framework
React
Headless domain bindings plus optional Chakra application and admin compositions, with server authority kept outside the client.
Model organizations, memberships, invitations, ownership, active-account switching, and fail-closed data scope.
available
Resolve active membership and application-defined roles for every account-scoped operation.
available
Issue expiring invitation tokens through an application-owned delivery bridge.
available
Reissue account-scoped sessions and synchronize the selected account in application UI.
available
Propose, deliver, accept, or cancel a single-use ownership transfer while preserving the one-owner invariant.
available
Hide an account immediately, permit restoration during grace, then run bounded application cascades before purge.
Packages
framework
Headless domain bindings plus optional Chakra application and admin compositions, with server authority kept outside the client.
framework
Compose Playstack server contracts, React bindings, SSR handoff, and route adapters at the Next.js application edge.
framework
Connect portable Playstack capabilities to dependency injection, guards, decorators, request context, workers, and lifecycle hooks.
integration
Persist Playstack capabilities through explicit application-owned Prisma clients, transactions, and managed schema fragments.
integration
Deliver rendered messages and SES templates through an application-configured AWS SDK client.
integration
Deliver rendered messages or stored Mailgun templates through an explicit regional provider client.
integration
Deliver rendered Playstack mail or Postmark provider templates through an explicit driver and native client escape hatch.
integration
Deliver transactional mail and synchronize consent-aware audience contacts through explicit Resend adapters.
integration
Deliver rendered messages and dynamic templates through an isolated SendGrid mail client.
integration
Deliver portable rendered email through an application-configured Nodemailer transport.
Accounts model the tenant a user is acting within and the membership that permits that scope. Framework adapters carry the validated result; they do not infer account access from request parameters.
Authenticate first, resolve account membership second, then apply roles and fail-closed persistence scope before executing product behavior.
The service exposes member and invitation lists, account name/slug updates, self-service leaving, and account-scoped session switching. Ownership changes use a delivered single-use proposal rather than an immediate administrative mutation, keeping the owner pointer and both membership roles in one transaction.
Signup can register userRegistrationHandler() on auth’s transactional
registration event to create the initial account and owner membership before
the user commits. Recoverable deletion hides an account immediately, supports
restoration during the configured grace period, and leaves scheduling plus
cross-database erasure to the application.
administration: 'owners-only' restricts membership administration; the default remains owners-and-admins. mutationPolicy.assertAllowed(input, transaction) can enforce product-owned personal-account rules before writes. Hooks restrict built-in permissions rather than grant extra authority, and must use the supplied transaction.
slugPolicy supports normalization and reserved-slug decisions. createAccountPolicy() provides named permissions for the Nest guard; service policy and resource authorization remain separate. Single-owner behavior is still the shipped model: hooks do not implement multi-owner accounts or automatic personal-to-team conversion.
An optional Nest resolveRequestAccount strategy supports user-wide sessions with current membership checks. A session already scoped to an account cannot select another; ordinary account switching retains its session-rotation behavior.