Pluggable Authentication Subsystem
MTVL supports flexible authentication backends through theauth.AuthProvider interface, enabling native JWT auth or enterprise identity providers (Clerk, Auth0, Supabase, Keycloak, OIDC).
The AuthProvider Interface
1. Built-in JWT Auth Provider (jwt.go)
- Storage: Stores users and password hashes in the application database using
bcryptcost factor 12. - Tokens: Signs JWT tokens containing
user_id,username, andexpclaims with HMAC-SHA256. - API Personal Access Tokens: Validates opaque token prefixes (
mtvl_pat_...) against theapi_tokensdatabase table.
2. External Identity Adapter (adapter.go)
For organizations using OAuth2 / OIDC providers (Clerk, Supabase, Auth0, Keycloak):
- Validates standard OpenID Connect JWT signatures via JWKS public keys.
- Extracts the subject claim (
sub) as the canonical user identifier. - Automatically maps external users to MTVL personal lists without requiring local password storage.