Install and verify
View @qentrah/auth-sdk on npm ↗
Before you start
The package does not declare an engine requirement. Use a maintained Node.js release appropriate to your host application.
Use a project with a package.json. Check the runtime and package manager:
node --version
npm --versionInstall the documented version
npm install @qentrah/auth-sdk@0.3.4Confirm the installation
npm ls @qentrah/auth-sdkThe output should show @qentrah/auth-sdk@0.3.4. Commit the lockfile so another developer installs the same dependency tree.
Environment Variables
Use your own secret manager, hosting provider settings, or deployment environment.
QENTRAH_WORKSPACE_BASE_URL=https://app.qentrah.com
QENTRAH_PARTNER_CLIENT_ID=<your-partner-client-id>
QENTRAH_PARTNER_CLIENT_SECRET=<optional-confidential-client-secret>
QENTRAH_PARTNER_REDIRECT_URI=https://your-app.example.com/api/qentrah/oauth/callback
QENTRAH_PARTNER_SCOPES="organization:read client:read"
QENTRAH_WEBHOOK_SIGNING_SECRET=<your-webhook-signing-secret>QENTRAH_PARTNER_CLIENT_SECRET is only needed for confidential client setups. Never place it in browser-visible configuration.
You can normalize the public OAuth settings with:
import { qentrahPartnerAuthorityFromEnv } from "@qentrah/auth-sdk/partner";
const authority = qentrahPartnerAuthorityFromEnv({
QENTRAH_WORKSPACE_BASE_URL: process.env.QENTRAH_WORKSPACE_BASE_URL,
QENTRAH_PARTNER_CLIENT_ID: process.env.QENTRAH_PARTNER_CLIENT_ID,
QENTRAH_PARTNER_REDIRECT_URI: process.env.QENTRAH_PARTNER_REDIRECT_URI,
QENTRAH_PARTNER_SCOPES: process.env.QENTRAH_PARTNER_SCOPES,
});Browser Connect Button
<button id="qentrah-authorize">Authorize with Qentrah</button>import { mountQentrahAuthorizeButton } from "@qentrah/auth-sdk/partner/browser";
mountQentrahAuthorizeButton({
buttonId: "qentrah-authorize",
startUrl: "/api/qentrah/oauth/start",
label: "Authorize with Qentrah",
disabledLabel: "Opening...",
onError(error) {
reportConnectionError(error);
},
});The button should point at a backend route in your app. It should not receive tokens or secrets.
Expected result
The connect button opens your backend start route. It cannot complete authorization until you implement server-side state and token storage and register the callback URI.
Source captured: 2026-10-11