Users & Auth
DevMatrix uses a JWT-based session model shared by the web app and the API. This page covers the User and Session entities and the auth flow.
User & Session
Every account is a User. Signing in issues a Session backed by a JWT token.
user-and-session.schema.ts
interface User {
id: string;
name: string;
email: string;
password: string; // hashed, never returned by the API
avatar?: string;
createdAt: Date;
}
interface Session {
id: string;
userId: string;
token: string;
expiresAt: Date;
}How the flow works
- 1The client calls /api/auth/register or /api/auth/login.
- 2The API verifies credentials and creates a Session, returning a signed JWT.
- 3The client stores the token and sends it as an Authorization: Bearer <token> header on every request.
- 4Every module — Playground, Debugging, Analytics, Idea Validator — trusts this same token.
Tokens are bearer credentialsAnyone holding a valid token can act as that user. Keep
DEVMATRIX_API_KEY and session tokens server-side or in secure storage — never in client-exposed code.For the exact request and response shapes, see API Reference → Authentication.