# tr-oauth2

> Relatively simple OAUTH2 token issuer and validator.

Latest version **4.0.5** (published 2025-04-18) · GPL-2.0 license · 0 weekly downloads

## Install

```sh
npm install tr-oauth2
pnpm add tr-oauth2
yarn add tr-oauth2
bun add tr-oauth2
```

## Health

**Score 25/100 (F)** — status: maintenance-mode.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: stale; low maintenance score.

## Facts

| | |
|---|---|
| Version | 4.0.5 |
| Published | 2025-04-18 |
| First published | 2020-08-21 |
| Weekly downloads | 0 |
| License | GPL-2.0 |
| TypeScript types | none |
| Module format | CommonJS |
| Node | >=20.0.0 |
| Dependencies | 4 |
| Unpacked size | 84.7 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Author | Timo J. Rinne |
| Maintainers | rinne |

## Links

- npm: https://www.npmjs.com/package/tr-oauth2
- Repository: https://github.com/rinne/node-tr-oauth2
- Homepage: https://github.com/rinne/node-tr-oauth2#readme
- Issues: https://github.com/rinne/node-tr-oauth2/issues
- npm.io page: https://npm.io/package/tr-oauth2

## Dependencies (4)

- [optist](https://npm.io/package/optist.md) ^2.0.1
- [pem-jwk](https://npm.io/package/pem-jwk.md) ^2.0.0
- [csv-parser](https://npm.io/package/csv-parser.md) ^3.2.0
- [jsonwebtoken](https://npm.io/package/jsonwebtoken.md) ^9.0.2

## Recent versions

- 4.0.5 (latest) — 2025-04-18
- 4.0.4 — 2025-04-18
- 4.0.3 — 2025-04-17
- 4.0.2 — 2025-04-16
- 4.0.1 — 2025-04-16
- 4.0.0 — 2025-04-16
- 3.3.0 — 2025-04-15
- 3.2.0 — 2025-04-15
- 3.1.0 — 2025-04-15
- 3.0.0 — 2025-04-15
- 2.0.0 — 2020-08-21

## README

In a Nutshell
=============

A client library maintaining valid OAUTH2 client token as background
operation.


Reference
=========

```
const DOC = require('tr-oauth2');

var doc = new DOC('https://oauth2-auth-server.in.my.domain/oauth/token',
                  { grant_type: 'client_credentials' },
		  'my-username',
		  'my-very-secret-password');
doc.on('refresh', function(expiresIn) { console.log('Token refreshed.'); });
doc.on('error', function(e) { console.log(e); process.exit(1); });
```

In your code, you'll want to wait for the first `refresh`
callback. After this, if everything works, `doc.token` will
automatically be maintained so that it points to a valid token.

Server
======

While this package is mainly a client library maintaining a valid
OAUTH2 token for some other use, there is also actually a fully
functional OAUTH2 server that can yield access tokens for clients and
can also handle token verification and revocation. User database is a
CSV file (example in users.dat) and can contain also scopes and
authorities. The token is a JWT token which is either signed with RSA
key or using a static symmetric secret.

This is not really aimed for serious production use and it also
naturally needs a HTTPS termination service (such as a nginx reverse
proxy) in front of itself. However if someone spots a security
problem, please report them so I can fix or document them.

```
Usage:
  oauthserver [<opt> ...]
  Options:
       --listen-address=<arg>   IP address the server listens to.
       --listen-port=<arg>      TCP port the server listens to.
       --token-ttl=<arg>        Default validity time for tokens in seconds.
       --token-issuer=<arg>     Issuer name to be included into tokens.
       --users-file=<arg>       CSV file containing users data.
       --secret-key-file=<arg>  Read token signing key from file.
       --public-key-file=<arg>  Read token verifying key from file.
       --secret=<arg>           Symmetric secret for token signing.
       --secret-file=<arg>      Read symmetric secret from file.
   -h  --help                   Show help and exit
```


Author
======

Timo J. Rinne <tri@iki.fi>


License
=======

GPL-2.0

---
_Source: https://npm.io/package/tr-oauth2 · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
