He also mentions that if you just want API authentication then Passport has two sibling projects for that purpose - OAuthorize and OAuth2orize.
You would most likely be using bearer tokens issued by OAuth2 to implement this, and Passport supports this pretty well, with the bonus that it's actively maintained: https://github.com/jaredhanson/passport-http-bearer
app.get('/dashboard', ensureAuthenticated(), function(req, res) { });
Your ensureAuthenticated function would look like this:
function ensureAuthenticated(req, res, next) { if (req.isAuthenticated()) { next(); } else { res.send('You are not authorized to access this page.'); } }
Passport provides a few of these utility middlewares out of the box. It seems intimidating at first and I could spend a long time explaining it, but it would be much better just to dive in and give it a try. You can even head over to their IRC, which is #passportjs if I remember correctly, and ask which strategy would be best for your application and get started from there.