Framework-agnostic OpenID Connect (OIDC) SDK for JavaScript runtimes
Build secure authentication flows with OpenID Connect, PKCE, encrypted sessions, JWT verification, and automatic token refresh.
📚 Documentation: https://ssojet.com/docs
@ssojet/server-js is the core authentication engine that powers the official SSOJet SDKs.
It implements the complete OpenID Connect Authorization Code Flow with PKCE, including:
- OpenID Connect (OIDC)
- OAuth 2.0 Authorization Code Flow
- PKCE
- ID Token Verification
- JWKS Validation
- Session Encryption
- Automatic Access Token Refresh
Built entirely on Web Standards (fetch, Web Crypto, Request, Response) with zero Node.js-specific APIs, the same code runs on:
- Node.js
- Bun
- Deno
- Cloudflare Workers
- Vercel Edge
- 🔐 OpenID Connect Authentication
- 🔑 OAuth 2.0 Authorization Code Flow
- 🛡 PKCE Support
- ✅ JWT / ID Token Verification
- 🔄 Automatic Token Refresh
- 🍪 Encrypted Session Cookies
- ⚡ Edge Runtime Compatible
- 🌍 Web Standard APIs
- 📦 TypeScript First
- 🚀 Zero Framework Dependencies
Use this package if you're building your own authentication integration or framework adapter.
Examples include:
- Custom authentication middleware
- Express middleware
- Fastify plugin
- Next.js authentication
- Hono middleware
- Cloudflare Workers
- Edge runtimes
If you're using Hono, we recommend:
@ssojet/hono
which provides middleware built on top of this SDK.
npm install @ssojet/server-jsimport { SSOJetClient } from "@ssojet/server-js";
const client = new SSOJetClient({
domain: "your-tenant.auth.ssojet.com",
clientId: process.env.SSOJET_CLIENT_ID!,
clientSecret: process.env.SSOJET_CLIENT_SECRET!,
appBaseUrl: "https://your-app.com",
sessionSecrets: [process.env.SSOJET_SESSION_ENCRYPTION_KEY!],
});Start login:
const { authorizationUrl, transactionCookie } =
await client.startLogin({
returnTo: "/dashboard",
});Handle callback:
const {
session,
sessionCookie,
returnTo,
} = await client.handleCallback({
code,
state,
transactionCookie,
});Read session:
const session =
await client.readSession(sessionCookie);Refresh tokens:
const {
accessToken,
session: refreshedSession,
} = await client.getAccessToken(session);Logout:
const { redirectTo } =
await client.logout({
returnTo: "/",
idToken: session.idToken,
});Browser
│
▼
Framework Adapter
(Hono / Express / Fastify)
│
▼
@ssojet/server-js
│
▼
SSOJet Identity Platform
│
▼
Okta • Microsoft Entra ID • Google Workspace • Auth0
| Method | Description |
|---|---|
| startLogin() | Starts Authorization Code Flow |
| handleCallback() | Validates callback and creates session |
| readSession() | Reads encrypted session |
| getAccessToken() | Returns valid access token |
| logout() | Ends session |
The SDK automatically validates:
- State (CSRF)
- Nonce
- ID Token Signature
- JWT Claims
- JWKS Keys
- Token Expiration
All errors extend:
SSOJetError
with stable error codes.
| Runtime | Supported |
|---|---|
| Node.js | ✅ |
| Bun | ✅ |
| Deno | ✅ |
| Cloudflare Workers | ✅ |
| Vercel Edge | ✅ |
- Enterprise Authentication
- OpenID Connect
- OAuth2
- API Authentication
- Multi-tenant SaaS
- Identity Providers
- B2B SaaS
- Session Management
- Edge Authentication
- @ssojet/hono
- JavaScript SDK
- React SDK
- Next.js SDK
Contributions are welcome.
Please open an issue before submitting large pull requests.
Found a bug?
Please open an issue on GitHub.
Security issues should be reported privately.
SSOJet helps B2B SaaS companies add enterprise authentication without rebuilding their authentication stack.
Supported capabilities include:
- Enterprise SSO
- OpenID Connect
- SAML
- SCIM
- Directory Sync
- Organizations
- MFA
- Passkeys
- Social Login
Learn more:
Documentation:
MIT License