Package overview
Vestibule separates the core flow, transport middleware, and provider strategies into different packages.
Choose who owns the auth routes
Start with Wisp or Mist middleware if it can handle the request and callback routes. Use core directly if your app must handle those routes.
For Wisp appsvestibule_wispUse Wisp middleware if your app routes requests with Wisp. The middleware handles the request and callback phases.Wisp request and callback routing with signed session cookies and single-use ETS state storage.Read package guideFor plain Mist appsvestibule_mistUse Mist middleware if your app runs directly on Mist and does not use Wisp.Plain Mist request and callback routing with HMAC-SHA256 signed session cookies and the shared Vestibule state store.Read package guideFor custom routingvestibuleUse the core package if your app must control the request and callback phases or provide a custom transport integration.Core types, a two-phase OAuth2 flow, PKCE, CSRF state, token refresh, and a shared state store.Read package guide
Add provider strategies after the route shape
Add provider packages to the base request and callback flow. Add one package for each identity provider that your app supports.
| Provider package | Default scopes | Important behavior |
|---|---|---|
| vestibule_github | user:email | Requests user:email by default. |
| vestibule_google | openid email profile | user_info.email only returns a value when email_verified is true. |
| vestibule_microsoft | openid User.Read | The default strategy uses /common and performs no tenant validation. |
| vestibule_apple | name email | init initializes the JWKS cache used to verify Apple ID tokens. |
| vestibule_indieauth | profile | The identity is a URL. auth.uid(auth) returns the user's canonical me URL. |
| vestibule_oidc | openid profile email | discover reads /.well-known/openid-configuration and builds a Strategy. |
Read generated API reference
The website build generates reference pages from Gleam docs metadata. Thus, each page matches the package's public API.
| Package | Reference |
|---|---|
| vestibule | Open generated reference |
| vestibule_wisp | Open generated reference |
| vestibule_mist | Open generated reference |
| vestibule_github | Open generated reference |
| vestibule_google | Open generated reference |
| vestibule_microsoft | Open generated reference |
| vestibule_apple | Open generated reference |
| vestibule_indieauth | Open generated reference |
| vestibule_oidc | Open generated reference |