theauth-go: auth for AI agents and humans in Go
theauth-go is the Go library in the theAuth family. Install it, see what it covers, and pick between the Go library and the TypeScript SDK.
2 min read
Gagan Deep Singh
Founder | GLINR Studios
theAuth has joined GLINR Studios, and it has a Go library: theauth-go. If you run your auth in Go and care about AI agents as first-class identities, this is the one to look at.
Install
go get github.com/glincker/theauth-go/v2The module path carries the /v2 suffix, as Go requires for major version 2 and above. The current release is v2.7.1.
What it covers
- OAuth 2.1 and MCP authorization. Protected resource metadata, resource indicators and a zero-dependency
mcpresourcemodule for MCP servers. - Agent identity. Scoped API tokens, service accounts and agent tokens, with delegation and actor chains.
- Human authentication. Email and password with Argon2id, magic links, WebAuthn passkeys, TOTP with recovery codes, and 12 OAuth providers.
- Enterprise. SAML 2.0, SCIM 2.0, RBAC, organizations and an append-only audit log with pluggable sinks.
- Storage. Postgres, MySQL, SQLite and an in-memory store for tests.
- Supply chain. Releases are signed with Sigstore and ship with an SBOM and SLSA provenance.
TypeScript or Go
theauth-go is its own Go implementation, not a port of the TypeScript SDK. Both follow the same model: agents get their own credentials, permissions are delegated with limits, and every grant is audited.
- Use the TypeScript SDK when your agents and apps run on Node, Bun, Deno or edge runtimes.
- Use theauth-go when your services are written in Go.
- Run both side by side if your stack mixes the two.