Authentication in Damat has two explicit layers:
- Framework contract: The framework normalizes credentials from headers and cookies, applies route auth settings, enforces 401 failures, and exposes the request principal in typed context helpers.
- Provider module: Your module defines identities, credentials, key storage,
and verification behavior for the
authrole.
This means security behavior is explicit, swappable, and unit-testable.
Quick mental model
- A route can require auth with
auth: { type: "session" },apiKey, orflexible. - Route auth is opt-in and never implies “all routes are private”.
- Public routes remain public unless explicitly secured.
- A protected request fails closed with
401when no auth provider is bound.
export const config = {
method: "GET",
auth: { type: "session" },
};
When verification succeeds, route handlers can use context principal helpers and
request-scoped identity data (user, userId, optional team) stays available
for authorization checks.
Read next for provider implementation patterns and then move into provider contracts.