BuildWithVikesh Identity Platform
A production-oriented identity platform with password, email OTP, Google ID-token authentication, recovery, account controls, sessions, devices, and authorization.
Project overview
This platform is the identity foundation for BuildWithVikesh. The public website and account experience live in one Next.js application, while a centralized Express API owns authentication, authorization, persistence, and email delivery.
Why I built it
The goal was to learn and implement the security boundaries behind a dependable account system instead of treating sign-in as a visual form alone.
Architecture
- Next.js renders the public, authentication, and account surfaces.
- Express exposes versioned API routes and enforces validation, CORS, CSRF, rate limits, and authorization.
- MongoDB stores identity, session, authorization, and application data.
- Redis supports rate limits, authorization caching, and the durable email queue.
- The backend consumes queued email jobs in-process and sends them directly through Gmail SMTP.
Security decisions
Browser access and refresh credentials stay in HttpOnly cookies. Refresh credentials rotate on use, replay revokes the token family, and state-changing authenticated requests require a signed CSRF value from an allow-listed origin.
What I learned
Identity work is mostly about boundaries: credential exposure, recovery behavior, failure handling, lifecycle state, queue durability, and making security controls understandable to the person using them.