Skip to main content

Pluggable Authentication Subsystem

MTVL supports flexible authentication backends through the auth.AuthProvider interface, enabling native JWT auth or enterprise identity providers (Clerk, Auth0, Supabase, Keycloak, OIDC).

The AuthProvider Interface


1. Built-in JWT Auth Provider (jwt.go)

  • Storage: Stores users and password hashes in the application database using bcrypt cost factor 12.
  • Tokens: Signs JWT tokens containing user_id, username, and exp claims with HMAC-SHA256.
  • API Personal Access Tokens: Validates opaque token prefixes (mtvl_pat_...) against the api_tokens database table.

2. External Identity Adapter (adapter.go)

For organizations using OAuth2 / OIDC providers (Clerk, Supabase, Auth0, Keycloak):
The adapter:
  1. Validates standard OpenID Connect JWT signatures via JWKS public keys.
  2. Extracts the subject claim (sub) as the canonical user identifier.
  3. Automatically maps external users to MTVL personal lists without requiring local password storage.