Operate
Security
What the platform does for you, and what your app must still do.
Built in#
- Per-environment signing keys. RS256 session tokens, published as JWKS and verified in your app without an API call.
- One-time sign-in codes. The hosted page returns a 60-second, single-use code bound to your redirect URI; tokens never appear in URLs.
- Registered redirects only. Unknown redirect URIs are refused, and return paths stay on your own origin.
- Shared rate limits. Per account across all servers: 10 sign-ins a minute, 3 password resets or magic codes a minute.
- Password protection. Breach check with k-anonymity and bcrypt hashing; administrators can block an account at once.
- Single-use reset links. Stored as hashes; a reset ends every existing session of that user.
- Cloudflare Turnstile. On the first-factor forms of hosted pages served from 3een subdomains, verified on the server and failing closed.
- Audit log and signed webhooks. Authentication attempts and security changes, delivered with HMAC signatures and retries.
- Password policy. 8 to 128 characters, not the account's email, not breached. Repeated attempts are held back by the rate limits; there is no automatic lockout.
- Secrets at rest. Provider secrets and private keys are encrypted. API keys are matched by hash and kept encrypted so their owner can reveal them.
In your app#
- Keep the API key on the server. Anything in a Client Component or a
NEXT_PUBLIC_variable is public. - Enforce permissions on the server; treat UI gating as presentation.
- Use
getUserwhere a revoked session must stop working immediately. - Verify webhook signatures on the raw body, and make handlers idempotent.
- Don't log tokens, cookies or
Authorizationheaders.