# Finqu Account Portal

> Central sign-in, account security, sessions, two-factor authentication, and OAuth 2.0 authorization for connected Finqu products.

## One account across connected products

The Account Portal centralizes sign-in, account security, and authorization for connected Finqu products. It carries registration, login, profile and password management, session handling, and two-factor authentication across two brand frontends sharing one backend.

A person is not tied to one tenant. Someone can hold several merchant accounts and a partner account at once, so authorization has to resolve which context a request is for before it issues anything.

## Authorization path

1. **Sign in**: Password authentication with lockout on repeated failures.
2. **Verify**: Time-based codes, SMS, or a recovery code.
3. **Authorize**: Consent resolved for the merchant or partner context.
4. **Issue**: Access and refresh tokens for the connected application.
5. **Revoke**: Sessions and app consents listed and revocable remotely.

## What the portal handles

- The complete Account and Login frontend across both brand applications
- Backend identity, session, and account-security logic
- An OAuth 2.0 authorization and resource server with discovery and JWKS endpoints
- Scopes separated by merchant and partner context
- Two-factor authentication and remote session revocation

## Technologies

- PHP
- Vue
- OAuth 2.0
- JWT
- Redis
- Two-factor authentication
