Member Junction
    Preparing search index...

    WorkOS (AuthKit) authentication provider — browser side.

    Wraps the vanilla-JS @workos-inc/authkit-js SDK behind MJAuthBase so the rest of MemberJunction never sees WorkOS-specific details. AuthKit issues a JWT access token (returned by getAccessToken()) that MJ sends to the GraphQL API as a Bearer token; the server validates it via @memberjunction/auth-providers' WorkOSProvider.

    Unlike the Auth0/MSAL/Okta providers, AuthKit is not an Angular library — there is no module to import. This provider creates the client itself in initialize using config supplied through the 'workosConfig' injection token.

    Email note: getUser() always returns the user's email for display here, but the access token only carries email if a WorkOS JWT Template adds it. MJ resolves users by email server-side, so configuring that template is required. See WORKOS.md in @memberjunction/auth-providers.

    Hierarchy (View Summary)

    Implements

    • OnDestroy
    Index

    Constructors

    Properties

    isAuthenticated$: BehaviorSubject<boolean> = ...
    type: "workos" = MJWorkOSProvider.PROVIDER_TYPE

    Provider type identifier Must be implemented by concrete providers

    userEmail$: BehaviorSubject<string> = ...
    userInfo$: BehaviorSubject<StandardUserInfo | null> = ...
    PROVIDER_TYPE: "workos" = 'workos'

    Accessors

    • get preservedLocalStorageKeys(): Set<string>

      localStorage keys that survive a logout (e.g. UI theme preference).

      Override this getter in a subclass to preserve additional keys specific to your provider or application.

      Returns Set<string>

    Methods

    • Get profile picture URL from auth provider

      Returns the user's profile picture URL if available from the auth provider. This abstracts away provider-specific logic:

      • Microsoft/MSAL: Fetches from Graph API
      • Auth0/Okta: Returns from user claims

      Returns Promise<string | null>

      Promise resolving to image URL or null if not available

      const pictureUrl = await this.authBase.getProfilePictureUrl();
      if (pictureUrl) {
      this.userAvatar = pictureUrl;
      }
    • Logout — clears all MJ client-side caches then delegates to the provider.

      Cache clearing happens universally regardless of auth provider so that a subsequent login as a different user never sees the previous user's data. Providers that need to clear additional caches should override logoutInternal() and call super.logoutInternal() if applicable.

      Returns Promise<void>

    • Refresh authentication token

      Attempts to obtain a fresh authentication token using the provider's refresh mechanism. If silent refresh fails due to session expiry, the provider will handle re-authentication automatically (which may involve redirecting to the auth provider's login page).

      Returns StandardAuthToken on success, or throws on complete failure.

      IMPORTANT: If the provider requires interactive re-authentication (redirect or popup), this method may never return. The app will reload after authentication completes and re-initialize with a fresh token.

      Returns Promise<StandardAuthToken>

      Promise resolving to StandardAuthToken or throws on failure

      const token = await this.authBase.refreshToken();
      return token.idToken; // Always succeeds or throws
    • Factory function to provide the Angular dependencies required by WorkOS. Stored as a static property so the factory can read it without instantiation.

      Parameters

      • environment: Record<string, unknown>

      Returns {
          provide: string;
          useValue: {
              apiHostname: string | undefined;
              clientId: string;
              devMode: boolean;
              redirectUri: string;
          };
      }[]