integration
OAuth 2 providers
Configurable OAuth 2 credential lifecycle for provider APIs, separate from application login.
Authorize, encrypt, refresh, and revoke third-party credentials without moving provider APIs or product workflows into a generic abstraction.
available
Run purpose-bound PKCE authorization and keep encrypted rotating credentials in user or account scope.
Packages
available
Use GitHub, LinkedIn, Mastodon, and X drivers or the standards-based OAuth 2 factory.
Packages
Frameworks and integrations
available
Preserve official AT Protocol discovery, PAR, PKCE, DPoP, nonce, and session-store behavior.
Packages
Frameworks and integrations
integration
Configurable OAuth 2 credential lifecycle for provider APIs, separate from application login.
integration
A packaged LinkedIn connection adapter with application-owned scopes and product operations.
integration
A packaged Mastodon connection adapter with explicit instance and credential ownership.
integration
A packaged X OAuth 2 connection adapter with explicit application permissions.
integration
Connect OAuth credentials, GitHub App installation tokens, and verified webhook delivery through explicit Playstack boundaries.
integration
Use the official AT Protocol OAuth client while keeping discovery, PAR, PKCE, DPoP, nonces, and session storage intact.
framework
Compose Playstack server contracts, React bindings, SSR handoff, and route adapters at the Next.js application edge.
framework
Connect portable Playstack capabilities to dependency injection, guards, decorators, request context, workers, and lifecycle hooks.
@playstack/connections provides purpose-bound OAuth state, PKCE, encrypted credential persistence, refresh serialization, and revocation. The core returns a valid access token while the application calls provider SDKs and owns product actions such as publishing, importing, or repository management.
const connections = createConnections({
persistence,
crypto,
events,
clock,
ids,
providers: [github, mastodon, x],
scope: 'account',
redirectUri: 'https://app.example/api/connections/callback',
returnUrlOrigins: ['https://app.example'],
})GitHub, LinkedIn, Mastodon, and X have named providers. A standards-based OAuth 2 factory covers conventional authorization-code providers while preserving explicit identity lookup and native driver access.
AT Protocol is not flattened into a bearer-token preset. @playstack/atproto wraps the official OAuth client so discovery, PAR, PKCE, DPoP keys and nonces, rotating refresh tokens, and shared session storage keep their native semantics.
Playstack publishes user, account, and account-member Prisma variants. Mature applications can instead implement the portable persistence contract against an existing schema and keep identifier or table mappings application-owned.