From sign-up to production
Start with getting started, then pick the guide for each kind of app you have. Every snippet uses @anchring/auth; the full reference is the SDK README.
1. Getting started
Create your account, create a project with a test and a production environment, open its admin console and register your first apps.
2. Single-page app
A browser app signs users in with @anchring/auth/browser: hosted login with passkeys, PKCE, refresh before expiry and a fetch that adds the token.
3. Web app with an API
Verify access tokens offline in Hono, Express or any other framework, read the user, add policies and permissions, accept personal access tokens.
4. Command-line tool
The device flow for CLIs: the user approves in a browser, tokens persist in ~/.config/anchring and refresh on their own. Personal access tokens for CI.
5. Service to service
A confidential service app gets tokens for itself with the client_credentials grant; your API verifies them like any other token, within their ceilings.
6. Webhooks
Signed, retried events for users, sessions and organisations, verified and deduplicated by the SDK; back-channel logout for ended sessions.
7. Going live
Import your users, promote apps, webhooks and settings from test to prod, swap in the prod client ids and secrets, and optionally add a custom domain.