Saturday, October 3, 2026

What is custom Auth provider in Langgraph

Custom authentication in [LangGraph](https://docs.langchain.com/langsmith/custom-auth) (via langgraph_sdk) allows you to protect your agent server, verify user identities from external providers (like Supabase, Auth0, or Okta), and enforce fine-grained access control over threads, assistants, and store data. [1, 2, 3] 

------------------------------

## How It Works

The authentication flow relies on three core pieces working together: an Identity Provider, the LangGraph Backend, and the Client Application: [2] 


   1. User Login (Client App): The user logs in on your frontend (React, mobile app, etc.) using an external authentication service like Supabase or Auth0. [2, 4] 

   2. Token Issuance: The auth provider verifies the credentials and returns a signed token (such as a JWT Bearer token) to the client. [4] 

   3. Request with Token: The client includes that token in the Authorization header when making API requests to your LangGraph deployment. [4, 5] 

   4. Server Verification (@auth.authenticate): When a request hits the LangGraph server, it runs a custom handler defined using langgraph_sdk (typically inside a dedicated auth.py file).

   * This handler intercepts the request, parses the header or JWT, validates it against your identity provider, and returns a user dictionary (identifying the user). [1, 3, 6, 7] 

   5. Authorization (@auth.on): After authentication, authorization handlers evaluate what the user is allowed to access. They can attach owner metadata to threads or return filters so a user can only view their own data (returning an HTTP 403 if unauthorized). [1, 7, 8, 9] 

   6. Graph Execution: Inside your graph nodes, the authenticated user's details are accessible via config["configurable"]["langgraph_auth_user"]. [6] 


------------------------------

## Key Components to Implement


* The Auth File (auth.py): Uses the Auth class from langgraph_sdk with decorators like @auth.authenticate to validate credentials and @auth.on to control resource-level permissions.

* Configuration (langgraph.json): You register your custom auth script path under the auth configuration field so the LangGraph server loads it automatically: [1, 3, 8] 


{

  "auth": {

    "path": "./auth.py:my_auth"

  }

}



If you're setting this up right now, let me know:


* Which authentication provider you plan to use (e.g., Supabase, Auth0, custom JWT)

* Whether you need help writing the @auth.authenticate or @auth.on code handlers



[1] [https://www.langchain.com](https://www.langchain.com/blog/custom-authentication-and-access-control-in-langgraph)

[2] [https://docs.langchain.com](https://docs.langchain.com/langsmith/auth)

[3] [https://reference.langchain.com](https://reference.langchain.com/python/langgraph-sdk/auth)

[4] [https://github.com](https://github.com/langchain-ai/custom-auth)

[5] [https://www.youtube.com](https://www.youtube.com/watch?v=g7s_6t5Jm4I&t=505)

[6] [https://docs.langchain.com](https://docs.langchain.com/langsmith/custom-auth)

[7] [https://github.com](https://github.com/langchain-ai/custom-auth/blob/main/README.md)

[8] [https://reference.langchain.com](https://reference.langchain.com/python/langgraph-sdk/auth/Auth)

[9] [https://docs.langchain.com](https://docs.langchain.com/langsmith/resource-auth)

 

No comments:

Post a Comment