Skip to content

Authentication

TODO: API key vs session token, anonymous device IDs, POST /auth/device/code and /auth/device/* polling, POST /auth/google and /auth/apple (id_token, not access_token). Sessions last 30 days and renew on use.

Can't be taken away. Open source backend and SDKs.