Authentication Flows
ButtrBase supports multiple authentication strategies to suit different application needs. All successful flows result in a JSON Web Token (JWT) that must be included in the Authorization header of subsequent requests.
1. Standard Email/Password
The most common flow.
1.
Register: User provides email and password.
2.
Login: User provides credentials -> Receive JWT.
2. Passwordless (Magic Link)
Secure and low-friction.
1.
Request: User enters email.
2.
Send: ButtrBase sends an email with a unique, time-sensitive link.
3.
Verify: User clicks link -> Client sends token to API -> Receive JWT.
3. Social Login (OAuth)
Federated identity with providers like Google, Microsoft, and Apple (via Apple-tagged OIDC connections).
1.
Initiate: User clicks the desired social login button (Google, Microsoft, Apple).
2.
Redirect: User authorizes app on provider's site.
3.
Callback: Provider redirects back with code.
4.
Exchange: Backend verifies code -> Receive JWT.
4. OTP (One-Time Password)
Ideal for mobile apps or 2FA.
1.
Request: User enters email or phone.
2.
Send: ButtrBase sends 6-digit code via Email or SMS.
3.
Verify: User enters code -> Receive JWT.