Compose credentials, magic links, sessions, passkeys, MFA, and connected-provider access without handing application identity to a framework.
Email and password · Magic links · Sessions · Passkeys and MFA · Auth.js provider sign-in · OAuth connections
Model organizations, memberships, invitations, ownership, active-account switching, and fail-closed data scope.
Memberships and roles · Invitations · Ownership transfer · Recoverable deletion
Carry typed domain events, operation context, transactional delivery, and replay-safe processing across application boundaries.
Event storage and replay
Apply fail-closed limits with trustworthy subjects and explicit Redis, Prisma, or Durable Object storage.
Distributed counters
Register application devices, manage push destinations, establish bounded trust, and revoke device-backed access from one explicit identity boundary.
Device registration and inventory · Push destinations · Trusted-device sessions
Synchronize subscription state, project purchased access into stable grants, and enforce capabilities without scattering plan-name checks through application code.
Subscription lifecycle · Entitlement projection · Request enforcement · No-card product trials · Billing operations
Issue scoped machine credentials, authenticate them at the server boundary, and record security-relevant actions without turning logs into policy.
API key lifecycle · Structured audit recording
Compose server-authored products, one-time checkout, finite stock, immutable orders, and physical fulfillment without turning one provider into the domain model.
Catalog and quotes · One-time checkout · Refunds and reconciliation · Physical fulfillment
Define typed notifications, resolve recipient preferences, deliver across explicit channels, and retain one provider-independent history of every send.
In-app inbox · Delivery history and feedback
Build waitlists, newsletters, release lists, and preference centers with explicit consent, segmentation, confirmation, and delivery boundaries.
Subscription lifecycle · Consent and preferences · Segmentation
Verify provider requests from raw bytes, claim events transactionally, enqueue normalized work exactly once, and keep provider parsing outside domain handlers.
Transactional receipt claims
Issue signed licenses, activate device-bound seats, verify access offline, rotate refresh credentials, and revoke grants without coupling product policy to the token protocol.
Issuance and activation · Refresh and revocation · Entitlement projection