Open Source Friday with Tesseral - Auth Infra for SaaS Apps

GitHubAbout 6 min readAug 2, 2025Watch original
THE SUMMARYAI-generated

Key Concepts

  • GitHub Copilot: An AI pair programmer that assists developers with code completion, bug fixing, and more.
  • Model Context Protocol (MCP): A protocol that allows Copilot to access external tools and data sources, such as Notion, to enhance its capabilities.
  • GitHub Issues: A system for tracking tasks, bugs, and feature requests within a GitHub repository.
  • Pull Request: A request to merge code changes from one branch into another.
  • React: A JavaScript library for building user interfaces.
  • Open Source: Software with source code that is freely available and can be modified and distributed.
  • B2B SaaS: Business-to-business software as a service.
  • Authentication: The process of verifying the identity of a user or device.
  • Authorization: The process of granting access to specific resources or functionalities based on the user's identity and permissions.
  • SAML SSO, Enterprise OIDC SSO: Protocols that big companies use in order to log into software.
  • SKIM Provisioning: A way for customer companies to like offline like bulk create and delete users when they sort of hire people and let people go or have them like change departments.
  • Passkeys: A password replacement that is more secure.
  • Authenticator Apps: An application that provides multi-factor authentication.

GitHub Copilot and Coding Agent

  • GitHub Copilot can now create GitHub issues directly from Copilot Chat in github.com.
  • Example: The product team behind Copilot Airways wants to create a GitHub issue for user reviews on the travel guide, which is documented in Notion.
  • Copilot can be assigned issues directly from Copilot Chat.
  • The Model Context Protocol (MCP) allows Copilot to access external tools like Notion.
  • MCP servers and associated tools are configured during Copilot setup in GitHub Actions.
  • Copilot can summarize changes made in a pull request to provide context for review.
  • The Copilot coding agent can read files, make code edits, and run builds and tests.

Building a Front-End Project with GitHub Copilot

  • GitHub Copilot can be used to build a React client.
  • Copilot Chat can provide detailed descriptions of the code in a directory.
  • Copilot allows editing multiple files at once.
  • Developers can provide additional suggestions to Copilot during the development process.
  • Example: Building a fully functional MVP of an application in a short time with GitHub Copilot.
  • MCP allows the agent to create a repository, which wasn't possible before.
  • The mcp.json file configures the MCP servers and tools available for a project.
  • MCP servers can run npm packages, pip packages, Docker images, or local commands.
  • Authentication with GitHub requires a personal access token, which should not be stored in source code.
  • Copilot can push multiple files to a GitHub repo in a single commit.

Tesserol: Open-Source Infrastructure for SaaS Applications

  • Tesserol is an open-source user and authentication management software for B2B SaaS applications.
  • It solves the pain of building user management and authentication from scratch for businesses selling software to other businesses.
  • Tesserol is different from Auth0, Clerk, or Supabase Auth because it is entirely open source and specifically focused on B2B software.
  • By being opinionated and focused on B2B, Tesserol makes it easy for engineers to implement authentication quickly.
  • Tesserol is a good fit for applications where the customer is a company, not an individual.
  • Example: Proctor and Gamble using the Facebook ads platform vs. an individual user on Facebook.
  • Tesserol provides a test roll provider component that handles login, user settings, and logout.
  • The test roll provider is hooked up to the testal console, where most of the magic happens.
  • The login page is powered on a domain called the vault, which is run by Tesserol.
  • Users can change the branding of the application and add login methods in the console.
  • Big companies want to opt into each authentication method individually.
  • Role-based access control is built-in, allowing administrators to assign permissions to users.
  • API keys can be created and scoped to specific permissions.
  • An audit log tracks all actions performed in the console.
  • Tesserol provides the "whole enchilada" of user management and authentication without requiring developers to implement it themselves.

Technical Components of Tesserol

  • Everything is done on a domain that provides a UI for managing settings and APIs for the front end.
  • The vault domain provides APIs for knowing the current user and logging out.
  • Everything that can be done from the console has an API.
  • Tesserol is self-hostable, with the core storage being a PostgreSQL database.
  • Key management is handled by a key management service (KMS) like Amazon KMS or Google KMS.
  • Tesserol can be bundled and added to the set of things given to customers to deploy inside their cloud.

Customization and Onboarding

  • Developers can build their own UI for Tesserol.
  • Tesserol provides APIs to get all the users and other data.
  • SAML SSO, Enterprise OIDC SSO, and skim provisioning are built-in.
  • The onboarding experience involves signing up for Tesserol, creating a new project, and turning on/off login methods.
  • The front end can be set up in a morning.
  • The backend can enforce authentication with one line of code.

SDKs and CLI Tools

  • Tesserol has SDKs in React, Node, Express, Flask, Fast API, Django, Axom, Rust, Nex.js, and JS.
  • SDKs are programmatically generated using Fern.
  • A Java SDK is in the works.
  • There are no CLI tools, but you can curl against all of the APIs.

Security and Compliance

  • When self-hosting, Tesserol does not "phone home."
  • If an attacker has read-only access to the database, they would only know how many customers you have.
  • API keys are 256-bit, making them difficult to brute force.
  • Access tokens are JSON web tokens using ECDSA.
  • Tesserol has a security program with pentesters and security test.com for responsible disclosure.
  • Tesserol enforces authentication, and code is not called if the request cannot be authenticated.
  • The obvious way to do something is the secure way to do something.
  • Emails are always verified.

User Impersonation

  • User impersonation can be done from the console.
  • Clicking the impersonate user button logs you in as that user for a temporary session (5 minutes).
  • The system generates an access token that is the same as being logged in.
  • The code provides access to whether the user is impersonated.
  • You can know when the current session will expire.

Passkeys and Authenticator Apps

  • Tesserol supports passkeys and authenticator apps.
  • They can be turned on in the authentication settings for the project.

Future of Tesserol

  • Tesserol will remain developer tooling and a platform for developers.
  • It will stay focused on making it easy to do authentication for B2B software.
  • It will remain open source.

Community Contributions

  • People have gained confidence from being able to view the code.
  • One of the first PRs was for adding support for the Department of Defense version of Microsoft login.

Contributing to Tesserol

  • Tesserol will work on making good first contributor issues.
  • Use GitHub discussions to ask questions and provide feedback.
  • Contribute to the documentation.

Conclusion

The video highlights the capabilities of GitHub Copilot and introduces Tesserol as an open-source solution for simplifying user management and authentication in B2B SaaS applications. Copilot, enhanced by MCP, streamlines development workflows, while Tesserol offers a comprehensive, customizable, and secure platform for managing user access and permissions in enterprise environments. The emphasis on open-source principles, ease of integration, and robust security practices positions Tesserol as a valuable tool for developers building B2B applications.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.