Identity and access
Authentication, tenancy, devices, credentials, MFA, third-party connections, and audit boundaries.
Identity packages separate who a user is, which account they are acting within, which device or credential is involved, and what the application is allowed to do next.
Authentication and accounts
| Package | Plan | Responsibility |
|---|---|---|
@playstack/auth | Identity and opaque session primitives. | |
@playstack/auth-contracts | Client-safe session projection and parsing. | |
@playstack/auth-react | React session state and client auth actions. | |
@playstack/auth-next | Pages and App Router session handoff and protection. | |
@playstack/auth-authjs | Auth.js callback and safe-session bridge. | |
@playstack/nest-auth | NestJS guards, decorators, and CSRF transport. | |
@playstack/accounts | Tenancy, membership, invitations, and account scope. | |
@playstack/accounts-react | React account-list and active-account state. | |
@playstack/nest-accounts | NestJS account scope and role guards. | |
@playstack/client-auth | PKCE authentication for public native clients. |
Trust and credentials
| Package | Plan | Responsibility |
|---|---|---|
@playstack/devices | Registered devices, push targets, trust, and revocation. | |
@playstack/mfa | Passkeys, TOTP, recovery, and recent-auth proofs. | |
@playstack/api-keys | Customer API-key issuance, scopes, and revocation. | |
@playstack/nest-api-keys | NestJS API-key guards and rate-limit declarations. | |
@playstack/connections | Encrypted third-party API credentials and refresh. | |
@playstack/atproto | DPoP-aware AT Protocol OAuth lifecycle. | |
@playstack/extension | MV3-safe extension auth, messaging, and storage. | |
@playstack/extension-react | Reactive extension session and permission state. | |
@playstack/audit | Tamper-evident per-scope audit chains. | |
@playstack/nest-audit | Explicit NestJS route audit declarations. |
Billing and platform access
| Package | Plan | Responsibility |
|---|---|---|
@playstack/billing | Provider-neutral subscription projection and checkout boundary. | |
@playstack/nest-billing | NestJS account-aware billing composition. | |
@playstack/entitlements | Source-projected capabilities and numeric limits. | |
@playstack/nest-entitlements | NestJS entitlement guards and subject resolution. | |
@playstack/github-app | Scoped GitHub App installation-token lifecycle. | |
@playstack/nest-github-app | NestJS binding for the GitHub App service. |
Licensing
| Package | Plan | Responsibility |
|---|---|---|
@playstack/licensing | Portable signed-license parsing and offline verification. | |
@playstack/licensing-issuer | Server-side issuance, activation, refresh, seats, and revocation. | |
@playstack/nest-licensing | NestJS client and administration composition for license issuers. |
Keep the boundaries separate
Authentication proves identity. Accounts establish tenancy and membership. API keys authenticate external callers. Connections hold credentials for acting against another provider. Audit records what happened. Keeping those jobs separate prevents one package from becoming the authorization policy for an entire application.