Auth is the layer teams hand to a vendor first. Here it is one package we own, mounted in two lines, with no password table to leak.
How it is wired
One handler, two lines
@yannvr/auth speaks plain Request → Response, so Waku mounts it like any other file under src/pages/_api/. Storage is injected: this demo hands it a SQLite file through node:sqlite, which ships inside Node.
// src/pages/_api/api/auth/[...route].ts
import { auth } from '../../../../lib/auth';
export const POST = (request: Request) => auth.handleAuth(request);
One session read per request
React's cache() verifies the cookie once, however many components ask. Sign-out is a server function with the same guard as every other one: no session, nothing to do.
this page used to say auth was not wired. we had probed the wrong folder, then ported our own passkey package off Next.js. the account you make here is a throwaway: no email asked, nothing worth stealing