v1.0.0 Production Ready

Auth for
Cloudflare Workers.

The authentication framework built specifically for Cloudflare Workers and the edge.

OAuth Email & Password Magic Links Sessions MFA Plugins
$ npx @gately/auth-cli init
Hono Next.js Astro SvelteKit Remix React
bash
$ npx @gately/auth-cli init
Creating project...
Installing dependencies...
Setting up auth...
✔ Done. Your project is ready!
cd my-app && npm run dev
➜ Local: http://localhost:8787
auth.ts middleware
import { gatelyAuth } from '@gately/auth-core'
export const auth = gatelyAuth({
  providers: [
    { provider: 'google' },
    { provider: 'github' },
  ],
  session: { strategy: 'jwt' },
})
services.ts worker
export default {
  async fetch(req, env) {
    return auth.handler(req)
  }
}
// Response
{
  "success": true,
  "user": { "id": "usr_01j..." }
}
Setup

Install in seconds.

Add Gately Auth to your project with your favourite package manager.

$ npm i @gately/auth-core
Agent Prompt
Kiro / Cursor / Claude
Set up gately-auth in this Cloudflare Worker. Install @gately/auth-core and @gately/auth-client. Create src/auth.ts using gatelyAuth() with createD1Adapter(env.AUTH_DB), createKVStore(env.AUTH_KV), and gatelyEmail plugin. Enable emailAndPassword. Mount auth.handler(request) on /auth/*. Add bindings to wrangler.toml. Run migrations.
MCP Server
Live
url https://mcp.auth.usegately.com/mcp
Quick start

Three files.
That's it.

Create your auth instance, mount the handler. Every route is live immediately.

auth.ts middleware
import { gatelyAuth } from '@gately/auth-core'
import { createD1Adapter, createKVStore }
from '@gately/auth-core/adapters'
 
export const auth = gatelyAuth({
  secret: env.AUTH_SECRET,
  db: createD1Adapter(env.AUTH_DB),
  kv: createKVStore(env.AUTH_KV),
  emailAndPassword: { enabled: true },
})
middleware.tsworker
import { auth } from './auth'
 
export default {
  async fetch(req, env) {
    return auth.handler(req)
  }
}
 
// Protect any route
const session = await auth.api.getSession(req)
services.tshono
import { Hono } from 'hono'
import { auth } from './auth'
 
const app = new Hono()
 
app.all('/auth/*', (c) =>
  auth.handler(c.req.raw))
 
app.get('/api/me', async (c) => {
  const s = await auth.api.getSession(c.req.raw)
  return c.json(s)
})
 
export default app
Capabilities

Everything built in.

All the tools you need. No fluff.

Authentication

Email + Password Magic Links OAuth / Social Email OTP

Databases

Cloudflare D1 Cloudflare KV Durable Objects Postgres, MySQL

User Management

Roles & Permissions RBAC Organisations Session control

Adapters

D1 + KV native Prisma Drizzle Turso

Security

Rate Limiting CSRF Protection PKCE built-in Account linking

Email

Gately Email Resend Postmark AWS SES

MCP / AI

Cursor, Kiro, Claude Live doc access Code generation Agent skills

Plugins

Custom endpoints Schema extensions Lifecycle hooks Admin panel
API Surface

Every route, out of the box.

RESTful API endpoints ready to use. Mount on /auth/* and everything is live.

POST/auth/sign-up/emailCreate account
POST/auth/sign-in/emailLogin with email + password
POST/auth/sign-outLogout the current user
GET/auth/sessionGet current user
POST/auth/magic-link/sendSend magic link
GET/auth/magic-link/verifyVerify magic link token
POST/auth/otp/sendSend OTP code
POST/auth/otp/verifyVerify OTP code
GET/auth/oauth/:providerStart OAuth flow
GET/auth/oauth/:provider/callbackOAuth callback
POST/auth/password/resetSend reset email
GET/auth/sessionsList active sessions
DEL/auth/sessions/:tokenRevoke session
GET/auth/healthHealth check
Extensible

Official plugins.

Drop-in plugins that extend schema, routes, and email — without forking the core.

Gately Email

Plug-and-play transactional email. Handles password reset, magic links, OTP, and verification automatically.

magic-link otp verification

Admin Plugin

Protected /auth/admin/* endpoints for user listing, banning, session revocation, and deletion.

ban sessions X-Admin-Key

Username Plugin

Adds a unique username field to sign-up with validation, uniqueness check, and a public availability endpoint.

unique validation

Google One Tap

Exchange a Google ID token for a session — no redirect flow. Works with the One Tap JS snippet.

no-redirect id-token
Social sign-in

Every OAuth provider.

Pre-built integrations with 20+ providers.

Google GitHub Discord Microsoft Apple Facebook Slack LinkedIn Twitter / X GitLab Bitbucket Spotify Notion + More
Docs

Documentation.

Everything you need to ship fast.

auth.usegately.com
Getting Started › Quick Start
Quick Start
Install Gately Auth using your preferred package manager.
npm pnpm bun yarn demo
$ npm i @gately/auth-core
Example TypeScript
import { gatelyAuth } from '@gately/auth-core'
import { createD1Adapter, createKVStore } from '@gately/auth-core/adapters'
import { gatelyEmail } from '@gately/auth-core/plugins'
 
export const auth = gatelyAuth({
  appName: 'My App',
  secret: env.AUTH_SECRET,
  db: createD1Adapter(env.AUTH_DB),
  kv: createKVStore(env.AUTH_KV),
  emailAndPassword: { enabled: true },
  providers: [
    { provider: 'google', clientId: env.GOOGLE_ID },
  ],
  plugins: [gatelyEmail({ apiKey: env.GATELY_API_KEY })],
})
Hono Framework
Next.js Framework
Astro Framework
SvelteKit Framework
Remix Framework
React Client
Google OAuth
GitHub OAuth
Discord OAuth
Microsoft OAuth
Apple OAuth
Slack OAuth
Twitter / X OAuth
LinkedIn OAuth
Facebook OAuth
Hono Framework
Next.js Framework
Astro Framework
SvelteKit Framework
Remix Framework
React Client
Google OAuth
GitHub OAuth
Discord OAuth
Microsoft OAuth
Apple OAuth
Slack OAuth
Twitter / X OAuth
LinkedIn OAuth
Facebook OAuth
Cloudflare D1 Database
Cloudflare KV Storage
Magic Link Authentication
Email OTP Authentication
Passkeys Authentication
Cursor MCP
Claude Code MCP
Kiro MCP
Resend Email
Postmark Email
GitLab OAuth
Bitbucket OAuth
Spotify OAuth
Notion OAuth
Drizzle Adapter
Prisma Adapter
Cloudflare D1 Database
Cloudflare KV Storage
Magic Link Authentication
Email OTP Authentication
Passkeys Authentication
Cursor MCP
Claude Code MCP
Kiro MCP
Resend Email
Postmark Email
GitLab OAuth
Bitbucket OAuth
Spotify OAuth
Notion OAuth
Drizzle Adapter
Prisma Adapter
MCP

Built for AI agents.

Connect Cursor, Claude Code, Kiro, or any MCP client directly to the gately-auth docs.

How to connect

Cursor — ~/.cursor/mcp.json
Claude Code — claude mcp add
Kiro — .kiro/settings/mcp.json
Any HTTP MCP client
endpoint https://mcp.auth.usegately.com/mcp

mcp.json

{
  "gately-auth": {
    "url": "https://mcp.auth.usegately.com/mcp"
  }
}
Available tools
search_docsSearch docs by keyword or concept
get_docFetch a full article by slug
list_docsList all articles by category
get_quickstartComplete scaffold for Hono or Next.js
get_install_commandRight install command for any package manager
get_all_docsFull documentation as a single text file
Roadmap

What's coming.

We're building the future of auth.

Coming soon

WebAuthn / Passkeys

Passwordless sign-in using device biometrics. FIDO2 compliant, works on all platforms.

Coming soon

Organisations

Multi-tenant auth with organisations, teams, invitations, and role-based access control.

Coming soon

Auth Logs

Tamper-evident audit log of every auth event. Replay, filter, and export.

Coming soon

Admin Panel

Drop-in user management UI. Search, ban, impersonate, and manage sessions.

Getting started

Three steps to production.

From zero to auth in under 5 minutes.

01

Install

Add the package to your project. npm install @gately/auth-core

02

Configure

Set up your providers and D1/KV bindings. One function call, fully typed.

03

Ship

You're ready to authenticate users. npx wrangler deploy

Ready to build?

From install to production auth in under 5 minutes. No account required to get started.