Skip to content

Authentication Sharing

Understanding authentication sharing helps you work with Module Federation confidently. Here you will learn the core ideas behind authentication sharing, see working code, and pick up best practices used on real teams.

Authentication Sharing Overview

Authentication Sharing lets you structure Module Federation work so it stays readable, testable, and easy to scale. Instead of ad-hoc code, you follow a clear pattern that other developers can recognise immediately.

The key is to keep authentication sharing focused and predictable. Start from the minimal example here, then layer in only the complexity your feature actually needs.

const ProductList = React.lazy(() =>
  import('catalog/ProductList').catch(() => ({
    default: () => <p>Catalog is temporarily unavailable</p>,
  })),
);

Always provide a fallback so a failing remote degrades gracefully instead of crashing the shell.

Authentication Sharing Example

new ModuleFederationPlugin({
  name: 'app',
  filename: 'remoteEntry.js',
  exposes: { './Widget': './src/Widget' },
  remotes: { other: 'other@http://host/remoteEntry.js' },
  shared: { react: { singleton: true } },
});
  • Start from a minimal Authentication Sharing example and grow it only as needed.
  • Keep configuration explicit so Authentication Sharing behaves the same in every environment.
  • Name things clearly so teammates understand your Authentication Sharing at a glance.
  • Add tests around Authentication Sharing early to lock in expected behaviour.

Module Federation Cheatsheet

Key Module Federation settings related to authentication sharing.

Option Example Purpose
name name: 'shell' Unique container name
filename filename: 'remoteEntry.js' Remote entry manifest
exposes exposes: { './X': './src/X' } Modules a remote shares
remotes remotes: { app: 'app@url' } Remotes a host consumes
shared shared: { react: { singleton: true } } Deduplicate libraries
lazy load import('remote/Module') Load remotes on demand
Suspense <Suspense fallback={...}> Handle async loading

How Authentication Sharing Works in Module Federation

Authentication Sharing builds on Module Federation's ability to load code from another independently built and deployed application at runtime. Each app can be a host, a remote, or both.

Always provide a fallback so a failing remote degrades gracefully instead of crashing the shell.

  • Remotes expose modules through a remoteEntry.js manifest.
  • Hosts declare remotes and import exposed modules dynamically.
  • Shared dependencies are deduplicated, ideally as singletons.
  • Each micro frontend builds and deploys on its own schedule.

Practical Guidance for Authentication Sharing

In production, authentication sharing needs careful version management and graceful failure handling. Align shared dependency versions and always render a fallback when a remote cannot load.

Concern Recommendation
Shared versions Use singletons with requiredVersion
Runtime errors Wrap remotes in error boundaries and fallbacks
Deployment Resolve remotes from a runtime manifest
Performance Lazy-load remotes and cache remoteEntry.js

Common Mistakes

  • Skipping error handling and edge cases when wiring up authentication sharing.
  • Leaving authentication sharing untested, so regressions slip into production.
  • Over-engineering authentication sharing before you actually need the extra flexibility.
  • Ignoring documentation, which makes authentication sharing hard for the next developer to change.

Key Takeaways

  • Authentication Sharing is a core part of working effectively with Module Federation.
  • Start small and keep authentication sharing focused on a single responsibility.
  • Apply consistent patterns so authentication sharing scales across your project.
  • Test and document authentication sharing to keep it maintainable over time.

Pro Tip

When you get stuck on authentication sharing, reduce it to the smallest reproducible example first — most Module Federation issues become obvious once the noise is gone.