Realurls

Auth.js

Also known as authjs, next auth, next-auth, nextauthjs, nextauthjs/next-auth. GitHub nextauthjs.

Official domains: authjs.dev

Identity anchored by github-history:nextauthjs/next-auth(age=8y,contrib=905,stars=28365). Display name from github_org_display_name(self-declared).

authjs.dev verified primary · confidence 0.70 · verified 2026-09-05

1 independent anchor(s) + 3 independent corroboration(s): meets the verified threshold

EvidenceWhat it shows
A1 not counted GitHub verified this organization's domain (DNS-level check performed by GitHub)
org=nextauthjs org_verified=false blog=https://authjs.dev
source
A8 anchor Anchored repository's homepage points here, and this site links back
repo=nextauthjs/next-auth org=nextauthjs repo_anchored=true homepage=https://authjs.dev backlink=true stars=28365 age_days=3143 contributors=905
source
B2 corroboration Package registry homepage field
package=next-auth homepage=https://authjs.dev
source
A3 not counted Corporate registrar fingerprint (brand-protection registrar, long prepaid term, registry locks)
registrar=Tucows Domains Inc created=2022-10-06 expires=2026-10-06 remaining_days=31 locks=[]
source
A4 not counted TLS certificate carries the organization name (OV/EV)
subject_org= validation_type=DV issuer=Let's Encrypt san_count=2
TLS handshake authjs.dev:443
B5 corroboration Tranco top-1M ranking
rank=268063 source=top-1m list
source
B4 corroboration Wayback Machine history
first_snapshot=2022-12-14 history_days=1361
source
3 piece(s) of evidence not counted — why
  • A1: GitHub organization has not verified this domain (is_verified != true)
  • A3: registrar (Tucows Domains Inc) is not a brand-protection registrar
  • A4: DV certificate carries no organization name (most modern tech companies use DV; this is expected)
Reproduce this yourself
# A1 — GitHub verified this org's domain
curl -s https://api.github.com/orgs/nextauthjs | jq '{name, blog, is_verified}'

# A8 — anchored repo's homepage
curl -s https://api.github.com/repos/nextauthjs/next-auth | jq '{homepage, created_at, stargazers_count}'

# A3 — registrar / dates / locks
curl -sL https://rdap.org/domain/authjs.dev | jq '{status, events, registrar: [.entities[]|select(.roles[]=="registrar")|.vcardArray[1][1][3]]}'

# B5 — Tranco rank
curl -s https://tranco-list.eu/api/ranks/domain/authjs.dev

# B4 — first Wayback snapshot
curl -s "http://web.archive.org/cdx/search/cdx?url=authjs.dev&limit=1&output=json"

# Re-run the whole pipeline for this domain
git clone https://github.com/zhouchungong/realurls-registry && cd realurls-registry && pip install -e . && python -m src.verify authjs.dev

Think this is wrong? Open a dispute — the burden of proof is on us, and the record is downgraded while we check. Source record: YAML.