Skip to main content

providers

Type Aliases​

EndpointHandler​

<P, C, R> AdvancedEndpointHandler<P, C, R>

Either an URL (containing all the parameters) or an object with more granular control.

Type parameters​

  • P extends UrlParams
  • C = any
  • R = any

Provider​

<P> OIDCConfig<P> | OAuth2Config<P> | EmailConfig | CredentialsConfig & {

}

Must be a supported authentication provider config:

  • OAuthConfig
  • EmailConfigInternal
  • CredentialsConfigInternal

For more information, see the guides:

See​

Type parameters​


ProviderType​

"oidc" | "oauth" | "email" | "credentials"

Providers passed to Auth.js must define one of these types.

See​

Interfaces​

CommonProviderOptions​

Shared across all ProviderType

Properties​

id​

string

Uniquely identifies the provider in AuthConfig.providers It's also part of the URL

name​

string

The provider name used on the default sign-in page's sign-in button. For example if it's "Google", the corresponding button will say: "Sign in with Google"

type​

ProviderType

See ProviderType


OAuth2Config​

TODO:

Type parameters​

  • Profile

Properties​

id​

string

Identifies the provider when you want to sign in to a specific provider.

Example​
signIn('github') // "github" is the provider ID

Overrides: CommonProviderOptions.id

name​

string

The name of the provider. shown on the default sign in page.

Overrides: CommonProviderOptions.name

allowDangerousEmailAccountLinking?​

boolean

Documentation

authorization?​

string | AuthorizationEndpointHandler

The login process will be initiated by sending the user to this URL.

Authorization endpoint

checks?​

("none" | "state" | "nonce" | "pkce")[]

The CSRF protection performed on the callback endpoint.

Default​

["pkce"]

RFC 7636 - Proof Key for Code Exchange by OAuth Public Clients (PKCE) | RFC 6749 - The OAuth 2.0 Authorization Framework | OpenID Connect Core 1.0 |

client?​

Partial<Client>

Pass overrides to the underlying OAuth library. See oauth4webapi client for details.

profile?​

ProfileCallback<Profile>

Receives the profile object returned by the OAuth provider, and returns the user object. This will be used to create the user in the database. Defaults to: id, email, name, image

Documentation

wellKnown?​

string

OpenID Connect (OIDC) compliant providers can configure this instead of authorize/token/userinfo options without further configuration needed in most cases. You can still use the authorize/token/userinfo options for advanced control.

Authorization Server Metadata


OIDCConfig​

TODO:

Type parameters​

  • Profile

Properties​

id​

string

Identifies the provider when you want to sign in to a specific provider.

Example​
signIn('github') // "github" is the provider ID

Inherited from: Omit.id

name​

string

The name of the provider. shown on the default sign in page.

Inherited from: Omit.name

allowDangerousEmailAccountLinking?​

boolean

Documentation

Inherited from: Omit.allowDangerousEmailAccountLinking

authorization?​

string | AuthorizationEndpointHandler

The login process will be initiated by sending the user to this URL.

Authorization endpoint

Inherited from: Omit.authorization

checks?​

("none" | "state" | "nonce" | "pkce")[]

The CSRF protection performed on the callback endpoint.

Default​

["pkce"]

RFC 7636 - Proof Key for Code Exchange by OAuth Public Clients (PKCE) | RFC 6749 - The OAuth 2.0 Authorization Framework | OpenID Connect Core 1.0 |

Inherited from: Omit.checks

client?​

Partial<Client>

Pass overrides to the underlying OAuth library. See oauth4webapi client for details.

Inherited from: Omit.client

profile?​

ProfileCallback<Profile>

Receives the profile object returned by the OAuth provider, and returns the user object. This will be used to create the user in the database. Defaults to: id, email, name, image

Documentation

Inherited from: Omit.profile

wellKnown?​

string

OpenID Connect (OIDC) compliant providers can configure this instead of authorize/token/userinfo options without further configuration needed in most cases. You can still use the authorize/token/userinfo options for advanced control.

Authorization Server Metadata

Inherited from: Omit.wellKnown