Authlier

Authlier

Composable authentication for Go applications.

GitHub

Authlier is a composable authentication library that runs inside your Go server. It provides the server-side flows for passwords, sessions, email verification and recovery, TOTP, passkeys, Google authentication, OIDC, and SAML SSO.

Your Go server configures Authlier once, gives it a database adapter, and mounts its http.Handler. A browser, mobile application, CLI, or another server then calls the enabled authentication routes. Your application keeps control of its profiles, business data, roles, and permissions.

How it fits into an application

Authlier is part of your Go server. It does not run as a separate service.
1
Sign inThe Go server creates the authenticated session.
Browser clientSends a sign-in request
Your Go serverAuthlier handlerVerifies the credential and creates a session
Your databaseStores users, credentials, and session hashes

Authlier returns the result and an HttpOnly session cookie to the browser.

2
Use the sessionYour server decides what the authenticated user may do.
Browser clientRequests one of your application routes
Your Go serverResolveSessionValidates the session and returns its subject ID
Your applicationLoads its user data, roles, and permissions

The client sends an authentication request to your Go server. The Authlier handler verifies the credential or provider response, writes the required authentication records through the configured database adapter, and creates a session.

The application chooses how that session reaches the client: an HttpOnly cookie or an access-and-refresh-token pair. Cookie sessions are the usual browser default, while bearer tokens are available to browsers, mobile applications, command-line tools, and server clients. Your own Go handlers resolve either credential to a stable Authlier subject ID, then use that ID to load application data and enforce application permissions.

Included authentication methods

Authentication methodWhat it provides
Email and passwordSign-up, sign-in, password changes, and secure password hashing
Email verification and recoveryEmail ownership verification and password reset flows
GoogleGoogle sign-in and account linking
TOTPAuthenticator-app verification and recovery codes
PasskeysWebAuthn registration and passwordless sign-in
OIDC and SAMLSingle sign-on with organization identity providers

New passwords use Argon2id by default. Applications that must remain compatible with a legacy credential system can select bcrypt while they complete a staged migration. Authlier continues to recognize both supported formats.

Start with Getting started for a complete working Go server. Basic usage continues with browser client code, and Configuration explains every top-level choice before the individual feature guides.

On this page