types":"./dist/middleware.d.ts"}},"scripts":{"build":"tsup","typecheck":"tsc --noEmit","clean":"rm -rf dist"},"peerDependencies":{"next":">=14.0.0","react":">=18.0.0"},"dependencies":{"@credocentral/e-identity-core":"^1.0.0","@credocentral/e-identity-react":"^1.0.0"},"devDependencies":{"tsup":"*","typescript":"*","@types/react":"^19","next":"^16.2.6"},"_id":"@credocentral/e-identity-nextjs@1.0.2","gitHead":"657a1038da2e8b8a04600dbc7aaaef2d3b16cd5a","_nodeVersion":"22.22.2","_npmVersion":"10.9.7","dist":{"integrity":"sha512-sXvj7Bc2r2gErtgGTkzhy5lTUDk6U8zcMy6NuSk/HqxGb28/OijJzae7oOW+aIBEzdQVxhEx2HngyGkNnJq66g==","shasum":"04eb7b47636e60c97f382c0369c9c8afac46e15b","tarball":"https://registry.npmjs.org/@credocentral/e-identity-nextjs/-/e-identity-nextjs-1.0.2.tgz","fileCount":28,"unpackedSize":70182,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICIDcZXtQvV69bwkh8PKImFwO/wAVQ9BICoDmoFnCSiUAiBLaPeXlgJX0cM+rXWk2Pja720GjcRqo5AfW36vSE23ZQ=="}]},"_npmUser":{"name":"stephen.obi","email":"stephen.obi@etranzact.com"},"directories":{},"maintainers":[{"name":"valenteeena","email":"toun.olayemi2@gmail.com"},{"name":"stephen.obi","email":"stephen.obi@etranzact.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/e-identity-nextjs_1.0.2_1779467078322_0.8489448496201193"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-19T19:54:09.625Z","modified":"2026-05-22T16:24:38.593Z","1.0.0":"2026-05-19T19:54:09.924Z","1.0.1":"2026-05-19T20:01:08.154Z","1.0.2":"2026-05-22T16:24:38.463Z"},"license":"MIT","keywords":["oauth2","oidc","nextjs","e-identity","etranzact"],"description":"Next.js SDK for e-identity OAuth2/OIDC authentication (App Router)","maintainers":[{"name":"valenteeena","email":"toun.olayemi2@gmail.com"},{"name":"stephen.obi","email":"stephen.obi@etranzact.com"}],"readme":"# @credocentral/e-identity-nextjs\n\nNext.js SDK for **e-identity** — OAuth2/OIDC authentication for the App Router, with server-side session, route handler, middleware protection, and full MFA/forced-password-change support.\n\n## Features\n\n- App Router-native: server components, `cookies()`, and middleware\n- OAuth2 Authorization Code + PKCE (CSRF-safe state + verifier cookies)\n- HTTP-only session cookie (base64-encoded `TokenSet`)\n- `getSession()` for server components and Route Handlers\n- `GET /api/auth/[...eidentity]` route handler: `callback`, `logout`, `session`\n- `withEIdentityAuth` middleware: route-level protection + optional AAL2 (MFA) requirement\n- Re-exports `EIdentityProvider`, `useEIdentity`, `EIdentityCallback`, `EIdentityGuard` from the React SDK\n- Full TypeScript support\n\n## Installation\n\n```sh\nnpm install @credocentral/e-identity-nextjs @credocentral/e-identity-core @credocentral/e-identity-react\n```\n\nPeer dependencies: `next >=14`, `react >=18`.\n\n## Environment Variables\n\n```env\nNEXT_PUBLIC_E_IDENTITY_ISSUER=https://id.example.com\nNEXT_PUBLIC_E_IDENTITY_APP_ID=550e8400-e29b-41d4-a716-446655440000\n```\n\n## Quick Start\n\n### 1. Route Handler\n\nCreate `app/api/auth/[...eidentity]/route.ts`:\n\n```ts\nexport { GET, POST } from '@credocentral/e-identity-nextjs/handler';\n```\n\nThis exposes three endpoints automatically:\n\n| Path | Description |\n|---|---|\n| `GET /api/auth/callback` | Receives the authorization code, exchanges it for tokens, sets the session cookie |\n| `GET /api/auth/logout` | Revokes tokens and clears the session cookie |\n| `GET /api/auth/session` | Returns `{ user }` JSON — useful for client-side auth state checks |\n\n### 2. Middleware\n\nCreate `middleware.ts` at the project root:\n\n```ts\nimport { withEIdentityAuth } from '@credocentral/e-identity-nextjs/middleware';\n\nexport default withEIdentityAuth({\n  protectedRoutes: ['/dashboard/:path*', '/settings/:path*', '/admin/:path*'],\n  callbackPath: '/api/auth/callback',\n});\n\nexport const config = {\n  matcher: ['/dashboard/:path*', '/settings/:path*', '/admin/:path*'],\n};\n```\n\nUnauthenticated requests to protected routes are redirected to the authorization server with a fresh PKCE challenge. The state, verifier, and redirect URI are stored in short-lived HTTP-only cookies (10 min TTL).\n\n### 3. Server Component Session\n\n```tsx\nimport { getSession } from '@credocentral/e-identity-nextjs/server';\nimport { redirect } from 'next/navigation';\n\nexport default async function DashboardPage() {\n  const session = await getSession();\n  if (!session) redirect('/api/auth/login');\n\n  return <h1>Welcome, {session.user.name}</h1>;\n}\n```\n\n### 4. Client Components (optional)\n\nRe-exported from `@credocentral/e-identity-react` for client-side auth state:\n\n```tsx\n'use client';\nimport { useEIdentity } from '@credocentral/e-identity-nextjs';\n\nexport function UserMenu() {\n  const { user, logout } = useEIdentity();\n  return <button onClick={logout}>{user?.name}</button>;\n}\n```\n\n## `getSession()` — Session Object\n\n```ts\ninterface Session {\n  user: User;            // parsed JWT claims\n  accessToken: string;\n  refreshToken?: string;\n  expiresAt: number;     // Unix timestamp (seconds)\n  amr: string[];         // Authentication Method References, e.g. ['pwd', 'totp', 'mfa']\n  acr: string;           // Assurance level: 'aal1' | 'aal2'\n  mfaVerified: boolean;  // true when token is AAL2\n  forcePasswordChange: boolean; // true when user must change password\n}\n```\n\nReturns `null` when no session cookie is present or the token has expired.\n\n## `withEIdentityAuth` Options\n\n```ts\nwithEIdentityAuth({\n  /** Route patterns to protect. Default: ['/dashboard/:path*', '/settings/:path*'] */\n  protectedRoutes?: string[];\n\n  /** Path for your Next.js login page. Omit to redirect directly to the identity server. */\n  loginPath?: string;\n\n  /** Callback path to pass as `redirect_uri`. Default: '/api/auth/callback' */\n  callbackPath?: string;\n\n  /**\n   * Require AAL2 (MFA-verified token) for protected routes.\n   * - true: all protectedRoutes require AAL2\n   * - string[]: only these specific patterns require AAL2\n   * Default: false\n   */\n  requireMfa?: boolean | string[];\n})\n```\n\n### AAL2 Example\n\n```ts\nexport default withEIdentityAuth({\n  protectedRoutes: ['/dashboard/:path*', '/admin/:path*'],\n  requireMfa: ['/admin/:path*'],  // only /admin/* requires MFA\n});\n```\n\nUsers with an AAL1 token accessing `/admin/*` are redirected back to the authorization server to complete MFA.\n\n## Initiate Login (Server Action or Route)\n\nThe handler doesn't expose a `/login` route because the PKCE redirect is handled by the middleware. To add an explicit login button, initiate the redirect from a Server Action:\n\n```ts\n'use server';\nimport { generateVerifier, generateChallenge, generateState, generateNonce } from '@credocentral/e-identity-core';\nimport { cookies } from 'next/headers';\nimport { redirect } from 'next/navigation';\n\nexport async function login() {\n  const verifier = generateVerifier();\n  const challenge = await generateChallenge(verifier);\n  const state = generateState();\n  const nonce = generateNonce();\n  const redirectUri = `${process.env.NEXT_PUBLIC_APP_URL}/api/auth/callback`;\n\n  const jar = await cookies();\n  jar.set('e_identity_state', state, { httpOnly: true, sameSite: 'lax', maxAge: 600 });\n  jar.set('e_identity_verifier', verifier, { httpOnly: true, sameSite: 'lax', maxAge: 600 });\n  jar.set('e_identity_redirect_uri', redirectUri, { httpOnly: true, sameSite: 'lax', maxAge: 600 });\n\n  const params = new URLSearchParams({\n    response_type: 'code',\n    client_id: process.env.NEXT_PUBLIC_E_IDENTITY_APP_ID!,\n    redirect_uri: redirectUri,\n    scope: 'openid profile email',\n    state, nonce,\n    code_challenge: challenge,\n    code_challenge_method: 'S256',\n  });\n\n  redirect(`${process.env.NEXT_PUBLIC_E_IDENTITY_ISSUER}/identity/authorize?${params}`);\n}\n```\n\n## Exports\n\n| Import path | Exports |\n|---|---|\n| `@credocentral/e-identity-nextjs` | `EIdentityProvider`, `useEIdentity`, `EIdentityCallback`, `EIdentityGuard` (re-exported from React SDK) |\n| `@credocentral/e-identity-nextjs/server` | `getSession`, `encodeSessionCookie`, `SESSION_COOKIE`, `Session` type |\n| `@credocentral/e-identity-nextjs/handler` | `GET`, `POST` (Next.js Route Handler) |\n| `@credocentral/e-identity-nextjs/middleware` | `withEIdentityAuth`, `EIdentityMiddlewareConfig` |\n\n## Requirements\n\n- Next.js 14+ (App Router)\n- React 18+\n- `@credocentral/e-identity-core` and `@credocentral/e-identity-react` (installed automatically as dependencies)\n","readmeFilename":"README.md"}