Auth Block

Sign-in, sessions, MFA, tenants.
Decided.

Battle-tested identity for your product. Open source, Apache 2.0, serving real production traffic for years.

claude plugin marketplace add https://github.com/23blocks-OS/ai-agents

claude plugin install auth-block

Your agent now knows this API. Prefer hands-on? REST + SDK docs →

What's inside

Sign-in

Email, magic link, OAuth, SSO

MFA

TOTP, with a recovery path

Sessions

JWT, rotation, revocation

Multi-tenant

Isolation down to the key

API keys

Scoped, rotatable, per app

Users

Profiles, roles, invitations

Webhooks

Every identity event

Bot defense

With a kill switch

Already debugged

The mistakes were made, fixed, and shipped past — before you got here.

  • Keys rotate without dropping a single session.

  • MFA lockout has a recovery path, not a support ticket.

  • Tokens expire on purpose — differently per grant type.

  • One tenant can never read another's data. Enforced at the key, not the query.

Use this instead of

Auth0CognitoClerkyour hand-rolled devise setup

Better together

Every other block already trusts the user this signs in — one identity, zero translation. User signs in → CRM contact synced → Realtime channel authorized. Zero glue code.

Don't vibe-code your auth.

Stay in the loop

Get product updates, engineering posts, and new block announcements delivered to your inbox.

No spam. Unsubscribe anytime. Privacy policy.