Source & license
Upstream license: MIT
License TL;DR
You can use it, change it, self-host it and sell it. Keep the original copyright and license notice with copies of the code. You don’t have to publish your changes. The authors don’t promise it will work.
Explain MIT in plain English →Summary of the main license. Separate packages and assets can have different terms.
Inspect repository ↗Read this project’s actual license ↗Repository owner
See the upstream repository for the original creator and contributors.
Maintain this project? Maintainer verification →Cloudflare hosting
Free tier eligible within limits
The reviewed Cloudflare deployment is eligible for Free-plan allowances for the stated small workload and feature scope. Usage limits, CPU, required account setup and separate services apply.
Hosting requirements
- Use a minimal OAuth/password or passkey configuration with email verification, password reset and email/SMS MFA disabled unless you configure a separate provider.
- Replace upstream D1 and KV IDs and deploy both server and optional admin-panel Worker in your own account.
- Keep dynamic traffic below 100,000 requests/day across the account, D1 within free row/storage quotas and KV writes/deletes/list operations below 1,000/day.
- Measure login/password hashing and token signing against the 10 ms Workers Free CPU limit; a paid plan may be needed.
- Cloudflare deployment excludes Node-only SAML SSO and SMTP; OAuth, mail and SMS provider charges are outside Cloudflare hosting.
- Workers Free dynamic requests are shared across this account (100,000/day), with 10 ms CPU per invocation; workload fit is conditional and has not been measured.
- D1 Free allowance: 5 million rows read/day, 100,000 rows written/day and 5 GB total storage; unindexed scans and history retention consume quota.
- KV Free allowance: 100,000 keys read/day and 1,000 each writes/deletes/list requests/day; this may constrain updates before Worker request limits.
Sources checked 01/10/2026
Repository snapshot: fb47fb9. Hosting eligibility reflects the deployment documentation and listed assumptions.
- auth0 ↗
uth.valuemelody.com/admin-panel-setup.html) - **React/Angular/Vue/Web SDK** to seamlessly integrate PKCE-based authentication into your frontend application. - react-sdk [[Package]](https://www.npmjs.com/package/@melody-auth/react) [[Doc]](https://auth.valuemelody.com/react-sdk.html) - angular-sdk [[Package]](https://www.npmjs.com/package/@melody-auth/angular) [[Doc]](https://auth.valuemelody.com/angular-sdk.html) - vue-sdk [[Package]](https://www.npmjs.com/package/@melody-auth/vue) [[Doc]](https://auth.valuemelody.com/vue-sdk.html) - web-sdk [[Package]](h
- clerk ↗
SMS Logs - Sign-in Logs ## Admin Panel & S2S REST API Features Supported - View Configurations - Manage Users - [User Invite](https://auth.valuemelody.com/user-invite.html) - [Impersonation](https://auth.valuemelody.com/impersonation.html) - Manage User Attributes - Manage Apps - [App Level MFA Config](https://auth.valuemelody.com/mfa-setup.html#_app-level-mfa-configuration) - [App Banner Config](https://auth.valuemelody.com/app-banners.html) - Manage Scopes - Manage Roles - Manage Organizations - Manage SAML SSO IDPs - [Manage Logs](https://auth.valuem
- workers ↗
name = "melody-auth-admin-panel" main = ".open-next/worker.js" compatibility_date = "2024-09-23" compatibility_flags = ["nodejs_compat"] assets = { directory = ".open-next/assets", binding = "ASSETS" } [observability.logs] enabled = true
- d1 ↗
id = "7d9be060a7bc48919251b37caa7e1fcd" # Replace with your own KV ID [[d1_databases]] binding = "DB" database_name = "melody-auth" database_id = "8dc67df2-771d-4e73-9c16-d04341b9740e" # Replace with your own D1 ID migrations_dir = "./migrations/sqlite" [assets] directory = "./dist/static" [observability] enabled = false # Set to true to enable Cloudflare workers logs. https://developers.cloudflare.com/workers/observability/logs/workers-logs/
- kv ↗
your privacy policy, and comply with all relevant legal requirements. [[kv_namespaces]] binding = "KV" id = "7d9be060a7bc48919251b37caa7e1fcd" # Replace with your own KV ID [[d1_databases]] binding = "DB" database_name = "melody-auth" database_id = "8dc67df2-771d-4e73-9c16-d04341b9740e" # Replace with your own D1 ID migrations_dir = "./migrations/sqlite" [assets] directory = "./dist/static" [observability] enabled = false # Set to true to enable Cloudflare workers logs. https://developers.cloudflare.com/workers/observability/logs/workers-logs/
- free-tier-eligible ↗
name = "melody-auth" compatibility_date = "2025-01-01" keep_vars = true # Cloudflare account id, required if your cloudflare account is sharing access with other cloudflare accounts # account_id = "" # Enable this if you want to use workers with postgres database # compatibility_flags = [ "nodejs_compat" ] [vars] # Information COMPANY_LOGO_URL="https://valuemelody.com/logo.svg" COMPANY_EMAIL_LOGO_URL="https://valuemelody.com/logo.jpg" # be aware that svg format
- free-tier-eligible ↗
ount Manager. | | Requests<sup>1, 2, 3, 4</sup> | Duration | CPU time | | --- | --- | --- | --- | | **Free** | 100,000 per day | No charge for duration | 10 milliseconds of CPU time per invocation | | **Standard** | 10 million included per month <br> +$0.30 per additional million | No charge or limit for duration | 30 million CPU milliseconds included per month<br> +$0.02 per additional million CPU milliseconds<br><br> Max of [5 minutes of CPU time](https://developers.cloudflare.com/workers/platform/limits/#account-plan-limits) per invocation (default: 30 second
- free-tier-eligible ↗
rs Paid](https://developers.cloudflare.com/workers/platform/pricing/#workers) | | --- | --- | --- | | Rows read | 5 million / day | First 25 billion / month included + $0.001 / million rows | | Rows written | 100,000 / day | First 50 million / month included + $1.00 / million rows | | Storage (per GB stored) | 5 GB (total) | First 5 GB included + $0.75 / GB-mo | Track your D1 usage To accurately track your usage, use the [meta object](https://developers.cloudflare.com/d1/worker-api/return-object/), [GraphQL Analytics API](https://developers.cloudflare.com/d1/obs
- free-tier-eligible ↗
flare.com/workers/platform/pricing/). | | Free plan<sup>1</sup> | Paid plan | | --- | --- | --- | | Keys read | 100,000 / day | 10 million/month, + $0.50/million | | Keys written | 1,000 / day | 1 million/month, + $5.00/million | | Keys deleted | 1,000 / day | 1 million/month, + $5.00/million | | List requests | 1,000 / day | 1 million/month, + $5.00/million | | Stored data | 1 GB | 1 GB, + $0.50/ GB-month | <sup>1</sup> The Workers Free plan includes limited Workers KV usage. All limits reset daily at 00:00 UTC. If you exceed any one of these limits, further o
- MIT ↗
MIT License Copyright (c) 2025 Value Melody Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this
- architecture ↗
name = "melody-auth-admin-panel" main = ".open-next/worker.js" compatibility_date = "2024-09-23" compatibility_flags = ["nodejs_compat"] assets = { directory = ".open-next/assets", binding = "ASSETS" } [observability.logs] enabled = true
- architecture ↗
name = "melody-auth" compatibility_date = "2025-01-01" keep_vars = true # Cloudflare account id, required if your cloudflare account is sharing access with other cloudflare accounts # account_id = "" # Enable this if you want to use workers with postgres database # compatibility_flags = [ "nodejs_compat" ] [vars] # Information COMPANY_LOGO_URL="https://valuemelody.com/logo.svg" COMPANY_EMAIL_LOGO_URL="https://valuemelody.com/logo.jpg" # be aware that svg format
Upstream screenshot · ValueMelody/melody-auth repository contributors ↗. Depicts the upstream project. We have not deployed and tested a fresh installation here.
What it can replace
Compare the workflow you need. These mappings describe overlap; full feature parity requires a separate comparison.
Editorial workflow alternative: OAuth login, PKCE integration, user/app management and roles; Cloudflare SAML and SMTP support are excluded.
See supporting source ↗Editorial workflow alternative: Self-hosted authentication server, framework SDKs and administrative user management; no managed-service or UI-component parity guarantee.
See supporting source ↗How it works
The shape of Melody Auth on Cloudflare, and how it stacks up against the rented tools it replaces.
Architecture
Diagram of deployment declarations at the reviewed commit. Each app has its own entrypoint; declared resources do not prove runtime calls. Follow file and line sources below.
View upstream source ↗Configuration and workflow sources
Reviewed commit fb47fb923e86. Files were read as data; upstream applications and CI jobs were not executed.
Deployment configuration · 2 files
Cloudflare Workers · compatibility 2024-09-23
melody-auth-admin-panel · default
Entrypoint: .open-next/worker.js
Static assets: .open-next/assets
ASSETS→ Static assets
Cloudflare Workers · compatibility 2025-01-01
melody-auth · default
Static assets: ./dist/static
DB→ D1KV→ KVStatic assets→ Static assets
Named environments are separate deployments. Bindings are shown only where declared. Configured routes are URL patterns, not verified application endpoints.
Runtime source · handlers, binding usage and workflow steps
Observed TypeScript/JavaScript declarations from Worker entrypoints and resolved relative imports. Calls and workflow steps may run conditionally; their listed order is not a proven end-to-end request flow. Router declarations may be mounted under a prefix or may not be registered. This shows code wiring, not a successful deployment or runtime test. Dynamic wiring, aliases and generated code may not resolve.
No direct runtime declarations resolved from this snapshot. Generated framework bundles or dynamic entrypoints need manual tracing.
Build and deployment pipeline · 12 GitHub Actions workflows
Repository CI declarations, separate from runtime request processing. Job dependencies and conditions are shown as written; long commands are shortened with an ellipsis; a workflow file does not prove a recent successful run.
Triggers: workflow_dispatch, push
Deploy · no job dependencies declared
- actions/checkout@v4
actions/checkout@v4 - Set up Node.js
actions/setup-node@v4 - Create .env file
echo "NEXT_PUBLIC_CLIENT_URI=${NEXT_PUBLIC_CLIENT_URI}" >> admin-panel/.env echo "NEXT_PUBLIC_SERVER_URI=${NEXT_PUBLIC_SERVER_URI}" >> admin-panel/.env echo "NEXT_PUBLIC_CLIENT_ID=${NEXT_PUBLIC_CLIENT_ID}" >> admin-panel/.env - Install dependencies
cd admin-panel && npm ci - Build package
cd admin-panel && npm run cf:build - Deploy
cloudflare/wrangler-action@v4Wrangler command: deploy
Triggers: workflow_dispatch
publish · no job dependencies declared
- Checkout repository
actions/checkout@v2 - amondnet/vercel-action@v25
amondnet/vercel-action@v25
Triggers: workflow_dispatch
publish · no job dependencies declared
- Checkout repository
actions/checkout@v2 - Set up Node.js
actions/setup-node@v3 - Install dependencies
cd sdks/angular-sdk && npm ci - Build angular-sdk package
cd sdks/angular-sdk && npm run build - Publish to npm
cd sdks/angular-sdk && npm publish
Triggers: workflow_dispatch, push
deploy-gh-pages · no job dependencies declared
- Checkout
actions/checkout@v3 - Setup Node.js
actions/setup-node@v3 - Install Deps
npm ci - Build Docs
npm run docs:build > docs/.vuepress/dist/.nojekyll - Deploy Docs
JamesIves/github-pages-deploy-action@v4
Triggers: workflow_dispatch
publish · no job dependencies declared
- Checkout repository
actions/checkout@v2 - Set up Node.js
actions/setup-node@v3 - Install dependencies
cd sdks/nextjs-sdk && npm ci - Build nextjs-sdk package
cd sdks/nextjs-sdk && npm run build - Publish to npm
cd sdks/nextjs-sdk && npm publish
Triggers: workflow_dispatch, pull_request
root · no job dependencies declared
- Checkout code
actions/checkout@v4 - Setup Node.js
actions/setup-node@v4 - Install root dependencies
npm ci - Build documentation
npm run docs:build
lint · no job dependencies declared
- Checkout code
actions/checkout@v4 - Setup Node.js
actions/setup-node@v4 - Install all dependencies
npm ci npm ci --prefix ./admin-panel npm ci --prefix ./server npm ci --prefix ./shared npm ci --prefix ./sdks/web-sdk npm ci --prefix ./sdks/react-sdk npm ci --prefix ./sdks/vue-sdk npm ci --prefix ./sdks/angular-sdk npm ci --prefix ./sdks/nextjs-sdk - Run linting
npm run lint:check
shared · no job dependencies declared
- Checkout code
actions/checkout@v4 - Setup Node.js
actions/setup-node@v4 - Install dependencies
npm ci - Check and build shared package
npm run type:check npm run test:check npm run build
web-sdk · no job dependencies declared
- Checkout code
actions/checkout@v4 - Setup Node.js
actions/setup-node@v4 - Install dependencies
npm ci - Check and build web SDK
npm run type:check npm run test:check npm run build
react-sdk · no job dependencies declared
- Checkout code
actions/checkout@v4 - Setup Node.js
actions/setup-node@v4 - Install dependencies
npm ci - Check and build React SDK
npm run type:check npm run test:check npm run build
vue-sdk · no job dependencies declared
- Checkout code
actions/checkout@v4 - Setup Node.js
actions/setup-node@v4 - Install dependencies
npm ci - Check and build Vue SDK
npm run type:check npm run test:check npm run build
angular-sdk · no job dependencies declared
- Checkout code
actions/checkout@v4 - Setup Node.js
actions/setup-node@v4 - Install dependencies
npm ci - Check and build Angular SDK
npm run type:check npm run test:check npm run build
nextjs-sdk · no job dependencies declared
- Checkout code
actions/checkout@v4 - Setup Node.js
actions/setup-node@v4 - Install dependencies
npm ci - Check and build Next.js SDK
npm run type:check npm run test:check npm run build
server-cf · no job dependencies declared
- Checkout code
actions/checkout@v4 - Setup Node.js
actions/setup-node@v4 - Install dependencies
npm ci - Check and test server (CF)
npm run type:check npm run node:secret:generate npm run node:saml:secret:generate npm run test:check:cf npm run node:secret:generate npm run test:check:cf-key-rotate
server-node · no job dependencies declared
- Checkout code
actions/checkout@v4 - Setup Node.js
actions/setup-node@v4 - Install dependencies
npm ci - Test server (Node shard ${{ matrix.shard }}/2)
npm run node:secret:generate npm run node:saml:secret:generate npm run test:check:node -- --shard=${{ matrix.shard }}/2
server-node-key-rotate · no job dependencies declared
- Checkout code
actions/checkout@v4 - Setup Node.js
actions/setup-node@v4 - Install dependencies
npm ci - Test server (Node - key rotate) and build
npm run node:secret:generate npm run node:saml:secret:generate npm run node:secret:generate npm run test:check:node-key-rotate npm run node:build
admin-panel · no job dependencies declared
- Checkout code
actions/checkout@v4 - Setup Node.js
actions/setup-node@v4 - Install dependencies
npm ci - Check and test admin panel
npm run type:check npm run test:check - Build admin panel
npm run build npm run cf:build
Triggers: workflow_dispatch
publish · no job dependencies declared
- Checkout repository
actions/checkout@v2 - Set up Node.js
actions/setup-node@v3 - Install dependencies
cd sdks/react-sdk && npm ci - Build react-sdk package
cd sdks/react-sdk && npm run build - Publish to npm
cd sdks/react-sdk && npm publish
Triggers: workflow_dispatch, push
Deploy · no job dependencies declared
- actions/checkout@v4
actions/checkout@v4 - Set up Node.js
actions/setup-node@v4 - Install dependencies
cd server && npm ci - Build Server View
cd server && npm run build - Run Migration
cloudflare/wrangler-action@v4Wrangler command: d1 migrations apply melody-auth --remote deploy --minify src/index.tsx
Triggers: workflow_dispatch
Run tests and collect coverage · no job dependencies declared
- Checkout
actions/checkout@v4 - Set up Node
actions/setup-node@v4 - Install dependencies
cd ./server && npm ci - Build
cd ./server && npm run build - Generate secret
cd ./server && npm run node:secret:generate - Generate saml secret
cd ./server && npm run node:saml:secret:generate - Run tests
cd ./server && npm run test:coverage - Upload results to Codecov
codecov/codecov-action@v5
Triggers: workflow_dispatch
publish · no job dependencies declared
- Checkout repository
actions/checkout@v2 - Set up Node.js
actions/setup-node@v3 - Install dependencies
cd shared && npm ci - Build shared package
cd shared && npm run build - Publish to npm
cd shared && npm publish
Triggers: workflow_dispatch
publish · no job dependencies declared
- Checkout repository
actions/checkout@v2 - Set up Node.js
actions/setup-node@v3 - Install dependencies
cd sdks/vue-sdk && npm ci - Build vue-sdk package
cd sdks/vue-sdk && npm run build - Publish to npm
cd sdks/vue-sdk && npm publish
Triggers: workflow_dispatch
publish · no job dependencies declared
- Checkout repository
actions/checkout@v2 - Set up Node.js
actions/setup-node@v3 - Install dependencies
cd sdks/web-sdk && npm ci - Build web-sdk package
cd sdks/web-sdk && npm run build - Publish to npm
cd sdks/web-sdk && npm publish
build: next build
build: rm -rf ./dist && mkdir ./dist && ng-packagr -p ./ng-package.json
build: rollup -c
build: rm -rf ./dist && mkdir ./dist && rollup -c --bundleConfigAsCjs
build: rm -rf ./dist && mkdir ./dist && rollup -c --bundleConfigAsCjs
build: rm -rf ./dist && mkdir ./dist && rollup -c --bundleConfigAsCjs
build: vite build --mode client && vite build
build: rm -rf ./dist && tsc --build && cp src/index.d.ts dist/index.d.ts
Repository README
View original on GitHub ↗Full upstream document by @ValueMelody · README.md · snapshot fb47fb9
Melody Auth
Melody Auth is a user-friendly, robust solution for implementing and hosting your own OAuth and authentication system.
- Deploy to Cloudflare using Workers, D1, and KV in just minutes — minimizing infrastructure and DevOps overhead.
- Self-Host with Node.js, Redis, and PostgreSQL — giving you full control over your data and infrastructure.
Disclaimer All French translations provided in this project have been generated by AI. Please review them carefully for accuracy before use.
What's included?
- OAuth & Authentication Server [Setup] [Config]
- Server-to-Server REST API for backend integrations [Setup] [Swagger]
- Admin Panel for managing resources (also serves as a full-stack implementation example) [Setup]
- React/Angular/Vue/Web SDK to seamlessly integrate PKCE-based authentication into your frontend application.
- Embedded Auth API for embedding authentication flows directly within your application. [Setup] [Swagger]
Auth Server Features Supported
- OAuth 2.0:
- Authorize
- Token Exchange
- Refresh Token Revoke
- App Consent
- App Scopes
- User Info Retrieval
- OpenID Configuration
- Authorization:
- Sign-In
- Passwordless Sign-In
- Sign-Up
- Sign-Out
- Email Verification
- Password Reset
- Role-Based Access Control
- User Attribute
- Account Linking
- Localization
- External Identity Providers:
- Social Sign-In
- Google Sign-In
- Facebook Sign-In
- GitHub Sign-In
- Discord Sign-In
- Apple Sign-In
- OIDC Auth Provider Sign-In
- SAML SSO Sign-In (Node.js environment only)
- Social Sign-In
- Multi-Factor Authentication
- Email MFA
- OTP MFA
- SMS MFA
- MFA Self Enrollment
- Passkey Enrollment
- Recovery Code
- Remember Device for 30 days
- Policy
- sign_in_or_sign_up
- update_info
- change_password
- change_email
- reset_mfa
- manage_passkey
- manage_recovery_code
- saml_sso_[idp_name]
- oidc_sso_[provider_name]
- Organization:
- Mailer Option
- SendGrid
- Mailgun
- Brevo
- Resend
- Postmark
- SMTP (Node.js environment only)
- SMS Option
- Twilio
- JWT Authentication
- Brute-force Protection:
- Log in attempts
- Password reset attempts
- OTP MFA attempts
- SMS MFA attempts
- Email MFA attempts
- Change Email attempts
- Email Verification attempts
- Logging:
- Logger Level
- Email Logs
- SMS Logs
- Sign-in Logs
Admin Panel & S2S REST API Features Supported
- View Configurations
- Manage Users
- Manage User Attributes
- Manage Apps
- Manage Scopes
- Manage Roles
- Manage Organizations
- Manage SAML SSO IDPs
- Manage Logs
- Admin Panel Access Control
Demo & Examples
- Demo Site
- Vite React Example
- Angular Example
- Vite Vue Example
- Next.js Full stack implementation Example
- Next.js Auth.js Example
- React Native Example
- Vanilla JavaScript Example
- Embedded Auth API Example
Screenshots
Authorization Screenshots
Admin Panel Screenshots
License
This project is licensed under the MIT License. See the LICENSE file for details.
Frequently asked about Melody Auth
What is Melody Auth?+
Melody Auth is a self-hosted Auth0/Clerk alternative built on the Cloudflare developer platform. Self-hosted OAuth and authentication with a Cloudflare server and admin panel.
What does Melody Auth replace?+
Melody Auth is listed as an alternative to Auth0, Clerk. Compare the features and tradeoffs before migrating.
What Cloudflare primitives does Melody Auth use?+
Melody Auth is built on D1, KV, Workers.
How much does Melody Auth cost to run?+
The reviewed Cloudflare deployment is eligible for Free-plan allowances for the stated small workload and feature scope. Usage limits, CPU, required account setup and separate services apply. Use a minimal OAuth/password or passkey configuration with email verification, password reset and email/SMS MFA disabled unless you configure a separate provider. Replace upstream D1 and KV IDs and deploy both server and optional admin-panel Worker in your own account. Keep dynamic traffic below 100,000 requests/day across the account, D1 within free row/storage quotas and KV writes/deletes/list operations below 1,000/day. Measure login/password hashing and token signing against the 10 ms Workers Free CPU limit; a paid plan may be needed. Cloudflare deployment excludes Node-only SAML SSO and SMTP; OAuth, mail and SMS provider charges are outside Cloudflare hosting. Workers Free dynamic requests are shared across this account (100,000/day), with 10 ms CPU per invocation; workload fit is conditional and has not been measured. D1 Free allowance: 5 million rows read/day, 100,000 rows written/day and 5 GB total storage; unindexed scans and history retention consume quota. KV Free allowance: 100,000 keys read/day and 1,000 each writes/deletes/list requests/day; this may constrain updates before Worker request limits. Check current Cloudflare pricing before deploying.
Is Melody Auth open source?+
The upstream repository declares the MIT license. Read its terms at https://raw.githubusercontent.com/ValueMelody/melody-auth/fb47fb923e86063d5442dc1fc4c15e5a407f7c2e/LICENSE. Source code and contributor credit are available at https://github.com/ValueMelody/melody-auth.



Discussion · 0
sign in to comment →