
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@authup/client-auth-console
Advanced tools
Authup's auth console: the SSR auth workflow UI (authorize, register, activate, password recovery, logout) rendered by server-core on the IdP origin.
The auth console: authup's SSR auth workflow UI. It renders the hosted pages
on the IdP origin: /authorize (login + consent), /register, /activate,
/password-forgot, /password-reset, /device (device verification,
RFC 8628) and /logout.
This package is not a standalone application. @authup/server-auth-console
depends on it, renders each request through the built server bundle
(dist/server/server.js) with a per-request hydration payload, and serves the
client assets (dist/client/). The auth pages are architecturally inseparable
from the IdP origin (WebAuthn origin binding, first-party session cookies,
same-path GET-HTML/POST-JSON routes), so there is nothing meaningful to host
without the IdP's own API.
The supported boundary between the auth console service and this package is
the render contract in src/contract.ts (render(RenderContext) => RenderResult).
Operators who want a custom login/consent UI can substitute this package with
one that fulfills the same contract instead of forking @authup/server-auth-console.
This package has no dev script of its own: it is SSR and architecturally
inseparable from the IdP origin, so it cannot be hosted standalone. Run
npm run dev from the repository root instead. That EXPERIMENTAL command
(authup dev) detects that this package is a source checkout and serves it
through a vite dev server with hot module replacement, mounted in front of
@authup/server-auth-console's own handler on server-core's listener, so an
edit here shows up on the next request with no build step. See
.agents/architecture.md → Development mode for how it works.
To find out how to use Authup, visit the documentation.
Distributed under the AGPL-3.0-only license (with a commercial license
available). See the LICENSE file and the repository's LICENSING.md for
details.
FAQs
Authup's auth console: the SSR auth workflow UI (authorize, register, activate, password recovery, logout) rendered by server-core on the IdP origin.
The npm package @authup/client-auth-console receives a total of 428 weekly downloads. As such, @authup/client-auth-console popularity was classified as not popular.
We found that @authup/client-auth-console demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.