Skip to content

Authorization

Understanding authorization helps you work with single-spa confidently. Here you will learn the core ideas behind authorization, see working code, and pick up best practices used on real teams.

Authorization Overview

At its core, authorization is about doing one thing well inside your single-spa project. Once you understand the pattern, you can apply it consistently across features and teams.

Good authorization pays off across the whole codebase: fewer surprises, easier testing, and smoother onboarding. The snippet below is a solid starting point.

import { registerApplication, start } from 'single-spa';

registerApplication({
  name: '@org/app',
  app: () => System.import('@org/app'),
  activeWhen: ['/app'],
});

start();

single-spa orchestrates multiple framework apps on one page through a root config.

Authorization Example

registerApplication({
  name: '@org/app',
  app: () => System.import('@org/app'),
  activeWhen: ['/app'],
});
start();
  • Start from a minimal Authorization example and grow it only as needed.
  • Keep configuration explicit so Authorization behaves the same in every environment.
  • Name things clearly so teammates understand your Authorization at a glance.
  • Add tests around Authorization early to lock in expected behaviour.

Single-SPA Cheatsheet

Core single-spa APIs related to authorization.

API Example Purpose
registerApplication registerApplication({ name, app, activeWhen }) Register a micro frontend
activeWhen activeWhen: ['/checkout'] Route ownership
start start() Begin routing
bootstrap export async function bootstrap() One-time setup
mount export async function mount(props) Render the app
unmount export async function unmount(props) Clean up the app
import map systemjs-importmap Locate app bundles

How Authorization Works in Single-SPA

Authorization is part of how single-spa lets multiple applications — even in different frameworks — coexist on one page. A root config registers each app and controls when it is active.

single-spa orchestrates multiple framework apps on one page through a root config.

  • A root config registers apps and calls start().
  • Each app exports bootstrap, mount, and unmount lifecycles.
  • activeWhen decides which routes each app owns.
  • Import maps resolve each app's bundle at runtime.

Practical Guidance for Authorization

For reliable micro frontends, authorization should isolate failures and keep shared state minimal. Let each team own its app end to end while agreeing on a few shared contracts.

Concern Recommendation
Isolation One app's crash should not break others
Shared state Prefer shared utility modules over globals
Routing Keep activeWhen rules explicit and non-overlapping
Deployment Release via import-map updates per app

Common Mistakes

  • Skipping error handling and edge cases when wiring up authorization.
  • Leaving authorization untested, so regressions slip into production.
  • Over-engineering authorization before you actually need the extra flexibility.
  • Ignoring documentation, which makes authorization hard for the next developer to change.

Key Takeaways

  • Authorization is a core part of working effectively with single-spa.
  • Start small and keep authorization focused on a single responsibility.
  • Apply consistent patterns so authorization scales across your project.
  • Test and document authorization to keep it maintainable over time.

Pro Tip

Bookmark this authorization pattern and reuse it. Consistency across your single-spa codebase is worth more than clever one-off solutions.