Skip to content

Architecture ​

agent-auth is one process with one SQLite file. The same package provides the server, the CLI, the SDK client and the tool-server middleware.

Components ​

ModuleResponsibility
src/scope/Parses scopes, matches requests and checks that a child scope set is covered by its parent. Pure functions, no I/O.
src/service.tsGrants, tokens, checks, use counts, revocation, approvals and audit entries, in SQLite transactions.
src/server.tsThe REST API described by openapi.yaml.
src/tokens.ts, src/keys.tsSigns and verifies tokens with an Ed25519 key that the server creates on first start.
src/audit.tsHashes each audit entry over the previous hash and verifies the chain.
src/db.tsOpens SQLite with better-sqlite3 on Node.js or bun:sqlite in the standalone executables, and installs the append-only triggers.
src/middleware.tsverify() for Hono, verifyNode() for Connect-style servers, and the online and offline verifiers.
src/client.ts, src/cli.tsThe typed HTTP client and the agent-auth command built on it.

What happens on a check ​

A check writes its audit entry in the same transaction as the use count, so a decision is never returned without a record of it.

Design decisions ​

The architecture decision records explain why the service works this way.

Released under the Apache-2.0 license.