# @scribelabsai/auth

> Library to connect to Scribe's platform.

Latest version **2.0.5** (published 2025-10-21) · MIT License license · 0 weekly downloads

## Install

```sh
npm install @scribelabsai/auth
pnpm add @scribelabsai/auth
yarn add @scribelabsai/auth
bun add @scribelabsai/auth
```

Provides the command `auth`.

## Health

**Score 65/100 (B)** — status: stable.

Positive: has types; esm support; no vulnerabilities; has provenance; high quality score.

Warnings: low downloads.

## Facts

| | |
|---|---|
| Version | 2.0.5 |
| Published | 2025-10-21 |
| First published | 2023-05-23 |
| Weekly downloads | 0 |
| License | MIT License |
| TypeScript types | bundled |
| Module format | ESM + CommonJS |
| Dependencies | 4 |
| Unpacked size | 41.9 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Provenance | attested (GitHub Actions) |
| GitHub stars | 0 |
| Author | Ailín Venerus |
| Maintainers | ailinvenerus, ehadoux |

## Links

- npm: https://www.npmjs.com/package/@scribelabsai/auth
- Repository: https://github.com/ScribeLabsAI/ScribeAuthNode
- Homepage: https://github.com/ScribeLabsAI/ScribeAuthNode#readme
- Issues: https://github.com/ScribeLabsAI/ScribeAuthNode/issues
- npm.io page: https://npm.io/package/@scribelabsai/auth

## Dependencies (4)

- [jsonwebtoken](https://npm.io/package/jsonwebtoken.md) ^9.0.2
- [amazon-cognito-identity-js](https://npm.io/package/amazon-cognito-identity-js.md) ^6.2.0
- [@aws-sdk/client-cognito-identity](https://npm.io/package/@aws-sdk/client-cognito-identity.md) ^3.348.0
- [@aws-sdk/client-cognito-identity-provider](https://npm.io/package/@aws-sdk/client-cognito-identity-provider.md) ^3.760.0

## Recent versions

- 2.0.5 (latest) — 2025-10-21
- 1.4.1 — 2023-11-10
- 1.3.0 — 2023-08-07
- 1.2.1 — 2023-06-20
- 1.2.0 — 2023-06-14
- 1.1.0 — 2023-06-09
- 1.0.0 — 2023-05-23

## README

# Scribe Auth Node

Most calls to Scribe's API require authentication and authorization. This library simplifies this process.

You first need a Scribe account and a client ID. Both can be requested at support[atsign]scribelabs[dotsign]ai or through Intercom on https://platform.scribelabs.ai if you already have a Scribe account.

This library interacts directly with our authentication provider [AWS Cognito](https://aws.amazon.com/cognito/) meaning that your username and password never transit through our servers.

## Installation

Add the dependency to your package.json and save it:

```
"dependencies": {
	"@scribelabsai/auth": ">=2.0.0"
}
```

Install it from command line:

```
npm install
```

## Requirements

This library requires Node.js >= 16.20.0

## Methods

### 1. Changing password

```javascript
import { Auth, Tokens } from '@scribelabsai/auth';
const access = new Auth(clientId);
access.changePassword('username', 'password', 'newPassword');
```

### 2. Recovering an account in case of forgotten password

```javascript
import { Auth, Tokens } from '@scribelabsai/auth';
const access = new Auth(clientId);
access.forgotPassword('username', 'password', 'confirmationCode');
```

### 3. Get or generate tokens

##### With username and password

```javascript
import { Auth, Tokens } from '@scribelabsai/auth';
const access = new Auth(clientId);
access.getTokens({ username: 'username', password: 'password' });
```

##### With username and password (MFA enabled)

```javascript
import { Auth, Tokens, Challenge } from '@scribelabsai/auth';
const access = new Auth(clientId);
const result = await access.getTokens({ username: 'username', password: 'password' });

// Check if MFA challenge is required
if ('challengeName' in result && result.challengeName === 'SOFTWARE_TOKEN_MFA') {
  // Prompt user for MFA code from their authenticator app
  const mfaCode = '123456'; // Get this from user input
  const tokens = await access.respondToAuthChallengeMfa(
    result.user,
    mfaCode,
    result.challengeParameters
  );
  console.log(tokens);
} else {
  // No MFA required, result is already the tokens
  console.log(result);
}
```

##### With refresh token

```javascript
import { Auth, Tokens } from '@scribelabsai/auth';
const access = new Auth(clientId);
access.getTokens({ refreshToken: 'refreshToken' });
```

### 4. Revoking a refresh token

#### Disclaimer: revokeToken(refreshToken) is not ready yet, you may use our [Python lib](https://github.com/ScribeLabsAI/ScribeAuth) or call AWS services directly.

## Flow

- If you never have accessed your Scribe account, it probably still contains the temporary password we generated for you. You can change it directly on the [platform](https://platform.scribelabs.ai) or with the `changePassword` method. You won't be able to access anything else until the temporary password has been changed.

- Once the account is up and running, you can request new tokens with `getTokens`. You will initially have to provide your username and password. The access and id tokens are valid for up to 30 minutes. The refresh token is valid for 30 days.

- While you have a valid refresh token, you can request fresh access and id tokens with `getTokens` but using the refresh token this time, so you're not sending your username and password over the wire anymore.

- You can get your federated id by using `getFederatedId` and providing your id token. The federated id will allow you to use `getFederatedCredentials` to get an access key id, secret key and session token.

- Every API call to be made to Scribe's API Gateway needs to have a signature. You can get the signature for your request by using `getSignatureForRequest`. Provide the request you'll be using and your credentials (use `getFederatedCredentials` to get them).

---

To flag an issue, open a ticket on [Github](https://github.com/ScribeLabsAI/ScribeAuthNode/issues) and contact us on Intercom through the platform.

---
_Source: https://npm.io/package/@scribelabsai/auth · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
