awesome_node_auth_flutter
A Flutter/Dart authentication client for the awesome-node-auth backend. Supports web (including WASM) via cookie + CSRF and native platforms via Bearer token.
What this package is like to depend on
Last release 3 months ago
20 May 2026
Too new to tell
only 2 release windows
Nearly every release is documented
notes for 7 of 7 stable releases
Nothing withdrawn
no release was ever pulled
3 months old
7 releases · first in 2026
7 releases in the last 12 months
see the full history below
Release timeline
7 releases · Apr 2026 to May 2026Releases
latest 7-
1.10.020 May 2026Release notes
Open source →What's Changed
- Align client auth events and retry exclusions with awesome-node-auth v1.10 by @Copilot in #18
- feat: v1.10 parity — cleanupSessions, OAuth helpers, docs alignment by @Copilot in #20
Full Changelog: v1.9.4...v1.10.0
Release notes
Open source →Added
cleanupSessions()— callsPOST /auth/sessions/cleanupto prune expired/invalid sessions from the server store (closes section 7 of the v1.10 parity audit).getOAuthUrl(String provider)— returns the full OAuth redirect URL for a given provider (e.g.'github','google'). Use this to initiate a redirect-based OAuth flow on web or open the URL in a webview/system browser on native.handleOAuthCallback()— picks up the authenticated session after a successful OAuth callback. Internally callscheckSession()and, on success, emits anAuthEventType.loggedInevent.
Changed
- Version bumped to 1.10.0 to align with
awesome-node-authbackend v1.10.
Notes
- Section 15 (UI widgets): this library is intentionally headless — no pre-built Flutter widgets are provided. Build your own UI against the
AuthClientAPI andauth.state.userStream. - Background token refresh on app resume: the library does not hook into the Flutter app lifecycle automatically. Add a call to
auth.checkSession()inside yourAppLifecycleListener.onResume(orWidgetsBindingObserver.didChangeAppLifecycleState) to restore the session after the app returns to the foreground. - Deep-link handling (native): wire your platform deep-link handler (Android
intent-filter/ iOSCFBundleURLTypes) to callauth.verifyMagicLink(token),auth.resetPassword(password, token), orauth.verifyEmail(token)as appropriate. For OAuth callbacks, callauth.handleOAuthCallback()once the redirect is complete.
-
1.9.429 Apr 2026Release notes
Open source →- Doc fix: clarify that
requestConflictLinkingEmailis a semantic alias ofrequestLinkingEmailwith identical payload, and that the backend infers the context from the presence or absence of a valid auth token in the request. TheisConflictfield is no longer sent in the request body, but if your backend version supports it, it is safely ignored if unused.
- Doc fix: clarify that
-
1.9.328 Apr 2026 -
1.9.228 Apr 2026Release notes
Open source →- Added example project with a simple Node.js backend and Flutter frontend demonstrating usage of the package.
-
1.9.128 Apr 2026 -
1.9.028 Apr 2026 -
1.8.528 Apr 2026Release notes
Open source →- Initial public release, aligned with awesome-node-auth backend v1.8.5.
- Web (WASM-compatible) cookie + CSRF authentication via HttpOnly cookies and
X-CSRF-Tokenheader, same-origin only. - Native (iOS, Android, Desktop) Bearer token authentication with pluggable
TokenStorage. - Automatic token refresh with concurrent-request deduplication.
- Full API coverage: login, register, logout, 2FA (TOTP / SMS / magic-link), email verification and change, password reset and change, account linking, session management, account deletion.
AuthState.userStreamreplays the current user to new subscribers immediately upon subscription.- WASM-compatible: no
dart:html, nodart:io, no native plugins.