Skip to content
anchr.ing
Guide

Getting started on anchr.ing

Create your account, create a project with a test and a production environment, open its admin console and register your first apps.

anchr.ing runs anchring for you. You get an account on the platform, and each project you create is your own identity provider with two environments: test to build against and prod for real users.

1. Create your account

Create your account: you sign in to the platform through anchring's own hosted login. Enter your email, type the code that arrives, and you are in the dashboard. Add a passkey on your account page afterwards if you like.

2. Create a project

The dashboard starts you on Create your first project: pick a name and a project ID. The ID is permanent: it becomes your two hosts and the passkey domain of each environment.

  • https://acme.test.anchr.ing: test
  • https://acme.prod.anchr.ing: production

The dashboard checks the ID as you type. IDs that use www, api, admin, prod or test as a part, or contain anchr, are reserved. The project shows as provisioning for a few seconds while its databases, keys and users are created.

3. Open the admin console

When the project is ready you get an admin invite by email for each environment. Open the test one and set up your sign-in; you land in the admin console at https://acme.test.anchr.ing/admin/. Everything below starts in test.

Mail in test goes only to verified admins of the project. Every other message (sign-in codes and invites for your test users) is written to the test environment's mail log instead, so testing never emails real people. Production sends to everyone.

Teammates: add them under Members on the project's page in the dashboard. Later projects come from the project switcher in the top bar (New project). Each gets the same admin invites for test and prod.

4. Register your apps

In the admin console, Apps, add one app per client. An example with a browser app, a CLI and the API they call:

AppKindRedirect / grantAudienceYou getWebspa (public, PKCE)http://localhost:5173/auth/callbackacme-apiclient id test_…CLIcli (public, device grant)noneacme-apiclient id test_…APIresourcenone (verifies tokens)acme-apinothing to copy

Set the audience on the web and CLI apps too: an access token's aud is the app's audience, or its client id when none is set, and your API accepts only acme-api. Other kinds: web (server-rendered, confidential), native (desktop and mobile, PKCE) and service (machine to machine, see Service to service).

5. Install the SDK

terminal
bun add @anchring/auth   # or: npm i @anchring/auth

Version 0.2.0 is not on npm yet (npm still serves 0.1.0). Until it is, build it from the repository:

terminal
git clone https://github.com/Anchring/anchring && cd anchring && bun install
bun run --cwd packages/sdk build
# then, in your app:
bun add file:/path/to/anchring/packages/sdk/dist

Use one file per surface, each importing its own entry point, so the browser bundle carries no server code and nothing reads process.env in the browser:

// web/auth.ts
import { createAuth } from '@anchring/auth/browser';
export const auth = createAuth({ project: 'acme', env: import.meta.env.VITE_AUTH_ENV ?? 'test', clientId: import.meta.env.VITE_AUTH_CLIENT_ID });

// api/auth.ts
import { createAuth } from '@anchring/auth/server';
export const auth = createAuth({ project: 'acme', env: process.env.AUTH_ENV ?? 'test', audience: 'acme-api' });

// cli/auth.ts (tokens persist in ~/.config/anchring/tokens.json)
import { createAuth } from '@anchring/auth/cli';
export const auth = createAuth({ project: 'acme', env: process.env.AUTH_ENV ?? 'test', clientId: process.env.ACME_CLI_CLIENT_ID });

The project and environment determine the issuer (https://acme.test.anchr.ing), discovery, keys and endpoints. Then follow the guide for each app you registered.

Every option, error and token type: the SDK README.