33 Logo

Description

A composable authentication library for Go applications, providing email and password authentication, session management, MFA, passkeys, OAuth, and SSO through OIDC and SAML.

Highlights

  • Built Authlier, a composable authentication library for Go applications providing configurable server-side flows for passwords, sessions, email verification and recovery, MFA, passkeys, Google authentication, OIDC, and SAML SSO through a unified HTTP handler.
  • Designed pluggable PostgreSQL, MySQL, MongoDB, and Redis storage adapters, supporting opaque server-side sessions and JWT access tokens with rotating opaque refresh tokens.
  • Implemented security-sensitive flows including Argon2id/bcrypt password hashing, token hashing and one-time consumption, session revocation, refresh-token reuse detection, WebAuthn, TOTP recovery codes, and OIDC/SAML validation
  • Applied OWASP ASVS 5.0 and relevant OWASP Cheat Sheets as engineering and verification references across authentication, session management, password storage, recovery, and MFA.