Skip to main content
vly’s built-in auth covers the common flows. This page documents the patterns so you understand what’s happening and can customize if needed.

Sign-up

  1. User submits email + password.
  2. Server creates user row, sends verification email.
  3. User clicks verification link.
  4. Account marked verified; user redirected to onboarding.

Sign-in (password)

  1. User submits email + password.
  2. Server compares hashed password.
  3. On match: create session, set HTTP-only cookie.
  4. Redirect to app.
  1. User submits email.
  2. Server generates a one-time token (15-min TTL), sends email.
  3. User clicks link → server verifies token → creates session.

Password reset

  1. User submits email on “Forgot?” page.
  2. Server generates a reset token (1-hour TTL), sends email.
  3. User clicks link → enters new password → server updates and invalidates token.

MFA setup

  1. User opens MFA setup in settings.
  2. Server generates a TOTP secret, returns QR code.
  3. User scans with authenticator app, enters first 6-digit code.
  4. Server verifies, marks MFA enabled.
  5. Subsequent sign-ins require code in addition to password.

OAuth

  1. User clicks “Sign in with Google”.
  2. Redirect to Google OAuth.
  3. Google redirects back with code.
  4. Server exchanges code for token, fetches profile.
  5. Match by email to existing user OR create new.
  6. Create session.

Session management

  • Sessions are server-side, stored in Convex.
  • Cookie is HTTP-only, SameSite=Lax, Secure in production.
  • Default TTL: 30 days, sliding (renews on activity).
  • Revoke: Workspace settings → Sessions, or programmatically via auth.revoke(sessionId).

Account deletion

  1. User confirms (modal: “type your email”).
  2. Server marks user deletedAt, soft-deletes owned data per cascade rules.
  3. Hard-delete after 30 days (allows recovery if requested).
See Account deletion.

Built-in auth

The high-level overview.

OAuth providers

Setup per provider.

Security

Best practices.
Last modified on April 18, 2026