Open SWE implements a comprehensive authentication system that secures both client-side interactions and server-side operations. The authentication flow involves GitHub OAuth for user authentication, encrypted token handling, and multi-layered security for LangGraph server requests.
## GitHub OAuth Authentication
Open SWE uses GitHub OAuth for client-side authentication, providing secure access to user accounts and repository permissions.
### Authentication Flow
- **Unauthenticated users** are automatically redirected to GitHub OAuth login
- **Authenticated users** are redirected directly to the chat interface
- **Settings management** is available at `/settings` for updating GitHub authentication
<Note>
GitHub OAuth provides the foundation for all user interactions, enabling Open SWE to access repositories and perform actions on behalf of authenticated users.
</Note>
## LangGraph Server Authentication
All requests to the LangGraph server are authenticated through a sophisticated proxy system that ensures secure communication between the web interface and the agent backend.
### Proxy Route Architecture
The Next.js application includes a proxy route (`apps/web/src/app/api/[..._path]/route.ts`) that acts as an intermediary for all LangGraph server requests. This proxy uses the [`langgraph-nextjs-api-passthrough`](https://www.npmjs.com/package/langgraph-nextjs-api-passthrough) package to handle request forwarding with enhanced security.
<Tip>
The proxy route ensures that sensitive authentication tokens never reach the client directly, maintaining security while enabling seamless communication with the LangGraph server.
</Tip>
### Header Injection System
The proxy route automatically injects the following encrypted headers into each request:
- **`x-github-installation-name`** - Installation name (username or organization name)
<Note>
All headers are prefixed with `x-` to ensure they're included in LangGraph run configurations, making them accessible during execution while maintaining security through encryption.
</Note>
### Token Encryption
Open SWE implements AES-256-GCM encryption for all GitHub tokens to prevent exposure in:
- LangSmith trace metadata
- Run configurations
- Potential unauthorized access scenarios
The encryption process uses the `GITHUB_TOKEN_ENCRYPTION_KEY` environment variable and includes:
- **Initialization Vector (IV)** for unique encryption per token
- **Authentication Tag** for data integrity verification
- **Base64 encoding** for safe transport
<Tip>
The same encryption key must be configured in both the web application and LangGraph agent for proper token decryption.
</Tip>
## Authentication Middleware
The LangGraph server implements comprehensive authentication middleware (`apps/open-swe/src/security/auth.ts`) that validates all incoming requests.
### Webhook Authentication
The middleware first checks for GitHub webhook requests by detecting the `X-Hub-Signature-256` header:
1. **Signature verification** using the configured webhook secret
2. **Automatic authorization** for valid webhook signatures
3. **Separate user verification** in subsequent run creation requests
<Note>
Webhook authentication is handled separately from user authentication to enable automated GitHub issue processing while maintaining security.
</Note>
### Standard Request Authentication
For non-webhook requests, the middleware validates: