Use @authbound/nextjs when you want the shortest path from a Next.js app to a wallet verification screen.

Install

Environment

.env.local
Use a preset policy ID such as pol_kyc_basic_eudi_v1, or copy one of your own from the Authbound dashboard. The browser SDK sends this policy ID to the server route when it creates a verification. See SDKs and frameworks for the complete preset list.

Server route

Create app/api/authbound/[...authbound]/route.ts.
app/api/authbound/[...authbound]/route.ts
The handler exposes the SDK routes under /api/authbound: verification creation, same-origin session finalization, status, webhook callback, and sign out. It calls https://api.authbound.io/v1/verifications from your server and sends your secret key as X-Authbound-Key. During session finalization it checks the pending browser binding and fetches the signed verification result with your secret key before setting the SDK cookie.

Provider

Create app/authbound-provider.tsx.
app/authbound-provider.tsx
Wrap your app.
app/layout.tsx

Verification page

app/verify/page.tsx
Open /verify, start the flow, and scan the QR code with a compatible wallet.

Session mode

By default, AuthboundProvider uses sessionMode="sdk". After verified status, the browser calls POST /api/authbound/session; the route checks the pending browser binding, fetches the signed result with your secret key, and sets the SDK session cookie. SDK-managed sessions require navigator.locks. Same-origin tabs serialize verification creation and session finalization under a lock keyed by the resolved endpoint origin. If you need to support a browser or embedded webview without Web Locks, use sessionMode="manual" and create the trusted session on your server. If your backend only creates verifications and does not expose /api/authbound/session, set sessionMode="manual" on AuthboundProvider and persist trusted state with your own webhook or signed-result flow.

Station BFF routes

Unlike @authbound/nuxt, the Next.js package does not auto-register station routes. Add one App Router route file per endpoint when you build station entry or operator flows with @authbound/react station components.
app/api/authbound/stations/[stationId]/entry/route.ts
app/api/authbound/stations/[stationId]/display/route.ts
app/api/authbound/stations/[stationId]/display/events/sse/route.ts
app/api/authbound/stations/[stationId]/operator/route.ts
app/api/authbound/stations/[stationId]/operator/events/sse/route.ts
app/api/authbound/stations/[stationId]/verifications/[verificationId]/disclosure/route.ts
These routes proxy tokenized station requests to Gateway without attaching your project secret key. Each factory accepts gatewayUrl and otherwise uses AUTHBOUND_API_URL or https://api.authbound.io.

EUDI provider options

For EUDI wallet flows, configure providerOptions on a server-owned verification route. The browser may send a provider preference such as "eudi", but SDK handlers ignore client-supplied providerOptions. The catch-all createAuthboundHandlers route does not accept providerOptions. Use createVerificationRoute when you want EUDI settings on the verification creation endpoint:
app/api/authbound/verification/route.ts
Point AuthboundProvider at that route with verificationEndpoint="/api/authbound/verification", or pass providerOptions to a server-side createVerification call.

Production checklist

  • Keep AUTHBOUND_SECRET_KEY server-only.
  • Use NEXT_PUBLIC_AUTHBOUND_PK as the browser-safe publishable key for AuthboundProvider and SDK server handlers.
  • Use a long random AUTHBOUND_SESSION_SECRET; the SDK uses it for HttpOnly session cookies.
  • Set allowedOrigins to your public app origin when the route runs behind a proxy or container URL.
  • Set trustProxy: true only when Forwarded or X-Forwarded-* headers are supplied by infrastructure you control.
  • Add webhooks or signed result lookups for backend reconciliation.
  • Store the final verified state in your own user or session model when the decision must outlive the browser flow.
  • Fetch signed results on the server for high-trust decisions.

Route protection

Protect pages after verification completes.

Webhooks

Sync results to your backend.