DEV Community

#authentication

User authentication mechanisms

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
How Does Password Hashing Actually Work? Why Isn't SHA-256 Enough?

How Does Password Hashing Actually Work? Why Isn't SHA-256 Enough?

1
Comments
5 min read
Permission Withdrawal: Auditable Data Consent and Active Session Access

Permission Withdrawal: Auditable Data Consent and Active Session Access

Comments
6 min read
Node.js Account Shutdown: Token Revocation and Eventual Deletion in 3 Steps

Node.js Account Shutdown: Token Revocation and Eventual Deletion in 3 Steps

Comments
5 min read
What are JWT tokens and why your app needs them

What are JWT tokens and why your app needs them

Comments
4 min read
Your AI Agent Has an OAuth Token. Does It Have an Identity?

Your AI Agent Has an OAuth Token. Does It Have an Identity?

1
Comments 1
3 min read
Authentication APIs Explained: Template-Owned US/EU Login OTP with SMS and Email Fallback

Authentication APIs Explained: Template-Owned US/EU Login OTP with SMS and Email Fallback

Comments
7 min read
Your Recovery Path Is Your Real Login

Your Recovery Path Is Your Real Login

1
Comments
10 min read
High-Risk Login Controls with Device Fingerprints, Event Reports, and Step-Up Verification

High-Risk Login Controls with Device Fingerprints, Event Reports, and Step-Up Verification

Comments
6 min read
Progressive Profiling: Updating Verified User Identity Without Account Rebuilds in Fintech

Progressive Profiling: Updating Verified User Identity Without Account Rebuilds in Fintech

Comments
5 min read
Edtech Identity Linking in Go: Resolve, Inspect, Attach Safely (with Recovery)

Edtech Identity Linking in Go: Resolve, Inspect, Attach Safely (with Recovery)

Comments
7 min read
Support Account Defense: Balancing JWKS Caching Against Live Session Introspection

Support Account Defense: Balancing JWKS Caching Against Live Session Introspection

Comments
8 min read
Candidate Consent Categories for Auditable Recruiting Auth Flows (A 4-State Model)

Candidate Consent Categories for Auditable Recruiting Auth Flows (A 4-State Model)

Comments
6 min read
Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint

Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint

Comments
5 min read
HMAC Proves Origin, Not Freshness: Replay Attacks Against Signed APIs

HMAC Proves Origin, Not Freshness: Replay Attacks Against Signed APIs

Comments
6 min read
OAuth Flow CSRF: How a Missing State Parameter Enables Forced Authorization

OAuth Flow CSRF: How a Missing State Parameter Enables Forced Authorization

Comments
5 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.