DocsCore ConceptsUsers & Auth

Users & Auth

DevMatrix uses a JWT-based session model shared by the web app and the API. This page covers the User and Session entities and the auth flow.

User & Session

Every account is a User. Signing in issues a Session backed by a JWT token.

user-and-session.schema.ts
interface User {
  id: string;
  name: string;
  email: string;
  password: string; // hashed, never returned by the API
  avatar?: string;
  createdAt: Date;
}

interface Session {
  id: string;
  userId: string;
  token: string;
  expiresAt: Date;
}

How the flow works

  1. 1The client calls /api/auth/register or /api/auth/login.
  2. 2The API verifies credentials and creates a Session, returning a signed JWT.
  3. 3The client stores the token and sends it as an Authorization: Bearer <token> header on every request.
  4. 4Every module — Playground, Debugging, Analytics, Idea Validator — trusts this same token.
Tokens are bearer credentialsAnyone holding a valid token can act as that user. Keep DEVMATRIX_API_KEY and session tokens server-side or in secure storage — never in client-exposed code.

For the exact request and response shapes, see API Reference → Authentication.