Authentication & Authorization Packages
Authentication, authorization, and identity/session libraries for handling login, permissions, and access control securely (JWT, Passport, Sanctum).
Packages in Authentication & Authorization
Kind
Sort:Used by Most Apps
express-rate-limit
Basic IP rate-limiting middleware for Express to throttle repeated requests and protect public APIs and sensitive endpoints.
openid-client
Certified OAuth 2 and OpenID Connect client for every modern JavaScript runtime.
casl
Isomorphic JavaScript/TypeScript authorization library for defining and checking fine-grained user permissions.
passport-oauth2
A generic OAuth 2.0 authentication strategy for Passport, the base class most provider-specific Passport login strategies are built on.
oidc-provider
Certified OAuth 2.0 and OpenID Connect authorization server you mount into your own Node.js app.
OAuthLib
Generic, spec-compliant OAuth1, OAuth2, and OpenID Connect implementation for Python
Open Policy Agent (OPA)
Open source policy engine for unified authorization and compliance decisions across your stack.
league/oauth2-client
A framework-agnostic PHP client for building OAuth 2.0 login and API-authorization flows.
Social Auth Core
The core authentication backend engine behind Python Social Auth, supporting OAuth, OpenID, and SAML.
Bouncer
Elegant roles and abilities authorization for Laravel using Eloquent.
supabase-py
The official Python client for Supabase, wrapping Postgres, Auth, Storage, Edge Functions, and Realtime in one typed SDK.
django-guardian
Per-object (row-level) permissions for the Django authorization system.
accesscontrol
Role- and attribute-based access control (RBAC + ABAC) for Node.js, with enforced ownership, conditions, and require() gates.
Laratrust
Flexible role-based access control (RBAC) for Laravel with roles, permissions, teams, and caching
django-rules
Object-level permissions and rule-based authorization for Django, with no database required.
axios-auth-refresh
Automatically refresh expired auth tokens and retry failed requests with Axios interceptors.
OAuth2 Google Provider
Google OAuth 2.0 provider for The PHP League's OAuth 2.0 Client
pyrad
A pure-Python library for building RADIUS clients and servers, covering authentication, accounting, and Change-of-Authorization out of the box.
Biscuit-Auth
Rust implementation of Biscuit — a decentralized authorization token with offline attenuation and a Datalog policy language.
Logto JS Core SDK
The framework-agnostic TypeScript core that powers Logto's entire JavaScript SDK family for OIDC authentication.