CarpoSDK docs

Server authentication

Use Better Auth's framework agnostic client with Carpo Project Auth.

The server auth client is Better Auth's framework agnostic client configured for the selected Carpo project and environment. It exposes Better Auth methods and Carpo's configured plugin clients.

With createCarpoServerClient(), pass the current request headers for operations that need to read or act on the user's session:

const { data: session, error } = await carpo.auth.getSession({
  fetchOptions: { headers: request.headers },
})

if (error || !session) {
  return null
}

The server client does not read headers from a framework global. Pass the headers from the request that is currently being handled. createCarpoServerRequestClient() takes a Fetch Request and applies its selected identity headers to Auth calls by default.

For a browser sign in or sign out, use the browser Auth client so the browser can receive and send the session cookie. A server client can inspect or use an incoming session, but it does not replace the browser cookie flow.

Use createCarpoServerAuthClient() from @carpodev/carpo-sdk/server/auth to create only the Auth client. Its config also accepts Better Auth fetchOptions, disableDefaultFetchPlugins, optional oneTapClientId, and extra plugins that are enabled by Project Auth.