No description
  • JavaScript 95.6%
  • Nunjucks 4.4%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-10-09 08:15:10 +02:00
assets feat: initial commit - IndieAuth endpoint for Indiekit 2026-02-06 16:34:46 +01:00
lib style: lint JavaScript 2026-10-05 22:17:03 +01:00
locales feat: initial commit - IndieAuth endpoint for Indiekit 2026-02-06 16:34:46 +01:00
test test: drop client-origin.js, covered by upstream's client tests 2026-09-15 20:04:07 +02:00
views feat: initial commit - IndieAuth endpoint for Indiekit 2026-02-06 16:34:46 +01:00
.gitignore feat: initial commit - IndieAuth endpoint for Indiekit 2026-02-06 16:34:46 +01:00
CHANGELOG.md v1.0.0-beta.29 2026-08-16 23:22:42 +00:00
CLAUDE.md docs: add fork notice to README, adopt version-in-package.json policy 2026-08-15 21:46:17 +02:00
index.js feat(endpoint-auth): support profile scope and add userinfo endpoint 2026-09-14 00:43:41 +01:00
package.json release: v1.0.0-beta.41 2026-10-07 18:42:26 +02:00
README.md feat(endpoint-auth): support profile scope and add userinfo endpoint 2026-09-14 00:43:41 +01:00

@indiekit/endpoint-auth

IndieAuth authentication and authorization endpoint for Indiekit. Grants and verifies access tokens and authenticates users.

Installation

npm install @indiekit/endpoint-auth

Note

This package is installed alongside @indiekit/indiekit

Usage

To customise the behaviour of this plug-in, add @indiekit/endpoint-auth to your configuration, specifying options as required:

{
  "@indiekit/endpoint-auth": {
    "mountPath": "/authorize",
  },
}

You will also need to set the following environment variables:

  • SECRET - used to sign and verify tokens and salt password
  • PASSWORD_SECRET - hashed and salted password used when signing in. You can generate this value by visiting /auth/new-password

Options

Option Type Description
mountPath string Path to authorization endpoint. Optional, defaults to /auth.
profile object Profile information (name, url, photo) returned to clients granted the profile scope. Optional; anything not configured is discovered from the h-card on your website.