tauth-sdk/README.md
2026-04-14 00:59:45 +02:00

1.8 KiB

tauth-sdk

TypeScript SDK for TAuth-based login and transport session bootstrap.

This SDK starts a local HTTP callback server, verifies a challenge, and opens an authenticated TTP transport client per userId:sessionId.

What this SDK does

  • Generates and verifies authentication challenges
  • Starts callback and auth endpoints (/callback, /auth)
  • Redirects users to your TAuth frontend URL
  • Creates and tracks TTP clients in clientMap

Requirements

  • A modern version of Bun
  • A domain with TXT record support
  • App X448 key pair (privateKey, publicKey) (can be generated)

Install

bun add https://git.methanium.net/tensamin/tauth-sdk/archive/0.0.1.tar.gz

Generate an app key pair

Use the built-in helper once and store the keys securely:

import { generateKeyPair } from "@tensamin/tauth-sdk";

const keys = generateKeyPair();
console.log(keys.private);
console.log(keys.public);

Add the TXT record

Add a TXT record at tauth.your.domain with your app public key as the value (base64 format). This is used to verify that your app is authorized for your domain.

Basic usage

import z from "zod";
import { TAuthClient } from "@tensamin/tauth-sdk";

const client = new TAuthClient({
  frontendUrl: "http://localhost:3000",
  identifier: "your-app-identifier",
  privateKey: "<APP_PRIVATE_KEY_BASE64>",
  publicKey: "<APP_PUBLIC_KEY_BASE64>",
  redirectUrl: "http://localhost:7878/callback",
  appData: z.object({
    my: z.string(),
    cool: z.string(),
    data: z.string(),
  }),
  httpServer: {
    hostname: "localhost",
    port: 7878,
  },
});

Endpoints exposed by the SDK

  • GET /auth: Redirects user to TAuth frontend
  • GET /callback: Handles challenge flow and session bootstrap

These endpoints need to be exposed behind some kind of http proxy to apply ssl