Skip to content

OAuth 2.1 · OpenID Connect · AdonisJS

Open sesame

Sésame turns your AdonisJS application into a full-featured OAuth 2.1 authorization server, with OpenID Connect when you need identity on top.

node ace add @julr/sesame

How it works

The authorization code flow, in four steps

An authorization code flow with PKCE, refresh token rotation, introspection and revocation, out of the box.

  1. Authorize

    GET /oauth/authorize

    The app redirects the user with its client_id, redirect_uri, scope, state and an S256 code_challenge.

  2. Consent

    consentPage

    The user logs in and approves the scopes. Already approved scopes skip consent.

  3. Exchange

    POST /oauth/token

    The code and the PKCE code_verifier are exchanged for an access_token and refresh_token.

  4. Call

    Authorization: Bearer

    The app passes the access token as a Bearer token when calling your API.

Behind the door

Everything an authorization server needs

Built on the OAuth 2.1 specification, with the guard, scopes and token tooling you expect from an AdonisJS package.

Quick start

Two commands to open the door

Install Sésame, run the migrations and register your OAuth routes.

node ace add @julr/sesameconfig/sesame.ts, migrations, provider, scope middleware
node ace migration:runclients, codes, tokens, grants, pending requests
start/routes.ts
import router from '@adonisjs/core/services/router'
import sesame from '@julr/sesame/services/main'

router.group(() => {
  sesame.registerRoutes()     // /oauth/authorize, /oauth/token…
}).prefix('/oauth')

sesame.registerDiscoveryRoutes()  // /.well-known/*, JWKS