Authentication

Nuxfire Auth: an independent authentication server built on OpenAuth.js, with login, signup and password recovery, deployed to auth.YOUR-DOMAIN.com.

Nuxfire Auth

Nuxfire ships with Nuxfire Auth, an independent authentication server built on OpenAuth.js. It can secure any frontend or backend and is deployed to auth.YOUR-DOMAIN.com.

Infrastructure

  • Cloudflare Worker:
    • Configured in infra/auth.ts with an Assets binding serving the frontend's static build.
    • Handles auth logic in apps/functions/src/auth.ts using OpenAuth.js.
    • Credentials for password-based accounts live only in a dedicated AuthKV Cloudflare KV namespace, bound exclusively to this Worker — never in the Postgres database.
  • Nuxt Frontend:
    Located in the apps/login package (built statically with nuxt generate, served as the auth Worker's static assets), it includes UI for:
    • Login
    • Signup
    • Forgot Password

Key Features

  • Social Logins: Google and GitHub, each independently toggled by the githubAuth/googleAuth flags in config.ts — the login UI only shows a provider button once both the flag is on and its client id/secret are actually loaded as secrets.
  • Code-based login
  • Email/password login
  • Password recovery
  • Email verification
  • Two-Factor Authentication (TOTP MFA): Optional self-service MFA for regular users, and mandatory MFA with elevated sessions for platform administrators.
  • Extendable: Easily add new authentication methods as needed.

Two-Factor Authentication (optional, self-service)

Any user can turn on TOTP two-factor authentication from Account Settings → Security — independent of, and architecturally separate from, the platform-owner MFA covered in Platform Admin Console. Requires USER_MFA_SESSION_SECRET and USER_MFA_ENCRYPTION_KEY to be set (see Environment Variables) — without them, enabling 2FA fails with a clear error rather than silently succeeding insecurely; nothing else in the app is affected if they're left unset.

  • Enrollment happens in a modal (components/account/MfaSetupModal.vue), not a full page: click Enable 2FA, scan the QR code with an authenticator app, enter the six-digit code it shows.
  • Verified once per login, not on a timer. After enrolling, the next time that account logs in on a browser that hasn't verified yet, layouts/dashboard.vue shows the same modal — this time asking only for a code, no QR — before any page underneath it can load data. That check is a UX shortcut; the actual enforcement is server-side, in protectedProcedure (server/trpc/trpc.ts), which every tRPC procedure in the app already runs through.
  • Disabling is a single confirmation in Security settings — reachable at all only because getting there already required passing the check above.
  • Recovery codes. Enrolling issues ten single-use recovery codes, shown once. At the prompt, Lost your authenticator? accepts one in place of the six-digit code (same rate limit, audited). Generate new codes in Security settings replaces the set after confirming an authenticator code, and disabling two-factor deletes it. Known limit: if both the authenticator and every code are lost, an operator resets the factor with apps/functions/src/database/reset-mfa.ts --scope=user (manual and audited), and the account enrols again.

Team Authentication

Team authentication is managed within the app package: apps/app. It includes:

  • Team Creation – Users can create teams and manage members.
  • Team Switcher – Users can switch between multiple teams.
  • Invites & User Management – Invite users, manage roles, and remove members. Server-side authorization for these actions is covered in Role-Based Access Control.
Nuxfire Production Kit

Ready to build and launch your SaaS?

Get 100% full source code ownership, zero proprietary wrappers, and architecture engineered for millions of requests on Cloudflare.

© 2026 Nuxfire