Back to Projects

theauth

Auth for AI agents and humans (rebranded from Kavachos). OAuth 27+ providers, enterprise SAML/OIDC, MCP 2.1 auth server, scoped permissions, and delegation chains.

theauth screenshot
TypeScriptAuthAIMCPEdge Runtime

theauth (formerly Kavachos) is an authentication and authorization system built for the AI-native era. It handles identity for both humans and AI agents with scoped permissions, delegation chains, and full audit trails. Supports OAuth with 27+ providers, enterprise SAML/OIDC, and ships an MCP 2.1 auth server. Runs on edge runtimes (Cloudflare, Deno, Bun). theauth-go is a companion Go implementation for non-JS stacks: sessions, magic links, WebAuthn/passkeys, TOTP, SAML, and SCIM, backed by Postgres, MySQL, or in-memory storage. The published npm packages (kavachos, @kavachos/react, @kavachos/nextjs) still ship under the original name -- only the source repo and site have rebranded so far.

Contact