Skip to content

basalt / auth/src / AuthOptions

Interface: AuthOptions ​

Defined in: auth/src/auth.ts:239

Properties ​

accessTtl? ​

> optional accessTtl?: DurationInput

Defined in: auth/src/auth.ts:245


> optional accountLinks?: AccountLinkStore

Defined in: auth/src/auth.ts:298

Store binding provider subjects to accounts (Auth.socialLogin). Default: in-memory — use a durable one (@basaltkit/auth-prisma, @basaltkit/auth-sqlite) with OAuth, or links are forgotten on restart and logins fall back to the email match.


emailRequestThrottle? ​

> optional emailRequestThrottle?: false | LoginThrottle

Defined in: auth/src/auth.ts:266

Per-account throttle on password-reset and email-verification requests. Over budget, a request is silently dropped (no new token, no hook, the live link keeps working) — so the endpoints cannot be used to mail-bomb a user or keep invalidating their reset link. Default: 3 per 15 minutes per account and purpose; pass false to disable.


enumerationSafeRegister? ​

> optional enumerationSafeRegister?: boolean

Defined in: auth/src/auth.ts:283

Make the public registration endpoint enumeration-safe: a request for an email that already exists returns the same response (and does equivalent work) as a fresh signup, instead of a 409 that reveals the account exists. Applies to Auth.registerSafely (used by the register route); the lower-level Auth.register always throws on a duplicate. Default true.


hasher? ​

> optional hasher?: PasswordHasher

Defined in: auth/src/auth.ts:242


hooks? ​

> optional hooks?: HookBus

Defined in: auth/src/auth.ts:249


ipLoginThrottle? ​

> optional ipLoginThrottle?: false | LoginThrottle

Defined in: auth/src/auth.ts:258

Per-IP login throttle — blunts password spraying (1 attempt across many accounts) and lockout-DoS that a per-email counter alone misses. Enabled by default with a higher budget than the per-email one; pass false to disable. Only applies when the caller passes the client ip to login.


loginThrottle? ​

> optional loginThrottle?: false | LoginThrottle

Defined in: auth/src/auth.ts:251

Brute-force lockout (per email). Enabled by default; pass false to disable.


mfa? ​

> optional mfa?: MfaStore

Defined in: auth/src/auth.ts:291

Store for MFA (TOTP) enrollment state. Default: in-memory.


mfaEncryption? ​

> optional mfaEncryption?: object

Defined in: auth/src/auth.ts:317

Encrypts TOTP secrets at rest (AES-256-GCM, HKDF-derived keys, each ciphertext bound to its user). keys is a ring: the first key seals new secrets, the others stay readable (rotation). A stored value that is not an envelope sealed for that user is refused — a database write cannot swap in a plaintext secret the writer knows. legacy reads v1: envelopes and/or plaintext during a migration only; move rows over with Auth.reencryptMfaSecret, then remove it.

Omit (and omit mfaEncryptionKey) to store secrets in plaintext.

keys ​

> keys: SecretBoxKey[]

legacy? ​

> optional legacy?: SecretBoxLegacyOptions


mfaEncryptionKey? ​

> optional mfaEncryptionKey?: string | Buffer<ArrayBufferLike>

Defined in: auth/src/auth.ts:324

Shorthand for mfaEncryption: { keys: [{ id: 'default', key }] } (at least 32 bytes). It does not read the old v1: envelopes or plaintext: to migrate from a pre-4.0 mfaEncryptionKey, use mfaEncryption with legacy: { v1Keys: [oldKey] }.


mfaIssuer? ​

> optional mfaIssuer?: string

Defined in: auth/src/auth.ts:326

Issuer name shown in authenticator apps. Default 'Basalt'.


refreshTokens? ​

> optional refreshTokens?: RefreshTokenStore

Defined in: auth/src/auth.ts:244


refreshTtl? ​

> optional refreshTtl?: DurationInput

Defined in: auth/src/auth.ts:246


resetTtl? ​

> optional resetTtl?: DurationInput

Defined in: auth/src/auth.ts:289

Password-reset link lifetime. Default 1h.


secret ​

> secret: string

Defined in: auth/src/auth.ts:241


sessionCookie? ​

> optional sessionCookie?: SessionCookieOptions

Defined in: auth/src/auth.ts:248


sessions? ​

> optional sessions?: SessionStore

Defined in: auth/src/auth.ts:243


sessionTtl? ​

> optional sessionTtl?: DurationInput

Defined in: auth/src/auth.ts:247


throttleStore? ​

> optional throttleStore?: ThrottleStore

Defined in: auth/src/auth.ts:275

Where the DEFAULT throttles above (login, per-ip login, email requests) keep their counters. Default: in memory, per process — each replica then grants its own budget. Pass a shared store (e.g. RedisThrottleStore) so a cluster enforces one budget; each throttle uses its own namespace (login, login-ip, email-request). Ignored for a throttle passed explicitly (give that one its own store).


tokens? ​

> optional tokens?: AuthTokenStore

Defined in: auth/src/auth.ts:285

Store for verification/reset tokens. Default: in-memory.


tokenVersions? ​

> optional tokenVersions?: TokenVersionStore

Defined in: auth/src/auth.ts:305

Enables access-token revocation. When set, access tokens carry a version (tv) and resetPassword/revokeAllTokens bump it — invalidating every token issued before the bump, even before its TTL expires. Opt-in; access verification then costs one store read per request. Default: off.


users ​

> users: UserSource

Defined in: auth/src/auth.ts:240


verificationTtl? ​

> optional verificationTtl?: DurationInput

Defined in: auth/src/auth.ts:287

Email-verification link lifetime. Default 24h.

Released under the MIT License.