Back to projects
Authlier
Description
A composable authentication library for Go applications, providing email and password authentication, session management, MFA, passkeys, OAuth, and SSO through OIDC and SAML.
Highlights
- Built Authlier, a composable authentication library for Go applications providing configurable server-side flows for passwords, sessions, email verification and recovery, MFA, passkeys, Google authentication, OIDC, and SAML SSO through a unified HTTP handler.
- Designed pluggable PostgreSQL, MySQL, MongoDB, and Redis storage adapters, supporting opaque server-side sessions and JWT access tokens with rotating opaque refresh tokens.
- Implemented security-sensitive flows including Argon2id/bcrypt password hashing, token hashing and one-time consumption, session revocation, refresh-token reuse detection, WebAuthn, TOTP recovery codes, and OIDC/SAML validation
- Applied OWASP ASVS 5.0 and relevant OWASP Cheat Sheets as engineering and verification references across authentication, session management, password storage, recovery, and MFA.
