theauth-go emits metrics via the pluggable Metrics adapter (see Wire OpenTelemetry Tracing for wiring details). The metric catalog below is the authoritative list as of v2.3.0.
Metric names are exported as constants (theauth.MetricOAuthTokenRequestsTotal, etc.) so dashboards can reference them by symbol rather than by string.
Counter metrics
Histogram metrics
LatencyBuckets is [0.001, 0.005, 0.01, 0.05, 0.1, 0.5, 1, 5] seconds. Consumers pre-registering Prometheus histograms MUST use this exact slice so bucket boundaries align between library call sites and consumer registrations. The slice is exported as theauth.LatencyBuckets.
Gauge metrics
Label values
Cardinality discipline
High-cardinality identifiers (client_id, user_id, session_id, IP) go on spans as attributes, NEVER on metric labels. This is enforced by review at library call sites. The public Labels type does not prevent adding high-cardinality values manually; operators should validate label sets with promtool check rules.
Adding a custom metric
To add a metric to your own dashboards alongside theauth metrics, implement the Metrics interface and record from your own handler code. Do not monkey-patch the library’s internal call sites.
Prometheus wiring example
A reference Prometheus adapter ships in the repository at examples/observability-prom/. It is not a published package; copy and adapt it.
Last modified on October 7, 2026