Composable, non-opinionated authentication toolkit for Go — import the modules you need (identity, tokens/JWT, sessions, passkeys, OAuth/OIDC, MFA, OTP) and wire them with DI. Secure-by-default, no framework.
Go Authentication, eXtended — embed multi-method auth (passwords, passkeys/QR, magic-link, OIDC, social) in one Go app: BFF sessions, CSRF, groups, API keys, LDAP & SCIM. No separate IdP.