Composition Packages
Composition Packages#
Optional packages around Otok core. Use them directly (composition) or through otok.config.ts plugins where a package exposes a plugin entry point. Core stays free of auth, validation, database, billing, and OAuth dependencies.
| Package | Purpose |
|---|---|
@kamod-ch/otok-config |
Typed plugin API (defineConfig, definePlugin) |
@kamod-ch/otok-plugin-hello |
Minimal example plugin |
@kamod-ch/otok-auth |
Cookie sessions, CSRF, password hashing, route/API middleware, memory/Kysely session adapters |
@kamod-ch/otok-validation |
Standard Schema validation with defineAction, field errors, Zod/Valibot/ArkType adapters |
@kamod-ch/otok-flash |
Signed one-time flash cookies for PRG redirects and SSR toasts |
@kamod-ch/otok-stripe |
Checkout, Customer Portal, webhooks, BillingAdapter |
@kamod-ch/otok-mail |
Provider-based mail — SMTP, Resend, Mailpit, test provider |
@kamod-ch/otok-storage |
Object storage — local, S3, R2, MinIO |
@kamod-ch/otok-queue |
Typed jobs, retry, idempotency, cron, in-memory provider |
@kamod-ch/otok-oauth |
GitHub/Google OAuth login with signed state/PKCE cookies and OAuthAdapter |
See also Plugins, docs/extension-roadmap.md in the repository, and docs/adr/0006-plugin-system.md.
Typical wiring#
- Persist users/sessions in your app (or use
otok-authadapters). - Validate forms with
otok-validation. - Mount OAuth/Stripe handlers in
createOtokApp({ configure }). - Show one-shot messages after redirects with
otok-flash.
Apps keep schema and business rules. Packages provide protocol helpers and middleware only.