Connections

Authorize, encrypt, refresh, and revoke third-party credentials without moving provider APIs or product workflows into a generic abstraction.

Supported approaches

OAuth connections

available

Run purpose-bound PKCE authorization and keep encrypted rotating credentials in user or account scope.

Packages

@playstack/connections

Frameworks and integrations

Named providers

available

Use GitHub, LinkedIn, Mastodon, and X drivers or the standards-based OAuth 2 factory.

Frameworks and integrations

AT Protocol sessions

available

Preserve official AT Protocol discovery, PAR, PKCE, DPoP, nonce, and session-store behavior.

Frameworks and integrations

Frameworks and integrations

integration

OAuth 2 providers

Configurable OAuth 2 credential lifecycle for provider APIs, separate from application login.

integration

LinkedIn

A packaged LinkedIn connection adapter with application-owned scopes and product operations.

integration

Mastodon

A packaged Mastodon connection adapter with explicit instance and credential ownership.

integration

X

A packaged X OAuth 2 connection adapter with explicit application permissions.

integration

GitHub

Connect OAuth credentials, GitHub App installation tokens, and verified webhook delivery through explicit Playstack boundaries.

integration

AT Protocol

Use the official AT Protocol OAuth client while keeping discovery, PAR, PKCE, DPoP, nonces, and session storage intact.

framework

Next.js

Compose Playstack server contracts, React bindings, SSR handoff, and route adapters at the Next.js application edge.

framework

NestJS

Connect portable Playstack capabilities to dependency injection, guards, decorators, request context, workers, and lifecycle hooks.

Package reference

@playstack/connections

Own credential lifecycle once

@playstack/connections provides purpose-bound OAuth state, PKCE, encrypted credential persistence, refresh serialization, and revocation. The core returns a valid access token while the application calls provider SDKs and owns product actions such as publishing, importing, or repository management.

ts
const connections = createConnections({
  persistence,
  crypto,
  events,
  clock,
  ids,
  providers: [github, mastodon, x],
  scope: 'account',
  redirectUri: 'https://app.example/api/connections/callback',
  returnUrlOrigins: ['https://app.example'],
})

GitHub, LinkedIn, Mastodon, and X have named providers. A standards-based OAuth 2 factory covers conventional authorization-code providers while preserving explicit identity lookup and native driver access.

Respect unusual protocols

AT Protocol is not flattened into a bearer-token preset. @playstack/atproto wraps the official OAuth client so discovery, PAR, PKCE, DPoP keys and nonces, rotating refresh tokens, and shared session storage keep their native semantics.

Select persistence ownership

Playstack publishes user, account, and account-member Prisma variants. Mature applications can instead implement the portable persistence contract against an existing schema and keep identifier or table mappings application-owned.

Go

Playstack Pro tag
OriginsPricingBlogNewsletterChangelogStatusRoadmap
ContributorsCommunityIn Use ShowcaseCase StudiesPartnersSponsors
FAQsSupportContact

© 2026 Playstack. All rights reserved.

With OSS
Terms of ServicePrivacy PolicyCookie PolicyImprint

By

Commune Software