# Overview

> What authbase is, how it fits next to your backend, and where to start reading.

authbase is an authentication service you run yourself. Run one instance,
create an **app** for each product you build, and let each product's
backend register and authenticate its **users** through authbase. Think of
it as a smaller, self-hostable Auth0 or Firebase Auth.

```
  end-user ──▶ your backend ──(API key)──▶ authbase ──▶ PostgreSQL
                    │                          │
                    └── verifies tokens ◀── JWKS (public keys, cached)
```

Your backend calls authbase with an API key for four things: sign-up,
login, refresh and logout. Every other request is checked **locally**: the
access token is a standard JWT that your backend verifies against the
app's public keys, so authbase is never on your hot path.

## What you get

- **The end-user API**: registration, login by email or username, refresh
  with reuse detection, logout and "sign out everywhere", roles and
  metadata, password reset and email verification with hosted pages.
- **A dashboard** at the instance's root: apps, API and signing keys,
  users, settings, the audit log and your own account.
- **SDKs** for Node ([`@authbase/node`](https://authbase.burakmetehan.com.tr/docs/sdk/node.md): Express, Hono,
  Next.js) and Kotlin/JVM ([Ktor and Spring Boot](https://authbase.burakmetehan.com.tr/docs/sdk/kotlin.md)).
  Anything else needs only JSON over HTTP and a JWT library
  ([integration guide](https://authbase.burakmetehan.com.tr/docs/integration.md)).
- **Standards**: Ed25519 (`EdDSA`) access tokens per RFC 9068, a JWKS and
  OIDC discovery document per app, RFC 9457 problem details with stable
  error codes, an [OpenAPI spec](https://authbase.burakmetehan.com.tr/openapi.yaml).
- **Protection that is always on**: Argon2id, a breached-password list,
  per-IP and per-key rate limits, lockout, an audit log, signing and API
  key rotation without downtime.
- **One binary, one PostgreSQL, one master key** to operate.

## Where to start

| You want to… | Read |
|---|---|
| see it work on your machine in under half an hour | [Quick start](https://authbase.burakmetehan.com.tr/docs/quickstart.md) |
| understand apps, keys and tokens first | [Concepts](https://authbase.burakmetehan.com.tr/docs/concepts.md) |
| add it to a Node or Kotlin backend | [Node SDK](https://authbase.burakmetehan.com.tr/docs/sdk/node.md), [Kotlin SDK](https://authbase.burakmetehan.com.tr/docs/sdk/kotlin.md) |
| add it to anything else | [Integration guide](https://authbase.burakmetehan.com.tr/docs/integration.md) |
| look up an endpoint or error code | [API reference](https://authbase.burakmetehan.com.tr/api/) |
| run it in production | [Self-hosting](https://authbase.burakmetehan.com.tr/docs/self-hosting.md), [Security model](https://authbase.burakmetehan.com.tr/docs/security-model.md) |
| have a coding agent do the integration | [Docs for agents](https://authbase.burakmetehan.com.tr/docs/agents.md), [Claude skills](https://authbase.burakmetehan.com.tr/docs/skills.md) |

## Status

authbase is **in active development**. The API, email flows, dashboard
and SDKs are complete, and it runs in production for its author. The
source code, the container image and the SDK packages are not public
yet: they come with the first public release, together with an
independent security review and signed builds. Until then, this site
introduces the project and documents how it works, and its install steps
describe the release.

Not there yet: teams that share apps, a hosted login page (OAuth 2.0 code
flow with PKCE), multi-factor authentication, social login and webhooks.
