theauth-go ships a complete OAuth 2.1 Authorization Server (AS) behind Config.AuthorizationServer. It is opt-in: callers who do not set this field get the v1.0 surface unchanged.
Wiring the AS
EncryptionKey is required when AuthorizationServer is set. It protects the Ed25519 signing key at rest.
Routes mounted by a.Mount(r)
When AuthorizationServer is configured:
Dynamic Client Registration
Agent identities and delegation
Add Config.AgentIdentity to enable agent CRUD and the delegation grant system:
Create an agent:
Trusted proxies
By default, X-Forwarded-For is not trusted. Enable it for specific proxy prefixes:
Key rotation
Signing keys rotate every 30 days. The JWKS endpoint always serves the current and one previous key so resource servers with a cached JWKS can verify tokens minted before the rotation. Call a.RotateSigningKey(ctx) to rotate ahead of schedule.
Admin surface for agents and delegations
When RBAC is enabled, the admin API gains org-scoped agent and delegation management:
These routes require the agents:admin and delegations:admin RBAC permissions respectively.
Next steps
Last modified on October 7, 2026