OAuth 2.1 · OpenID Connect · AdonisJS
Open sesame
Sésame turns your AdonisJS application into a full-featured OAuth 2.1 authorization server, with OpenID Connect when you need identity on top.
node ace add @julr/sesameHow it works
The authorization code flow, in four steps
An authorization code flow with PKCE, refresh token rotation, introspection and revocation, out of the box.
Authorize
GET /oauth/authorizeThe app redirects the user with its client_id, redirect_uri, scope, state and an S256 code_challenge.
Consent
consentPageThe user logs in and approves the scopes. Already approved scopes skip consent.
Exchange
POST /oauth/tokenThe code and the PKCE code_verifier are exchanged for an access_token and refresh_token.
Call
Authorization: BearerThe app passes the access token as a Bearer token when calling your API.
Behind the door
Everything an authorization server needs
Built on the OAuth 2.1 specification, with the guard, scopes and token tooling you expect from an AdonisJS package.
PKCE, for every client
S256 proof on every authorization request. Public or confidential.
S256Refresh. Rotate. Repeat.
New refresh tokens on use. Replay detection after the grace window.
Token rotationIdentity, when you need it
Add OpenID Connect for signed ID tokens, UserInfo and JWKS.
OpenID ConnectYour database. Your choice.
Use Lucid, Kysely, or implement your own storage driver.
Lucid · KyselyReady for MCP
Resource discovery and dynamic registration for MCP clients.
RFC 9728 · RFC 7591Secrets stay secret
Tokens, authorization codes and client secrets are hashed at rest.
SHA-256Quick start
Two commands to open the door
Install Sésame, run the migrations and register your OAuth routes.
node ace add @julr/sesameconfig/sesame.ts, migrations, provider, scope middlewarenode ace migration:runclients, codes, tokens, grants, pending requestsimport router from '@adonisjs/core/services/router'
import sesame from '@julr/sesame/services/main'
router.group(() => {
sesame.registerRoutes() // /oauth/authorize, /oauth/token…
}).prefix('/oauth')
sesame.registerDiscoveryRoutes() // /.well-known/*, JWKS