1"use strict";(self.webpackChunkdocs=self.webpackChunkdocs||[]).push([[686],{26005:(e,t,n)=>{n.r(t),n.d(t,{assets:()=>c,contentTitle:()=>r,default:()=>h,frontMatter:()=>s,metadata:()=>i,toc:()=>u});const i=JSON.parse('{"id":"core-concepts/authentication","title":"Authentication","description":"SpacetimeDB modules are exposed to the open internet and anyone can connect to","source":"@site/versioned_docs/version-1.12.0/00200-core-concepts/00500-authentication.md","sourceDirName":"00200-core-concepts","slug":"/core-concepts/authentication","permalink":"/docs/1.12.0/core-concepts/authentication","draft":false,"unlisted":false,"editUrl":"https://github.com/clockworklabs/SpacetimeDB/edit/master/docs/versioned_docs/version-1.12.0/00200-core-concepts/00500-authentication.md","tags":[],"version":"1.12.0","sidebarPosition":500,"frontMatter":{},"sidebar":"sidebar","previous":{"title":"Subscription Semantics","permalink":"/docs/1.12.0/subscriptions/semantics"},"next":{"title":"Overview","permalink":"/docs/1.12.0/core-concepts/authentication/spacetimeauth/"}}');var o=n(86106),a=n(56225);const s={},r="Authentication",c={},u=[{value:"SpacetimeAuth",id:"spacetimeauth",level:2},{value:"Third-party OIDC providers",id:"third-party-oidc-providers",level:2},{value:"Authenticate your services",id:"authenticate-your-services",level:2},{value:"Authorization in your module",id:"authorization-in-your-module",level:2}];function d(e){const t={a:"a",h1:"h1",h2:"h2",header:"header",li:"li",p:"p",strong:"strong",ul:"ul",...(0,a.R)(),...e.components};return(0,o.jsxs)(o.Fragment,{children:[(0,o.jsx)(t.header,{children:(0,o.jsx)(t.h1,{id:"authentication",children:"Authentication"})}),"\n",(0,o.jsx)(t.p,{children:"SpacetimeDB modules are exposed to the open internet and anyone can connect to\nthem. Therefore, authentication is a critical part of using SpacetimeDB securely."}),"\n",(0,o.jsx)(t.p,{children:"SpacetimeDB uses OpenID Connect (OIDC) identity tokens for authentication, making\nit compatible with most OIDC providers (e.g., Auth0, Firebase, Clerk, Google,\nGitHub, Facebook, and many more). You can choose any OIDC provider that fits your\nneeds, or even implement your own."}),"\n",(0,o.jsxs)(t.p,{children:["If you're new to OIDC, check out our ",(0,o.jsx)(t.a,{href:"https://spacetimedb.com/blog/who-are-you",children:"blog post about OIDC"}),"\nto learn more about how OIDC works and why it's a great choice for authentication."]}),"\n",(0,o.jsx)(t.h2,{id:"spacetimeauth",children:"SpacetimeAuth"}),"\n",(0,o.jsxs)(t.p,{children:["To make it easier to get started with authentication, SpacetimeDB offers\n",(0,o.jsx)(t.a,{href:"/docs/1.12.0/core-concepts/authentication/spacetimeauth/",children:"SpacetimeAuth"}),", a fully\nmanaged OIDC provider built specifically for SpacetimeDB applications. SpacetimeAuth\nhandles user management, authentication flows, and token issuance, so you don't have\nto worry about building and maintaining your own authentication service."]}),"\n",(0,o.jsx)(t.p,{children:"SpacetimeAuth is meant to be simple to use and easy to integrate with SpacetimeDB.\nWhile being production-ready and able to support most common use cases, it is not\nas feature-rich as some third-party OIDC providers. If you need advanced features\nor customization, you may want to consider using a third-party OIDC provider instead."}),"\n",(0,o.jsx)(t.h2,{id:"third-party-oidc-providers",children:"Third-party OIDC providers"}),"\n",(0,o.jsx)(t.p,{children:"You can also use any third-party OIDC provider with SpacetimeDB. Most OIDC\nproviders offer similar features, such as user management, authentication flows,\nand token issuance. When choosing a third-party OIDC provider, consider factors\nsuch as ease of integration, pricing, scalability, and security."}),"\n",(0,o.jsxs)(t.ul,{children:["\n",(0,o.jsxs)(t.li,{children:[(0,o.jsx)(t.a,{href:"https://auth0.com/",children:"Auth0"})," A managed identity and access\nmanagement service that provides, user management, and extensible login flows\nfor applications and APIs."]}),"\n",(0,o.jsxs)(t.li,{children:[(0,o.jsx)(t.a,{href:"https://clerk.c
1om/",children:"Clerk"})," A developer-focused\nauthentication and user management platform that provides OIDC-compliant\nsign-in, session management, and prebuilt UI components for modern web applications."]}),"\n",(0,o.jsxs)(t.li,{children:[(0,o.jsx)(t.a,{href:"https://www.keycloak.org/",children:"Keycloak"})," An open-source and\nself-hosted OIDC provider with extensive features, customization options and integrations."]}),"\n"]}),"\n",(0,o.jsx)(t.h2,{id:"authenticate-your-services",children:"Authenticate your services"}),"\n",(0,o.jsx)(t.p,{children:"Sometimes, you may need to authenticate your servers, APIs or other services that\ninteract with your SpacetimeDB database. OIDC tokens can also be used for this\npurpose, allowing secure communication between your services and SpacetimeDB."}),"\n",(0,o.jsx)(t.p,{children:"To authenticate your services, you have a few options depending on your OIDC provider:"}),"\n",(0,o.jsxs)(t.ul,{children:["\n",(0,o.jsxs)(t.li,{children:[(0,o.jsx)(t.strong,{children:"Client credentials flow"}),": Many OIDC providers support the client credentials\nflow, which allows your service to obtain an access token using its own\ncredentials (client ID and client secret). This is a common approach for\nservice-to-service authentication."]}),"\n",(0,o.jsxs)(t.li,{children:[(0,o.jsx)(t.strong,{children:"Service accounts"}),": Some OIDC providers offer service accounts, which are\nspecial user accounts designed for non-human users (e.g., servers, APIs). You\ncan create a service account and use its credentials to obtain an access token."]}),"\n"]}),"\n",(0,o.jsx)(t.h2,{id:"authorization-in-your-module",children:"Authorization in your module"}),"\n",(0,o.jsxs)(t.p,{children:["Obtaining an OIDC token is just the first step in securing your SpacetimeDB\nmodule, known as ",(0,o.jsx)(t.strong,{children:"authentication"}),". You also need to implement ",(0,o.jsx)(t.strong,{children:"authorization"}),"\nto control what authenticated users can do within your module."]}),"\n",(0,o.jsx)(t.p,{children:"When a client connects to your SpacetimeDB module, the SpacetimeDB server\nvalidates the client's OIDC token and extracts the identity claims. These claims\nare then made available to your module's reducers, views and procedures via the context."}),"\n",(0,o.jsxs)(t.p,{children:[(0,o.jsx)(t.a,{href:"/docs/1.12.0/core-concepts/authentication/usage",children:"Check out the usage guide"})," for more\ninformation on how to access and use authentication claims in your module:"]})]})}function h(e={}){const{wrapper:t}={...(0,a.R)(),...e.components};return t?(0,o.jsx)(t,{...e,children:(0,o.jsx)(d,{...e})}):d(e)}},56225:(e,t,n)=>{n.d(t,{R:()=>s,x:()=>r});var i=n(7378);const o={},a=i.createContext(o);function s(e){const t=i.useContext(a);return i.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function r(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(o):e.components||o:s(e.components),i.createElement(a.Provider,{value:t},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.