Skip to main content
Backend systemsActive development

BuildWithVikesh Identity Platform

A production-oriented identity platform with password, email OTP, Google ID-token authentication, recovery, account controls, sessions, devices, and authorization.

  • Next.js
  • Express
  • MongoDB
  • Redis
  • BullMQ
  • Gmail SMTP

Project overview

This platform is the identity foundation for BuildWithVikesh. The public website and account experience live in one Next.js application, while a centralized Express API owns authentication, authorization, persistence, and email delivery.

Why I built it

The goal was to learn and implement the security boundaries behind a dependable account system instead of treating sign-in as a visual form alone.

Architecture

  • Next.js renders the public, authentication, and account surfaces.
  • Express exposes versioned API routes and enforces validation, CORS, CSRF, rate limits, and authorization.
  • MongoDB stores identity, session, authorization, and application data.
  • Redis supports rate limits, authorization caching, and the durable email queue.
  • The backend consumes queued email jobs in-process and sends them directly through Gmail SMTP.

Security decisions

Browser access and refresh credentials stay in HttpOnly cookies. Refresh credentials rotate on use, replay revokes the token family, and state-changing authenticated requests require a signed CSRF value from an allow-listed origin.

What I learned

Identity work is mostly about boundaries: credential exposure, recovery behavior, failure handling, lifecycle state, queue durability, and making security controls understandable to the person using them.