Ready to deploy
Next.js
App Router, Authorization Code + PKCE, signed ID-token validation, HttpOnly cookies, and standard logout.
OPEN-SOURCE EXAMPLES
Try a real Hosted Auth flow, inspect the source, and start from the framework closest to your application.
HOSTED AUTH
App Router, Authorization Code + PKCE, signed ID-token validation, HttpOnly cookies, and standard logout.
Browser-only React with Authorization Code + PKCE and no client secret in frontend code.
NamoID owns authentication while Supabase stores application data behind an authenticated server boundary.
A separate Express API manages the confidential code exchange and application session for React.