Docs menu: Package overview

Package overview

Vestibule separates the core flow, transport middleware, and provider strategies into different packages.

Choose who owns the auth routes

Start with Wisp or Mist middleware if it can handle the request and callback routes. Use core directly if your app must handle those routes.

Add provider strategies after the route shape

Add provider packages to the base request and callback flow. Add one package for each identity provider that your app supports.

Provider package comparison
Provider packageDefault scopesImportant behavior
vestibule_githubuser:emailRequests user:email by default.
vestibule_googleopenid email profileuser_info.email only returns a value when email_verified is true.
vestibule_microsoftopenid User.ReadThe default strategy uses /common and performs no tenant validation.
vestibule_applename emailinit initializes the JWKS cache used to verify Apple ID tokens.
vestibule_indieauthprofileThe identity is a URL. auth.uid(auth) returns the user's canonical me URL.
vestibule_oidcopenid profile emaildiscover reads /.well-known/openid-configuration and builds a Strategy.

Read generated API reference

The website build generates reference pages from Gleam docs metadata. Thus, each page matches the package's public API.

Generated API reference links
PackageReference
vestibuleOpen generated reference
vestibule_wispOpen generated reference
vestibule_mistOpen generated reference
vestibule_githubOpen generated reference
vestibule_googleOpen generated reference
vestibule_microsoftOpen generated reference
vestibule_appleOpen generated reference
vestibule_indieauthOpen generated reference
vestibule_oidcOpen generated reference