Repository navigation
Conversation
Model AuthKitConfig as a union of a confidential config (apiKey) and a
public config (no apiKey), drop apiKey from the required keys while still
reading it from env, and build the WorkOS client with
new WorkOS({ apiKey, clientId, ...options }) so the SDK runs in public-client
mode when no key is configured.
nicknisi
marked this pull request as ready for review
October 7, 2026 17:22
Contributor
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Let @workos/authkit-session run as a keyless PKCE public client, bringing the experience shipped in workos/authkit-react-router#96 (workos/authkit-react-router#96, "feat: support keyless PKCE public clients", merged Oct 6) to authkit-session. A server that only signs users in should work with WORKOS_CLIENT_ID, WORKOS_REDIRECT_URI and WORKOS_COOKIE_PASSWORD and no WORKOS_API_KEY.
Read #96's diff first (
gh pr diff 96 --repo workos/authkit-react-router) and mirror its design and rigor:AuthKitConfigbecomes a discriminated union: a confidential config (apiKey: string) and a public config (no apiKey). It stays non-breaking: existing users with WORKOS_API_KEY via env or configure() keep working unchanged, and env-only configuration works for both modes.apiKeycomes out of the requiredKeys insrc/core/config/ConfigurationProvider.ts. Construct the client asnew WorkOS({ apiKey, clientId, ...options })insrc/core/client/workos.ts, so workos-node 8.x's keyless mode applies (authenticateWithCodewith a codeVerifier andauthenticateWithRefreshTokenomit client_secret when there's no key). Check the installed @workos-inc/node peer range supports this and raise the minimum if needed.featureFlags.createRuntimeClient, any organizations or userManagement admin calls) and list which need a key.expectTypeOf, or@ts-expect-errorcases)Then prove it end to end: authkit-session is the core used by authkit-tanstack-start, so use that package's example app (/Users/nicknisi/Developer/authkit-tanstack-start/example) as the harness. Copy it to a scratch directory outside both repos and point it at this branch's packed build (
pnpm pack, then a file: or overrides dependency in the copy only). Run it with no WORKOS_API_KEY, and show that GET on the sign-in route redirects to the AuthKit authorization URL withcode_challengeandcode_challenge_method=S256. Leave the dev server running and give Nick the URL and exact steps to sign in and see the session load and a refresh succeed. If a refresh can be shown without his login (e.g. a debug log line in the demo copy only), add it to the demo copy, not the library.Riker's check
pnpm install --frozen-lockfile >/dev/null && pnpm typecheck && pnpm lint && pnpm format:check && pnpm test && pnpm buildpassed.Opened as a draft by Riker (job 96).