---
title: "Identity and access"
description: "Authentication, tenancy, devices, credentials, MFA, third-party connections, and audit boundaries."
tags: ["packages","identity","access","security"]
---

Identity packages separate who a user is, which account they are acting within, which device or credential is involved, and what the application is allowed to do next.

## Authentication and accounts

| Package                                                               | Plan                        | Responsibility                                       |
| --------------------------------------------------------------------- | --------------------------- | ---------------------------------------------------- |
| [`@playstack/auth`](/docs/packages/identity/auth)                     | <PlanTierDot tier="free" /> | Identity and opaque session primitives.              |
| [`@playstack/auth-contracts`](/docs/packages/identity/auth-contracts) | <PlanTierDot tier="free" /> | Client-safe session projection and parsing.          |
| [`@playstack/auth-react`](/docs/packages/identity/auth-react)         | <PlanTierDot tier="pro" />  | React session state and client auth actions.         |
| [`@playstack/auth-next`](/docs/packages/identity/auth-next)           | <PlanTierDot tier="pro" />  | Pages and App Router session handoff and protection. |
| [`@playstack/auth-authjs`](/docs/packages/identity/auth-authjs)       | <PlanTierDot tier="pro" />  | Auth.js callback and safe-session bridge.            |
| [`@playstack/nest-auth`](/docs/packages/identity/nest-auth)           | <PlanTierDot tier="pro" />  | NestJS guards, decorators, and CSRF transport.       |
| [`@playstack/accounts`](/docs/packages/identity/accounts)             | <PlanTierDot tier="free" /> | Tenancy, membership, invitations, and account scope. |
| [`@playstack/accounts-react`](/docs/packages/identity/accounts-react) | <PlanTierDot tier="pro" />  | React account-list and active-account state.         |
| [`@playstack/nest-accounts`](/docs/packages/identity/nest-accounts)   | <PlanTierDot tier="pro" />  | NestJS account scope and role guards.                |
| [`@playstack/client-auth`](/docs/packages/identity/client-auth)       | <PlanTierDot tier="free" /> | PKCE authentication for public native clients.       |

## Trust and credentials

| Package                                                                 | Plan                        | Responsibility                                           |
| ----------------------------------------------------------------------- | --------------------------- | -------------------------------------------------------- |
| [`@playstack/devices`](/docs/packages/identity/devices)                 | <PlanTierDot tier="free" /> | Registered devices, push targets, trust, and revocation. |
| [`@playstack/mfa`](/docs/packages/identity/mfa)                         | <PlanTierDot tier="free" /> | Passkeys, TOTP, recovery, and recent-auth proofs.        |
| [`@playstack/api-keys`](/docs/packages/identity/api-keys)               | <PlanTierDot tier="free" /> | Customer API-key issuance, scopes, and revocation.       |
| [`@playstack/nest-api-keys`](/docs/packages/identity/nest-api-keys)     | <PlanTierDot tier="pro" />  | NestJS API-key guards and rate-limit declarations.       |
| [`@playstack/connections`](/docs/packages/identity/connections)         | <PlanTierDot tier="free" /> | Encrypted third-party API credentials and refresh.       |
| [`@playstack/atproto`](/docs/packages/identity/atproto)                 | <PlanTierDot tier="pro" />  | DPoP-aware AT Protocol OAuth lifecycle.                  |
| [`@playstack/extension`](/docs/packages/identity/extension)             | <PlanTierDot tier="free" /> | MV3-safe extension auth, messaging, and storage.         |
| [`@playstack/extension-react`](/docs/packages/identity/extension-react) | <PlanTierDot tier="pro" />  | Reactive extension session and permission state.         |
| [`@playstack/audit`](/docs/packages/identity/audit)                     | <PlanTierDot tier="free" /> | Tamper-evident per-scope audit chains.                   |
| [`@playstack/nest-audit`](/docs/packages/identity/nest-audit)           | <PlanTierDot tier="pro" />  | Explicit NestJS route audit declarations.                |

## Billing and platform access

| Package                                                                     | Plan                        | Responsibility                                                  |
| --------------------------------------------------------------------------- | --------------------------- | --------------------------------------------------------------- |
| [`@playstack/billing`](/docs/packages/identity/billing)                     | <PlanTierDot tier="free" /> | Provider-neutral subscription projection and checkout boundary. |
| [`@playstack/nest-billing`](/docs/packages/identity/nest-billing)           | <PlanTierDot tier="pro" />  | NestJS account-aware billing composition.                       |
| [`@playstack/entitlements`](/docs/packages/identity/entitlements)           | <PlanTierDot tier="free" /> | Source-projected capabilities and numeric limits.               |
| [`@playstack/nest-entitlements`](/docs/packages/identity/nest-entitlements) | <PlanTierDot tier="pro" />  | NestJS entitlement guards and subject resolution.               |
| [`@playstack/github-app`](/docs/packages/identity/github-app)               | <PlanTierDot tier="free" /> | Scoped GitHub App installation-token lifecycle.                 |
| [`@playstack/nest-github-app`](/docs/packages/identity/nest-github-app)     | <PlanTierDot tier="pro" />  | NestJS binding for the GitHub App service.                      |

## Licensing

| Package                                                                   | Plan                        | Responsibility                                                    |
| ------------------------------------------------------------------------- | --------------------------- | ----------------------------------------------------------------- |
| [`@playstack/licensing`](/docs/packages/identity/licensing)               | <PlanTierDot tier="free" /> | Portable signed-license parsing and offline verification.         |
| [`@playstack/licensing-issuer`](/docs/packages/identity/licensing-issuer) | <PlanTierDot tier="free" /> | Server-side issuance, activation, refresh, seats, and revocation. |
| [`@playstack/nest-licensing`](/docs/packages/identity/nest-licensing)     | <PlanTierDot tier="pro" />  | NestJS client and administration composition for license issuers. |

## Keep the boundaries separate

Authentication proves identity. Accounts establish tenancy and membership. API keys authenticate external callers. Connections hold credentials for acting against another provider. Audit records what happened. Keeping those jobs separate prevents one package from becoming the authorization policy for an entire application.
