Skip to content

[Magic Links] Infrastructure #571

Description

@2witstudios

Summary

Implement magic link authentication as a passwordless alternative.

Background

Schema already supports magic_link type in verificationTokens. Need service + routes.

New Files

  • packages/lib/src/auth/magic-link-service.ts
  • apps/web/src/app/api/auth/magic-link/send/route.ts
  • apps/web/src/app/api/auth/magic-link/verify/route.ts

Flow

  1. User enters email → rate-limited token generation
  2. Email sent with ps_magic_* token (5-min expiry)
  3. Click link → validate token → create session → redirect to app
  4. Token is one-time use (marked usedAt on consumption)

Technical Details

  • Token format: ps_magic_${randomBytes(32).toString('hex')}
  • Rate limiting: 3 requests per email per 15 minutes
  • Expiry: 5 minutes
  • One-time use enforcement
  • Existing user: log in
  • New user: create account + log in

Acceptance Criteria

  • Magic link service with send/verify methods
  • API routes for send and verify
  • Rate limiting implemented
  • Email template for magic link
  • Token expiry enforced
  • One-time use enforced
  • Unit tests for magic link service

Activity

  1. changed the title [-][Auth] Magic link login infrastructure[/-] [+][Magic Links] Infrastructure[/+] on Feb 12, 2026
  2. added a commit that references this issue on Feb 13, 2026
    0d457d1
  3. added a commit that references this issue on Feb 16, 2026
    0f9c600
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions