WorkOS AuthKit

WorkOS AuthKit is an optional authentication provider for your host app. The booking component does not require WorkOS or a particular sign-in system. You can allow guest bookings while requiring administrator access for setup and booking management.

Connect WorkOS to Convex

Follow the official Convex AuthKit integration guide for your framework and deployment. It covers the auth configuration and client provider that sends a verified identity to Convex. Use its existing-app path when adding authentication to an app you already have.

Complete authentication first: after sign-in, a host Convex function should receive a non-null identity from ctx.auth.getUserIdentity(). Configure development and production separately, including their redirect URLs and credentials.

If you need synchronized users or organization events, follow the optional WorkOS component setup linked from that guide. User synchronization alone does not grant booking administrator permissions.

Authorize Booking Operations

Once Convex validates the session, the booking integration uses the same host authorization checks as any other provider:

  1. Read the verified identity with ctx.auth.getUserIdentity().
  2. Resolve that identity's role and organization membership on the server.
  3. Check access to the target resource or booking before calling components.booking.*.

For a single organization, the authorization guide includes a complete administrator-allowlist example. For multiple organizations, verify membership against the organization stored on the target record. Do not accept a claimed role or organization from browser arguments as proof of permission.

The public booking gateway can stay anonymous if that matches your product. Protect booking details with management tokens or explicit ownership checks; being signed in does not grant access to someone else's booking.

Check the Integration

Test these cases through your actual host functions:

  • A signed-out visitor cannot administer resources or read private booking details.
  • A signed-in user without an administrator role also cannot administer resources.
  • An administrator of organization A cannot manage organization B.
  • An authorized administrator can manage the intended resources and bookings.

This site's demo uses guest administrator sessions for exploration. It is not a WorkOS integration example or an authorization policy to copy into production.