The AuthOptions define how authentication and authorization is managed.
booleanfalseDisable authentication & permissions checks. NEVER set the to true in production. It exists only to aid certain development tasks.
'cookie' | 'bearer' | ReadonlyArray<'cookie' | 'bearer' | 'api-key'>'cookie'Sets the method by which the session token is delivered and read.
Authorization: Bearer <token>.createApiKey will return a generated API-Key once, which should then be
stored by the User. Each request should include the API-Key inside the header defined by apiKeyHeaderKey
('vendure-api-key' by default).Note that if the bearer method is used, Vendure will automatically expose the configured
authTokenHeaderKey in the server's CORS configuration (adding Access-Control-Expose-Headers: vendure-auth-token
by default).
From v1.2.0 it is possible to specify both methods as a tuple: ['cookie', 'bearer'].
From v3.6.0 it is possible to include 'api-key' as additional method in the method-tuple to allow for long-lived API-Key based authorization.
CookieOptionsOptions related to the handling of cookies when using the 'cookie' tokenMethod.
string'vendure-auth-token'Sets the header property which will be used to send the auth token when using the 'bearer' method.
string'vendure-api-key'Defines which header will be used to read the API-Key when using the 'api-key' token method.
string | number'1y'Session duration, i.e. the time which must elapse from the last authenticated request after which the user must re-authenticate.
If passed as a number should represent milliseconds and if passed as a string describes a time span per
zeit/ms. Eg: 60, '2 days', '10h', '7d'
SessionCacheStrategy<a href='/reference/typescript-api/auth/default-session-cache-strategy#defaultsessioncachestrategy'>DefaultSessionCacheStrategy</a>This strategy defines how sessions will be cached. By default, since v3.1.0, sessions are cached using
the underlying cache strategy defined in the SystemOptions.cacheStrategy.
string | number300The "time to live" of a given item in the session cache. This determines the length of time that a cache entry is kept before being considered "stale" and being replaced with fresh data taken from the database.
If passed as a number should represent seconds and if passed as a string describes a time span per
zeit/ms. Eg: 60, '2 days', '10h', '7d'
booleantrueDetermines whether new User accounts require verification of their email address.
If set to "true", the customer will be required to verify their email address using a verification token
they receive in their email. See the registerCustomerAccount mutation for more details on the verification behavior.
string | number'7d'Sets the length of time that a verification token is valid for, after which the verification token must be refreshed.
If passed as a number should represent milliseconds and if passed as a string describes a time span per
zeit/ms. Eg: 60, '2 days', '10h', '7d'
SuperadminCredentialsConfigures the credentials to be used to create a superadmin
AuthenticationStrategy[]<a href='/reference/typescript-api/auth/native-authentication-strategy#nativeauthenticationstrategy'>NativeAuthenticationStrategy</a>Configures one or more AuthenticationStrategies which defines how authentication is handled in the Shop API.
AuthenticationStrategy[]<a href='/reference/typescript-api/auth/native-authentication-strategy#nativeauthenticationstrategy'>NativeAuthenticationStrategy</a>Configures one or more AuthenticationStrategy which defines how authentication is handled in the Admin API.
PermissionDefinition[][]Allows custom Permissions to be defined, which can be used to restrict access to custom GraphQL resolvers defined in plugins.
<a href='/reference/typescript-api/auth/bcrypt-password-hashing-strategy#bcryptpasswordhashingstrategy'>BcryptPasswordHashingStrategy</a>Allows you to customize the way passwords are hashed when using the NativeAuthenticationStrategy.
<a href='/reference/typescript-api/auth/default-password-validation-strategy#defaultpasswordvalidationstrategy'>DefaultPasswordValidationStrategy</a>Allows you to set a custom policy for passwords when using the NativeAuthenticationStrategy. By default, it uses the DefaultPasswordValidationStrategy, which will impose a minimum length of four characters. To improve security for production, you are encouraged to specify a more strict policy, which you can do like this:
Example
<a href='/reference/typescript-api/auth/default-verification-token-strategy#defaultverificationtokenstrategy'>DefaultVerificationTokenStrategy</a>Allows you to customize the way verification tokens are generated.
<a href='/reference/typescript-api/auth/entity-access-control-strategy#defaultentityaccesscontrolstrategy'>DefaultEntityAccessControlStrategy</a>Allows you to define access control for entity queries at three levels:
canAccess() — gate-level permission check (once per request)prepareAccessControl() — async pre-loading for row-level filtering (once per request)applyAccessControl() — synchronous row-level QB filtering (every entity query)Developer preview: this API is subject to change in future releases.
<a href='/reference/typescript-api/auth/customer-channel-assignment-strategy#defaultcustomerchannelassignmentstrategy'>DefaultCustomerChannelAssignmentStrategy</a>Determines whether an authenticated Customer is auto-assigned to the active Channel.
This is skipped for the default channel, disableAuth, and registration/checkout flows.
The default strategy always assigns.