On this page
  1. Authentication and accounts
  2. Trust and credentials
  3. Billing and platform access
  4. Licensing
  5. Keep the boundaries separate

Identity and access

Authentication, tenancy, devices, credentials, MFA, third-party connections, and audit boundaries.

Identity packages separate who a user is, which account they are acting within, which device or credential is involved, and what the application is allowed to do next.

Authentication and accounts

PackagePlanResponsibility
@playstack/authIdentity and opaque session primitives.
@playstack/auth-contractsClient-safe session projection and parsing.
@playstack/auth-reactReact session state and client auth actions.
@playstack/auth-nextPages and App Router session handoff and protection.
@playstack/auth-authjsAuth.js callback and safe-session bridge.
@playstack/nest-authNestJS guards, decorators, and CSRF transport.
@playstack/accountsTenancy, membership, invitations, and account scope.
@playstack/accounts-reactReact account-list and active-account state.
@playstack/nest-accountsNestJS account scope and role guards.
@playstack/client-authPKCE authentication for public native clients.

Trust and credentials

PackagePlanResponsibility
@playstack/devicesRegistered devices, push targets, trust, and revocation.
@playstack/mfaPasskeys, TOTP, recovery, and recent-auth proofs.
@playstack/api-keysCustomer API-key issuance, scopes, and revocation.
@playstack/nest-api-keysNestJS API-key guards and rate-limit declarations.
@playstack/connectionsEncrypted third-party API credentials and refresh.
@playstack/atprotoDPoP-aware AT Protocol OAuth lifecycle.
@playstack/extensionMV3-safe extension auth, messaging, and storage.
@playstack/extension-reactReactive extension session and permission state.
@playstack/auditTamper-evident per-scope audit chains.
@playstack/nest-auditExplicit NestJS route audit declarations.

Billing and platform access

PackagePlanResponsibility
@playstack/billingProvider-neutral subscription projection and checkout boundary.
@playstack/nest-billingNestJS account-aware billing composition.
@playstack/entitlementsSource-projected capabilities and numeric limits.
@playstack/nest-entitlementsNestJS entitlement guards and subject resolution.
@playstack/github-appScoped GitHub App installation-token lifecycle.
@playstack/nest-github-appNestJS binding for the GitHub App service.

Licensing

PackagePlanResponsibility
@playstack/licensingPortable signed-license parsing and offline verification.
@playstack/licensing-issuerServer-side issuance, activation, refresh, seats, and revocation.
@playstack/nest-licensingNestJS client and administration composition for license issuers.

Keep the boundaries separate

Authentication proves identity. Accounts establish tenancy and membership. API keys authenticate external callers. Connections hold credentials for acting against another provider. Audit records what happened. Keeping those jobs separate prevents one package from becoming the authorization policy for an entire application.

Go

Playstack Pro tag
OriginsPricingBlogNewsletterChangelogStatusRoadmap
ContributorsCommunityIn Use ShowcaseCase StudiesPartnersSponsors
FAQsSupportContact

© 2026 Playstack. All rights reserved.

With OSS
Terms of ServicePrivacy PolicyCookie PolicyImprint

By

Commune Software