Skip to content
anchr.ing
OpenID Connect · passkeys · SSO

Identity for your apps, on your own terms

anchring is a multi-tenant identity provider built on SurrealDB. Every tenant gets a test and a production environment, hosted login with passkeys, SSO for your business customers, and one SDK for the browser, your API and your CLI. Create an account and your first tenant in a minute.

  • Test and prod per tenant, promoted in one step
  • Tokens verified offline in your API
  • Passkeys, MFA and SSO built in
web/auth.ts
import { createAuth } from '@anchring/auth/browser';

export const auth = createAuth({ tenant: 'acme', env: 'test', clientId: 'test_…' });

await auth.ready();                    // finishes the callback, restores the session
if (!auth.user()) await auth.signIn(); // hosted login: passkey, password or email code

const res = await auth.fetch('/api/reports'); // adds Authorization, refreshes first
auth.user();                                   // { sub, email, name, claims }

npm i @anchring/auth · browser, server and CLI entry points in one package

What you get

Everything sign-in needs, nothing you have to build

Hosted login, tokens and the admin console come with every tenant. Your apps talk to it through standard OpenID Connect and one SDK.

Passkeys and MFA

Passkeys, passwords, email codes and magic links, with TOTP step-up and recovery codes. Require MFA per tenant, or per API route with a policy.

SSO, SAML and SCIM

Organisations with verified domains sign in through their own Entra, Google Workspace, Okta or SAML 2.0 IdP. Enforce SSO with break-glass owners; provision users with SCIM 2.0.

Webhooks and logout

Signed, retried events when users are created, changed or deleted, verified and deduplicated by the SDK. OIDC back-channel logout ends your app sessions too.

Test, then promote

Every tenant has a test and a production environment with their own issuers. Build against test; promote apps, webhooks and settings to prod in one step.

One SDK everywhere

@anchring/auth signs in from browsers and CLIs, verifies tokens offline in Hono, Express or anything else, and evaluates your permissions locally.

See how it fits your app in the guides

Test and production

Two environments per tenant, from the first minute

Your tenant's slug becomes two hosts: one for testing, one for real users. They share nothing but the name: separate users, keys, apps and webhook secrets. In test, mail goes only to your verified admins; everything else lands in the mail log.

  • test
    https://acme.test.anchr.ing
  • prod
    https://acme.prod.anchr.ing

When it works, Promote to production copies apps with their audiences and claims templates, webhooks, social connections, settings and branding. Never users.

api/auth.ts
import { createAuth } from '@anchring/auth/server';

// Same code in both environments: only AUTH_ENV changes.
export const auth = createAuth({
  tenant: 'acme',
  env: process.env.AUTH_ENV ?? 'test', // 'prod' after the promote
  audience: 'acme-api',
});

app.use('/api/*', auth.middleware()); // offline verification, no call per request

Start in test, go live in an afternoon

Create your account, create a tenant, register your apps. The admin console invites arrive by email.