Home
Developer
Apps
Articles
Releases
Roadmap
LetsTalk
Explore More
Resume
Home
Products
authx-identity
Security
🔑
authx-identity
v1.1.1
Share
Overview
Install
Security
Releases
Docs
↗
Security
Security and trust-boundary notes for authx-identity.
Passwords are hashed on arrival and never reproduced through the API — AuthX owns credential storage end-to-end.
Access tokens are signed with an RSA private key that never leaves AuthX; consumers verify independently via the public JWKS endpoint.
Refresh tokens are tracked server-side, enabling rotation, expiration, and revocation instead of trusting a token indefinitely.
Trusted backend services authenticate to the internal identity API with a dedicated service token — never with end-user credentials.
Issuer/audience validation and restricted CORS origins keep the token contract from being silently reused where it shouldn’t be.
Documentation
Security architecture (docs)
Trust boundaries (docs)
Authentication debugging (docs)
DjangoPlay · authx-identity