Use @authbound/server when you want a small verification backend for Hono, workers, or edge-style Node runtimes.

Install

Environment

The browser SDK sends the selected policy ID to the server route when it creates a verification.

Server

server.ts
The app provides: The browser can use @authbound/react, @authbound/vue, or direct fetches against POST /api/authbound/verification. SDK-managed sessions require navigator.locks. Same-origin tabs serialize verification creation and session finalization under a lock keyed by the resolved endpoint origin. If you need to support a browser or embedded webview without Web Locks, set sessionMode: "manual" and create the trusted session on your server.
If your backend only creates verifications and does not expose /api/authbound/session, set sessionMode: "manual" in the browser SDK and persist trusted state with your own webhook or result flow.
Set allowedOrigins to your public app origin when the API runs behind a proxy or container URL. Set trustProxy: true only when Forwarded or X-Forwarded-* headers come from infrastructure you control.

Next

Add webhooks so your backend can persist verification outcomes without relying on the browser.