authv0.01users./core/profile[MOBILE] KMM Android/iOS app dev[FE] Web frontend (React/Tailwind) dev[BE-RUST] Axum service dev[BE-DB] PostgreSQL/Redis opsUser Registration
email_tokenUser Login
Logout
Password Reset
Two-Factor Authentication (2FA)
JWT Token Refresh
Email Verification
Google OAuth Login
[MOBILE][FE]429, use exponential backoff with jitter.[BE-RUST][FE][MOBILE]| Method | Path | Purpose | Auth |
|---|---|---|---|
| POST | /api/auth/register |
Register new user | none |
| POST | /api/auth/login |
Login with email + password | none |
| POST | /api/auth/login/google |
Login using Google OAuth | none |
| POST | /api/auth/login/apple |
Login using Apple OAuth | none |
| POST | /api/auth/verify-email |
Verify email using token | none |
| POST | /api/auth/resend-verification |
Resend verification email | none |
| POST | /api/auth/logout |
Logout and blacklist token | JWT |
| POST | /api/auth/refresh |
Refresh JWT using existing token | JWT |
| POST | /api/auth/verify-2fa |
Verify 2FA code after login attempt | temp |
[MOBILE][FE][BE-RUST]{ "error": { "code":"STRING", "http":INT, "message":"STRING", "trace_id":"UUIDv4" } }
[BE-RUST][BE-DB]| Key | Required | Example | Notes |
|---|---|---|---|
JWT_SECRET |
yes | base64 | HMAC secret for JWT signing |
JWT_EXPIRY_MINUTES |
yes | 60 |
Access token lifetime |
JWT_REFRESH_MINUTES |
yes | 43200 (30 days) |
Refresh token lifetime |
BCRYPT_COST |
yes | 12 |
Password hashing cost |
GOOGLE_CLIENT_ID |
no | client.apps.google.com | For Google OAuth |
SMTP_SERVER |
yes | smtp.example.com | Email sending |
SMS_API_KEY |
no | key123 | Required if 2FA SMS enabled |
REDIS_URL |
yes | redis://... | Token blacklist + rate limit |
RATE_RPS |
yes | 5 |
Per-IP requests/sec for sensitive routes |
[MOBILE][FE][BE-RUST][BE-DB][MOBILE]EncryptedSharedPreferences for secure token storage[FE]UI for register/login/logout/reset flows.
Token management via HTTP headers
2FA flows integrated into login UI
Email verification via clickable links
Google OAuth flow triggered by frontend SDK
Apple OAuth flow triggered by frontend SDK
Acceptance:
[BE-RUST]Axum handlers for all endpoints.
SeaORM integration for DB queries
Passwords hashed (bcrypt).
JWT issue/refresh/validate.
Redis for blacklist and rate limits.
Google ID token validation.
Apple ID token validation.
Rate-limiting:
users table is source of truthdb_generic SeaORM connectoris_rate_limited helper| Endpoint | Cooldown (seconds) |
|---|---|
/api/auth/resend-verification |
60 |
aud matches GOOGLE_CLIENT_ID env var| Field | Type | Purpose |
|---|---|---|
password_hash |
Option<String> |
Set to "GOOGLE_ACCOUNT" placeholder |
email_verified |
bool |
Set to true |
generate_and_dispatch_2faverify_2fa| Field | Type | Purpose |
|---|---|---|
requires_2fa |
bool (optional) |
Enables 2FA login enforcement |
[BE-DB]users| Field | Type | Description |
|---|---|---|
| id | UUID | Primary key |
| name | String (optional) | Display name |
| String | Unique email address | |
| password_hash | Option | Bcrypt hash or placeholder for OAuth |
| email_verified | bool | Whether email has been verified |
| email_token | Option | Token used for email verification |
| requires_2fa | Option | Whether user requires 2FA |
| created_at | Timestamp | Creation time |
| role | String | User role (e.g. "user", "admin") |
email_verification| Field | Type | Description |
|---|---|---|
| id | UUID | Primary key |
| user_id | UUID | FK → users.id |
| code | String | Verification code |
| expires_at | DateTimeUtc | Expiry |
password_reset| Field | Type | Description |
|---|---|---|
| id | UUID | Primary key |
| user_id | UUID | FK → users.id |
| reset_token | String | Reset token |
| expires_at | DateTimeUtc | Expiry |
two_fa_token| Field | Type | Description |
|---|---|---|
id |
UUID | Primary key |
user_id |
UUID | Foreign key to users |
code |
String | The 2FA code sent (typically 6-digit numeric or alphanumeric) |
temp_token |
String | Temporary session token issued after login, before 2FA success |
expires_at |
DateTimeUtc | Timestamp after which the code becomes invalid |
attempts |
i32 | Tracks how many times user attempted to verify the code |
sent_via |
String | Delivery method, e.g. "email" or "sms" |
created_at |
DateTimeUtc | Timestamp when the token was created |
bl:{jwt_id} with TTL.rl:login:{ip}, rl:resend:{ip}, etc.[BE-RUST][BE-RUST][BE-DB][MOBILE][FE][MOBILE][FE][BE-RUST][BE-DB]users, email_verification, password_reset, two_fa_token.