Forge Auth
Centralized OAuth for the BlueForge ecosystem.
Deployed 2026-09-24· 85af7f4f· forge-auth
Categories
- Developer Tools
- authentication
- infrastructure
Tags
- #oauth
- #better-auth
- #mcp
- #nextjs
- #stripe
- #postgresql
About Forge Auth
Forge Auth replaces the per-app Supabase Auth wiring that every `-os` repo used to ship and is the canonical identity provider for the portfolio. It is a single Next.js 16 app at the repo root (no monorepo). It ships multi-tenant organizations (personal orgs, invitations, legacy-team migration, per-plan entitlements read by sibling apps), device-flow user-bound API keys, a key-resolve verifier (`@forge/auth-client`), Stripe checkout/portal/webhook with subscription table, and Federation Spec 1 service-account mint/resolve + admin CRUD.
Features
- One OAuth flow shared across every BlueForge app — Google, GitHub, and Gitea credentials live in Forge Auth and are federated to each consumer.
- MCP OAuth resource server for the `mcp.app.<product>.blueforge.studio` subdomain family, so any portfolio app can mount an MCP endpoint without re-wiring auth.
- Show all 7 features
Gold
$39/moComplete developer operations suite with mission control and agents.
- Everything in Silver, plus:
- forge-control (Mission Control): unified dashboard, team access, audit logs, agent orchestration
- forge-error-tracker Pro: 5M events/month, unlimited projects, 90-day retention, SSO, Slack + PagerDuty
- MailForge Pro: unlimited emails, multi-domain, webhooks, priority support
- forge-registry (early access): private package registry
- forge-secrets (early access): secret management
Try Forge Auth today
Forge Auth is running now. Open it, or join the list to hear about new features first.
Related products
Forge Control
Self-hosted BaaS control plane with portfolio-wide operator dashboard.
Self-hosted Backend-as-a-Service platform with per-project isolated Postgres databases, auto-generated REST APIs, AI-native storage with NL + graph search, auth, realtime, edge functions, and a sandboxed compute layer — running on infrastructure you own.