Configuration
Authentication
Demo sessions and production integration.
Buyer documentation is provided in English.
What Lite implements
The portal signs in through POST /auth/login and sends the returned opaque access token as a Bearer token. Lite stores token hashes in a local session file for 24 hours, so fixture-user sessions survive API restarts. Sessions for users registered only in memory do not survive a restart.
Account flows
Registration creates an organization and owner membership. Change-password verifies the current password. Forgot-password returns a demo reset token without sending email; reset-password validates input and returns a preview response without changing any password. Registered users and organizations are in memory and reset when Lite restarts.
Before production
Implement durable user storage, secure session lifecycle, rate limiting, verified email, and password recovery. JWT, Clerk, and NextAuth integrations are not included in Lite.