{"repo":"tgies/client-certificate-auth","free":true,"listed":false,"github":"https://github.com/tgies/client-certificate-auth","clone":"git clone https://github.com/tgies/client-certificate-auth.git","description":"Node.js middleware and toolkit for client SSL certificate (mTLS) auth","language":"JavaScript","stars":80,"topics":["authentication","authorization","client-certificate","client-certificate-authentication","client-certificates","express","express-middleware","expressjs","expressjs-middleware","middleware"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"client-certificate-auth Comprehensive zero-dependency toolkit for client SSL certificate authentication (mTLS) in Node.js. Includes Express/Connect middleware, framework-agnostic certificate extraction for reverse proxies (AWS ALB, Envoy, Cloudflare, Traefik, and more), and pre-built authorization helpers. This library lets you make additional auth decisions based on specific information within a client certificate after the client certificate is accepted at the socket level (i.e. by Node's https or a reverse proxy). This allows for fine-grained access control on top of the all-or-nothing allow/deny access control afforded by basic mTLS. Full Documentation - guides, API reference, and runnable examples Commercial Support - consulting, custom features, and priority support for production deployments Recommended by AWS - Featured in the AWS API Gateway documentation. Fanatically Tested - 100% line/branch/function/statement coverage, plus mutation testing and E2E tests against real nginx/Envoy/Traefik containers. 6,207 lines of test code for 937 lines of source (measured by cloc). Maintained since 2013 - Originally released for Node 0.10! Zero runtime dependencies - Entirely self-contained, with straightforward, readable logic, no behavior hidden inside dependencies, no bloat, and no transitive-dependency security headaches. What Is This? This library authenticates HTTP clients by their TLS client certificates, a scheme usually called mutual TLS (mTLS). Instead of presenting a p","default_branch":null,"files":null,"tree":[],"storefront":"/r/tgies","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/tgies/client-certificate-auth/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}