Skip to content
Architecture 2026-07-01 10 min

Authentication

Session, JWT and OAuth patterns with secure defaults.

By Mohammad Zayed

Overview

Authentication is where most security incidents start. Use a battle-tested provider and secure defaults.

Sessions

Prefer short-lived access tokens with HTTP-only refresh cookies. Never store secrets in the client bundle.

OAuth

callback
const { data, error } = await supabase.auth
  .exchangeCodeForSession(code);
if (error) redirect("/login");

Security

  • Enforce MFA for admin roles.
  • Rate-limit login and magic-link endpoints.
  • Rotate and scope API keys; never log them.

Frequently asked questions

Is this the only way to build it?
No. These are reference patterns we reuse. Adapt the boundaries to your constraints, team and compliance needs.
Should I copy this exactly?
Use it as a starting point. Validate each decision against your traffic, data sensitivity and team size.
Can NorthFlow implement this?
Yes. Book a strategy call and we'll tailor the architecture to your product.

Continue reading

Want this architecture for your product?

Book a free strategy call. We'll map your bottlenecks to the right systems and send a clear roadmap — even if we don't work together.

Chat on Telegram

Usually replies within minutes. Chat on Telegram: @northflowstudio

No obligation consultationFounder-led projectsInternational clientsFast responseSecure communication