{"_id":"@workos/authkit-sveltekit","_rev":"16-aadfd249019b3e724d7dc7d8a21cd37d","name":"@workos/authkit-sveltekit","dist-tags":{"alpha":"0.0.1-alpha.1","latest":"0.3.0"},"versions":{"0.0.1-alpha.0":{"name":"@workos/authkit-sveltekit","version":"0.0.1-alpha.0","keywords":["workos","authkit","sveltekit","authentication","auth"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/authkit-sveltekit@0.0.1-alpha.0","maintainers":[{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"},{"name":"lucasmotta.workos","email":"lucas.motta@workos.com"}],"homepage":"https://github.com/workos/authkit-sveltekit#readme","bugs":{"url":"https://github.com/workos/authkit-sveltekit/issues"},"dist":{"shasum":"c060c03124f8a58e5c953a7a8d55535e234c9b97","tarball":"https://registry.npmjs.org/@workos/authkit-sveltekit/-/authkit-sveltekit-0.0.1-alpha.0.tgz","fileCount":9,"integrity":"sha512-FTuWzx6ytl2kFElynm95DESaMNGwJwzbQ77UJsJH1+PWPxmvua4NmrbiVulOyBS/YLwLp369Sqczmh6f77MAHg==","signatures":[{"sig":"MEQCIGn0HE9qIYyR/HyUjQlc4y0YnOwGPbcOi7GxzS6OjwOMAiBSuIbxvHLYqmX9jPyQgNzxzUreGe8PijoQLrpWlYOitQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":758565},"main":"./dist/index.cjs","pnpm":{"overrides":{"@workos/authkit-session":"file:../authkit-session"}},"type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"gitHead":"3b219a3d89a5f9c67e7a88e922550e7d0a23f21d","scripts":{"dev":"tsup --watch","lint":"eslint src --ext .ts","test":"vitest","build":"tsup","format":"prettier --write src/**/*.ts","type-check":"tsc --noEmit","test:coverage":"vitest --coverage","prepublishOnly":"npm run build && npm run test"},"_npmUser":{"name":"nicknisi","email":"nick@nisi.org"},"repository":{"url":"git+https://github.com/workos/authkit-sveltekit.git","type":"git"},"_npmVersion":"11.4.2","description":"Official WorkOS AuthKit SDK for SvelteKit","directories":{},"_nodeVersion":"22.13.1","dependencies":{"cookie":"^1.0.2","@workos/authkit-session":"^0.0.1-alpha.1"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.0","eslint":"^9.32.0","vitest":"^3.2.4","prettier":"^3.6.2","typescript":"^5.8.3","@types/node":"^24.1.0","@sveltejs/kit":"^2.26.1","@types/cookie":"^0.6.0","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.38.0","@sveltejs/vite-plugin-svelte":"^6.1.0","@typescript-eslint/eslint-plugin":"^8.38.0"},"peerDependencies":{"@sveltejs/kit":">=2.0.0"},"_npmOperationalInternal":{"tmp":"tmp/authkit-sveltekit_0.0.1-alpha.0_1753590456902_0.21178913224057894","host":"s3://npm-registry-packages-npm-production"}},"0.0.1-alpha.1":{"name":"@workos/authkit-sveltekit","version":"0.0.1-alpha.1","keywords":["workos","authkit","sveltekit","authentication","auth"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/authkit-sveltekit@0.0.1-alpha.1","maintainers":[{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"},{"name":"lucasmotta.workos","email":"lucas.motta@workos.com"}],"homepage":"https://github.com/workos/authkit-sveltekit#readme","bugs":{"url":"https://github.com/workos/authkit-sveltekit/issues"},"dist":{"shasum":"9b4ac64809258d6f17326cccf5e1124b0310e970","tarball":"https://registry.npmjs.org/@workos/authkit-sveltekit/-/authkit-sveltekit-0.0.1-alpha.1.tgz","fileCount":9,"integrity":"sha512-FB60pT8R7URbGl5Ruw1AuMWxd7RxtwMmuWI1SWl/JOYvmzurgFidFdndh8ClyKyrJnvgTQuxHHJ4zDuNP3wVwg==","signatures":[{"sig":"MEQCIFrv7wLdtQJCmew6EkrX9C9RAulTnU0R80E6sJ+kkOpwAiBY+JVTsD5SvPOMTHrvniXMIWvk7BJYo5q9RrsB2pwrKw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":759819},"main":"./dist/index.cjs","pnpm":{"overrides":{"cookie":">=0.7.0"}},"type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"gitHead":"8080e6078132bb12622f3753736fc95fff761860","scripts":{"dev":"tsup --watch","lint":"eslint src --ext .ts","test":"vitest","build":"tsup","format":"prettier --write .","prettier":"prettier --check .","type-check":"tsc --noEmit","test:coverage":"vitest --coverage","prepublishOnly":"npm run build && npm run test"},"_npmUser":{"name":"nicknisi","email":"nick@nisi.org"},"repository":{"url":"git+https://github.com/workos/authkit-sveltekit.git","type":"git"},"_npmVersion":"11.4.2","description":"Official WorkOS AuthKit SDK for SvelteKit","directories":{},"_nodeVersion":"22.13.1","dependencies":{"cookie":"^1.0.2","@workos/authkit-session":"^0.0.1-alpha.3"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"tsup":"^8.5.0","eslint":"^9.32.0","vitest":"^3.2.4","prettier":"^3.6.2","typescript":"^5.8.3","@types/node":"^24.1.0","@sveltejs/kit":"^2.26.1","@types/cookie":"^0.6.0","@vitest/coverage-v8":"^3.2.4","@typescript-eslint/parser":"^8.38.0","@sveltejs/vite-plugin-svelte":"^6.1.0","@typescript-eslint/eslint-plugin":"^8.38.0"},"peerDependencies":{"@sveltejs/kit":">=2.0.0"},"_npmOperationalInternal":{"tmp":"tmp/authkit-sveltekit_0.0.1-alpha.1_1753811288191_0.5872365587438542","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"@workos/authkit-sveltekit","version":"0.1.0","keywords":["workos","authkit","sveltekit","authentication","auth"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/authkit-sveltekit@0.1.0","maintainers":[{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"gioworkos","email":"gio@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"},{"name":"lucasmotta.workos","email":"lucas.motta@workos.com"}],"homepage":"https://github.com/workos/authkit-sveltekit#readme","bugs":{"url":"https://github.com/workos/authkit-sveltekit/issues"},"dist":{"shasum":"3f4381bc3e923614ecdd76c84da329a8b83ae1a2","tarball":"https://registry.npmjs.org/@workos/authkit-sveltekit/-/authkit-sveltekit-0.1.0.tgz","fileCount":9,"integrity":"sha512-X1OXIkkWg1CLyEaDyXYsLtOuYgyB6M/o9I0ZPDCqxmXSN/5SfUzXpqpdNnM4YFspTbGOmfBhzpW5vOQtsZUK5Q==","signatures":[{"sig":"MEUCIFAfejUtNXVqeRzs1EK21JO7AzmZjOyK3FYZGKpmf2s6AiEAhhdhFc+I/sgK+aBLAPTDxPWCt2m6TfuGyVWMrgfAw8w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2fauthkit-sveltekit@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2493714},"main":"./dist/index.cjs","type":"module","_from":"file:workos-authkit-sveltekit-0.1.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"dev":"tsup --watch","lint":"eslint src --ext .ts","test":"vitest","build":"tsup","format":"prettier --write .","prettier":"prettier --check .","typecheck":"tsc --noEmit","test:coverage":"vitest --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:5d870e54-f5a7-4933-9aa0-6fb40fab236d"}},"_resolved":"/tmp/25bf68ad99bf5f64dd9b4d1641e01481/workos-authkit-sveltekit-0.1.0.tgz","_integrity":"sha512-X1OXIkkWg1CLyEaDyXYsLtOuYgyB6M/o9I0ZPDCqxmXSN/5SfUzXpqpdNnM4YFspTbGOmfBhzpW5vOQtsZUK5Q==","repository":{"url":"git+https://github.com/workos/authkit-sveltekit.git","type":"git"},"_npmVersion":"11.6.2","description":"Official WorkOS AuthKit SDK for SvelteKit","directories":{},"_nodeVersion":"24.13.0","dependencies":{"cookie":"^1.1.1","@workos/authkit-session":"^0.3.4"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","eslint":"^9.39.0","vitest":"^4.0.18","prettier":"^3.8.1","typescript":"^5.9.3","@types/node":"^24.1.0","@sveltejs/kit":"^2.50.2","@types/cookie":"^0.6.0","@vitest/coverage-v8":"^4.0.18","prettier-plugin-svelte":"^3.4.1","@typescript-eslint/parser":"^8.54.0","@sveltejs/vite-plugin-svelte":"^6.2.4","@typescript-eslint/eslint-plugin":"^8.54.0"},"peerDependencies":{"@sveltejs/kit":">=2.0.0"},"_npmOperationalInternal":{"tmp":"tmp/authkit-sveltekit_0.1.0_1770240207885_0.7865208126231706","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@workos/authkit-sveltekit","version":"0.2.0","keywords":["workos","authkit","sveltekit","authentication","auth"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/authkit-sveltekit@0.2.0","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/authkit-sveltekit#readme","bugs":{"url":"https://github.com/workos/authkit-sveltekit/issues"},"dist":{"shasum":"813f8233f4c589772819d61d8b3312a12cb248b0","tarball":"https://registry.npmjs.org/@workos/authkit-sveltekit/-/authkit-sveltekit-0.2.0.tgz","fileCount":9,"integrity":"sha512-iHDRhESpo8kB29VIcWElGqpV3c+by1QFnN0aNNK9XZruzG7yZmI1bbXZ46KkYydk6Ud3sQZYW+PsU65k+f5c1Q==","signatures":[{"sig":"MEQCIFXTn+lblaW62CQZuPm/pY16VjIJ93kKDkWXCmKUe4XHAiATq30tJKppanZFEvhNTIUxDN8u0Ku2VD+0/9AVHu+Fgw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2fauthkit-sveltekit@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3494791},"main":"./dist/index.cjs","type":"module","_from":"file:workos-authkit-sveltekit-0.2.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"dev":"tsup --watch","lint":"eslint src --ext .ts","test":"vitest","build":"tsup","format":"prettier --write .","prettier":"prettier --check .","typecheck":"tsc --noEmit","test:coverage":"vitest --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:5d870e54-f5a7-4933-9aa0-6fb40fab236d"}},"_resolved":"/tmp/b059519afdbf89934687b775850c6e07/workos-authkit-sveltekit-0.2.0.tgz","_integrity":"sha512-iHDRhESpo8kB29VIcWElGqpV3c+by1QFnN0aNNK9XZruzG7yZmI1bbXZ46KkYydk6Ud3sQZYW+PsU65k+f5c1Q==","repository":{"url":"git+https://github.com/workos/authkit-sveltekit.git","type":"git"},"_npmVersion":"11.11.0","description":"Official WorkOS AuthKit SDK for SvelteKit","directories":{},"_nodeVersion":"24.14.1","dependencies":{"cookie":"^1.1.1","set-cookie-parser":"^3.1.0","@workos/authkit-session":"^0.4.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","eslint":"^9.39.0","vitest":"^4.0.18","prettier":"^3.8.1","typescript":"^5.9.3","@types/node":"^24.1.0","@sveltejs/kit":"^2.50.2","@types/cookie":"^0.6.0","@vitest/coverage-v8":"^4.0.18","prettier-plugin-svelte":"^3.4.1","@types/set-cookie-parser":"^2.4.10","@typescript-eslint/parser":"^8.54.0","@sveltejs/vite-plugin-svelte":"^6.2.4","@typescript-eslint/eslint-plugin":"^8.54.0"},"peerDependencies":{"@sveltejs/kit":">=2.20.0"},"_npmOperationalInternal":{"tmp":"tmp/authkit-sveltekit_0.2.0_1776893084295_0.6422085981690497","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@workos/authkit-sveltekit","version":"0.3.0","keywords":["workos","authkit","sveltekit","authentication","auth"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/authkit-sveltekit@0.3.0","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/authkit-sveltekit#readme","bugs":{"url":"https://github.com/workos/authkit-sveltekit/issues"},"dist":{"shasum":"e7999e770929861e29058ae7720b7dc51422391b","tarball":"https://registry.npmjs.org/@workos/authkit-sveltekit/-/authkit-sveltekit-0.3.0.tgz","fileCount":9,"integrity":"sha512-44HLylxP3fWuUXvjXF8ptOCHKQt3Ccf0wWaZTSaazbzIliArvCN6sJkISrRRJk3DaLGyXIOfBVu0gvMARORuvA==","signatures":[{"sig":"MEUCIQDti5XH9gsY7oUWy02GP1S8zVDEVs+fA5XcU3JBTlz0NQIgJonHsQGXWHTbN+Q/LEPsMYe/iX6oredLLwXnp/T2Nh4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2fauthkit-sveltekit@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3507951},"main":"./dist/index.cjs","type":"module","_from":"file:workos-authkit-sveltekit-0.3.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"dev":"tsup --watch","lint":"eslint src --ext .ts","test":"vitest","build":"tsup","format":"prettier --write .","prettier":"prettier --check .","typecheck":"tsc --noEmit","test:coverage":"vitest --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:5d870e54-f5a7-4933-9aa0-6fb40fab236d"}},"_resolved":"/tmp/62a254a6d58a79c924e883a2968802e1/workos-authkit-sveltekit-0.3.0.tgz","_integrity":"sha512-44HLylxP3fWuUXvjXF8ptOCHKQt3Ccf0wWaZTSaazbzIliArvCN6sJkISrRRJk3DaLGyXIOfBVu0gvMARORuvA==","repository":{"url":"git+https://github.com/workos/authkit-sveltekit.git","type":"git"},"_npmVersion":"11.11.0","description":"Official WorkOS AuthKit SDK for SvelteKit","directories":{},"_nodeVersion":"24.14.1","dependencies":{"cookie":"^1.1.1","set-cookie-parser":"^3.1.0","@workos/authkit-session":"^0.5.1"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","eslint":"^9.39.0","vitest":"^4.0.18","prettier":"^3.8.1","typescript":"^5.9.3","@types/node":"^24.1.0","@sveltejs/kit":"^2.50.2","@types/cookie":"^0.6.0","@vitest/coverage-v8":"^4.0.18","prettier-plugin-svelte":"^3.4.1","@types/set-cookie-parser":"^2.4.10","@typescript-eslint/parser":"^8.54.0","@sveltejs/vite-plugin-svelte":"^6.2.4","@typescript-eslint/eslint-plugin":"^8.54.0"},"peerDependencies":{"@sveltejs/kit":">=2.20.0"},"_npmOperationalInternal":{"tmp":"tmp/authkit-sveltekit_0.3.0_1777072975871_0.8894062070037092","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2025-07-27T04:27:36.786Z","modified":"2026-08-19T19:51:32.358Z","0.0.1-alpha.0":"2025-07-27T04:27:37.155Z","0.0.1-alpha.1":"2025-07-29T17:48:08.441Z","0.1.0":"2026-02-04T21:23:28.119Z","0.2.0":"2026-04-22T21:24:44.480Z","0.3.0":"2026-04-24T23:22:56.086Z"},"bugs":{"url":"https://github.com/workos/authkit-sveltekit/issues"},"author":{"name":"WorkOS"},"license":"MIT","homepage":"https://github.com/workos/authkit-sveltekit#readme","keywords":["workos","authkit","sveltekit","authentication","auth"],"repository":{"url":"git+https://github.com/workos/authkit-sveltekit.git","type":"git"},"description":"Official WorkOS AuthKit SDK for SvelteKit","maintainers":[{"email":"gjtorikian@gmail.com","name":"gjtorikian"},{"email":"jacob.card-howe@workos.com","name":"jch-workos"},{"email":"matt@mattdavidson.kiwi","name":"mjdavidson"},{"email":"service+npm@workos.com","name":"npm-workos"},{"email":"matt.peake@workos.com","name":"peakematt-workos"},{"email":"jacobia@workos.com","name":"jacobia"},{"email":"mark@workos.com","name":"mark-workos"},{"email":"mgrinich@gmail.com","name":"grinich"},{"email":"nick@nisi.org","name":"nicknisi"}],"readme":"# AuthKit SDK for SvelteKit\n\nThe official WorkOS AuthKit SDK for SvelteKit applications. Provides seamless authentication with minimal setup.\n\n> **Looking for a complete example?** Check out the [example app](./example) in this repo.\n\n## Features\n\n- 🚀 **Quick Setup** - Get authenticated in under 5 minutes\n- 🔒 **Secure by Default** - Session-based auth with encrypted cookies\n- 🎯 **Type Safe** - Full TypeScript support with IntelliSense\n- 🏗️ **SvelteKit Native** - Built for SvelteKit's architecture\n- 🎨 **Flexible** - Easy to customize and extend\n- 🐛 **Developer Friendly** - Clear errors and debug mode\n\n## Installation\n\n```bash\nnpm install @workos/authkit-sveltekit\n```\n\n## Quick Start\n\n### 1. Set Environment Variables\n\nCreate a `.env` file in your project root:\n\n```env\nWORKOS_CLIENT_ID=client_01234567890123456789012345\nWORKOS_API_KEY=sk_test_1234567890\nWORKOS_REDIRECT_URI=http://localhost:5173/callback\nWORKOS_COOKIE_PASSWORD=your-secure-password-at-least-32-chars\n```\n\n> **Note**: Generate a secure password using `openssl rand -base64 24`\n\n### 2. Update `app.d.ts`\n\n```typescript\n/// <reference types=\"@sveltejs/kit\" />\n\ndeclare global {\n  namespace App {\n    interface Locals {\n      auth: import('@workos/authkit-sveltekit').AuthKitAuth;\n    }\n  }\n}\n\nexport {};\n```\n\n### 3. Add to `hooks.server.ts`\n\n```typescript\nimport { configureAuthKit, authKitHandle } from '@workos/authkit-sveltekit';\nimport { env } from '$env/dynamic/private';\n\n// Configure AuthKit with SvelteKit's environment variables\nconfigureAuthKit({\n  clientId: env.WORKOS_CLIENT_ID,\n  apiKey: env.WORKOS_API_KEY,\n  redirectUri: env.WORKOS_REDIRECT_URI,\n  cookiePassword: env.WORKOS_COOKIE_PASSWORD,\n});\n\nexport const handle = authKitHandle();\n```\n\n> **Note**: For simpler setups where you're using `process.env`, you can skip the `configureAuthKit` call and the SDK will automatically read from `process.env`.\n\n### 4. Create Callback Route\n\nCreate `src/routes/callback/+server.ts`:\n\n```typescript\nimport { authKit } from '@workos/authkit-sveltekit';\nimport type { RequestHandler } from './$types';\n\nexport const GET: RequestHandler = async (event) => {\n  const handler = authKit.handleCallback();\n  return handler(event);\n};\n```\n\n### 5. Create Sign-in Endpoint\n\nCreate a route that initiates the AuthKit sign-in flow. This route is used as the **Sign-in endpoint** (also known as `initiate_login_uri`) in your WorkOS dashboard settings.\n\nCreate `src/routes/sign-in/+server.ts`:\n\n```typescript\nimport { redirect } from '@sveltejs/kit';\nimport { authKit } from '@workos/authkit-sveltekit';\nimport type { RequestHandler } from './$types';\n\nexport const GET: RequestHandler = async () => {\n  const signInUrl = await authKit.getSignInUrl();\n  throw redirect(302, signInUrl);\n};\n```\n\nIn the [WorkOS dashboard **Redirects** settings](https://dashboard.workos.com/redirects), set the **Sign-in endpoint** to match this route (e.g., `http://localhost:5173/sign-in`).\n\n> **Important**: The sign-in endpoint is required for features like [impersonation](https://workos.com/docs/user-management/impersonation) to work correctly. Without it, WorkOS-initiated flows (such as impersonating a user from the dashboard) will fail because they cannot complete the PKCE/CSRF verification this library enforces on every callback.\n\n### 6. Protect Routes\n\nIn any `+page.server.ts`:\n\n```typescript\nimport { authKit } from '@workos/authkit-sveltekit';\n\nexport const load = authKit.withAuth(async ({ auth }) => {\n  // auth.user is guaranteed to exist\n  return {\n    user: auth.user,\n    organizationId: auth.organizationId,\n    role: auth.role,\n    permissions: auth.permissions,\n  };\n});\n```\n\n## API Reference\n\n### Authentication Helpers\n\n#### `authKit.withAuth(handler)`\n\nProtect a route or action, redirecting unauthenticated users to sign in.\n\n```typescript\nexport const load = authKit.withAuth(async ({ auth, ...event }) => {\n  // Your authenticated logic here\n});\n```\n\n> Apply `withAuth` only to routes that serve top-level HTML documents.\n> Using it on JSON API endpoints will set PKCE verifier cookies on XHR\n> responses that can't complete the OAuth flow, which (with per-flow cookie\n> naming in authkit-session 0.5.0) can accumulate into HTTP 431 under\n> concurrent load.\n\n#### `authKit.getUser(event)`\n\nGet the current user (nullable).\n\n```typescript\nexport const load = async (event) => {\n  const user = await authKit.getUser(event);\n  return { user };\n};\n```\n\n#### `authKit.getSignInUrl(options)`\n\nGet the WorkOS sign-in URL.\n\n```typescript\nconst signInUrl = authKit.getSignInUrl({\n  returnTo: '/dashboard',\n  organizationId: 'org_123', // optional\n  loginHint: 'user@example.com', // optional\n});\n```\n\n#### `authKit.getSignUpUrl(options)`\n\nGet the WorkOS sign-up URL.\n\n```typescript\nconst signUpUrl = authKit.getSignUpUrl({\n  returnTo: '/dashboard',\n  organizationId: 'org_123', // optional\n  loginHint: 'user@example.com', // optional\n});\n```\n\n#### `authKit.signOut(event)`\n\nSign out the current user.\n\n```typescript\nexport const actions = {\n  signout: async (event) => {\n    return authKit.signOut(event);\n  },\n};\n```\n\n### Hooks\n\n#### `authKitHandle(options)`\n\nSvelteKit handle function that manages authentication.\n\n```typescript\nexport const handle = authKitHandle({\n  debug: true, // Enable debug logging\n  onError: (error) => console.error('Auth error:', error),\n});\n```\n\n## Configuration\n\n```typescript\ninterface AuthKitConfig {\n  clientId: string; // WorkOS Client ID\n  apiKey: string; // WorkOS API Key\n  redirectUri: string; // OAuth redirect URI\n  cookiePassword: string; // Cookie encryption password (min 32 chars)\n  cookieName?: string; // Custom cookie name (default: 'wos-session')\n  cookieDomain?: string; // Cookie domain restriction\n  cookieMaxAge?: number; // Cookie max age in seconds (default: 400 days)\n}\n```\n\n### Environment Variables\n\nAuthKit supports multiple ways to configure environment variables in SvelteKit:\n\n#### Option 1: Using SvelteKit's `$env` (Recommended)\n\n```typescript\n// hooks.server.ts\nimport { configureAuthKit, authKitHandle } from '@workos/authkit-sveltekit';\nimport { env } from '$env/dynamic/private';\n\nconfigureAuthKit({\n  clientId: env.WORKOS_CLIENT_ID,\n  apiKey: env.WORKOS_API_KEY,\n  redirectUri: env.WORKOS_REDIRECT_URI,\n  cookiePassword: env.WORKOS_COOKIE_PASSWORD,\n});\n\nexport const handle = authKitHandle();\n```\n\n#### Option 2: Using Static Environment Variables\n\n```typescript\n// hooks.server.ts\nimport { configureAuthKit, authKitHandle } from '@workos/authkit-sveltekit';\nimport { WORKOS_CLIENT_ID, WORKOS_API_KEY, WORKOS_REDIRECT_URI, WORKOS_COOKIE_PASSWORD } from '$env/static/private';\n\nconfigureAuthKit({\n  clientId: WORKOS_CLIENT_ID,\n  apiKey: WORKOS_API_KEY,\n  redirectUri: WORKOS_REDIRECT_URI,\n  cookiePassword: WORKOS_COOKIE_PASSWORD,\n});\n\nexport const handle = authKitHandle();\n```\n\n#### Option 3: Automatic Configuration (Node.js environments)\n\nIf your environment supports `process.env`, the SDK will automatically read configuration:\n\n```typescript\n// hooks.server.ts\nimport { authKitHandle } from '@workos/authkit-sveltekit';\n\n// No configureAuthKit needed - reads from process.env automatically\nexport const handle = authKitHandle();\n```\n\n## Advanced Usage\n\n### Organization Switching\n\n```typescript\nexport const actions = {\n  switchOrg: async (event) => {\n    const formData = await event.request.formData();\n    const orgId = formData.get('organizationId') as string;\n\n    return authKit.switchOrganization(event, { organizationId: orgId });\n  },\n};\n```\n\n### Custom Sign-in Page\n\n```svelte\n<script lang=\"ts\">\n  import { authKit } from '@workos/authkit-sveltekit';\n\n  // Note: These methods are async and should be called server-side\n  // For client-side, pass the URL from a server load function\n</script>\n\n<!-- Use URLs generated server-side -->\n<a href={data.signInUrl}>Sign In</a>\n<a href={data.signUpUrl}>Sign Up</a>\n```\n\nServer-side load function:\n\n```typescript\n// +page.server.ts\nimport { authKit } from '@workos/authkit-sveltekit';\n\nexport const load = async () => {\n  return {\n    signInUrl: await authKit.getSignInUrl({ returnTo: '/dashboard' }),\n    signUpUrl: await authKit.getSignUpUrl({ returnTo: '/dashboard' }),\n  };\n};\n```\n\n### Form Actions\n\nProtect form actions the same way as load functions:\n\n```typescript\nexport const actions = {\n  update: authKit.withAuth(async ({ auth, request }) => {\n    const formData = await request.formData();\n    // Process authenticated form submission\n  }),\n};\n```\n\n## TypeScript\n\nThe SDK is fully typed. Access auth data with type safety:\n\n```typescript\nimport type { PageServerLoad } from './$types';\n\nexport const load: PageServerLoad = async ({ locals }) => {\n  if (locals.auth.user) {\n    // TypeScript knows user exists and its shape\n    console.log(locals.auth.user.email);\n    console.log(locals.auth.organizationId);\n    console.log(locals.auth.role);\n    console.log(locals.auth.permissions);\n    console.log(locals.auth.accessToken);\n  }\n};\n```\n\n## Debugging\n\nEnable debug mode to see detailed logs:\n\n```typescript\nexport const handle = authKitHandle({ debug: true });\n```\n\n## Error Handling\n\nThe SDK provides clear error messages:\n\n```\nMissing required environment variables: WORKOS_CLIENT_ID, WORKOS_API_KEY\nPlease add them to your .env file. See https://github.com/workos/authkit-sveltekit#setup for details.\n```\n\n## Troubleshooting\n\n### `Missing required auth parameter` when impersonating from the WorkOS dashboard\n\nThis error occurs when WorkOS-initiated flows (like dashboard impersonation) redirect directly to your callback URL without going through your application's sign-in flow. Because this library enforces PKCE/CSRF verification on every callback, the request is rejected when the required `state` parameter is missing.\n\n**Fix:** Configure a [sign-in endpoint](#5-create-sign-in-endpoint) in your WorkOS dashboard so that impersonation flows route through your app first, allowing PKCE/state to be set up before redirecting to WorkOS.\n\n## License\n\nMIT - see [LICENSE](LICENSE) for details.\n","readmeFilename":"README.md"}