Custom authentication in [LangGraph](https://docs.langchain.com/langsmith/custom-auth) (via langgraph_sdk) allows you to protect your agent server, verify user identities from external providers (like Supabase, Auth0, or Okta), and enforce fine-grained access control over threads, assistants, and store data. [1, 2, 3]
------------------------------
## How It Works
The authentication flow relies on three core pieces working together: an Identity Provider, the LangGraph Backend, and the Client Application: [2]
1. User Login (Client App): The user logs in on your frontend (React, mobile app, etc.) using an external authentication service like Supabase or Auth0. [2, 4]
2. Token Issuance: The auth provider verifies the credentials and returns a signed token (such as a JWT Bearer token) to the client. [4]
3. Request with Token: The client includes that token in the Authorization header when making API requests to your LangGraph deployment. [4, 5]
4. Server Verification (@auth.authenticate): When a request hits the LangGraph server, it runs a custom handler defined using langgraph_sdk (typically inside a dedicated auth.py file).
* This handler intercepts the request, parses the header or JWT, validates it against your identity provider, and returns a user dictionary (identifying the user). [1, 3, 6, 7]
5. Authorization (@auth.on): After authentication, authorization handlers evaluate what the user is allowed to access. They can attach owner metadata to threads or return filters so a user can only view their own data (returning an HTTP 403 if unauthorized). [1, 7, 8, 9]
6. Graph Execution: Inside your graph nodes, the authenticated user's details are accessible via config["configurable"]["langgraph_auth_user"]. [6]
------------------------------
## Key Components to Implement
* The Auth File (auth.py): Uses the Auth class from langgraph_sdk with decorators like @auth.authenticate to validate credentials and @auth.on to control resource-level permissions.
* Configuration (langgraph.json): You register your custom auth script path under the auth configuration field so the LangGraph server loads it automatically: [1, 3, 8]
{
"auth": {
"path": "./auth.py:my_auth"
}
}
If you're setting this up right now, let me know:
* Which authentication provider you plan to use (e.g., Supabase, Auth0, custom JWT)
* Whether you need help writing the @auth.authenticate or @auth.on code handlers
[1] [https://www.langchain.com](https://www.langchain.com/blog/custom-authentication-and-access-control-in-langgraph)
[2] [https://docs.langchain.com](https://docs.langchain.com/langsmith/auth)
[3] [https://reference.langchain.com](https://reference.langchain.com/python/langgraph-sdk/auth)
[4] [https://github.com](https://github.com/langchain-ai/custom-auth)
[5] [https://www.youtube.com](https://www.youtube.com/watch?v=g7s_6t5Jm4I&t=505)
[6] [https://docs.langchain.com](https://docs.langchain.com/langsmith/custom-auth)
[7] [https://github.com](https://github.com/langchain-ai/custom-auth/blob/main/README.md)
[8] [https://reference.langchain.com](https://reference.langchain.com/python/langgraph-sdk/auth/Auth)
[9] [https://docs.langchain.com](https://docs.langchain.com/langsmith/resource-auth)
No comments:
Post a Comment