Authbound is designed to be easy for AI coding agents to integrate correctly. Use this section when working with Codex, Claude Code, Cursor, GitHub Copilot, Windsurf, Gemini CLI, or another agentic editor.

Start here

Choose the right SDK

Match the package to your framework and runtime.

Use Authbound prompts

Copy prompts for verification, issuance, webhooks, route protection, and framework setup.

Follow Authbound rules

Keep secret keys server-only, verify webhooks, and use the right package for each runtime.

Read machine-friendly docs

Point agents at llms.txt, Markdown docs, API reference, and SDK guides.
1

Identify the runtime

Decide whether the target app is Next.js, React, Vue, Nuxt, Express, Hono, or a plain Node server.
2

Choose the SDK package

Use @authbound/nextjs for Next.js App Router, @authbound/server for server-side API calls, and browser packages only for UI handoff and status.
3

Keep trust decisions on the server

Browser status is for UX. Webhooks and signed results are for backend state changes.
4

Verify the integration

Test route handlers, webhook signature checks, idempotent mutations, and UI state transitions.

Package map

Never put AUTHBOUND_SECRET_KEY or any sk_* key in browser code. Publishable keys are browser-safe identifiers for SDK flows, not privileged credentials.

Common paths