Identity for your apps, on your own terms
anchring is a multi-tenant identity provider built on SurrealDB. Every tenant gets a test and a production environment, hosted login with passkeys, SSO for your business customers, and one SDK for the browser, your API and your CLI. Create an account and your first tenant in a minute.
- Test and prod per tenant, promoted in one step
- Tokens verified offline in your API
- Passkeys, MFA and SSO built in
import { createAuth } from '@anchring/auth/browser';
export const auth = createAuth({ tenant: 'acme', env: 'test', clientId: 'test_…' });
await auth.ready(); // finishes the callback, restores the session
if (!auth.user()) await auth.signIn(); // hosted login: passkey, password or email code
const res = await auth.fetch('/api/reports'); // adds Authorization, refreshes first
auth.user(); // { sub, email, name, claims }npm i @anchring/auth · browser, server and CLI entry points in one package
Everything sign-in needs, nothing you have to build
Hosted login, tokens and the admin console come with every tenant. Your apps talk to it through standard OpenID Connect and one SDK.
Passkeys and MFA
Passkeys, passwords, email codes and magic links, with TOTP step-up and recovery codes. Require MFA per tenant, or per API route with a policy.
SSO, SAML and SCIM
Organisations with verified domains sign in through their own Entra, Google Workspace, Okta or SAML 2.0 IdP. Enforce SSO with break-glass owners; provision users with SCIM 2.0.
Webhooks and logout
Signed, retried events when users are created, changed or deleted, verified and deduplicated by the SDK. OIDC back-channel logout ends your app sessions too.
Test, then promote
Every tenant has a test and a production environment with their own issuers. Build against test; promote apps, webhooks and settings to prod in one step.
One SDK everywhere
@anchring/auth signs in from browsers and CLIs, verifies tokens offline in Hono, Express or anything else, and evaluates your permissions locally.
Two environments per tenant, from the first minute
Your tenant's slug becomes two hosts: one for testing, one for real users. They share nothing but the name: separate users, keys, apps and webhook secrets. In test, mail goes only to your verified admins; everything else lands in the mail log.
- test
https://acme.test.anchr.ing - prod
https://acme.prod.anchr.ing
When it works, Promote to production copies apps with their audiences and claims templates, webhooks, social connections, settings and branding. Never users.
import { createAuth } from '@anchring/auth/server';
// Same code in both environments: only AUTH_ENV changes.
export const auth = createAuth({
tenant: 'acme',
env: process.env.AUTH_ENV ?? 'test', // 'prod' after the promote
audience: 'acme-api',
});
app.use('/api/*', auth.middleware()); // offline verification, no call per requestStart in test, go live in an afternoon
Create your account, create a tenant, register your apps. The admin console invites arrive by email.