How do I secure login in an AI-built app?
Use your platform's auth service (Supabase Auth, Firebase Auth, Clerk, Auth0 or similar) rather than generated login code, require email verification, rate limit login and reset, make reset links single-use and short-lived, expire sessions, and offer multi-factor authentication at least for admins. Then check the server trusts the session, not a user ID from the request.
Checks
- Sign-up requires email confirmation before the account can act.
- Password reset tokens expire and are single-use.
- Errors do not reveal whether an email exists.
- Login and reset are rate limited.
- Sessions expire and logout invalidates them.
- Redirect URLs after login are limited to your domain.
- Admins use multi-factor authentication.
Mistakes in generated auth code
- Custom password storage without a proper hashing algorithm.
- JWTs verified without checking the signature or expiry.
- User ID read from the request body instead of the token.
- Magic links that work more than once.
If your app has hand-rolled auth, move it to a provider.
Choosing an auth provider
If your app builder set up authentication through Supabase Auth or Firebase Auth, keep it and configure it properly rather than replacing it: turn on email confirmation, restrict redirect URLs, set session lifetimes, and enable the provider's protections against weak or leaked passwords where offered. If the AI tool wrote its own login with a users table and password hashing, move to a managed provider. Hand-rolled auth is where the worst mistakes hide, such as tokens that never expire or reset links that can be predicted.
For business customers, plan for single sign-on. Enterprise buyers often require it, and managed providers support it without you writing the protocol code. Whatever you use, the server must take the user's identity from the verified session on every request and never from a field in the request body.
Getting it checked
TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.
Related questions
Get a scope for your app
Tell us what you built, what it stores and who is about to use it.
Get matchedCommon questions
Is social login safer?
It moves password handling to the provider, which helps. Your server still needs to verify tokens correctly.
Do I need MFA for users?
Offer it; require it for admins and staff.