Skip to content

How sign-in and API keys work

Day Planner handles sign-in itself, with Better Auth, and stores accounts in its own database. No outside service is needed.

Each person has one account, identified by email. An account can have:

  • a password, stored as a slow, salted hash (scrypt);
  • one or more external logins from an OIDC provider;
  • a role: user or admin.

Signing in creates a session and sets an httpOnly cookie that scripts in the page can’t read. Resetting a password ends all of that account’s sessions, and so does banning.

Sign-in requests are only accepted from BETTER_AUTH_URL and any TRUSTED_ORIGINS, which blocks other sites from submitting forms on a signed-in person’s behalf. Sign-in, sign-up and password-reset requests are rate limited per visitor IP.

An API key acts as the user who created it, with the same access to their data and no access to anyone else’s. Keys:

  • start with dp_, so they’re easy to spot if leaked;
  • are stored only as a hash;
  • can expire, and can be revoked at any time;
  • stop working when their owner is banned.

A key can’t sign in to the web app or manage other keys.

When someone signs in with an external provider using an email that already has an account, the login is linked only if both the provider and Day Planner consider that email verified. Otherwise the person sees account_not_linked.

This matters because anyone can register any email with some providers. Without the check, someone could create a provider account with your email and get into your Day Planner.