Case study
Finqu Account Portal
Central sign-in, account security, sessions, two-factor authentication, and OAuth 2.0 authorization for connected Finqu products.
overview
One account across connected products
The Account Portal centralizes sign-in, account security, and authorization for connected Finqu products. It carries registration, login, profile and password management, session handling, and two-factor authentication across two brand frontends sharing one backend.
A person is not tied to one tenant. Someone can hold several merchant accounts and a partner account at once, so authorization has to resolve which context a request is for before it issues anything.
system flow
Authorization path
- 01Sign in
Password authentication with lockout on repeated failures.
- 02Verify
Time-based codes, SMS, or a recovery code.
- 03Authorize
Consent resolved for the merchant or partner context.
- 04Issue
Access and refresh tokens for the connected application.
- 05Revoke
Sessions and app consents listed and revocable remotely.
engineering
What the portal handles
- The complete Account and Login frontend across both brand applications
- Backend identity, session, and account-security logic
- An OAuth 2.0 authorization and resource server with discovery and JWKS endpoints
- Scopes separated by merchant and partner context
- Two-factor authentication and remote session revocation
Next step
Interested in this kind of work?
I'd be happy to talk through the decisions behind this case or the kind of problem your team is working on.