# @node-oauth/express-oauth-server

> OAuth provider for express

Latest version **4.2.0** (published 2026-07-19) · MIT license · 0 weekly downloads

## Install

```sh
npm install @node-oauth/express-oauth-server
pnpm add @node-oauth/express-oauth-server
yarn add @node-oauth/express-oauth-server
bun add @node-oauth/express-oauth-server
```

## Health

**Score 65/100 (B)** — status: active.

Positive: has types; no vulnerabilities; recently updated; high maintenance score; high quality score.

Warnings: low downloads; no esm support.

## Facts

| | |
|---|---|
| Version | 4.2.0 |
| Published | 2026-07-19 |
| First published | 2023-05-26 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | CommonJS |
| Node | >=16 |
| Dependencies | 1 |
| Unpacked size | 14.6 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 41 |
| Maintainers | jkuester, happyzombies |
| Keywords | express, oauth, oauth2, @node-oauth, oauth2-server |

## Links

- npm: https://www.npmjs.com/package/@node-oauth/express-oauth-server
- Repository: https://github.com/node-oauth/express-oauth-server
- Homepage: https://github.com/node-oauth/express-oauth-server#readme
- Issues: https://github.com/node-oauth/express-oauth-server/issues
- npm.io page: https://npm.io/package/@node-oauth/express-oauth-server

## Dependencies (1)

- [@node-oauth/oauth2-server](https://npm.io/package/@node-oauth/oauth2-server.md) ^5.3.0

## Alternatives

- [@clerk/clerk-expo](https://npm.io/package/@clerk/clerk-expo.md) — 133.6K weekly downloads
- [@pothos/plugin-authz](https://npm.io/package/@pothos/plugin-authz.md) — 12.4K weekly downloads
- [@bounded-sh/client](https://npm.io/package/@bounded-sh/client.md) — 3.2K weekly downloads
- [@luigi-project/plugin-auth-oauth2](https://npm.io/package/@luigi-project/plugin-auth-oauth2.md) — 2.3K weekly downloads
- [@nocobase/plugin-verification](https://npm.io/package/@nocobase/plugin-verification.md) — 2.0K weekly downloads

## Recent versions

- 4.2.0 (latest) — 2026-07-19
- 4.0.0-rc.0 (next) — 2024-01-09
- 4.1.5 — 2026-01-26
- 4.1.4 — 2025-07-22
- 4.1.3 — 2025-04-30
- 4.1.2 — 2025-01-22
- 4.1.1 — 2024-09-27
- 4.1.0 — 2024-07-31
- 4.0.0 — 2024-02-05
- 3.0.1 — 2023-05-30
- 3.0.0 — 2023-05-26

## README

<div align="center">
  <h1>Express OAuth Server</h1>
</div>

<p align="center">
Complete, compliant and well tested module for implementing an OAuth2 Server/Provider with <a alt="express" href="https://github.com/expressjs/express">express</a> in <a alt="node.js" href="http://nodejs.org/">Node.js</a>.
</p>

<div align="center">

[![Tests](https://github.com/node-oauth/express-oauth-server/actions/workflows/tests.yml/badge.svg)](https://github.com/node-oauth/express-oauth-server/actions/workflows/tests.yml)
[![CodeQL](https://github.com/node-oauth/express-oauth-server/actions/workflows/github-code-scanning/codeql/badge.svg)](https://github.com/node-oauth/express-oauth-server/actions/workflows/github-code-scanning/codeql)
[![Project Status: Active – The project has reached a stable, usable state and is being actively developed.](https://www.repostatus.org/badges/latest/active.svg)](https://www.repostatus.org/#active)
[![npm Version](https://img.shields.io/npm/v/@node-oauth/express-oauth-server?label=version)](https://www.npmjs.com/package/@node-oauth/oauth2-server)
[![npm Downloads/Week](https://img.shields.io/npm/dw/@node-oauth/express-oauth-server)](https://www.npmjs.com/package/@node-oauth/oauth2-server)
![GitHub](https://img.shields.io/github/license/node-oauth/express-oauth-server)

</div>

<div align="center">

[API Docs](https://node-oauth.github.io/express-oauth-server/)
·
[NPM Link](https://www.npmjs.com/package/@node-oauth/express-oauth-server)
·
[Node OAuth2 Server](https://github.com/node-oauth/node-oauth2-server)

</div>

## About

This package wraps the [@node-oauth/oauth2-server](https://github.com/node-oauth/node-oauth2-server) into an
express compatible middleware.
It's a maintained and up-to-date fork from the former
[oauthjs/express-oauth-server](https://github.com/oauthjs/express-oauth-server).


## Installation

```shell
$ npm install @node-oauth/express-oauth-server
```

## Quick Start

The module provides two middlewares - one for granting tokens and another to authorize them. 
`@node-oauth/express-oauth-server` and, consequently `@node-oauth/oauth2-server`,
expect the request body to be parsed already.
The following example uses `body-parser` but you may opt for an alternative library.

```js
const bodyParser = require('body-parser');
const express = require('express');
const OAuthServer = require('@node-oauth/express-oauth-server');

const app = express();

app.oauth = new OAuthServer({
  model: {}, // See https://github.com/node-oauth/node-oauth2-server for specification
});

app.use(bodyParser.json());
app.use(bodyParser.urlencoded({ extended: false }));
app.use(app.oauth.authorize());

app.use(function(req, res) {
  res.send('Secret area');
});

app.listen(3000);
```

## Options

> Note: The following options **extend** the default options from `@node-oauth/oauth2-server`!
> You can read more about all possible options in the
> [@node-oauth/oauth2-server documentation](https://node-oauthoauth2-server.readthedocs.io/en/master/api/oauth2-server.html)
 
```
const options = { 
  useErrorHandler: false, 
  continueMiddleware: false,
}
```

- `useErrorHandler`
(_type: boolean_ default: false)

  If false, an error response will be rendered by this component.
  Set this value to true to allow your own express error handler to handle the error.

- `continueMiddleware`
(_type: boolean default: false_)

  The `authorize()` and `token()` middlewares will both render their 
  result to the response and end the pipeline.
  next() will only be called if this is set to true.

  **Note:** You cannot modify the response since the headers have already been sent.

  `authenticate()` does not modify the response and will always call next()

## Migration notes

Beginning with **version 4.0** this package brings some potentially breaking changes:

- dropped old es5 code; moved to native async/await
- requires node >= 16
- ships with [@node-oauth/oauth2-server](https://github.com/node-oauth/node-oauth2-server) 5.x
- no express version pinned but declared as `'*'` peer dependency, so it should not cause conflicts with your express version

## More Examples

For more examples, please visit [our dedicated "examples" repo](https://github.com/node-oauth/node-oauth2-server-examples)
, which also contains express examples.

## License

MIT, see [license file](./LICENSE).

---
_Source: https://npm.io/package/@node-oauth/express-oauth-server · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
