Operate

Security

What the platform does for you, and what your app must still do.

Built in#

  • Per-environment signing keys. RS256 session tokens, published as JWKS and verified in your app without an API call.
  • One-time sign-in codes. The hosted page returns a 60-second, single-use code bound to your redirect URI; tokens never appear in URLs.
  • Registered redirects only. Unknown redirect URIs are refused, and return paths stay on your own origin.
  • Shared rate limits. Per account across all servers: 10 sign-ins a minute, 3 password resets or magic codes a minute.
  • Password protection. Breach check with k-anonymity and bcrypt hashing; administrators can block an account at once.
  • Single-use reset links. Stored as hashes; a reset ends every existing session of that user.
  • Cloudflare Turnstile. On the first-factor forms of hosted pages served from 3een subdomains, verified on the server and failing closed.
  • Audit log and signed webhooks. Authentication attempts and security changes, delivered with HMAC signatures and retries.
  • Password policy. 8 to 128 characters, not the account's email, not breached. Repeated attempts are held back by the rate limits; there is no automatic lockout.
  • Secrets at rest. Provider secrets and private keys are encrypted. API keys are matched by hash and kept encrypted so their owner can reveal them.

In your app#

  • Keep the API key on the server. Anything in a Client Component or a NEXT_PUBLIC_ variable is public.
  • Enforce permissions on the server; treat UI gating as presentation.
  • Use getUser where a revoked session must stop working immediately.
  • Verify webhook signatures on the raw body, and make handlers idempotent.
  • Don't log tokens, cookies or Authorization headers.