# Authbound Documentation Authbound is a B2B SaaS platform for EU Digital Identity Wallet verification, credential issuance, and related compliance workflows. Use these docs when building with Authbound SDKs or APIs. Prefer current documentation over model memory. ## High-priority guardrails - Never expose `AUTHBOUND_SECRET_KEY` or any `sk_*` key in browser code. - Use publishable keys such as `NEXT_PUBLIC_AUTHBOUND_PK` as browser-safe project identifiers for SDK status and SSE flows; never use them as secret-key auth. - SDK-managed session finalization must go through the same-origin server route, which validates the pending browser binding and fetches the signed result with the secret key. - SDK-managed browser sessions require the Web Locks API. Same-origin tabs serialize create and finalize mutations under a lock keyed by the resolved endpoint origin. Use manual mode and server-side coordination when Web Locks are unavailable or several origins share a parent-domain cookie. - Create verifications, issue credentials, and verify webhooks from trusted server code. - Use idempotency keys for mutation retries. - Verify webhook signatures before trusting event payloads. - Do not log PII, credentials, tokens, signatures, API keys, or wallet payloads. - Browser status is for UX. Webhooks and signed results are for backend trust decisions. ## AI docs - AI overview: https://docs.authbound.io/ai/overview - AI prompts: https://docs.authbound.io/ai/prompts - Rules for AI agents: https://docs.authbound.io/ai/rules - Machine-readable docs: https://docs.authbound.io/ai/llms ## Core docs - Introduction: https://docs.authbound.io/introduction - Quickstart: https://docs.authbound.io/quickstart - API keys: https://docs.authbound.io/get-api-keys - SDK overview: https://docs.authbound.io/sdks/overview - API reference: https://docs.authbound.io/api-reference/overview - Errors: https://docs.authbound.io/errors ## Verification - Overview: https://docs.authbound.io/verify/overview - Quickstart: https://docs.authbound.io/verify/quickstart - Next.js: https://docs.authbound.io/verify/nextjs - React: https://docs.authbound.io/verify/react - Vue: https://docs.authbound.io/verify/vue - Nuxt: https://docs.authbound.io/verify/nuxt - Express: https://docs.authbound.io/verify/express - Hono: https://docs.authbound.io/verify/hono - Webhooks and results: https://docs.authbound.io/verify/webhooks - Route protection: https://docs.authbound.io/verify/route-protection ## Credential issuance - Overview: https://docs.authbound.io/issue/overview - Quickstart: https://docs.authbound.io/issue/quickstart - Next.js: https://docs.authbound.io/issue/nextjs - Node.js: https://docs.authbound.io/issue/node - Credential definitions: https://docs.authbound.io/issue/credential-definitions - Credential offers: https://docs.authbound.io/issue/credential-offers - Deferred issuance: https://docs.authbound.io/issue/deferred-issuance ## SDK package map - `@authbound/nextjs`: Next.js App Router routes, middleware, manual station BFF route helpers, React components, and styles. - `@authbound/server`: Server API client, verification creation, issuance, webhooks, JWT helpers, Express, and Hono. - `@authbound/react`: React provider, hooks, QR code, deep link button, verification wall, and station runtime components. - `@authbound/vue`: Vue plugin, composables, verification UI, and station runtime components. - `@authbound/nuxt`: Nuxt module, verification and station BFF routes, middleware, and Vue composables. - `@authbound/core`: Low-level client, branded types, status helpers, link builders, and shared protocol types.