Open SWE implements a comprehensive authentication system that secures both client-side interactions and server-side operations. The authentication flow involves GitHub OAuth for user authentication, encrypted token handling, and multi-layered security for LangGraph server requests.
## GitHub OAuth Authentication
Open SWE uses GitHub OAuth for client-side authentication, providing secure access to user accounts and repository permissions.
### Authentication Flow
- **Unauthenticated users** are automatically redirected to GitHub OAuth login
- **Authenticated users** are redirected directly to the chat interface
- **Settings management** is available at `/settings` for updating GitHub authentication
All requests to the LangGraph server are authenticated through a sophisticated proxy system that ensures secure communication between the web interface and the agent backend.
### Proxy Route Architecture
The Next.js application includes a proxy route (`apps/web/src/app/api/[..._path]/route.ts`) that acts as an intermediary for all LangGraph server requests. This proxy uses the [`langgraph-nextjs-api-passthrough`](https://www.npmjs.com/package/langgraph-nextjs-api-passthrough) package to handle request forwarding with enhanced security.
For local development and scripted access, the LangGraph server also supports a simple bearer token scheme. When a request includes an `Authorization: Bearer <token>` header, this path is used and the rest of the auth flow is skipped.
### Setup (development)
- **Generate a token** (32+ bytes, URL-safe):
- OpenSSL: `openssl rand -hex 32`
- **Add to your `.env` for the LangGraph server**:
```bash
API_BEARER_TOKEN=<your-generated-token>
```
- For multiple/rotation: use comma-separated tokens
```bash
API_BEARER_TOKENS=<token1>,<token2>,<token3>
```
Restart the LangGraph server after updating environment variables.
### Usage
```typescript
import { Client } from "@langchain/langgraph-sdk";
- **Precedence**: If the `Authorization` header is present, bearer auth is used; otherwise the existing GitHub-based flow applies.
- **Rotation**: Add a new token to `API_BEARER_TOKENS`, deploy/restart, migrate clients, then remove old tokens and redeploy.
- **Scope**: All bearer tokens currently map to the same internal identity and permissions. If you need per-token identities/quotas, reach out to adjust the configuration.