Login Flow
Security
- Token Expiry: Magic links are short-lived.
- Cookie: The session token is stored in a
HttpOnlycookie to prevent XSS.
APIs
Login Request
Request a magic link.
Get Profile
Retrieve current session user.
Passwordless magic link login flow.
HttpOnly cookie to prevent XSS.