Skip to main content
The defaults in vly’s built-in auth are sane. These practices cover the application-level decisions that ship with every project.

Patterns

Email verification before privileged actions

Don’t let unverified accounts pay, invite teammates, or perform destructive actions.

Lock accounts after repeated failures

5 wrong passwords in 15 minutes → temporary lock. Built into vly’s auth flow.

Require MFA for admins

Workspace owners and admins should enable TOTP. Enforce with a setting.

Short session lifetime for sensitive surfaces

Reduce session TTL for billing pages; require re-auth before destructive actions.

Never email passwords

For password reset, send a one-time link, not the password itself.

Sanitize user-provided redirect URLs

“Sign in then return to ?redirect=…” — only allow same-origin redirects.

Don’t

vly’s built-in auth never does this; if you implement custom auth, use bcrypt / Argon2.
Use vly’s session model. Custom JWT implementations have notorious foot-guns (none algorithm, key confusion, etc.).
“No account with that email” leaks info to attackers. Either say “If an account exists, we sent a link” or accept the small UX hit for the security gain.

Built-in auth

The auth system.

Rate limiting

Defend auth endpoints.

Auth flows

Patterns for common scenarios.
Last modified on April 18, 2026