> ## Documentation Index
> Fetch the complete documentation index at: https://vlyai-1c28d863.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Auth flows

> Patterns for sign-up, sign-in, password reset, MFA, OAuth, magic links, and session management.

vly's built-in auth covers the common flows. This page documents the **patterns** so you understand what's happening and can customize if needed.

## Sign-up

1. User submits email + password.
2. Server creates user row, sends verification email.
3. User clicks verification link.
4. Account marked verified; user redirected to onboarding.

## Sign-in (password)

1. User submits email + password.
2. Server compares hashed password.
3. On match: create session, set HTTP-only cookie.
4. Redirect to app.

## Sign-in (magic link)

1. User submits email.
2. Server generates a one-time token (15-min TTL), sends email.
3. User clicks link → server verifies token → creates session.

## Password reset

1. User submits email on "Forgot?" page.
2. Server generates a reset token (1-hour TTL), sends email.
3. User clicks link → enters new password → server updates and invalidates token.

## MFA setup

1. User opens MFA setup in settings.
2. Server generates a TOTP secret, returns QR code.
3. User scans with authenticator app, enters first 6-digit code.
4. Server verifies, marks MFA enabled.
5. Subsequent sign-ins require code in addition to password.

## OAuth

1. User clicks "Sign in with Google".
2. Redirect to Google OAuth.
3. Google redirects back with code.
4. Server exchanges code for token, fetches profile.
5. Match by email to existing user OR create new.
6. Create session.

## Session management

* Sessions are server-side, stored in Convex.
* Cookie is HTTP-only, SameSite=Lax, Secure in production.
* Default TTL: 30 days, sliding (renews on activity).
* Revoke: Workspace settings → Sessions, or programmatically via `auth.revoke(sessionId)`.

## Account deletion

1. User confirms (modal: "type your email").
2. Server marks user `deletedAt`, soft-deletes owned data per cascade rules.
3. Hard-delete after 30 days (allows recovery if requested).

See [Account deletion](/security/account-deletion).

## Related

<CardGroup cols={3}>
  <Card title="Built-in auth" icon="lock" href="/features/auth/built-in-auth">
    The high-level overview.
  </Card>

  <Card title="OAuth providers" icon="key" href="/features/auth/oauth-providers">
    Setup per provider.
  </Card>

  <Card title="Security" icon="shield" href="/security/auth-best-practices">
    Best practices.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.