Convex component: convex-deploy-auth
  • TypeScript 100%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-11 18:46:07 -04:00
dist docs: explain deploy-auth as a Node-to-Convex write gate 2026-09-11 18:33:09 -04:00
src docs: explain deploy-auth as a Node-to-Convex write gate 2026-09-11 18:33:09 -04:00
.gitignore chore: publish-ready Convex component package metadata 2026-07-05 17:42:18 -04:00
LICENSE chore: publish-ready Convex component package metadata 2026-07-05 17:42:18 -04:00
package-lock.json chore: publish-ready Convex component package metadata 2026-07-05 17:42:18 -04:00
package.json chore: point package homepage at the public GitHub mirror 2026-09-11 18:46:07 -04:00
README.md docs: explain deploy-auth as a Node-to-Convex write gate 2026-09-11 18:33:09 -04:00
tsconfig.json chore: publish-ready Convex component package metadata 2026-07-05 17:42:18 -04:00
vitest.config.ts docs: explain deploy-auth as a Node-to-Convex write gate 2026-09-11 18:33:09 -04:00

convex-deploy-auth

Small helpers for server-to-Convex writes. This is not a Convex component and does not own tables.

Convex component functions have no ctx.auth. If a Node process (or any non-Convex caller) invokes mutations over HTTP, you need your own gate. This package is that gate: a shared secret stored as a Convex deployment env var, passed as deploySecret on write args.

Apps that only call components from other Convex functions should not use this. Put auth in those app wrappers instead (ctx.auth, API keys, etc.).

Install

npm install convex-deploy-auth

On the Convex deployment:

CONVEX_DEPLOY_SECRET=a-long-random-string

In a mutation:

import { assertDeploySecret, deploySecretArg } from "convex-deploy-auth";

export const save = mutation({
  args: { data: v.any(), ...deploySecretArg },
  handler: async (ctx, args) => {
    assertDeploySecret(args.deploySecret);
    // ...
  },
});

If CONVEX_DEPLOY_SECRET is unset, assertDeploySecret is a no-op so local dev works without extra config.

tenantIdArg / resolveTenantId are optional multi-tenant string helpers (tenantId defaults to "default").