Get started
Install
Homebrew
brew install --cask milon/bohurupee/bohurupee
bohurupee init
bohurupee
That taps milon/homebrew-bohurupee. macOS and Linux are both in the cask.
Release binary
Download from the
latest release. Archives
are named bohurupee_<version>_<os>_<arch>.tar.gz (zip on Windows).
VERSION=0.2.1 # or newer — check the releases page
curl -fsSL -o bohurupee.tar.gz \
"https://github.com/milon/bohurupee/releases/download/v${VERSION}/bohurupee_${VERSION}_darwin_arm64.tar.gz"
tar -xzf bohurupee.tar.gz
./bohurupee init
./bohurupee
Verify against checksums.txt from the same release before running a binary
you downloaded.
Docker
The image is the static binary on scratch. Inside the container it listens on
0.0.0.0 so Docker can publish the port. Publish on loopback only:
docker run --rm -p 127.0.0.1:4190:4190 ghcr.io/milon/bohurupee:v0.2.1
Mount your config at /bohurupee.yaml (or pass --config /
BOHURUPEE_CONFIG). The full YAML loads; a loopback bind in the file is
upgraded to 0.0.0.0 so the published port works:
docker run --rm \
-p 127.0.0.1:4190:4190 \
-v "$PWD/bohurupee.yaml:/bohurupee.yaml:ro" \
ghcr.io/milon/bohurupee:v0.2.1
docker run --rm -v "$PWD:/work" -w /work ghcr.io/milon/bohurupee:v0.2.1 init
From source
Requires Go 1.25+. See Contributing.
git clone https://github.com/milon/bohurupee.git
cd bohurupee
go build -o ./bohurupee ./cmd/bohurupee
./bohurupee init
./bohurupee
First sign-in
- Open http://127.0.0.1:4190 — the dashboard lists personas and copy-paste URLs.
- Start an authorize request (example):
http://127.0.0.1:4190/google/authorize?client_id=dev-client&redirect_uri=http%3A%2F%2F127.0.0.1%3A9999%2Fcallback&response_type=code&state=xyz&scope=openid%20profile%20email
- Pick a persona, or click Deny (
error=access_denied). - Your app exchanges
codeatPOST /google/token, then callsGET /google/userinfowith the access token.
NoteAny
client_idandclient_secretare accepted by default. Secrets are not validated. SeeopenClientandclientsif you want an allowlist.
Skip the consent page
| Mechanism | Use when |
|---|---|
?auto=alice |
Scripts and curl |
BOHURUPEE_AUTO_APPROVE=1 |
Every authorize uses the default persona |
POST /__login |
Browser tests (loginAs) without rewriting authorize URLs |
Playwright and PHP helpers: examples/playwright, examples/php.
Curl / OIDC smoke tests
From a git checkout with the server already running:
./examples/curl/run-all.sh
python3 examples/oidc-client/client.py
Configure personas
bohurupee init writes bohurupee.yaml. Edit people without rebuilding:
personas:
- id: alice
email: [email protected]
name: Alice Admin
claims:
role: admin
- id: bob
email: [email protected]
name: Bob User
email_verified: false
Apply changes while the server is up:
curl -s -X POST http://127.0.0.1:4190/__reload
Every YAML key is documented in Configuration. Routes and flags are in Endpoints and CLI.
Wire your app
- Generic OIDC / Auth.js → Any framework
- Laravel Socialite → Laravel Socialite
- GitHub-shaped userinfo → Provider profiles