Detect NextAuth.js
NextAuth.js is a complete open-source authentication solution for Next.js applications.
Detection looks at cookies across 2 fingerprint rules among the site's public responses.
01
Websites using NextAuth.js
Loading website list…
02
Signal classes
PluginView evaluates public page signals in these classes when identifying NextAuth.js. Individual fingerprint rule bodies are proprietary and are not published.
- Cookies
03
Example public indicators for NextAuth.js
Illustrative indicators derived from public catalog metadata for NextAuth.js. A live scan may match additional proprietary rules beyond these examples.
- __Host-next-auth.csrf-token
- __Secure-next-auth.callback-url
04
What a detection means
- Establishes
- One or more public signals on the scanned page matched a known NextAuth.js signature (2 rules) at the time of the scan.
- Does not establish
- A sitewide install of NextAuth.js, an active vendor contract, exclusive use, or that NextAuth.js is still in place today.
05
How to check a site for NextAuth.js
- 1. Enter the website URL in the scan form — homepage, pricing, checkout, or login pages usually expose the strongest NextAuth.js signals.
- 2. PluginView reads only public responses (cookies) and scores them against the NextAuth.js signature set (2 rules).
- 3. Review the confidence score and text explanation for NextAuth.js on the results page.
06
FAQ: detecting NextAuth.js
- Can PluginView detect NextAuth.js without logging in?
- Yes. PluginView only reads publicly accessible responses when checking for NextAuth.js — typically cookies. It does not bypass authentication or paywalls.
- What category is NextAuth.js?
- NextAuth.js is classified under Authentication in the PluginView directory.
- How many fingerprint rules cover NextAuth.js?
- This reference currently tracks 2 fingerprint rules across cookies. Individual rule bodies are proprietary and are not published.
- What public signals suggest a site uses NextAuth.js?
- Illustrative public indicators for NextAuth.js include __Host-next-auth.csrf-token; __Secure-next-auth.callback-url. A live scan may match additional proprietary rules beyond these examples.