@authbound/nextjs when you want the shortest path from a Next.js app to a wallet verification screen.
Install
Environment
.env.local
pol_kyc_basic_eudi_v1, or copy one of your own from the Authbound dashboard. The browser SDK sends this policy ID to the server route when it creates a verification. See SDKs and frameworks for the complete preset list.
Server route
Createapp/api/authbound/[...authbound]/route.ts.
app/api/authbound/[...authbound]/route.ts
/api/authbound: verification creation, same-origin session finalization, status, webhook callback, and sign out. It calls https://api.authbound.io/v1/verifications from your server and sends your secret key as X-Authbound-Key. During session finalization it checks the pending browser binding and fetches the signed verification result with your secret key before setting the SDK cookie.
Provider
Createapp/authbound-provider.tsx.
app/authbound-provider.tsx
app/layout.tsx
Verification page
app/verify/page.tsx
/verify, start the flow, and scan the QR code with a compatible wallet.
Session mode
By default,AuthboundProvider uses sessionMode="sdk". After verified status, the browser calls POST /api/authbound/session; the route checks the pending browser binding, fetches the signed result with your secret key, and sets the SDK session cookie.
SDK-managed sessions require navigator.locks. Same-origin tabs serialize verification creation and session finalization under a lock keyed by the resolved endpoint origin. If you need to support a browser or embedded webview without Web Locks, use sessionMode="manual" and create the trusted session on your server.
If your backend only creates verifications and does not expose /api/authbound/session, set sessionMode="manual" on AuthboundProvider and persist trusted state with your own webhook or signed-result flow.
Station BFF routes
Unlike@authbound/nuxt, the Next.js package does not auto-register station routes. Add one App Router route file per endpoint when you build station entry or operator flows with @authbound/react station components.
app/api/authbound/stations/[stationId]/entry/route.ts
app/api/authbound/stations/[stationId]/display/route.ts
app/api/authbound/stations/[stationId]/display/events/sse/route.ts
app/api/authbound/stations/[stationId]/operator/route.ts
app/api/authbound/stations/[stationId]/operator/events/sse/route.ts
app/api/authbound/stations/[stationId]/verifications/[verificationId]/disclosure/route.ts
gatewayUrl and otherwise uses AUTHBOUND_API_URL or https://api.authbound.io.
EUDI provider options
For EUDI wallet flows, configureproviderOptions on a server-owned verification route. The browser may send a provider preference such as "eudi", but SDK handlers ignore client-supplied providerOptions. The catch-all createAuthboundHandlers route does not accept providerOptions.
Use createVerificationRoute when you want EUDI settings on the verification creation endpoint:
app/api/authbound/verification/route.ts
AuthboundProvider at that route with verificationEndpoint="/api/authbound/verification", or pass providerOptions to a server-side createVerification call.
Production checklist
- Keep
AUTHBOUND_SECRET_KEYserver-only. - Use
NEXT_PUBLIC_AUTHBOUND_PKas the browser-safe publishable key forAuthboundProviderand SDK server handlers. - Use a long random
AUTHBOUND_SESSION_SECRET; the SDK uses it for HttpOnly session cookies. - Set
allowedOriginsto your public app origin when the route runs behind a proxy or container URL. - Set
trustProxy: trueonly whenForwardedorX-Forwarded-*headers are supplied by infrastructure you control. - Add webhooks or signed result lookups for backend reconciliation.
- Store the final verified state in your own user or session model when the decision must outlive the browser flow.
- Fetch signed results on the server for high-trust decisions.
Route protection
Protect pages after verification completes.
Webhooks
Sync results to your backend.