Authentication
Nuxfire Auth: an independent authentication server built on OpenAuth.js, with login, signup and password recovery, deployed to auth.YOUR-DOMAIN.com.
Nuxfire Auth
Nuxfire ships with Nuxfire Auth, an independent authentication server built on OpenAuth.js. It can secure any frontend or backend and is deployed to auth.YOUR-DOMAIN.com.
Infrastructure
- Cloudflare Worker:
- Configured in
infra/auth.tswith an Assets binding serving the frontend's static build. - Handles auth logic in
apps/functions/src/auth.tsusing OpenAuth.js. - Credentials for password-based accounts live only in a dedicated
AuthKVCloudflare KV namespace, bound exclusively to this Worker — never in the Postgres database.
- Configured in
- Nuxt Frontend:
Located in theapps/loginpackage (built statically withnuxt generate, served as the auth Worker's static assets), it includes UI for:- Login
- Signup
- Forgot Password
Key Features
- Social Logins: Google and GitHub, each independently toggled by the
githubAuth/googleAuthflags inconfig.ts— the login UI only shows a provider button once both the flag is on and its client id/secret are actually loaded as secrets. - Code-based login
- Email/password login
- Password recovery
- Email verification
- Two-Factor Authentication (TOTP MFA): Optional self-service MFA for regular users, and mandatory MFA with elevated sessions for platform administrators.
- Extendable: Easily add new authentication methods as needed.
Two-Factor Authentication (optional, self-service)
Any user can turn on TOTP two-factor authentication from Account Settings → Security — independent of, and architecturally separate from, the platform-owner MFA covered in Platform Admin Console. Requires USER_MFA_SESSION_SECRET and USER_MFA_ENCRYPTION_KEY to be set (see Environment Variables) — without them, enabling 2FA fails with a clear error rather than silently succeeding insecurely; nothing else in the app is affected if they're left unset.
- Enrollment happens in a modal (
components/account/MfaSetupModal.vue), not a full page: click Enable 2FA, scan the QR code with an authenticator app, enter the six-digit code it shows. - Verified once per login, not on a timer. After enrolling, the next time that account logs in on a browser that hasn't verified yet,
layouts/dashboard.vueshows the same modal — this time asking only for a code, no QR — before any page underneath it can load data. That check is a UX shortcut; the actual enforcement is server-side, inprotectedProcedure(server/trpc/trpc.ts), which every tRPC procedure in the app already runs through. - Disabling is a single confirmation in Security settings — reachable at all only because getting there already required passing the check above.
- Recovery codes. Enrolling issues ten single-use recovery codes, shown once. At the prompt, Lost your authenticator? accepts one in place of the six-digit code (same rate limit, audited). Generate new codes in Security settings replaces the set after confirming an authenticator code, and disabling two-factor deletes it. Known limit: if both the authenticator and every code are lost, an operator resets the factor with
apps/functions/src/database/reset-mfa.ts --scope=user(manual and audited), and the account enrols again.
Team Authentication
Team authentication is managed within the app package: apps/app. It includes:
- Team Creation – Users can create teams and manage members.
- Team Switcher – Users can switch between multiple teams.
- Invites & User Management – Invite users, manage roles, and remove members. Server-side authorization for these actions is covered in Role-Based Access Control.
Ready to build and launch your SaaS?
Get 100% full source code ownership, zero proprietary wrappers, and architecture engineered for millions of requests on Cloudflare.