# @passport-next/passport-strategy

> An abstract class implementing Passport's strategy API.

Latest version **2.4.0** (published 2026-08-14) · MIT license · 0 weekly downloads

## Install

```sh
npm install @passport-next/passport-strategy
pnpm add @passport-next/passport-strategy
yarn add @passport-next/passport-strategy
bun add @passport-next/passport-strategy
```

## Health

**Score 60/100 (C)** — status: active.

Positive: esm support; no vulnerabilities; recently updated; high maintenance score.

Warnings: low downloads; no types.

## Facts

| | |
|---|---|
| Version | 2.4.0 |
| Published | 2026-08-14 |
| First published | 2018-06-29 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | ESM + CommonJS |
| Node | ^22.22.2 \|\| >=24.15.0 |
| Dependencies | 2 |
| Unpacked size | 936.4 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 0 |
| Author | Rowan Wookey |
| Maintainers | adamhathcock, guyellis, brettz9, rwkyqwertee |
| Keywords | passport, strategy |

## Links

- npm: https://www.npmjs.com/package/@passport-next/passport-strategy
- Repository: https://github.com/passport-next/passport-strategy
- Issues: https://github.com/passport-next/passport-strategy/issues
- npm.io page: https://npm.io/package/@passport-next/passport-strategy

## Dependencies (2)

- [@passport-next/http-types](https://npm.io/package/@passport-next/http-types.md) ^0.2.0
- [@passport-next/passport-types](https://npm.io/package/@passport-next/passport-types.md) ^0.3.1

## Alternatives

- [@clerk/clerk-expo](https://npm.io/package/@clerk/clerk-expo.md) — 133.6K weekly downloads
- [@pothos/plugin-authz](https://npm.io/package/@pothos/plugin-authz.md) — 12.4K weekly downloads
- [@bounded-sh/client](https://npm.io/package/@bounded-sh/client.md) — 3.2K weekly downloads
- [@luigi-project/plugin-auth-oauth2](https://npm.io/package/@luigi-project/plugin-auth-oauth2.md) — 2.3K weekly downloads
- [@nocobase/plugin-verification](https://npm.io/package/@nocobase/plugin-verification.md) — 2.0K weekly downloads

## Recent versions

- 2.4.0 (latest) — 2026-08-14
- 2.3.0 — 2026-08-14
- 2.2.0 — 2026-08-13
- 2.1.0 — 2026-08-12
- 2.0.0 — 2026-08-12
- 1.1.0 — 2018-06-29

## README

# @passport-next/passport-strategy

[![Build Status](https://travis-ci.org/passport-next/passport-strategy.svg?branch=master)](https://travis-ci.org/passport-next/passport-strategy)
[![Coverage Status](https://coveralls.io/repos/github/passport-next/passport-strategy/badge.svg?branch=master)](https://coveralls.io/github/passport-next/passport-strategy?branch=master)
[![Maintainability](https://api.codeclimate.com/v1/badges/5c6d93b9711897ef2949/maintainability)](https://codeclimate.com/github/passport-next/passport-strategy/maintainability)
[![Dependencies](https://david-dm.org/passport-next/passport-strategy.png)](https://david-dm.org/passport-next/passport-strategy)
<!--[![SAST](https://gitlab.com/passport-next/passport-strategy/badges/master/build.svg)](https://gitlab.com/passport-next/passport-strategy/badges/master/build.svg)-->

An abstract class implementing [Passport](http://passportjs.org/)'s strategy
API.

## Install

```shell
npm install @passport-next/passport-strategy
```

## Usage

This module exports an abstract `Strategy` class that is intended to be
subclassed when implementing concrete authentication strategies.  Once
implemented, such strategies can be used by applications that utilize Passport
middleware for authentication.

### Subclass Strategy

Create a new `CustomStrategy` constructor which inherits from `Strategy`:

```javascript
import { Strategy } from '@passport-next/passport-strategy';

/**
 *
 */
class CustomStrategy extends Strategy {
  /**
   *
   */
  constructor(/* ... */) {
    super();
    doSomething();
  }
}
```

### Implement Authentication

Implement `authenticate()`, performing the necessary operations required by the
authentication scheme or protocol being implemented.

```javascript
import { Strategy } from '@passport-next/passport-strategy';

/**
 *
 */
class CustomStrategy extends Strategy {
  /**
   *
   * @param {object} req
   * @param {object} options
   */
  #authenticateRequest(req, options) {
    try {
      // TODO: authenticate request
      return findUser(req, options); // Returns user object or false if not found
    } catch {
      this.error(new Error('Database error during authentication'));
      return false;
    }
  }

  // ...
  /**
   * @param req
   * @param options
   */
  authenticate(req, options) {
    const user = this.#authenticateRequest(req, options);
    if (user) {
      this.success({
        username: ''
      });
    } else {
      this.fail();
    }
  }
}
```

See "API" below for additional expected properties and methods.

## API

### Instance properties

Passport will identify mounted strategies by the instance's `name` attribute,
so be sure to set one in the constructor:

```javascript
import { Strategy } from '@passport-next/passport-strategy';

class CustomStrategy extends Strategy {
  constructor() {
    super();
    this.name = 'custom'; // set instance name
  }
}
```

Later, when a user calls `passport.authenticate` to acquire
the authentication middleware that employs this strategy, the value
of this `name` attribute is what must be passed in as the first argument
(as a string or an array of strings):

```javascript
const authMiddleware = passport.authenticate('custom');
```

### Augmented Methods

The `Strategy.authenticate` method is called on an instance of this Strategy
which is augmented with the following action functions.

These action functions are bound via closure the the request/response pair.

The end goal of the strategy is to invoke *one* of these action methods, in
order to indicate successful or failed authentication, redirect to a
third-party identity provider, etc.

* [.success(user, info)](#Strategy+success)
* [.fail(challenge, status)](#Strategy+fail)
* [.redirect(url, status)](#Strategy+redirect)
* [.pass()](#Strategy+pass)
* [.error(err)](#Strategy+error)

#### `strategy.success(user, info)`

Authenticate `user`, with optional `info`.

Strategies should call this method to successfully authenticate a
user. `user` should be an object supplied by the application after it
has been given an opportunity to verify credentials.  `info` is an
optional object containing additional authentication information, or a string
containing a success message. The object form is useful for third-party
authentication strategies to pass profile details.

```javascript
strategy.success(user, { scope: 'read' });
strategy.success(user, 'Welcome!');
```

**Kind**: instance method of [Strategy](#Strategy)
**API**: public

| Param | Type |
| --- | --- |
| user | object |
| info | object\|string |

#### strategy.fail(challenge, status)

Fail authentication, with optional `challenge` and `status`, defaulting
to 401.

Strategies should call this function to fail an authentication attempt.

**Kind**: instance method of [Strategy](#Strategy)
**API**: public

| Param | Type |
| --- | --- |
| challenge | string\|{type?: string, message: string} |
| status | number |

#### strategy.redirect(url, status)

Redirect to `url` with optional `status`, defaulting to 302.

Strategies should call this function to redirect the user (via their
user agent) to a third-party website for authentication.

**Kind**: instance method of [Strategy](#Strategy)
**API**: public

| Param | Type |
| --- | --- |
| url | string |
| status | number |

#### strategy.pass()

Pass without making a success or fail decision.

Under most circumstances, Strategies should not need to call this
function.  It exists primarily to allow previous authentication state
to be restored, for example from an HTTP session.

**Kind**: instance method of [Strategy](#Strategy)
**API**: public

#### strategy.error(err)

Internal error while performing authentication.

Strategies should call this function when an internal error occurs
during the process of performing authentication; for example, if the
user directory is not available.

**Kind**: instance method of [Strategy](#Strategy)
**API**: public

| Param | Type |
| --- | --- |
| err | Error |

## Related Modules

- [chai-passport-strategy](https://github.com/jaredhanson/chai-passport-strategy) — helpers for testing strategies with the Chai assertion library

## Tests

    $ npm install
    $ npm test

---
_Source: https://npm.io/package/@passport-next/passport-strategy · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
