Auth.js 259,565 is the library formerly called NextAuth.js, still published on npm 2,036 as next-auth. It solves the part nobody enjoys writing: the OAuth dance with eighty-odd providers, the callback URLs, the token exchange, the account-linking table (OAuth and OIDC). You bring a database adapter, or none if a JWT session is enough.
Versions matter here more than usual. The v5 line, written for the App Router, has been on the beta dist-tag since October 2023 and stands at 5.0.0-beta.32; the stable line is 4.24.15, which predates Server Actions. New projects install next-auth@beta, as the official guide instructs — a real risk, not a formality.
The configuration is one file exporting four things; everything else imports them.
// auth.ts
import NextAuth from "next-auth";
import GitHub from "next-auth/providers/github";
export const { handlers, signIn, signOut, auth } = NextAuth({ providers: [GitHub] });
// app/api/auth/[...nextauth]/route.ts
export const { GET, POST } = handlers;
// proxy.ts — the optimistic check, for free
export { auth as proxy } from "@/auth";
export const config = { matcher: ["/dashboard/:path*"] };auth() is the piece you use everywhere else: in a Server Component, a Server Action or a route handler it returns the session or null, and wrapped around a proxy it populates req.auth. signIn and signOut are server functions, so a sign-in button is a form whose action calls signIn("github").
Auth.js is MIT-licensed with no hosted component and no per-user cost, which is its strongest argument. The weakest is the surface you still own: the adapter schema, the session callback that decides which claims reach the token, and every authorization decision after sign-in.