Skip to main content
theauth-go ships a complete OAuth 2.1 Authorization Server (AS) behind Config.AuthorizationServer. It is opt-in: callers who do not set this field get the v1.0 surface unchanged.

Wiring the AS

EncryptionKey is required when AuthorizationServer is set. It protects the Ed25519 signing key at rest.

Routes mounted by a.Mount(r)

When AuthorizationServer is configured:

Dynamic Client Registration

Agent identities and delegation

Add Config.AgentIdentity to enable agent CRUD and the delegation grant system:
Create an agent:

Trusted proxies

By default, X-Forwarded-For is not trusted. Enable it for specific proxy prefixes:

Key rotation

Signing keys rotate every 30 days. The JWKS endpoint always serves the current and one previous key so resource servers with a cached JWKS can verify tokens minted before the rotation. Call a.RotateSigningKey(ctx) to rotate ahead of schedule.

Admin surface for agents and delegations

When RBAC is enabled, the admin API gains org-scoped agent and delegation management:
These routes require the agents:admin and delegations:admin RBAC permissions respectively.

Next steps

Last modified on October 7, 2026