//Authentication Flows

Authentication Flows

ButtrBase supports multiple authentication strategies to suit different application needs. All successful flows result in a JSON Web Token (JWT) that must be included in the Authorization header of subsequent requests.

1. Standard Email/Password

The most common flow. 1. Register: User provides email and password. 2. Login: User provides credentials -> Receive JWT.

2. Passwordless (Magic Link)

Secure and low-friction. 1. Request: User enters email. 2. Send: ButtrBase sends an email with a unique, time-sensitive link. 3. Verify: User clicks link -> Client sends token to API -> Receive JWT.

3. Social Login (OAuth)

Federated identity with providers like Google, Microsoft, and Apple (via Apple-tagged OIDC connections). 1. Initiate: User clicks the desired social login button (Google, Microsoft, Apple). 2. Redirect: User authorizes app on provider's site. 3. Callback: Provider redirects back with code. 4. Exchange: Backend verifies code -> Receive JWT.

4. OTP (One-Time Password)

Ideal for mobile apps or 2FA. 1. Request: User enters email or phone. 2. Send: ButtrBase sends 6-digit code via Email or SMS. 3. Verify: User enters code -> Receive JWT.