Skip to content

Repository files navigation

SSOJet

@ssojet/server-js

Framework-agnostic OpenID Connect (OIDC) SDK for JavaScript runtimes

Build secure authentication flows with OpenID Connect, PKCE, encrypted sessions, JWT verification, and automatic token refresh.

📚 Documentation: https://ssojet.com/docs


Overview

@ssojet/server-js is the core authentication engine that powers the official SSOJet SDKs.

It implements the complete OpenID Connect Authorization Code Flow with PKCE, including:

  • OpenID Connect (OIDC)
  • OAuth 2.0 Authorization Code Flow
  • PKCE
  • ID Token Verification
  • JWKS Validation
  • Session Encryption
  • Automatic Access Token Refresh

Built entirely on Web Standards (fetch, Web Crypto, Request, Response) with zero Node.js-specific APIs, the same code runs on:

  • Node.js
  • Bun
  • Deno
  • Cloudflare Workers
  • Vercel Edge

Features

  • 🔐 OpenID Connect Authentication
  • 🔑 OAuth 2.0 Authorization Code Flow
  • 🛡 PKCE Support
  • ✅ JWT / ID Token Verification
  • 🔄 Automatic Token Refresh
  • 🍪 Encrypted Session Cookies
  • ⚡ Edge Runtime Compatible
  • 🌍 Web Standard APIs
  • 📦 TypeScript First
  • 🚀 Zero Framework Dependencies

When should I use this package?

Use this package if you're building your own authentication integration or framework adapter.

Examples include:

  • Custom authentication middleware
  • Express middleware
  • Fastify plugin
  • Next.js authentication
  • Hono middleware
  • Cloudflare Workers
  • Edge runtimes

If you're using Hono, we recommend:

@ssojet/hono

which provides middleware built on top of this SDK.


Installation

npm install @ssojet/server-js

Quick Start

import { SSOJetClient } from "@ssojet/server-js";

const client = new SSOJetClient({
  domain: "your-tenant.auth.ssojet.com",
  clientId: process.env.SSOJET_CLIENT_ID!,
  clientSecret: process.env.SSOJET_CLIENT_SECRET!,
  appBaseUrl: "https://your-app.com",
  sessionSecrets: [process.env.SSOJET_SESSION_ENCRYPTION_KEY!],
});

Start login:

const { authorizationUrl, transactionCookie } =
  await client.startLogin({
    returnTo: "/dashboard",
  });

Handle callback:

const {
  session,
  sessionCookie,
  returnTo,
} = await client.handleCallback({
  code,
  state,
  transactionCookie,
});

Read session:

const session =
  await client.readSession(sessionCookie);

Refresh tokens:

const {
  accessToken,
  session: refreshedSession,
} = await client.getAccessToken(session);

Logout:

const { redirectTo } =
  await client.logout({
    returnTo: "/",
    idToken: session.idToken,
});

Architecture

Browser
    │
    ▼
Framework Adapter
(Hono / Express / Fastify)
    │
    ▼
@ssojet/server-js
    │
    ▼
SSOJet Identity Platform
    │
    ▼
Okta • Microsoft Entra ID • Google Workspace • Auth0

API

Method Description
startLogin() Starts Authorization Code Flow
handleCallback() Validates callback and creates session
readSession() Reads encrypted session
getAccessToken() Returns valid access token
logout() Ends session

Security

The SDK automatically validates:

  • State (CSRF)
  • Nonce
  • ID Token Signature
  • JWT Claims
  • JWKS Keys
  • Token Expiration

All errors extend:

SSOJetError

with stable error codes.


Supported Runtimes

Runtime Supported
Node.js ✅
Bun ✅
Deno ✅
Cloudflare Workers ✅
Vercel Edge ✅

Common Use Cases

  • Enterprise Authentication
  • OpenID Connect
  • OAuth2
  • API Authentication
  • Multi-tenant SaaS
  • Identity Providers
  • B2B SaaS
  • Session Management
  • Edge Authentication

Related SDKs

  • @ssojet/hono
  • JavaScript SDK
  • React SDK
  • Next.js SDK

Contributing

Contributions are welcome.

Please open an issue before submitting large pull requests.


Reporting Issues

Found a bug?

Please open an issue on GitHub.

Security issues should be reported privately.


About SSOJet

SSOJet helps B2B SaaS companies add enterprise authentication without rebuilding their authentication stack.

Supported capabilities include:

  • Enterprise SSO
  • OpenID Connect
  • SAML
  • SCIM
  • Directory Sync
  • Organizations
  • MFA
  • Passkeys
  • Social Login

Learn more:

https://ssojet.com

Documentation:

https://ssojet.com/docs


License

MIT License

About

Official Node.js server SDK for SSOJet. Verify JWTs, validate access tokens, integrate with SSOJet APIs, and build secure authentication flows for backend applications.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages