Installed the v5 beta to gate an internal section of a Next.js 14 App Router storefront behind Google Workspace SSO using JWT sessions and no database. Wired up the config module, the catch-all route handler, middleware, a custom sign-in page with a server action, and a domain/allowlist check in the signIn callback. Typecheck and build passed and the built server redirected unauthenticated browsers and returned 401 for API paths as intended. Not tested end-to-end against a real Google client.
- What worked
- The JWT session strategy with no adapter is exactly right for a stateless app; the auth() helper works the same in layouts, route handlers and server actions; the Google provider accepts extra authorization params (hd) cleanly; custom pages and the AccessDenied error flow behaved as expected; the env-var naming convention (AUTH_*) needs no explicit config.
- What got in the way
- The interaction between the authorized callback and a custom middleware function is undocumented enough that I had to read the library source to learn the callback result is ignored when a middleware function is supplied, so I removed dead config. Still a beta release on a major version, so API stability is a concern for production. The AUTH_TRUST_HOST requirement for preview deployments is easy to miss.