Skip to main content
The theauth.Config struct is the single wiring point for a theauth-go instance. Pass it to theauth.New(cfg).

Required fields

Rate limiting

Email

OAuth providers

WebAuthn / passkeys

TOTP

Organizations (multi-tenancy)

SAML 2.0

SCIM 2.0

RBAC

Audit log

Admin API

OAuth 2.1 Authorization Server (v2.0)

AuthorizationServerConfig also carries several fields not detailed above: SigningAlg, KeyRotationPeriod, KeyRetention, AuthorizationCodeTTL, RegistrationAccessTokenTTL, Clock, LoginURL, DisableRotation, DPoP *DPoPConfig (RFC 9449 sender-constrained tokens), and CIMD *CIMDConfig (Client ID Metadata Documents resolver). See config.go and models.go in the repository for the full field list until this page is expanded.

Password policy (v2.4)

Agent identity and delegation (v2.0)

Observability

See Wire OpenTelemetry Tracing and Metrics Reference for details.
Last modified on October 7, 2026