passport-local

Passport strategy for authenticating users with a username and password in Node.js and Express applications.

Library
npm
v1.0.0
2,754 stars
MIT License

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
42 /100 Fair
Development Activity 0
Maintenance 0
Community 68
Maturity 60
Momentum 40

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
79 /100 Good
Architecture 78
Code Quality 80
Innovation 88
Learning Curve 88

passport-local is the official Passport strategy for username-and-password authentication in Node.js. It lets you add classic password-based sign in to any application built on Connect-style middleware, including Express, by wiring a single verify callback that checks the submitted credentials against your own user store.

Because it plugs into Passport’s unified authentication framework, passport-local stays deliberately small and unopinionated: it extracts the username and password from the request, hands them to your verify function, and leaves password hashing, session handling, and user lookup entirely up to you. That separation makes it the de facto standard for local login across the Node.js ecosystem.

What You Get

  • A drop-in local strategy that integrates with Passport’s authenticate() middleware
  • A single verify-callback contract for validating credentials against any user store
  • Configurable form field names via usernameField and passwordField options
  • Optional access to the request object in the verify callback through passReqToCallback

Common Use Cases

  • Adding email/password login to an Express application
  • Authenticating API requests with credentials submitted from an HTML form
  • Building a custom sign-in flow backed by your own database and password hashing

Under The Hood

Architecture The module is a compact strategy-pattern implementation split across three files in lib/: index.js re-exports the Strategy constructor, strategy.js defines it, and utils.js holds a single lookup helper. Strategy extends passport.Strategy from the passport-strategy base via util.inherits, and its authenticate(req, options) method pulls the username and password from req.body or req.query, short-circuits with this.fail() on missing credentials, and otherwise invokes the user-supplied verify callback, routing its result through this.error, this.fail, or this.success.

Tech Stack Written in plain ES5 JavaScript with a single runtime dependency, passport-strategy (1.x), and Node’s built-in util. It declares engines.node >= 0.4.0 and uses main: ./lib. Development tooling is minimal: Mocha and Chai (with chai-passport-strategy) driven through a Makefile, plus make-node for build scaffolding.

Code Quality For its size the codebase is well covered: eight Mocha test files under test/ exercise the normal, failure, error, custom-fields, options, and passReqToCallback paths. The source is thoroughly documented with JSDoc, including annotated callback contracts and usage examples. It reflects its age with var declarations and callback-style APIs rather than modern async/await, but the logic is tight and readable.

API Design The public surface is a single constructor that accepts an optional options hash and a verify callback, throwing a TypeError when the callback is missing. Getting started requires almost no boilerplate, field names are trivially remappable, and the verify contract is consistent with the rest of the Passport ecosystem, making the developer experience approachable and predictable.

Used by 21 apps in this directory

TypeScript
97%
AGPL 3.0

Bigcapital

Invoicing Finance

3,916

Self-hostable double-entry accounting platform with invoicing, inventory, multi-currency, and real-time financial reporting for small and medium businesses.

View details
90
Repo Health
77
Technical
61
Dependency
Built with
TypeScript 97%
Updated 1 weeks ago
TypeScript
92%
GPL 3.0

Blinko

Knowledge Management · Note Taking

11,049

A self-hosted, AI-powered card note-taking tool that lets you capture fleeting thoughts instantly and retrieve them with natural language search.

View details
75
Repo Health
69
Technical
63
Dependency
Built with
TypeScript 92%
Updated 1 months ago
TypeScript
70%
Other

Budibase

Low Code Platforms · No Code Platforms

28,324

Build AI agents, automations, and internal apps on a single open-source platform with full self-hosting control.

View details
91
Repo Health
81
Technical
63
Dependency
Built with
TypeScript 70%
Svelte 26%
Updated 1 weeks ago
TypeScript
62%
Other

Flowise

AI Development · Automation · Developer Tools

55,490

Drag-and-drop visual builder for AI agents, RAG pipelines, and multi-agent systems—deploy anywhere in minutes.

View details
82
Repo Health
77
Technical
63
Dependency
Built with
TypeScript 62%
JavaScript 27%
Updated 1 months ago
TypeScript
98%
Other

Hexabot

AI Development · Automation

1,260

Build and run agentic workflows across channels with YAML, tools, and RAG

View details
78
Repo Health
76
Technical
65
Dependency
Built with
TypeScript 98%
Updated 1 weeks ago
TypeScript
67%
MIT

Hoppscotch

Developer Tools

80,529

A lightweight, offline-capable API development ecosystem for testing HTTP, GraphQL, WebSocket, MQTT, and SSE endpoints across web, desktop, and CLI.

View details
91
Repo Health
83
Technical
65
Dependency
Built with
TypeScript 67%
Vue 25%
Updated 1 weeks ago
TypeScript
96%
MIT

HyperDX

Analytics · Developer Tools · Monitoring

9,916

Open source observability platform that unifies logs, traces, metrics, and session replays on ClickHouse — now the core of ClickStack.

View details
87
Repo Health
83
Technical
65
Dependency
Built with
TypeScript 96%
Updated 1 weeks ago
JavaScript
46%
MIT

Kutt

Analytics · Marketing

11,125

Self-hosted URL shortener with custom domains, per-link analytics, and zero build step required.

View details
74
Repo Health
62
Technical
72
Dependency
Built with
JavaScript 46%
Handlebars 24%
HTML 16%
Updated 1 months ago
TypeScript
94%
AGPL 3.0

Laudspeaker

Automation · Marketing

2,626

Open-source customer engagement platform for building visual, event-triggered messaging journeys across email, SMS, push, in-app, and webhooks.

View details
51
Repo Health
66
Technical
62
Dependency
Built with
TypeScript 94%
Updated 2 months ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers