{"_id":"@curiousnwbldr/finance-command-center-auth","_rev":"7-2d56c59333bf24763ab3b08ed492d8e7","name":"@curiousnwbldr/finance-command-center-auth","dist-tags":{"latest":"0.1.9"},"versions":{"0.1.0":{"name":"@curiousnwbldr/finance-command-center-auth","version":"0.1.0","_id":"@curiousnwbldr/finance-command-center-auth@0.1.0","maintainers":[{"name":"curiousnwbldr","email":"sandeep@vercel.com"}],"homepage":"https://github.com/curiousnwbldr/finance-command-center#readme","bugs":{"url":"https://github.com/curiousnwbldr/finance-command-center/issues"},"bin":{"command-center-auth":"dist/bin/install-auth-kit.js","finance-command-center-auth":"dist/bin/install-auth-kit.js"},"dist":{"shasum":"b093ca779bfd4b635546c776c317938f325a66ae","tarball":"https://registry.npmjs.org/@curiousnwbldr/finance-command-center-auth/-/finance-command-center-auth-0.1.0.tgz","fileCount":18,"integrity":"sha512-UCPahRMR2CBu3VU3WKmdzhp3XDXScn2K5lAwaGP2xMUzldIlKf9K21ujxOLsozUZYzL/whMa1qfPXzb1OeOQdw==","signatures":[{"sig":"MEYCIQCpz/wlM1FdWKJbnbwwwNVg7TT5Ahj+sg0f4oRlgjuOJwIhAOAW89M5QRCA6D+eYSmCT2r3lXObYmULEF+qf7/f7t/R","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":32353},"type":"module","gitHead":"c0b8863e6f61b437ba35f2ac9e597118fed6347d","private":false,"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","install:example":"node dist/bin/install-auth-kit.js install --target ./example-app --app-name \"Example Command Center\" --provider okta"},"_npmUser":{"name":"curiousnwbldr","email":"sandeep@vercel.com"},"repository":{"url":"git+https://github.com/curiousnwbldr/finance-command-center.git","type":"git"},"_npmVersion":"11.11.0","description":"Reusable Okta/Auth.js starter kit for finance command-center style Next.js applications.","directories":{},"_nodeVersion":"24.14.1","dependencies":{"next-auth":"^5.0.0-beta.30"},"publishConfig":{"access":"public","provenance":"false"},"_hasShrinkwrap":false,"packageManager":"pnpm@10.30.3","devDependencies":{"typescript":"^5.9.3","@types/node":"^22.15.21"},"peerDependencies":{"next":">=15","react":">=18","react-dom":">=18"},"_npmOperationalInternal":{"tmp":"tmp/finance-command-center-auth_0.1.0_1781648781090_0.9918749468058825","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@curiousnwbldr/finance-command-center-auth","version":"0.1.4","_id":"@curiousnwbldr/finance-command-center-auth@0.1.4","maintainers":[{"name":"curiousnwbldr","email":"sandeep@vercel.com"}],"homepage":"https://github.com/curiousnwbldr/finance-command-center#readme","bugs":{"url":"https://github.com/curiousnwbldr/finance-command-center/issues"},"bin":{"command-center-auth":"dist/bin/install-auth-kit.js","finance-command-center-auth":"dist/bin/install-auth-kit.js"},"dist":{"shasum":"da64ce503dec5d6a7eb042f156ea419c3a040384","tarball":"https://registry.npmjs.org/@curiousnwbldr/finance-command-center-auth/-/finance-command-center-auth-0.1.4.tgz","fileCount":18,"integrity":"sha512-TVgUWQj82+C/p9CVbQfXIvj5oiVGW0NuneMNQO7Za7Vy3eM5KgfU0Cvu8ycepNNV07yyMMwOIxC5u/iryya74A==","signatures":[{"sig":"MEUCIQDy7RErm8I0B+psjc0GsokQWGXGA0C6NfmOPuHfmq6ElQIgYtZXFGIIGURkRSdSITptk/qdTWiSZkNNYMh01IVozkE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@curiousnwbldr%2ffinance-command-center-auth@0.1.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":32352},"type":"module","gitHead":"6238a3404337c87b8bd85d743772ce1eace96a72","private":false,"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","install:example":"node dist/bin/install-auth-kit.js install --target ./example-app --app-name \"Example Command Center\" --provider okta"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2c5bc2d8-a223-4e51-9b9f-9cba349ba551"}},"repository":{"url":"git+https://github.com/curiousnwbldr/finance-command-center.git","type":"git"},"_npmVersion":"11.13.0","description":"Reusable Okta/Auth.js starter kit for finance command-center style Next.js applications.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"next-auth":"^5.0.0-beta.30"},"publishConfig":{"access":"public","provenance":"true"},"_hasShrinkwrap":false,"packageManager":"pnpm@10.30.3","devDependencies":{"typescript":"^5.9.3","@types/node":"^22.15.21"},"peerDependencies":{"next":">=15","react":">=18","react-dom":">=18"},"_npmOperationalInternal":{"tmp":"tmp/finance-command-center-auth_0.1.4_1781650565204_0.9605063311814661","host":"s3://npm-registry-packages-npm-production"}},"0.1.5":{"name":"@curiousnwbldr/finance-command-center-auth","version":"0.1.5","_id":"@curiousnwbldr/finance-command-center-auth@0.1.5","maintainers":[{"name":"curiousnwbldr","email":"sandeep@vercel.com"}],"homepage":"https://github.com/curiousnwbldr/finance-command-center#readme","bugs":{"url":"https://github.com/curiousnwbldr/finance-command-center/issues"},"bin":{"command-center-auth":"dist/bin/install-auth-kit.js","finance-command-center-auth":"dist/bin/install-auth-kit.js"},"dist":{"shasum":"f5c6b12d77a0e306936b9b3e53f6aabf9d79f8ed","tarball":"https://registry.npmjs.org/@curiousnwbldr/finance-command-center-auth/-/finance-command-center-auth-0.1.5.tgz","fileCount":18,"integrity":"sha512-QfrSRBfsd+9f7A2EUeZ6eVL5BsGVztJby9G1jUUCLDJijCyd650HaO962J74rC2h7OZQrxMM8xnqG7/6wiIdpQ==","signatures":[{"sig":"MEUCIH2l21e4275yGeVuPPKYWwZX0/H6s5/SW1hRtfAINVz3AiEAl5Wk42yoGKaX7xqXxAl5t58YplWsQHwY0H1257qPEGA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@curiousnwbldr%2ffinance-command-center-auth@0.1.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":32689},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"465b4b23d2ac92d59a2dcb45914145f41bdea6bc","private":false,"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","install:example":"node dist/bin/install-auth-kit.js install --target ./example-app --app-name \"Example Command Center\" --provider okta"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2c5bc2d8-a223-4e51-9b9f-9cba349ba551"}},"repository":{"url":"git+https://github.com/curiousnwbldr/finance-command-center.git","type":"git"},"_npmVersion":"11.13.0","description":"Reusable Okta/Auth.js starter kit for finance command-center style Next.js applications.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"next-auth":"^5.0.0-beta.30"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"packageManager":"pnpm@10.30.3","devDependencies":{"typescript":"^5.9.3","@types/node":"^25.9.3"},"peerDependencies":{"next":">=15","react":">=18","react-dom":">=18"},"_npmOperationalInternal":{"tmp":"tmp/finance-command-center-auth_0.1.5_1781651731265_0.8223370999718631","host":"s3://npm-registry-packages-npm-production"}},"0.1.6":{"name":"@curiousnwbldr/finance-command-center-auth","version":"0.1.6","_id":"@curiousnwbldr/finance-command-center-auth@0.1.6","maintainers":[{"name":"curiousnwbldr","email":"sandeep@vercel.com"}],"homepage":"https://github.com/curiousnwbldr/finance-command-center#readme","bugs":{"url":"https://github.com/curiousnwbldr/finance-command-center/issues"},"bin":{"command-center-auth":"dist/bin/install-auth-kit.js","finance-command-center-auth":"dist/bin/install-auth-kit.js"},"dist":{"shasum":"ff732008111108d1df0f57b0c074b4217baa7f9e","tarball":"https://registry.npmjs.org/@curiousnwbldr/finance-command-center-auth/-/finance-command-center-auth-0.1.6.tgz","fileCount":18,"integrity":"sha512-niuYLiqEloBmVgBRpytDRx4SQMeYN381MEKOf/LA5weNwkbINnBoVFrAv1LVLM5Hy+YYLZ7BGd+5AopvEfGDdg==","signatures":[{"sig":"MEQCIDov8RldZVVNrudC2iWIstJXPxLELagL/DakxCgSSDmLAiAeqazwayFYUvWZLRo4lRtsXZ4aG60/uFB/n6RP/KXZrA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@curiousnwbldr%2ffinance-command-center-auth@0.1.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":32687},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"80aee49f4a39870e69a2376542540f4cb5dd73d5","private":false,"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","install:example":"node dist/bin/install-auth-kit.js install --target ./example-app --app-name \"Example Command Center\" --provider okta"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2c5bc2d8-a223-4e51-9b9f-9cba349ba551"}},"repository":{"url":"git+https://github.com/curiousnwbldr/finance-command-center.git","type":"git"},"_npmVersion":"11.13.0","description":"Reusable Okta/Auth.js starter kit for finance command-center style Next.js applications.","directories":{},"_nodeVersion":"24.16.0","dependencies":{},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"packageManager":"pnpm@10.30.3","devDependencies":{"typescript":"^5.9.3","@types/node":"^25.9.3"},"peerDependencies":{"next":">=15","react":">=18","next-auth":"^5.0.0-beta.31","react-dom":">=18"},"_npmOperationalInternal":{"tmp":"tmp/finance-command-center-auth_0.1.6_1781655303509_0.10169050499676646","host":"s3://npm-registry-packages-npm-production"}},"0.1.7":{"name":"@curiousnwbldr/finance-command-center-auth","version":"0.1.7","keywords":["nextjs","authjs","next-auth","okta","auth0","starter-kit","authentication","command-center","finance"],"license":"MIT","_id":"@curiousnwbldr/finance-command-center-auth@0.1.7","maintainers":[{"name":"curiousnwbldr","email":"sandeep@vercel.com"}],"homepage":"https://github.com/curiousnwbldr/finance-command-center#readme","bugs":{"url":"https://github.com/curiousnwbldr/finance-command-center/issues"},"bin":{"command-center-auth":"dist/bin/install-auth-kit.js","finance-command-center-auth":"dist/bin/install-auth-kit.js"},"dist":{"shasum":"8d631036b56587cc96e59071ff2302a0e9388abf","tarball":"https://registry.npmjs.org/@curiousnwbldr/finance-command-center-auth/-/finance-command-center-auth-0.1.7.tgz","fileCount":18,"integrity":"sha512-ZiA0r1cz9ERxFSILs6YGlCh+MY4KR5P9nsKst75kOc3CeSYmWSytgHVF5eOC5L0oiowRJZ4z3bjXZ3S6s0L8xg==","signatures":[{"sig":"MEYCIQCXAj00n40Cws2DBax/2j6T3Eyxqum2DC6my1gxTZg0BgIhAJDU/NZEBmIlm8JJ9ki34f1jDatxYHUu9zyGQoyFmEBF","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@curiousnwbldr%2ffinance-command-center-auth@0.1.7","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":32905},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"7275321102bc418b8d8e948e809915fecbb31789","private":false,"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","install:example":"node dist/bin/install-auth-kit.js install --target ./example-app --app-name \"Example Command Center\" --provider okta"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2c5bc2d8-a223-4e51-9b9f-9cba349ba551"}},"repository":{"url":"git+https://github.com/curiousnwbldr/finance-command-center.git","type":"git"},"_npmVersion":"11.13.0","description":"Reusable Okta/Auth.js starter kit for finance command-center style Next.js applications.","directories":{},"_nodeVersion":"24.16.0","dependencies":{},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"packageManager":"pnpm@10.30.3","devDependencies":{"typescript":"^5.9.3","@types/node":"^25.9.3"},"peerDependencies":{"next":">=15","react":">=18","next-auth":"^5.0.0-beta.31","react-dom":">=18"},"_npmOperationalInternal":{"tmp":"tmp/finance-command-center-auth_0.1.7_1781657428178_0.29380896931729583","host":"s3://npm-registry-packages-npm-production"}},"0.1.8":{"name":"@curiousnwbldr/finance-command-center-auth","version":"0.1.8","keywords":["nextjs","authjs","next-auth","okta","auth0","starter-kit","authentication","command-center","finance"],"license":"MIT","_id":"@curiousnwbldr/finance-command-center-auth@0.1.8","maintainers":[{"name":"curiousnwbldr","email":"sandeep@vercel.com"}],"homepage":"https://github.com/curiousnwbldr/finance-command-center#readme","bugs":{"url":"https://github.com/curiousnwbldr/finance-command-center/issues"},"bin":{"command-center-auth":"dist/bin/install-auth-kit.js","finance-command-center-auth":"dist/bin/install-auth-kit.js"},"dist":{"shasum":"7c7b7415ca8aa0e0c8ab03bb02535282e439ffba","tarball":"https://registry.npmjs.org/@curiousnwbldr/finance-command-center-auth/-/finance-command-center-auth-0.1.8.tgz","fileCount":19,"integrity":"sha512-0B92jjo+NSuOkY6XPCudwHPwBqBT0CSTgMv0BXiRsUdIcPkjZfSJZb1PxuGPfEessLS8RBNQzaNb8AYY9/KIQA==","signatures":[{"sig":"MEUCIFN8ad+hqLKmureiaKPhgXszNpudI6F7kjsI9s6uRMVXAiEA1j23Yn82K7dLUr8+hs6uMuXSZ//vaXsAR8Chb4nhgWU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@curiousnwbldr%2ffinance-command-center-auth@0.1.8","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":54235},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"8eaab7280a518789fe30e39ab21003e10ddc3fbb","private":false,"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","install:example":"node dist/bin/install-auth-kit.js install --target ./example-app --app-name \"Example Command Center\" --provider okta"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2c5bc2d8-a223-4e51-9b9f-9cba349ba551"}},"repository":{"url":"git+https://github.com/curiousnwbldr/finance-command-center.git","type":"git"},"_npmVersion":"11.13.0","description":"Reusable Okta/Auth.js starter kit for finance command-center style Next.js applications.","directories":{},"_nodeVersion":"24.16.0","dependencies":{},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"packageManager":"pnpm@10.30.3","devDependencies":{"typescript":"^5.9.3","@types/node":"^25.9.3"},"peerDependencies":{"next":">=15","react":">=18","next-auth":"^5.0.0-beta.31","react-dom":">=18"},"_npmOperationalInternal":{"tmp":"tmp/finance-command-center-auth_0.1.8_1781661185158_0.5459335111421364","host":"s3://npm-registry-packages-npm-production"}},"0.1.9":{"name":"@curiousnwbldr/finance-command-center-auth","version":"0.1.9","private":false,"type":"module","description":"Reusable Okta/Auth.js starter kit for finance command-center style Next.js applications.","license":"MIT","keywords":["nextjs","authjs","next-auth","okta","auth0","starter-kit","authentication","command-center","finance"],"packageManager":"pnpm@10.30.3","repository":{"type":"git","url":"git+https://github.com/curiousnwbldr/finance-command-center.git"},"homepage":"https://github.com/curiousnwbldr/finance-command-center#readme","bugs":{"url":"https://github.com/curiousnwbldr/finance-command-center/issues"},"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"bin":{"finance-command-center-auth":"dist/bin/install-auth-kit.js","command-center-auth":"dist/bin/install-auth-kit.js"},"publishConfig":{"access":"public","provenance":true},"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","install:example":"node dist/bin/install-auth-kit.js install --target ./example-app --app-name \"Example Command Center\" --provider okta"},"dependencies":{},"peerDependencies":{"next":">=15","next-auth":"^5.0.0-beta.31","react":">=18","react-dom":">=18"},"devDependencies":{"@types/node":"^25.9.3","typescript":"^5.9.3"},"gitHead":"6e127f637a7ac7d9f7f7c993c6c1519069390957","_id":"@curiousnwbldr/finance-command-center-auth@0.1.9","_nodeVersion":"24.16.0","_npmVersion":"11.13.0","dist":{"integrity":"sha512-i8887/dxYbCQYEO4k0eJ93f3Xf6Q+UD01wDX+sDB28sWIeolAV01lLMLf+8V0a13hEZv4PUHCs84XukIwt1ugA==","shasum":"3363ecbf3dcfaa1e876dbe2ed1afc70f0cb3505c","tarball":"https://registry.npmjs.org/@curiousnwbldr/finance-command-center-auth/-/finance-command-center-auth-0.1.9.tgz","fileCount":20,"unpackedSize":58491,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@curiousnwbldr%2ffinance-command-center-auth@0.1.9","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIDIaFef2ui+EcJPQvdEbsC1YMQvAEyJjd0bayPgNp/SMAiBe42u/Kdgk5hkV/tDbz/qOSxbmyhE2aWWDjDLoQZbvXw=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2c5bc2d8-a223-4e51-9b9f-9cba349ba551"}},"directories":{},"maintainers":[{"name":"curiousnwbldr","email":"sandeep@vercel.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/finance-command-center-auth_0.1.9_1781663832193_0.05450113187018202"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-16T22:26:20.910Z","modified":"2026-06-17T02:37:12.643Z","0.1.0":"2026-06-16T22:26:21.218Z","0.1.4":"2026-06-16T22:56:05.362Z","0.1.5":"2026-06-16T23:15:31.422Z","0.1.6":"2026-06-17T00:15:03.619Z","0.1.7":"2026-06-17T00:50:28.350Z","0.1.8":"2026-06-17T01:53:05.303Z","0.1.9":"2026-06-17T02:37:12.336Z"},"bugs":{"url":"https://github.com/curiousnwbldr/finance-command-center/issues"},"license":"MIT","homepage":"https://github.com/curiousnwbldr/finance-command-center#readme","keywords":["nextjs","authjs","next-auth","okta","auth0","starter-kit","authentication","command-center","finance"],"repository":{"type":"git","url":"git+https://github.com/curiousnwbldr/finance-command-center.git"},"description":"Reusable Okta/Auth.js starter kit for finance command-center style Next.js applications.","maintainers":[{"name":"curiousnwbldr","email":"sandeep@vercel.com"}],"readme":"# Command Center Auth Kit\n\nReusable Okta/Auth.js starter kit for Next.js App Router applications.\n\nThis package extracts the reusable authentication pattern from Polaris without carrying over Polaris-specific SOX authorization, role catalogs, dashboards, agents, activity logging, or UI primitives. It is intended to give your team a consistent starting point for command-center style apps where users authenticate once through Okta and then land in a protected application shell.\n\n## Quick Start\n\nGenerate authentication scaffolding for a Next.js App Router application:\n\n```bash\npnpm dlx @curiousnwbldr/finance-command-center-auth install \\\n  --target ./my-app \\\n  --app-name \"Finance Command Center\"\n```\n\nOr with npm:\n\n```bash\nnpx @curiousnwbldr/finance-command-center-auth install \\\n  --target ./my-app \\\n  --app-name \"Finance Command Center\"\n```\n\nOkta is the default provider. Use `--provider auth0` or `--provider both` when the target app should use a different provider setup.\n\n### Programmatic Usage\n\nThe installer can also be imported as a library:\n\n```ts\nimport { installAuthKit } from \"@curiousnwbldr/finance-command-center-auth\"\n\nawait installAuthKit({\n  target: \"./my-app\",\n  appName: \"Finance Command Center\",\n  provider: \"okta\"\n})\n```\n\n### Peer Dependencies\n\nThe target application is expected to use:\n\n```bash\npnpm add next react react-dom next-auth\n```\n\n\n## When To Use It\n\nUse this kit when:\n\n- the target app is a Next.js App Router app\n- the target app should authenticate through Okta\n- you want a consistent login/session/proxy baseline across internal apps\n- you do not want to copy Polaris-specific SOX authorization logic into every project\n- your team needs a repeatable CLI command instead of hand-copying auth files\n\nDo not use this kit as-is when:\n\n- the target app is not Next.js App Router\n- you need a full central identity broker or token exchange service\n- you need SAML-only flows instead of OIDC/OAuth\n- you need app-specific authorization already wired end to end\n\n## Recommended Portfolio Architecture\n\nFor a broader app portfolio, keep authentication centralized:\n\n1. Users authenticate into the command center through Okta.\n2. The command center stores the canonical user profile, access status, and global role or entitlement state.\n3. Downstream apps either install this same kit or trust a command-center-issued session/token.\n4. App-specific authorization remains local to each app.\n\nThat separation matters. Authentication answers “who is this user?” App authorization answers “what can this user do in this app?”\n\n## Package Layout\n\n```text\nfinance-command-center-auth/\n  package.json\n  pnpm-lock.yaml\n  tsconfig.json\n  README.md\n  src/\n    index.ts\n    bin/\n      install-auth-kit.ts\n    install/\n      install-auth-kit.ts\n      template.ts\n      types.ts\n  templates/\n    next-app-router/\n      AUTH_SETUP_HANDOFF.md.hbs\n      auth.ts.hbs\n      proxy.ts.hbs\n      env.example.hbs\n      app/\n        login/page.tsx.hbs\n        api/auth/[...nextauth]/route.ts.hbs\n        types/next-auth.d.ts.hbs\n```\n\n## Package Files\n\n### `package.json`\n\nDefines the package name, build scripts, dependencies, peer dependencies, and CLI binary.\n\nImportant fields:\n\n- `bin.finance-command-center-auth`: primary CLI command exposed by the package.\n- `bin.command-center-auth`: compatibility CLI alias for shorter internal usage.\n- `peerDependencies.next`, `next-auth`, `react`, `react-dom`: required by the generated application.\n- The package intentionally ships with no runtime dependencies.\n\n### `tsconfig.json`\n\nBuilds the CLI and installer source into `dist/`.\n\nThis package uses ESM and NodeNext module resolution because the CLI runs under modern Node and imports generated `.js` outputs after TypeScript compilation.\n\n### `src/bin/install-auth-kit.ts`\n\nThe CLI entry point.\n\nIt parses commands such as:\n\n```bash\nfinance-command-center-auth install --target /path/to/app --app-name \"Finance Command Center\"\n```\n\nSupported options:\n\n- `--target <path>`: required. Target Next.js app folder.\n- `--app-name <name>`: display name used on the generated login page.\n- `--provider <okta|auth0|both>`: provider mode. Defaults to `okta`.\n- `--dashboard-path <path>`: post-login redirect path. Defaults to `/dashboard`.\n- `--no-proxy`: skip generating `proxy.ts`.\n- `--force`: overwrite existing generated files.\n- `--help`: print usage.\n\n### `src/install/install-auth-kit.ts`\n\nThe installer implementation.\n\nResponsibilities:\n\n- resolves the target app path\n- loads templates from `templates/next-app-router`\n- renders template variables\n- creates parent directories\n- writes generated files\n- skips existing files unless `--force` is provided\n- appends the auth block to `.env.example`\n\nIt intentionally does not edit existing source files in place, except appending `.env.example`. This makes the install safer and easier to review in Git.\n\n### `src/install/template.ts`\n\nSmall template renderer.\n\nIt replaces variables like:\n\n```text\n{{APP_NAME}}\n{{DASHBOARD_PATH}}\n{{OKTA_ENABLED_DEFAULT}}\n```\n\nIt throws if a template references a variable that was not provided.\n\n### `src/install/types.ts`\n\nShared TypeScript types for the installer:\n\n- `ProviderMode`\n- `InstallOptions`\n- `TemplateContext`\n\n### `src/index.ts`\n\nExports the installer and public types for programmatic usage.\n\nThis allows a future repo or script to import:\n\n```ts\nimport { installAuthKit } from \"@curiousnwbldr/finance-command-center-auth\"\n```\n\n## Generated Target Files\n\nThe CLI generates the following files inside the target app.\n\n### `auth.ts`\n\nAuth.js/NextAuth configuration.\n\nWhat it does:\n\n- configures Okta when `OKTA_ENABLED=true`\n- optionally configures Auth0 when `AUTH0_ENABLED=true`\n- uses JWT sessions\n- sets `/login` as the sign-in and error page\n- creates session claims from a profile hook\n- blocks inactive users when `profile.isActive === false`\n\nImportant extension hooks:\n\n```ts\nasync function onUserSignIn(input) { ... }\nasync function loadUserProfile(email) { ... }\nfunction buildSessionClaims(profile) { ... }\n```\n\nExpected target-app changes:\n\n- connect `onUserSignIn` to your user table or command-center profile API\n- connect `loadUserProfile` to your user table or entitlement service\n- add any required audit logging inside `onUserSignIn`\n- shape `buildSessionClaims` to match your app’s authorization needs\n\nConstraints:\n\n- keep provider secrets on the server only\n- do not expose `OKTA_CLIENT_SECRET` through `NEXT_PUBLIC_*`\n- avoid importing app client code into `auth.ts`\n- keep DB calls resilient because Auth callbacks run on every session refresh\n\n### `app/login/page.tsx`\n\nLogin page for the target app.\n\nWhat it does:\n\n- renders a simple provider selection screen\n- supports Okta\n- optionally supports Auth0\n- redirects to `--dashboard-path` after sign-in\n- signs out a prior session before switching providers\n- reads Auth.js errors from the URL\n\nConstraints:\n\n- this is intentionally unbranded and dependency-light\n- it uses plain Tailwind-style class names\n- it does not import Polaris UI primitives\n- the target app may restyle it after install\n\n### `app/api/auth/[...nextauth]/route.ts`\n\nAuth.js route handler.\n\nWhat it does:\n\n```ts\nimport { handlers } from \"@/auth\"\nexport const { GET, POST } = handlers\n```\n\nConstraints:\n\n- the target app must support the `@/` alias or change the import path\n- this route must remain server-only\n- Okta callback URLs must point to this route\n\n### `app/types/next-auth.d.ts`\n\nNextAuth type augmentation.\n\nWhat it does:\n\n- adds `user.id`\n- adds `user.provider`\n- adds `user.commandCenterClaims`\n- adds matching JWT fields\n\nConstraints:\n\n- keep this file included by the target app’s TypeScript config\n- update `CommandCenterClaims` when your role/entitlement payload changes\n- keep the claims small enough for JWT session storage\n\n### `proxy.ts`\n\nOptional route guard for Next.js 16.\n\nWhat it does:\n\n- allows `_next` assets and `/api/auth/*`\n- redirects unauthenticated users to `/login`\n- redirects active logged-in users away from `/login` to the dashboard path\n- blocks inactive sessions\n\nConstraints:\n\n- Next.js 16 uses `proxy.ts`; older apps may use `middleware.ts`\n- if the target app already has a proxy/middleware, merge manually\n- add public routes explicitly\n- keep proxy imports edge-safe\n\n### `AUTH_SETUP_HANDOFF.md`\n\nApp-owner handoff document.\n\nWhat it does:\n\n- summarizes the authentication scaffold that was installed\n- lists the files added or updated\n- records setup decisions such as app name, provider, dashboard route, and proxy generation\n- identifies IT/IAM, deployment, app-team, and security-review follow-up items\n- documents required environment variables, redirect URIs, and validation steps\n\nConstraints:\n\n- the installer generates this file automatically\n- generated values should be reviewed before production use\n- unknown manual setup items should remain marked as `Open`\n- never add real provider secrets to this document\n\n### `.env.example`\n\nThe installer appends an auth environment block:\n\n```env\nAUTH_SECRET=\nNEXTAUTH_SECRET=\nNEXTAUTH_URL=\nOKTA_ENABLED=true\nNEXT_PUBLIC_OKTA_ENABLED=true\nOKTA_CLIENT_ID=\nOKTA_CLIENT_SECRET=\nOKTA_ISSUER=\n```\n\nConstraints:\n\n- production values belong in the deployment environment, not committed files\n- `NEXTAUTH_URL` must match the deployed app origin\n- Okta redirect URIs must match the deployed app callback URL\n\n## Target App Prerequisites\n\nThe target app should have:\n\n* Next.js App Router\n* TypeScript\n* React\n* React DOM\n* Auth.js / NextAuth\n* a working `@/` alias, or manually adjust generated imports\n\nInstall required peer dependencies in the target app:\n\n```bash\npnpm add next react react-dom next-auth\n```\n\nIf the target app does not use Tailwind-style utility classes, the generated login page will still work structurally, but it will need styling changes.\n\n## Okta Setup\n\nThis kit requires an Okta OIDC application/client before a target app can use Okta sign-in.\n\nFor production use, ask the IT / IAM team to create and own the Okta application. Developers should not reuse a personal Okta client, a Polaris client, or a client from another app unless IT has explicitly approved that shared model.\n\nRecommended operating model:\n\n- Create a separate Okta OIDC application per app and environment, for example:\n  - `Finance Command Center - Dev`\n  - `Finance Command Center - Preview`\n  - `Finance Command Center - Production`\n- Assign ownership to the IT / IAM team or the platform identity owner.\n- Restrict app assignment to the correct Okta groups.\n- Store client secrets only in the deployment platform or secret manager.\n- Rotate client secrets through IT change control.\n- Document the redirect URIs and app owner in the target app runbook.\n\nWhy separate Okta clients are recommended:\n\n- each app has its own redirect URIs\n- compromised secrets can be rotated without affecting other apps\n- production access can be controlled independently from dev/preview access\n- audit logs map cleanly to the consuming app\n- decommissioning an app does not disturb unrelated applications\n\nWhen a shared Okta client may be acceptable:\n\n- the organization has a true central command-center identity app\n- all downstream apps rely on a command-center-issued session or token\n- IT has approved all redirect URIs, token claims, and access boundaries\n- app teams understand that rotating the shared secret impacts every consumer\n\nIn Okta, create or update an OIDC web application.\n\nRecommended settings:\n\n- Sign-in redirect URI:\n\n```text\nhttps://your-app.example.com/api/auth/callback/okta\n```\n\n- Local development redirect URI:\n\n```text\nhttp://localhost:3000/api/auth/callback/okta\n```\n\n- Sign-out redirect URI:\n\n```text\nhttps://your-app.example.com/login\n```\n\n- Grant type:\n\n```text\nAuthorization Code\n```\n\n- Scopes:\n\n```text\nopenid profile email\n```\n\nSet target app environment variables:\n\n```env\nOKTA_ENABLED=true\nNEXT_PUBLIC_OKTA_ENABLED=true\nOKTA_CLIENT_ID=...\nOKTA_CLIENT_SECRET=...\nOKTA_ISSUER=https://your-org.okta.com\nAUTH_SECRET=...\nNEXTAUTH_SECRET=...\nNEXTAUTH_URL=https://your-app.example.com\n```\n\nGenerate a secret:\n\n```bash\nopenssl rand -base64 32\n```\n\n## Build And Use The Kit\n\nFrom this package folder:\n\n```bash\npnpm install\npnpm build\n```\n\nUse from the published package:\n\n```bash\npnpm dlx @curiousnwbldr/finance-command-center-auth install \\\n  --target /path/to/next-app \\\n  --app-name \"Finance Command Center\" \\\n  --provider okta \\\n  --dashboard-path /dashboard\n```\n\nInstall into a target app as a dependency:\n\n```bash\npnpm add @curiousnwbldr/finance-command-center-auth\npnpm exec finance-command-center-auth install --target . --app-name \"Finance Command Center\"\n```\n\nInstall into a target app:\n\n```bash\nnode dist/bin/install-auth-kit.js install \\\n  --target /path/to/next-app \\\n  --app-name \"Finance Command Center\" \\\n  --provider okta \\\n  --dashboard-path /dashboard\n```\n\nInstall both Okta and Auth0 buttons:\n\n```bash\nnode dist/bin/install-auth-kit.js install \\\n  --target /path/to/next-app \\\n  --app-name \"Audit Command Center\" \\\n  --provider both\n```\n\nSkip proxy generation:\n\n```bash\nnode dist/bin/install-auth-kit.js install \\\n  --target /path/to/next-app \\\n  --no-proxy\n```\n\nOverwrite existing generated files:\n\n```bash\nnode dist/bin/install-auth-kit.js install \\\n  --target /path/to/next-app \\\n  --force\n```\n\n## Publishing\n\nThis package is published through npm Trusted Publishing and provenance.\n\nExample release:\n\n```bash\nnpm version patch\ngit push origin main --follow-tags\n\nPackage:\n\n```text\n@curiousnwbldr/finance-command-center-auth\n```\n\nPublishing workflow:\n\n```text\n.github/workflows/publish-auth.yml\n```\n\nRelease process:\n\n```bash\nnpm version patch\ngit push origin main --follow-tags\n```\n\nGitHub Actions builds the package and publishes it automatically using npm Trusted Publishing.\n\nConsumers can verify provenance and registry attestations with:\n\n```bash\nnpm audit signatures\n```\n\n## Recommended Team Workflow\n\n1. Put this package in its own repo.\n2. Keep it private until the API stabilizes.\n3. Require changes through PR review because auth templates are security-sensitive.\n4. Tag releases, for example `v0.1.0`.\n5. Team members install from the built CLI or private package.\n6. Each target app reviews generated changes before committing.\n\n## Security Constraints\n\n- Never commit real Okta client secrets.\n- Keep user provisioning and role assignment outside the generated starter unless the target app owns that model.\n- Keep JWT claims small and non-sensitive.\n- Avoid putting broad entitlements or sensitive metadata into client-readable session fields.\n- Treat `proxy.ts` as a first safety net, not the only authorization layer.\n- API routes should still perform their own authorization checks.\n- If a target app has admin-only areas, add app-specific route and API guards after installing the kit.\n\n## What This Kit Does Not Provide\n\nThis kit does not include:\n\n- a user database schema\n- team or role administration UI\n- app-specific permission checks\n- centralized token exchange for downstream apps\n- SCIM provisioning\n- group-to-role mapping\n- audit-log persistence\n- session revocation beyond the generated profile hook\n\nThose should be implemented by the command center or target app based on your operating model.\n\n## Common Customizations\n\n### Add user table lookup\n\nUpdate `loadUserProfile` in generated `auth.ts`:\n\n```ts\nasync function loadUserProfile(email: string): Promise<UserProfile | null> {\n  return await getUserByEmail(email)\n}\n```\n\n### Add group or role claims\n\nUpdate `buildSessionClaims`:\n\n```ts\nfunction buildSessionClaims(profile: UserProfile | null) {\n  return {\n    roles: profile?.roles ?? [],\n    apps: profile?.apps ?? [],\n  }\n}\n```\n\n### Add login audit\n\nUpdate `onUserSignIn`:\n\n```ts\nawait writeLoginEvent({\n  email: input.email,\n  provider: input.provider,\n  eventType: \"login\",\n})\n```\n\n### Add public routes\n\nUpdate generated `proxy.ts`:\n\n```ts\nif (pathname.startsWith(\"/public-docs\")) {\n  return NextResponse.next()\n}\n```\n\n## Troubleshooting\n\n### Okta redirects back to an error page\n\nCheck:\n\n- `NEXTAUTH_URL`\n- Okta redirect URI\n- `OKTA_ISSUER`\n- `OKTA_CLIENT_ID`\n- `OKTA_CLIENT_SECRET`\n- whether `OKTA_ENABLED=true`\n\n### The Okta button is disabled\n\nSet:\n\n```env\nNEXT_PUBLIC_OKTA_ENABLED=true\n```\n\nThe server provider uses `OKTA_ENABLED`; the client login button uses `NEXT_PUBLIC_OKTA_ENABLED`.\n\n### TypeScript cannot resolve `@/auth`\n\nThe target app may not use the `@/` alias. Either add the alias to `tsconfig.json` or change generated imports to relative imports.\n\n### Login works but app-specific access is missing\n\nThe kit only authenticates. Wire `commandCenterClaims` into the target app’s authorization model.\n\n### Existing proxy or middleware conflicts\n\nUse:\n\n```bash\n--no-proxy\n```\n\nThen manually merge the generated route-guard logic into the target app’s existing proxy/middleware.\n\n## Current Status\n\nThis package has been:\n\n- build-tested\n- type-checked\n- published through npm Trusted Publishing\n- validated as a CLI package\n- validated as a library package\n- smoke-tested against a clean Next.js target folder\n- reviewed for shipped runtime dependencies\n\nApplication-specific security review is still recommended before production deployment.\n","readmeFilename":"README.md"}