04·Hands-on·15 min

Auth from your code

Two tokens, never mixed. The API key identifies your project and rides on every request. The end-user access token identifies one signed-in person and rides in the X-Access-Token header, only on calls that act as that user.

Sign up

const res = await client.auth.signup({ email, password })

The response depends on a project setting. With email verification on, there are no tokens yet: verification_required is true and the user receives a 6-digit code by email. Your UI must show a code form and call verify-email with it. With verification off, the account is usable at once; send the user to login.

Log in

const login = await client.auth.login({ email, password })

Again two successes. If login.tokens is present, you have a session. If mfa_required is true, you hold a short-lived challenge_token instead; show an authenticator-code form and call mfa/challenge to trade it for tokens.

Keep the session

Your app owns the cookie. Store the access token httpOnly so page scripts cannot read it:

headers.append('Set-Cookie', serializeSessionCookie(login.tokens.AccessToken, {
    maxAge: login.tokens.ExpiresIn,
}))

Gate routes

sessionFromCookies(cookieHeader) decodes the token locally, with no network, and returns { status, user }. Use it on every navigation. Before anything sensitive, re-check with getSession({ accessToken, mode: 'verified' }), which asks the gateway and notices revocations. Optimistic for page loads, verified for payments and account changes.

Where DontCode fits

Password hashing, verification emails, MFA secrets, and rate limiting on login all happen in the platform's auth service. Your code renders the forms and branches on the responses. The one rule: a single submit can return "done" or "one more step"; never assume one round trip.

Go deeper

Check your understanding

  1. 1.Which header carries the end-user access token?

  2. 2.login() resolves with mfa_required: true. What do you hold?

  3. 3.When should you use getSession in verified mode?

Your task

Backend Project

From your code, sign up a test user with client.auth.signup (or POST /api/v1/auth/signup). The check passes once the new user exists in your project; you do not need to complete verification for this lesson.