> ## Documentation Index
> Fetch the complete documentation index at: https://docs.theauth.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# theAuth for Go

> A Go auth library that ships OAuth 2.1 MCP authorization, agent identities, and revocable delegation chains in a single import.

[![Go Reference](https://pkg.go.dev/badge/github.com/glincker/theauth-go.svg)](https://pkg.go.dev/github.com/glincker/theauth-go/v2)
[![CI](https://github.com/glincker/theauth-go/actions/workflows/ci.yml/badge.svg)](https://github.com/glincker/theauth-go/actions/workflows/ci.yml)
[![Release](https://img.shields.io/github/v/release/glincker/theauth-go)](https://github.com/glincker/theauth-go/releases)
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://github.com/glincker/theauth-go/blob/main/LICENSE)

**A Go auth library where OAuth 2.1 MCP authorization, agent identities, and revocable delegation chains ship in a single import.**

Drop it into a `chi` or `net/http` server in a few lines. Store sessions in Postgres, MySQL, SQLite, or memory.

## Install

```bash theme={"dark"}
go get github.com/glincker/theauth-go/v2
```

Requires **Go 1.25+**.

## Quick Start

```go theme={"dark"}
package main

import (
    "net/http"

    "github.com/glincker/theauth-go/v2"
    "github.com/glincker/theauth-go/v2/storage/memory"
    "github.com/go-chi/chi/v5"
)

func main() {
    a, _ := theauth.New(theauth.Config{
        Storage: memory.New(),
        BaseURL: "http://localhost:8080",
    })

    r := chi.NewRouter()
    a.Mount(r)

    r.With(a.RequireAuth()).Get("/me", func(w http.ResponseWriter, r *http.Request) {
        user, _ := theauth.UserFromContext(r.Context())
        w.Write([]byte("hello " + user.Email))
    })

    http.ListenAndServe(":8080", r)
}
```

Run it:

```bash theme={"dark"}
go run main.go
# POST http://localhost:8080/auth/magic-link  {"email":"you@example.com"}
```

## What it covers

| Area | Capability |
| - | - |
| Identity | Magic links, email/password (Argon2id), WebAuthn passkeys, TOTP, OAuth providers |
| Enterprise | SAML 2.0 SP, SCIM 2.0, multi-tenancy organizations, RBAC |
| OAuth 2.1 AS | Authorization code + PKCE, refresh rotation, DCR, EdDSA JWTs, audience binding |
| MCP | Agent identities, revocable delegation chains (RFC 8693), resource-server SDK |
| Hardening | Audit log, rate limiting, fuzz tests, benchmark gate, OTel/Prom adapter |

## Documentation

* [Getting Started](/go/getting-started/overview) - Installation, quick start, storage backends
* [Concepts](/go/concepts/oauth21-primer) - OAuth 2.1, MCP authorization, AS/RS roles
* [Guides](/go/guides/add-oauth-provider) - Step-by-step task guides
* [Reference](/go/reference/configuration) - Config shape, errors, metrics, spans, audit events
* [Security](/go/security/threat-model) - Threat model, release verification
* [Migrations](/go/migrations/v2.0-to-v2.1) - Upgrade guides between versions
* [Changelog](/go/changelog) - Full release history

## MCP Resource Server

For MCP servers that only need token validation (no auth server), install the zero-dependency SDK:

```bash theme={"dark"}
go get github.com/glincker/theauth-go/mcpresource
```

```go theme={"dark"}
v := mcpresource.New(
    "https://mcp.example.com",
    mcpresource.WithJWKS("https://as.example.com/oauth/jwks"),
    mcpresource.WithIntrospection(
        "https://as.example.com/oauth/introspect",
        "mcp-client-id", "mcp-client-secret",
    ),
)
r.Use(v.Middleware)
```

See [Resource Server (mcpresource)](/go/concepts/resource-server) for the full walkthrough.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.