How sign-in and API keys work
Day Planner handles sign-in itself, with Better Auth, and stores accounts in its own database. No outside service is needed.
Accounts
Section titled “Accounts”Each person has one account, identified by email. An account can have:
- a password, stored as a slow, salted hash (scrypt);
- one or more external logins from an OIDC provider;
- a role: user or admin.
Sessions
Section titled “Sessions”Signing in creates a session and sets an httpOnly cookie that scripts in the page can’t read. Resetting a password ends all of that account’s sessions, and so does banning.
Sign-in requests are only accepted from BETTER_AUTH_URL and any TRUSTED_ORIGINS, which blocks other sites from submitting forms on a signed-in person’s behalf. Sign-in, sign-up and password-reset requests are rate limited per visitor IP.
API keys
Section titled “API keys”An API key acts as the user who created it, with the same access to their data and no access to anyone else’s. Keys:
- start with
dp_, so they’re easy to spot if leaked; - are stored only as a hash;
- can expire, and can be revoked at any time;
- stop working when their owner is banned.
A key can’t sign in to the web app or manage other keys.
Linking external logins
Section titled “Linking external logins”When someone signs in with an external provider using an email that already has an account, the login is linked only if both the provider and Day Planner consider that email verified. Otherwise the person sees account_not_linked.
This matters because anyone can register any email with some providers. Without the check, someone could create a provider account with your email and get into your Day Planner.
See also
Section titled “See also”- External login (OIDC): set up a provider
- API keys: create and revoke keys
- Reverse proxy and client IPs: make per-visitor rate limits accurate