> ## Documentation Index
> Fetch the complete documentation index at: https://vlyai-1c28d863.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Auth best practices

> Patterns for safe sign-up, password reset, MFA, and session management.

The defaults in vly's built-in auth are sane. These practices cover the application-level decisions that ship with every project.

## Patterns

<CardGroup cols={2}>
  <Card title="Email verification before privileged actions" icon="mail-check">
    Don't let unverified accounts pay, invite teammates, or perform destructive actions.
  </Card>

  <Card title="Lock accounts after repeated failures" icon="lock-keyhole">
    5 wrong passwords in 15 minutes → temporary lock. Built into vly's auth flow.
  </Card>

  <Card title="Require MFA for admins" icon="shield-plus">
    Workspace owners and admins should enable TOTP. Enforce with a setting.
  </Card>

  <Card title="Short session lifetime for sensitive surfaces" icon="clock">
    Reduce session TTL for billing pages; require re-auth before destructive actions.
  </Card>

  <Card title="Never email passwords" icon="x-circle">
    For password reset, send a one-time link, not the password itself.
  </Card>

  <Card title="Sanitize user-provided redirect URLs" icon="link">
    "Sign in then return to ?redirect=..." — only allow same-origin redirects.
  </Card>
</CardGroup>

## Don't

<AccordionGroup>
  <Accordion title="Don't store passwords in plain text" icon="x-circle">
    vly's built-in auth never does this; if you implement custom auth, use bcrypt / Argon2.
  </Accordion>

  <Accordion title="Don't roll your own JWT library" icon="x-circle">
    Use vly's session model. Custom JWT implementations have notorious foot-guns (none algorithm, key confusion, etc.).
  </Accordion>

  <Accordion title="Don't reveal whether an email is registered" icon="x-circle">
    "No account with that email" leaks info to attackers. Either say "If an account exists, we sent a link" or accept the small UX hit for the security gain.
  </Accordion>
</AccordionGroup>

## Related

<CardGroup cols={3}>
  <Card title="Built-in auth" icon="lock" href="/features/auth/built-in-auth">
    The auth system.
  </Card>

  <Card title="Rate limiting" icon="gauge" href="/architecture/rate-limiting">
    Defend auth endpoints.
  </Card>

  <Card title="Auth flows" icon="key" href="/architecture/auth-flows">
    Patterns for common scenarios.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.