{"_id":"@activescott/auth","_rev":"18-ed85341da53e5770b011b8eb37e0c82d","name":"@activescott/auth","dist-tags":{"latest":"5.6.0"},"versions":{"0.1.1":{"name":"@activescott/auth","version":"0.1.1","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@0.1.1","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"0206ec71a21fb986ddbf16d582eaed6f0d538367","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-0.1.1.tgz","fileCount":25,"integrity":"sha512-B0oZMpVSW4FeWimpC+m8HxSWM/36OBfKxGN4Df3TDoXuZIUZTJ11Fbsq8wfuA7tXzcOoUgikw1yusJ5fNVgYKg==","signatures":[{"sig":"MEYCIQDatwwPo4mUT4NTm394UE9OKqofhsyyd60B8YgPMfFnswIhAKZ1JDF6b+7E1uXVSiQL5UtN17vmOVFZL/OY9yEUSoRm","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":58885},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"5a64c5f74cb44b53a723a3c507c43ee46ff256e5","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"activescott","email":"scott@willeke.com"},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"10.9.4","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"22.22.1","dependencies":{"zod":"^4.3.6","jsonwebtoken":"^9.0.2"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.16","typescript":"^5.7.2","@types/node":"^22","@types/jsonwebtoken":"^9.0.10"},"_npmOperationalInternal":{"tmp":"tmp/auth_0.1.1_1773687676617_0.10118039239279963","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@activescott/auth","version":"0.1.3","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@0.1.3","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"787789430ce3c322af4b5dfb78d872239795fda8","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-0.1.3.tgz","fileCount":27,"integrity":"sha512-FYXdvM5rlCDACTlDbnx2zerM8ZIqC/f3BT0/jZ+Jbti+vEttE33r4EwjYTFzswUW5MuPi/SO30U2D8WjmPcW9w==","signatures":[{"sig":"MEUCIB8rSFdNWms3BLtc+9MWEFNWRyipRRsbFSbB9G1NxerEAiEAnSub5XJjmTIwfe/qTnuzTIesgHG8Z7on6R0yuheDt0Q=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@activescott%2fauth@0.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":63560},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"a6c9490bc1c9257189044f5bd9679791e3c91ee2","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f149a3bb-4c70-4797-a4c8-ae9865aeaa50"}},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"11.11.0","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.3.6","jsonwebtoken":"^9.0.2"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.16","typescript":"^5.7.2","@types/node":"^22","@types/jsonwebtoken":"^9.0.10"},"_npmOperationalInternal":{"tmp":"tmp/auth_0.1.3_1778342282512_0.17329411707278664","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@activescott/auth","version":"1.0.0","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@1.0.0","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"fe04be49e68ebf86f6a6af62e9f2b84c19dd9ca8","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-1.0.0.tgz","fileCount":35,"integrity":"sha512-WfjVoQ9eP83v8MkTiqagmX5rJxprhRlk3TI37KF40frJxtVciX8cUfDxXL2L2ytCwUN1ZrycZtBTwgt+d0vkiw==","signatures":[{"sig":"MEQCIBC2pDBuW1GTpwk+svt9PzTt4GIdvspdm2hotPUWKUcoAiA6tX7V/3PZO4053Z4d3tqrfiauitqFNetywZEi8lkyeA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@activescott%2fauth@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":81542},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"f36371d391dccd803c32ef2a75600e9b4a9e2111","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f149a3bb-4c70-4797-a4c8-ae9865aeaa50"}},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"11.16.0","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.3.6","jsonwebtoken":"^9.0.2"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.16","typescript":"^5.7.2","@types/node":"^22","@types/jsonwebtoken":"^9.0.10"},"_npmOperationalInternal":{"tmp":"tmp/auth_1.0.0_1785522250106_0.3148439184148748","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"@activescott/auth","version":"2.0.0","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@2.0.0","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"d0855d4d65606c0d2c838c2ac446c1ae26d394a4","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-2.0.0.tgz","fileCount":35,"integrity":"sha512-uaqDCP+BDRwnIfIbOmqBkK2LBtSn2skfsXLhYjHqrZVdQSRdG7Aavs9zTKEl9Sm5qZrZAo+8BVwtnG66S7nEPQ==","signatures":[{"sig":"MEUCIFiFMznCX6lMAQi2a2YpU50qYpmG5BMNOUqCWAcVgbJGAiEA4G7L6lWtTvEeipbGxX3dptP20tuzrhKYwlp3jkDsAjI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@activescott%2fauth@2.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":82392},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"ade8601c4673589fbf6d3f4387976a4a5dea3a91","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f149a3bb-4c70-4797-a4c8-ae9865aeaa50"}},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"11.16.0","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"24.18.0","dependencies":{"jose":"^6.2.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.16","typescript":"^5.7.2","@types/node":"^22"},"_npmOperationalInternal":{"tmp":"tmp/auth_2.0.0_1785527639742_0.12624063965092502","host":"s3://npm-registry-packages-npm-production"}},"2.1.0":{"name":"@activescott/auth","version":"2.1.0","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@2.1.0","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"ef05f99a9cbf125ad694d4bc171a180412959e79","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-2.1.0.tgz","fileCount":39,"integrity":"sha512-UiH8J7VksXdiL5INfuM1a+TB5+CNYMuUPc5+AqF7fWtNUvjx1pVF2J2K1hDb+KDyAUK5VowvbuERwcdkv83j2Q==","signatures":[{"sig":"MEQCIBQyUJO9lbJDuaNGOS6381j2nfDfParPzBEz4CoeZQpLAiBGomyb/sPaR998wSHCi9v/DLhJoJ/afm+q5ocMyFBWpw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":98102},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"9405943132469bb2401e9ef502a324bc4906f4e4","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"activescott","email":"scott@willeke.com"},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"10.9.4","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"22.21.1","dependencies":{"jose":"^6.2.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.16","typescript":"^5.7.2","@types/node":"^22"},"_npmOperationalInternal":{"tmp":"tmp/auth_2.1.0_1785610697430_0.49994276600465093","host":"s3://npm-registry-packages-npm-production"}},"3.0.0":{"name":"@activescott/auth","version":"3.0.0","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@3.0.0","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"9e7cd8921c7ca49bb985de4eb92dcd78ac4038ee","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-3.0.0.tgz","fileCount":39,"integrity":"sha512-JPsubk/u3RAd3gDUMddjyAFjXbCSBe/g6aY1yEFMtybXk7Ye5RAdhpYictI9JRr24XRFv5bIQEQkLv0ZANxJBw==","signatures":[{"sig":"MEUCIQDbQDM7WEkc7BmY2xT5km/mALP+ubVA0mMyZXSJYK/xdwIgX8lq7XGPbQn8OuccAhDgXBD6kWzFMwyjuF/o1CEcJ4o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@activescott%2fauth@3.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":100595},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"248dd93ce638d887a6732d0aca0c30a2aba866f8","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f149a3bb-4c70-4797-a4c8-ae9865aeaa50"}},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"11.16.0","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"24.18.0","dependencies":{"jose":"^6.2.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.16","typescript":"^5.7.2","@types/node":"^22"},"_npmOperationalInternal":{"tmp":"tmp/auth_3.0.0_1785650597818_0.44622040768740634","host":"s3://npm-registry-packages-npm-production"}},"3.0.1":{"name":"@activescott/auth","version":"3.0.1","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@3.0.1","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"ad6c06bad3f5ac976fec2d32616e930a22f31c25","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-3.0.1.tgz","fileCount":39,"integrity":"sha512-EaN+c8S1dIhjg0ExXBIcbSGuoDG7zJexRegX3iB/kEUH1Gj6vN3Dv6DRN4IlektWMOjdQZxjlWM4fwqrDyRI6Q==","signatures":[{"sig":"MEQCIBGaZ8nA+F0mP+mkDERbJKGp8EtUXdHbBrd3lEng0543AiAgSuu3VN2lFKISlooBusyNnw2485xq/RCBJ4Bc4+aLnQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@activescott%2fauth@3.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":104162},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"857dde22c82e6945acdb99e8677579fbc1484aee","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f149a3bb-4c70-4797-a4c8-ae9865aeaa50"}},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"11.16.0","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"24.18.0","dependencies":{"jose":"^6.2.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.16","typescript":"^5.7.2","@types/node":"^22"},"_npmOperationalInternal":{"tmp":"tmp/auth_3.0.1_1785651667816_0.9165604795774114","host":"s3://npm-registry-packages-npm-production"}},"3.1.0":{"name":"@activescott/auth","version":"3.1.0","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@3.1.0","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"50bcedeff01fbb12382220dcfc3ad13a621af75b","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-3.1.0.tgz","fileCount":63,"integrity":"sha512-21rPcgKrY0Ny0liSYjm2NzkeyuoX/+i6SxjFMxttZ9Y2JYXuM87K6NYNd5+Pr8y2gC0hwV9vjgf4Sd8TKmojcQ==","signatures":[{"sig":"MEYCIQCZ0ZNuNAPdk4zhEk7n3J/ONdPQingQP5HEvq/ugw82ggIhAPZWkSP5HDEZvnw57eKgpKnyzKdImLq6ymx5fIS30yS5","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@activescott%2fauth@3.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":161963},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"7f88f666cbdf9b9562c66db181b0aef70be2a6fe","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f149a3bb-4c70-4797-a4c8-ae9865aeaa50"}},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"11.16.0","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"24.18.0","dependencies":{"jose":"^6.2.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.16","typescript":"^5.7.2","@types/node":"^22"},"_npmOperationalInternal":{"tmp":"tmp/auth_3.1.0_1786000558138_0.19607866502347093","host":"s3://npm-registry-packages-npm-production"}},"4.0.0":{"name":"@activescott/auth","version":"4.0.0","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@4.0.0","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"0dc8309e6d75131f003a28bbbeb22cc20123ee34","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-4.0.0.tgz","fileCount":67,"integrity":"sha512-DYgAL1tNJi0siRFKvV8Ly4UH7j/S6Af6o9gk9N1hanPGzMaaHgIr9eARfvuDBOuuWvKuzJOmUsAPnokmuHpDkg==","signatures":[{"sig":"MEUCIQCU/LrM8JGpNxgCOkXOR4GT7fWG9+FSewvASgzBut43bgIgQMToy4hogkXyyMjak0iaqco/HOJpVY/wyeNJqBTRoEw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@activescott%2fauth@4.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":188596},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./admin":{"types":"./dist/admin/admin-data.d.ts","import":"./dist/admin/admin-data.js"}},"gitHead":"843a5ec640514b2cda1ca6de8c63eec0ef9a69ed","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f149a3bb-4c70-4797-a4c8-ae9865aeaa50"}},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"11.16.0","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"24.18.0","dependencies":{"jose":"^6.2.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.16","typescript":"^5.7.2","@types/node":"^22"},"_npmOperationalInternal":{"tmp":"tmp/auth_4.0.0_1786208138962_0.38987435601417997","host":"s3://npm-registry-packages-npm-production"}},"4.1.0":{"name":"@activescott/auth","version":"4.1.0","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@4.1.0","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"6186710da770b38c06b0d070123b9a03430940ab","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-4.1.0.tgz","fileCount":67,"integrity":"sha512-EMoqv0hXFkXjF+R3cyNzxWG43V/O625LZNas0J94gC3qO0ZOsBI6KY6NmqjBHGGpBVHB99lgzxr1oQJpSPpjfQ==","signatures":[{"sig":"MEQCIB0E75Mj82drfLd8NPYMmsUR6Q6dmpo4HIlZ+jiw/XURAiBy1jaFG6xQVU+6KX/5X2yu7aGSe03FVNL9HdtIjcotEg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@activescott%2fauth@4.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":214554},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./admin":{"types":"./dist/admin/admin-data.d.ts","import":"./dist/admin/admin-data.js"}},"gitHead":"a1933ba2887884db3a1437db58c8fa323b6a32c2","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f149a3bb-4c70-4797-a4c8-ae9865aeaa50"}},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"11.16.0","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"24.18.0","dependencies":{"jose":"^6.2.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.16","typescript":"^5.7.2","@types/node":"^22"},"_npmOperationalInternal":{"tmp":"tmp/auth_4.1.0_1786467137704_0.5611689857399784","host":"s3://npm-registry-packages-npm-production"}},"5.0.0":{"name":"@activescott/auth","version":"5.0.0","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@5.0.0","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"c4cf4cd664ca9a00300fff026a078f9629ee5f9e","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-5.0.0.tgz","fileCount":67,"integrity":"sha512-Pv2XfyXvRtYHvUaoUiI3LJKVZf3eXlZg/eIAlIcvdXwNQRKqOjJ+k+w3FvKQjhEyiyFlnQv0uggm6tkt6B12CA==","signatures":[{"sig":"MEUCIQCnjdxF1DSqKEOf6ErQ2F5L6jDkUBF0dV3hTvHmJpbeOQIgA7MLG+5B6u8eTvmI50S3V3GJXzUtft5WUb0tytNBih4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@activescott%2fauth@5.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":218226},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./admin":{"types":"./dist/admin/admin-data.d.ts","import":"./dist/admin/admin-data.js"}},"gitHead":"f52acc55d81da8a0b3f8cbe8314f9b65ac02bc9c","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f149a3bb-4c70-4797-a4c8-ae9865aeaa50"}},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"11.16.0","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"24.18.0","dependencies":{"jose":"^6.2.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.0.16","typescript":"^5.7.2","@types/node":"^22"},"_npmOperationalInternal":{"tmp":"tmp/auth_5.0.0_1786467608931_0.2867729534601957","host":"s3://npm-registry-packages-npm-production"}},"5.1.0":{"name":"@activescott/auth","version":"5.1.0","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@5.1.0","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"b7d573b1c0a4de669e5c72b7d9770848dc841dc0","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-5.1.0.tgz","fileCount":67,"integrity":"sha512-CwlD6o8gmyR2dwjXGBajR0MAh1JTAX0p5l5U3eR44I/j55bYRaQWXMGCON7KxRSYItV6sK/Bl92LIjr/WVyfDw==","signatures":[{"sig":"MEQCIBulVoH4hXeF3nm9MN9jipVwHdf26EFanfpeWdYBBNyoAiA0nKmgQjgY5Tc29ZrtDg/O/QjZlkl0y3jSdT2m8wOVig==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIHw1IjhTMzDIHF7hM8MX+oHoRFld5shX+RmtCPaH+JmdAiEAj1K6vTXCC/GLjcFgP5TQB/Wep9LJlsRGhs3MbsLzQPQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@activescott%2fauth@5.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":228883},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./admin":{"types":"./dist/admin/admin-data.d.ts","import":"./dist/admin/admin-data.js"}},"gitHead":"4a5a69387f1b9f5148cae5735c125ab0f23577f0","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f149a3bb-4c70-4797-a4c8-ae9865aeaa50"}},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"11.19.0","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"24.20.0","dependencies":{"jose":"^6.2.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","typescript":"^5.7.2","@types/node":"^22"},"_npmOperationalInternal":{"tmp":"tmp/auth_5.1.0_1789757279484_0.10663272664580403","host":"s3://npm-registry-packages-npm-production"}},"5.2.0":{"name":"@activescott/auth","version":"5.2.0","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@5.2.0","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"9d22492cb5a22aef98ab38a0c1397682241b13b4","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-5.2.0.tgz","fileCount":71,"integrity":"sha512-6/OXvxUtksrPs2qBY5NaJ0FWlra91pp2kD8UmvMqfuBPjc0twQaX7YSuw578XLfugpN/uJV9sU/weXOLKb0bDQ==","signatures":[{"sig":"MEQCICo6rH+9zkAaTCyrPurcFiOE03qaklvRmTRo1MggggtHAiB30fclQi6UxkBQueRnJHkDYe6IzAV/VSt96XIdpunBzg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIAGx8Ir7vqoVxA/1N1YtYm5KUo0ZpjkT0W2hMtpgDpy4AiEAipkHJ+BUy62hcT/uzgcN0e1AjzQNIkYQcmwopwg6MGQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@activescott%2fauth@5.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":237130},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./admin":{"types":"./dist/admin/admin-data.d.ts","import":"./dist/admin/admin-data.js"}},"gitHead":"51982dc07b7eae322c66dfaded18e7fa584330d0","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f149a3bb-4c70-4797-a4c8-ae9865aeaa50"}},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"11.19.0","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"24.20.0","dependencies":{"jose":"^6.2.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","typescript":"^5.7.2","@types/node":"^22"},"_npmOperationalInternal":{"tmp":"tmp/auth_5.2.0_1789768951956_0.1300288265192613","host":"s3://npm-registry-packages-npm-production"}},"5.2.1":{"name":"@activescott/auth","version":"5.2.1","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@5.2.1","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"292a19b63ce544e9a09f9cc5d2aa7903e252dc48","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-5.2.1.tgz","fileCount":71,"integrity":"sha512-KsBapO4o2o7/A+b72PK5iTKn1LejnATtmrb8SXubkJFPPCQW+QiyWK8+sVhW+Xu4Dy3VHRxXLWQGP8b9ZiM62Q==","signatures":[{"sig":"MEUCIEi+RCw142SD5+5PSTJJ14Xu48mqxbCExwRibzyFn9MDAiEA7n1NURdT/JozOqORoRvvq5b1zGI+zaJYAnoYD4tfsag=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIE1KqqJX+JOeHOThDi7eeOIFKdqt3RGRUVWPaimx8zosAiAm4pTVy0VqqnBCBhhsqVak4fgNI5MJKx0JilzrPFwIiw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@activescott%2fauth@5.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":237183},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./admin":{"types":"./dist/admin/admin-data.d.ts","import":"./dist/admin/admin-data.js"}},"gitHead":"d6726e1bf2f21688eaaad5562cb15bef6a8b842f","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f149a3bb-4c70-4797-a4c8-ae9865aeaa50"}},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"11.19.0","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"24.20.0","dependencies":{"jose":"^6.2.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","typescript":"^5.7.2","@types/node":"^22"},"_npmOperationalInternal":{"tmp":"tmp/auth_5.2.1_1789802299926_0.9383195919365883","host":"s3://npm-registry-packages-npm-production"}},"5.3.0":{"name":"@activescott/auth","version":"5.3.0","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@5.3.0","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"3fe2e97befe7bdc5a7d1204858236d774e1b2cb1","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-5.3.0.tgz","fileCount":75,"integrity":"sha512-WtNAM1jW4nLTrB6LL4FuF1N47+vp6t74CR5lUWvXIGpoAhPCq8zHR0BuXPwd1uJisvHpq4ma9kxGbhXCRthLgw==","signatures":[{"sig":"MEUCIHX9YTdQF7mLJLnnIVr5THprZFPzREaMsIryOQIgwv3wAiEAk8BGQlSRgc/g3im8bNrpbJ8n+D1jcUBzT0U6bRgnETM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIBZAroKBx4j9rRIw/lNDgiC9REbCs509em1j2UtnRyfrAiA2n3kAV+zzCUx75qV9/mjql8EcN3ZH2xsrpg8UqdZ3Og==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@activescott%2fauth@5.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":249561},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./admin":{"types":"./dist/admin/admin-data.d.ts","import":"./dist/admin/admin-data.js"}},"gitHead":"f8e25560f4e822bcb80b3562a522773fc2353bfe","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f149a3bb-4c70-4797-a4c8-ae9865aeaa50"}},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"11.19.0","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"24.20.0","dependencies":{"jose":"^6.2.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","typescript":"^5.7.2","@types/node":"^22"},"_npmOperationalInternal":{"tmp":"tmp/auth_5.3.0_1789804381256_0.2492015251127151","host":"s3://npm-registry-packages-npm-production"}},"5.4.0":{"name":"@activescott/auth","version":"5.4.0","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@5.4.0","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"056436d06b88dd57e1b20e7558095e664b7c0c9b","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-5.4.0.tgz","fileCount":83,"integrity":"sha512-XTO9DWnewrqcv26BQxqZiSHMWGzJMd0ZfwtFPEHhsTCTaPdQlMVDD2T2KZZHryJPSjKkH889qvIooC73l2X/Lg==","signatures":[{"sig":"MEUCIH7kfeslAlNJ+798yR2i9OwYUlWLpPFqKgcD2OFu7Vg5AiEAjAcAR2BzB/xEdRe5eUs4a9qe4gxvSdtRTGo0fPbb1QU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCID3xXC+AFmvqvwIZ5NK6vS9NtILoLuB4csoVw0uw5JoCAiBWPpLuSN0bqxFT4oXYome/czG9SEJEV+Sc29vOx2a9pQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@activescott%2fauth@5.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":260161},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js"}},"gitHead":"fc83e994cd357dcf1fa2b0ce42b22eddfb5585b1","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f149a3bb-4c70-4797-a4c8-ae9865aeaa50"}},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"11.19.0","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"24.20.0","dependencies":{"jose":"^6.2.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","typescript":"^5.7.2","@types/node":"^22"},"_npmOperationalInternal":{"tmp":"tmp/auth_5.4.0_1789869015319_0.9066456949823389","host":"s3://npm-registry-packages-npm-production"}},"5.5.0":{"name":"@activescott/auth","version":"5.5.0","keywords":["auth","authentication","magic-link","jwt","session"],"author":{"name":"Scott Willeke"},"license":"MIT","_id":"@activescott/auth@5.5.0","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"homepage":"https://github.com/activescott/auth#readme","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"fd325319bd371d241fee45026c884b2026335206","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-5.5.0.tgz","fileCount":83,"integrity":"sha512-BL3Nf6cbBeLrSCob7bKos/N2fAdnQ3zCD0fCHMC97Xwbjjw8XHlY1rqP6zSs0C81lue9F72hx8EGYdol12g0pA==","signatures":[{"sig":"MEQCIBxO/Khdt374q8bf6VfIUunHhgyQ6Nsknk6J/Yz47jsqAiBInW6TRmq+bpfNJCEQKoOjQwIBTRdDitbtINcD8OZOAQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDvqrKOv/8Yd9nr3jWrl2a3prluaYc6qdPE6C/GkNHaxAIhAJMxhBZmFn2ZgSqUD8kN4F1kpsuBly1CsF0oJd+0a7G+","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@activescott%2fauth@5.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":261357},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js"}},"gitHead":"7884ce96df92ff547f23bab7f9060a88509c0e2a","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f149a3bb-4c70-4797-a4c8-ae9865aeaa50"}},"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"11.19.0","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"_nodeVersion":"24.20.0","dependencies":{"jose":"^6.2.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","typescript":"^5.7.2","@types/node":"^22"},"_npmOperationalInternal":{"tmp":"tmp/auth_5.5.0_1789869423987_0.7072751619412805","host":"s3://npm-registry-packages-npm-production"}},"5.6.0":{"_id":"@activescott/auth@5.6.0","bugs":{"url":"https://github.com/activescott/auth/issues"},"dist":{"shasum":"406be1e0cccb2cad85e7b29a67221102ed2bd917","tarball":"https://registry.npmjs.org/@activescott/auth/-/auth-5.6.0.tgz","fileCount":91,"integrity":"sha512-APpqBZ4216VeZIiODMlA9Z+jl2Y+irzCXMrA/e632xbJ7+jtUtp2b8Or9XtJgo5nQhjiikIEkbR+6R/k6fGaCA==","signatures":[{"sig":"MEQCICmV87H+h0WBRLt50hSrAgFmeeZblAbFkIrM4xBjhuFFAiBeCa12AME/Yl7FyFWXq73QnJO+eaPdGBvG27RZF/NkEg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIBiD0cmBvlAMbvjJVNpiSYk9yj0MPbYMKT8BIHYaU/9+AiEA1+pjfEt7fF1w7eVzACXK/KcKxjP+PlpGAULn6JegVCQ="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@activescott%2fauth@5.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":286235},"main":"./dist/index.js","name":"@activescott/auth","type":"module","types":"./dist/index.d.ts","author":{"name":"Scott Willeke"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js"}},"gitHead":"720495a27a782647cda0474b2b42589a79480ba4","license":"MIT","scripts":{"dev":"tsc --watch","test":"vitest run","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"version":"5.6.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f149a3bb-4c70-4797-a4c8-ae9865aeaa50"}},"homepage":"https://github.com/activescott/auth#readme","keywords":["auth","authentication","magic-link","jwt","session"],"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"_npmVersion":"11.19.0","description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","directories":{},"maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"_nodeVersion":"24.20.0","dependencies":{"jose":"^6.2.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","typescript":"^5.7.2","@types/node":"^22"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/auth_5.6.0_1789875790929_0.4199138492062142"}}},"time":{"created":"2026-03-16T19:01:16.521Z","modified":"2026-09-20T03:43:11.347Z","0.1.1":"2026-03-16T19:01:16.756Z","0.1.3":"2026-05-09T15:58:02.662Z","1.0.0":"2026-07-31T18:24:10.250Z","2.0.0":"2026-07-31T19:53:59.896Z","2.1.0":"2026-08-01T18:58:17.568Z","3.0.0":"2026-08-02T06:03:17.974Z","3.0.1":"2026-08-02T06:21:07.956Z","3.1.0":"2026-08-06T07:15:58.277Z","4.0.0":"2026-08-08T16:55:39.104Z","4.1.0":"2026-08-11T16:52:17.901Z","5.0.0":"2026-08-11T17:00:09.075Z","5.1.0":"2026-09-18T18:47:59.568Z","5.2.0":"2026-09-18T22:02:32.041Z","5.2.1":"2026-09-19T07:18:20.033Z","5.3.0":"2026-09-19T07:53:01.359Z","5.4.0":"2026-09-20T01:50:15.401Z","5.5.0":"2026-09-20T01:57:04.087Z","5.6.0":"2026-09-20T03:43:11.016Z"},"bugs":{"url":"https://github.com/activescott/auth/issues"},"author":{"name":"Scott Willeke"},"license":"MIT","homepage":"https://github.com/activescott/auth#readme","keywords":["auth","authentication","magic-link","jwt","session"],"repository":{"url":"git+https://github.com/activescott/auth.git","type":"git","directory":"packages/auth"},"description":"Framework-agnostic authentication with provider pattern for magic links, OAuth, and more","maintainers":[{"name":"activescott","email":"scott@willeke.com"}],"readme":"# @activescott/auth\n\n[![npm version](https://img.shields.io/npm/v/@activescott/auth.svg)](https://www.npmjs.com/package/@activescott/auth)\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\n\nFramework-agnostic direct authentication, deliberately small: single-use magic links and one-time codes via email and SMS, and passkeys (WebAuthn). No third-party identity providers. Runs on Node and edge runtimes (e.g. Cloudflare Workers).\n\nThis package is the core: the `Auth` class, JWT-cookie session management, and the provider/store interfaces. It does not handle any specific authentication method by itself — pair it with one or more provider packages and (optionally) a framework adapter:\n\n- [`@activescott/auth-provider-email`](https://www.npmjs.com/package/@activescott/auth-provider-email) — email magic links + one-time codes\n- [`@activescott/auth-provider-sms`](https://www.npmjs.com/package/@activescott/auth-provider-sms) — SMS one-time codes ([`@activescott/auth-sms-twilio`](https://www.npmjs.com/package/@activescott/auth-sms-twilio) provides both Twilio transports: Messaging and Verify)\n- [`@activescott/auth-provider-passkey`](https://www.npmjs.com/package/@activescott/auth-provider-passkey) — passkeys (WebAuthn)\n- [`@activescott/auth-adapter-react-router`](https://www.npmjs.com/package/@activescott/auth-adapter-react-router) — React Router v8 adapter\n\nUsed in production by [ramblefeed.com](https://ramblefeed.com) and [tinkerbellbot.com](https://tinkerbellbot.com).\n\n## Why direct, passwordless authentication?\n\nEveryone has an email address or a phone number. Nobody wants another password. And many users hesitate at \"Sign in with Google/Apple/Microsoft\" because it shares their sign-in activity with a third party. This library focuses on the ways a person can authenticate **directly** with your app:\n\n- **Lowest friction for your users.** No password to create, forget, or reset, and no account with a third party required. Modern platforms AutoFill the codes we send, so signing in is: type your email, type the code your OS offers you.\n- **Easiest for you.** No OAuth app registrations, no identity-provider dashboards, no extra services. An SMTP server and your database are the only dependencies.\n- **Private by design.** No third-party identity provider in the loop — big tech doesn't learn when (or that) your users sign in to your app.\n- **Deliberately small.** This is not a works-with-every-OAuth-provider auth library — that niche is well served by projects like [BetterAuth](https://www.better-auth.com/). Constraining the scope is what keeps this one easy to drop into a new app.\n\nPasskeys push the same idea further: phishing-resistant, no shared secret, and still no third party.\n\n## Features\n\n- ✅ **Email magic links** — single-use, server-backed sign-in links with a confirm step that email security scanners can't consume (see the [FAQ](https://github.com/activescott/auth#faq)). In production.\n- ✅ **Email one-time codes** — every sign-in email also includes a numeric code with iOS/macOS AutoFill support, so users can type the code instead of switching to the inbox tab.\n- ✅ **Bring your own database** — three small store interfaces (`IdentityStore`, `UserStore`, `ChallengeStore`); implement them with Prisma, Drizzle, raw SQL, Redis, whatever you use.\n- ✅ **Edge-ready, [WinterTC-compatible](https://wintertc.org/faq) core** — standard Fetch `Request`/`Response`, WebCrypto, and [`jose`](https://github.com/panva/jose) for session JWTs; no Node-only APIs, so it runs on Cloudflare Workers, Deno, Bun, and any WinterTC-aligned runtime.\n- ✅ **React Router v8 adapter** — `createAuthHandlers`, `requireAuth`, `optionalAuth`, `getSession`, `logout`.\n- ✅ **SMS one-time codes** — vendor-neutral provider with a Twilio Messaging transport (RCS-ready) and [WebOTP](https://developer.mozilla.org/docs/Web/API/WebOTP_API) autofill support.\n- ✅ **Hosted verification (no US A2P 10DLC)** — the same SMS provider accepts a `VerificationTransport` where the vendor generates, sends, and checks the code. `TwilioVerifyTransport` ships in the Twilio package: no number to buy, no brand or campaign registration — at the cost of ~4–6x per sign-in.\n- ✅ **Abuse protection, on by default** — per-IP and per-recipient rate limits, a minimum-form-fill-time check, blocked attempts logged, and a blocked caller gets the same response a successful send would produce. Optional packages add hosted bot checks ([Turnstile](https://www.npmjs.com/package/@activescott/auth-botcheck-turnstile)).\n- ✅ **Passkeys (WebAuthn)** — add a passkey while signed in, then sign in usernameless with Touch ID, Face ID, Windows Hello, 1Password, iCloud Keychain, or a security key; conditional UI (passkey autofill) supported. Verification via [`@simplewebauthn/server`](https://simplewebauthn.dev/); zero-dependency browser client included.\n\nThe provider interface (`AuthProvider`) is the extension point. Implementing a new provider does not require changes to this core package.\n\n## Documentation & example\n\nFull docs — quick start, architecture diagram, custom-provider guide, e2e-testing pattern, FAQ — and a runnable React Router framework-mode example with Playwright tests live in the monorepo:\n\n→ **https://github.com/activescott/auth**\n\nThe rest of this README covers what this core package itself exports and expects.\n\n## Install\n\n```bash\nnpm install @activescott/auth\n```\n\n## What's in the box\n\n| Export                                                            | Purpose                                                                                                               |\n| ----------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------- |\n| `Auth`                                                            | Orchestrator. Routes auth requests to providers, manages session cookies.                                             |\n| `SessionManager`                                                  | Standalone JWT session signer/verifier (rarely needed directly).                                                      |\n| `AuthProvider`                                                    | Interface every provider implements (`initiate`, `verify`, `canHandle`, optional `handleAction` for extra endpoints). |\n| `IdentityStore`, `UserStore`                                      | Interfaces you implement to plug in your database.                                                                    |\n| `ChallengeStore`, `InMemoryChallengeStore`                        | Storage for short-lived, single-use challenges (see below).                                                           |\n| `AbuseConfig`, `RateLimitStore`, `InMemoryRateLimitStore`         | Abuse protection for the initiate endpoints — on by default (see below).                                              |\n| `InitiateGate`                                                    | Your own policy on who may start a sign-in or link (see below).                                                       |\n| `createWaitlist`, `waitlistNotificationEmail`                     | Waitlist with admin approval, built on the initiate gate (see below).                                                 |\n| `BotCheckProvider`, `createFormToken`, `FORM_TOKEN_FIELD`         | Bot-check interface and the login form's anti-bot fields.                                                             |\n| `generateOtpCode`, `hashOtpCode`, `verifyOtpCode`                 | One-time-code utilities used by OTP-capable providers.                                                                |\n| `AuthUser`, `Identity`, `Session`, `AuthResult`, `AuthInitResult` | Core data types.                                                                                                      |\n| `AuthErrors`, `getAuthErrorMessage`, `AUTH_ERROR_CODES`           | Structured error helpers.                                                                                             |\n\nPlus the `@activescott/auth/admin` subpath: admin dashboard data and the admin allowlist check (see [Admin subpath](#admin-subpath)).\n\n## Data model\n\nYou bring three adapters — `IdentityStore`, `UserStore`, and `ChallengeStore` — that read/write your database. The library handles challenges, cookies, provider routing, and session verification.\n\nAn `Identity` is a `(provider, identifier)` pair (e.g. `(\"email\", \"alice@example.com\")`) linked to one of your `User` records. One user can have multiple identities — email, phone, and passkeys all use the same table.\n\n`Identity.metadata` is **provider-owned state**, opaque to your application: persist it unmodified (a JSON/JSONB column) and return it exactly as stored. Providers with per-identity state keep it there — the passkey provider stores each credential's public key and signature counter — and stateless providers store `{}`. It may contain sensitive material, so protect it like credential data (encryption at rest is a reasonable default). `IdentityStore.update(id, {metadata, verifiedAt})` replaces stored metadata wholesale; providers rely on it, so it is a required method.\n\n## Minimal shape\n\n```ts\nimport { Auth, InMemoryChallengeStore } from \"@activescott/auth\"\nimport { EmailProvider } from \"@activescott/auth-provider-email\"\n\nconst auth = new Auth({\n  session: {\n    secret: process.env.JWT_SECRET!,\n    maxAge: \"30d\",\n    cookieName: \"session\",\n    cookie: { secure: true, sameSite: \"lax\", path: \"/\" },\n  },\n  identityStore, // your impl\n  userStore, // your impl\n  challengeStore: new InMemoryChallengeStore(), // DB-backed in production\n  providers: [new EmailProvider({ ... })],\n})\n```\n\nThen call `auth.handleRequest(request)` from your framework's routing layer (or use a framework adapter), and `auth.verifySession(request)` to check the session cookie on protected routes.\n\n## Session cache\n\n`verifySession` keeps each verified session in memory for two minutes, so a page whose loaders each ask who is signed in costs one pair of store reads instead of one per loader. What you pay for it is staleness: for up to two minutes after you block or delete someone, their requests still verify.\n\n`session.cacheTtlMs` is that window in milliseconds, and `0` turns the cache off so every request reads your stores:\n\n```ts\nsession: {\n  secret: process.env.JWT_SECRET!,\n  maxAge: \"30d\",\n  cookieName: \"session\",\n  cookie: { secure: true, sameSite: \"lax\", path: \"/\" },\n  cacheTtlMs: 0, // block a user, and their next request is signed out\n}\n```\n\nWith the cache on, it holds at most 10,000 sessions and evicts the oldest past that, so a burst of sign-ins between sweeps cannot grow it without limit. Nothing is shared between instances: an entry is only ever a repeat of what that process's stores just said.\n\n## ChallengeStore\n\nEvery sign-in attempt is backed by a server-side challenge: magic links and one-time codes store the hashed secret, an attempt counter, and an expiry; passkey ceremonies record the WebAuthn challenge so it is redeemable exactly once. That state lives in the `challengeStore`, which is why it is a required part of the `Auth` config.\n\n`InMemoryChallengeStore` is right for a single server process (and dev/examples). Challenges are lost on restart and not shared across instances — for multi-instance deployments implement the four-method `ChallengeStore` interface against shared storage. A SQL implementation is roughly:\n\n```sql\nCREATE TABLE challenges (\n  id TEXT PRIMARY KEY,\n  type TEXT NOT NULL,\n  identifier TEXT NOT NULL,\n  hashed_code TEXT,\n  data JSONB,\n  attempts INT NOT NULL DEFAULT 0,\n  max_attempts INT NOT NULL,\n  created_at TIMESTAMPTZ NOT NULL DEFAULT now(),\n  expires_at TIMESTAMPTZ NOT NULL\n);\n```\n\nwith `incrementAttempts` as `UPDATE challenges SET attempts = attempts + 1 WHERE id = $1 RETURNING attempts` (the increment must be atomic — it enforces the guess limit), and a periodic `DELETE ... WHERE expires_at < now()`.\n\n## Abuse protection\n\nThe `initiate` endpoints send mail and texts to whatever address a caller submits, which makes them an attractive way to mail-bomb a third party or burn your sending reputation on bounces. Protection is **on by default** — you do not have to configure or implement anything:\n\n| Layer                  | Default                                                    |\n| ---------------------- | ---------------------------------------------------------- |\n| Per client IP          | 3 per minute, then 10 per hour                             |\n| Per recipient          | 3 per hour, then 10 per day                                |\n| Minimum form-fill time | 2 seconds (only enforced if the form posts a token, below) |\n| Counter storage        | `InMemoryRateLimitStore`                                   |\n| Blocked response       | identical to a successful send                             |\n\nBlocked attempts are always logged (`console.warn`) with the reason, provider, IP, requested identifier, and rule, so an abuse burst is visible:\n\n```\n[auth] blocked initiate: reason=identifier_rate_limited provider=email ip=203.0.113.7 identifier=victim@example.com rule=3/3600s retryAfter=2841s\n```\n\n### A blocked caller sees a success\n\nBy design a throttled or bot-flagged request gets exactly the response a real send would produce — the same 302 back to `?sent=1`, or the same `{success: true, message}` — minus the challenge cookie. Nothing is sent and nothing is stored. This is what keeps a bot from mapping which addresses or IPs are throttled. If you would rather return `429 RATE_LIMITED` (reasonable for an API-only deployment), set `abuse.respondWith: \"rateLimited\"`.\n\n### Tuning\n\n```ts\nconst auth = new Auth({\n  // ...\n  abuse: {\n    perIp: [\n      { windowSeconds: 60, max: 3 },\n      { windowSeconds: 3600, max: 10 },\n    ],\n    perIdentifier: [{ windowSeconds: 3600, max: 3 }],\n    store: myRedisRateLimitStore, // multi-instance: share the counters\n    onBlocked: (event) => logger.warn(event, \"auth abuse blocked\"),\n  },\n})\n```\n\n`abuse: { enabled: false }` turns everything off.\n\n`InMemoryRateLimitStore` counts per process, so a multi-instance deployment effectively multiplies every limit by the instance count. Implement the one-method `RateLimitStore` interface against Redis (`INCR` + `EXPIRE`) or your database to share counters.\n\nClient IPs come from `cf-connecting-ip`, then `x-forwarded-for` (rightmost hop; set `abuse.clientIp.trustedProxyHops` if more than one proxy appends), then `x-real-ip`. These headers are spoofable unless a proxy in front of your app rewrites them — supply `abuse.clientIp.getClientIp` when your runtime exposes the peer address. When no IP can be determined, per-IP limits are skipped and per-recipient limits still apply.\n\n### Form token\n\nThe minimum-form-fill-time check needs one hidden field in your login form:\n\n```tsx\nimport { createFormToken, FORM_TOKEN_FIELD } from \"@activescott/auth\"\n\n// in the route/loader that renders the form:\nconst formToken = await createFormToken(process.env.JWT_SECRET!)\n```\n\n```html\n<input type=\"hidden\" name=\"authFormToken\" value=\"{formToken}\" />\n```\n\nThe token is a signed render timestamp; the server rejects submissions that arrive faster than `minFormFillSeconds`. It must be signed — an unsigned timestamp is just another field to forge. A submission with **no** token is allowed, so adding the field is optional and can be rolled out later. A token older than a day is also allowed rather than rejected — a login page left open in a tab is a human.\n\n### Hosted bot checks\n\nCloudflare Turnstile, hCaptcha, and friends live in their own packages, so you only install the vendor you use:\n\n```ts\nimport { TurnstileBotCheck } from \"@activescott/auth-botcheck-turnstile\"\n\nabuse: {\n  botChecks: [new TurnstileBotCheck({ secretKey: process.env.TURNSTILE_SECRET_KEY! })],\n}\n```\n\nImplement `BotCheckProvider` (`{ id, verify({ request, body, ip, providerId }) }`) to add your own.\n\n## Initiate gate\n\nAn invite-only beta, an allowlist, or a blocked domain is a rule about _who_ may be sent a sign-in message. Put it in `gate.onInitiate` rather than in a preamble in your auth route:\n\n```ts\nconst auth = new Auth({\n  // ...\n  gate: {\n    async onInitiate({ provider, identifier, mode, request }) {\n      if (mode === \"link\") return \"allow\" // already signed in\n      if (await invites.has(provider, identifier)) return \"allow\"\n      return { redirect: \"/waitlist\" }\n    },\n  },\n})\n```\n\nThe gate runs inside `handleRequest`, after the provider has parsed, normalized, and validated the identifier (`User@Example.com ` arrives as `user@example.com`, a phone number as E.164) and before anything is created or sent. A malformed identifier is rejected by the provider first, so the gate never acts on one. `mode` is `\"signin\"` or `\"link\"` (see [linking identities](../../README.md#linking-identities--account-merge)); `request` is a clone of the initiate request, for headers or cookies.\n\nReturn one of:\n\n- `\"allow\"` — send as usual.\n- `{ redirect: \"/waitlist\" }` — send nothing and answer with a 302 to that URL, for every caller.\n- `{ error: AuthErrors.invalidCredentials({ reason: \"Invite only\" }) }` — send nothing and fail like any other initiate: a browser form post goes back to the submitting page with `?error=<code>`, a fetch caller gets the error as JSON.\n\nA gate that throws fails the initiate. Per-IP and per-recipient abuse limits run before the gate, so a throttled request still gets the silent \"sent\" answer.\n\nThe built-in email and SMS providers consult the gate. With `gate` set, `new Auth` throws if any provider that serves an initiate route does not declare `consultsInitiateGate: true` — an older provider package would otherwise skip your policy without a trace. A custom provider opts in by calling `context.gate?.check({ provider, identifier, mode })` once its identifier is valid, returning the result when there is one, and setting `consultsInitiateGate = true`.\n\n## Admin subpath\n\n`@activescott/auth/admin` is what the admin dashboard is built from, with no framework in it:\n\n| Export                         | Purpose                                                                              |\n| ------------------------------ | ------------------------------------------------------------------------------------ |\n| `createAdminData(auth)`        | `{ listUsers, describeConfig }` over your stores, as plain serializable rows.        |\n| `createAdminPredicate(admins)` | Builds the allowlist check from a delimited string, an array, or your own predicate. |\n| `isAdminUser(auth, user)`      | Answers that check for one user against `AUTH_ADMIN_IDENTIFIERS`.                    |\n\nThe allowlist is email addresses and E.164 phone numbers, separated by commas or whitespace, matched against **every** identity a user owns. An allowlisted address therefore admits its owner even when they signed in by SMS. An empty or missing allowlist admits nobody.\n\n```ts\nimport { isAdminUser } from \"@activescott/auth/admin\"\n\nconst session = await auth.verifySession(request)\nif (!session || !(await isAdminUser(auth, session.user))) {\n  return new Response(\"Not Found\", { status: 404 })\n}\n```\n\n`isAdminUser` reads the environment allowlist and loads the user's identities on each call. When the list comes from somewhere else, build the check with `createAdminPredicate(admins)` and hand it the user's identities yourself (`identityStore.findByUserId(user.id)`). The React Router adapter's dashboard uses these, so a page you gate yourself and the dashboard agree on who is an admin.\n\n## Logging\n\nRedirect destinations reach the library from `?redirectTo=`, form fields, and the `Referer` header. One that names another origin or another scheme is declined and a configured path is used instead, which is otherwise invisible to your app: a stale link or a proxy rewriting `Referer` shows up only as users landing somewhere unexpected. Give the library somewhere to say so:\n\n```ts\nconst auth = new Auth({\n  // ...\n  logger: console, // or { warn: (message, context) => log.warn(context, message) }\n})\n```\n\nEach declined destination logs one WARN naming the parameter it came from and that value's origin. The value itself is never logged, because a magic-link URL carries a single-use key in its query:\n\n```\n[auth] redirect destination declined, using fallback { source: 'redirectTo', fallback: '/', reason: 'other-origin', origin: 'https://other.example' }\n```\n\n`logger` is optional and nothing is logged through it when it is absent. Providers receive it as `AuthContext.logger`, and framework adapters read it off the `Auth` instance (`auth.getLogger()`), so configuring it here covers the whole flow. Abuse blocks are separate: those always go to `console.warn`, plus `abuse.onBlocked` if you set it.\n\n## Waitlist\n\n`createWaitlist` is an initiate gate for apps that approve new users by hand. An identifier without an account gets a PENDING user and lands on your waitlist page instead of receiving a code; admins hear about it through `notify`; an admin approves or blocks from the dashboard. Approved users sign in as usual.\n\nThe status lives in your database, behind an `ApprovalStore`. Its values, `\"PENDING\" | \"APPROVED\" | \"BLOCKED\"`, match the enum apps usually already have:\n\n```ts\nimport { createWaitlist, waitlistNotificationEmail } from \"@activescott/auth\"\n\nexport const waitlist = createWaitlist({\n  identityStore,\n  userStore,\n  approvalStore: {\n    getApprovalStatus: async (userId) =>\n      (await db.user.findUnique({ where: { id: userId } }))?.approvalStatus ??\n      null,\n    setApprovalStatus: async (userId, approvalStatus) => {\n      await db.user.update({ where: { id: userId }, data: { approvalStatus } })\n    },\n  },\n  waitlistUrl: \"/waitlist\",\n  blockedUrl: \"/login?error=blocked\", // defaults to waitlistUrl\n  // App rules that skip the waitlist. Never consulted for BLOCKED users.\n  autoApprove: ({ identifier }) => autoApproved.has(identifier),\n  notify: (notice) =>\n    transporter.sendMail({\n      ...waitlistNotificationEmail(notice, {\n        appName: \"Fernfiles\",\n        domain: \"fernfiles.com\",\n        from: \"noreply@fernfiles.com\",\n      }),\n      to: adminEmails,\n    }),\n  logger: console,\n})\n\nconst auth = new Auth({ /* ... */ gate: waitlist })\n```\n\nA new user's identity row is created at initiate, with the same calls the verify step would make, so the admin dashboard lists them before they ever get a code and verify finds that row instead of creating a second user. `notify` fires once when a user joins the waitlist (`reason: \"waitlisted\"`) and whenever `autoApprove` lets someone in (`reason: \"auto-approved\"`); a throw there is logged and does not fail the sign-in. The email is plain and generic on purpose: app name, domain, sender, and a link to `/admin/users` (`adminPath` changes it). Sending it is yours, so the core takes no mail dependency.\n\nA user with no recorded status counts as not approved. Mark existing users APPROVED before turning the waitlist on.\n\nThe gate only sees email and SMS sign-ins, and only at initiate. Passkey sign-ins and a user you block after they signed in need a per-request check; `waitlist.redirectFor(userId)` returns null for approved users and the URL to send anyone else to. With the React Router adapter:\n\n```ts\ncreateAuthHandlers(auth, {\n  // ...\n  onSessionVerified: async ({ user }) => {\n    const to = await waitlist.redirectFor(user.id)\n    if (to) return logout(to)\n  },\n})\n```\n\nFor the dashboard, render approve and block buttons in `AdminUsersPage`'s `rowActions` as forms posting `userId` and `intent` (`\"approve\"` or `\"block\"`) to your admin route, and in that route's action call `waitlist.handleAdminAction(await request.formData())` after checking the caller is an admin. `waitlist.approve(userId)` and `waitlist.block(userId)` do the same from your own code. The form has no CSRF token of its own; it relies on the session cookie being `SameSite=Lax` or stricter, as the example configures. The [example app](../../examples/react-router/app/routes/admin.users.tsx) has the whole flow.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}