Design an Authentication System

Problem Design the system behind a login page: user signup and login, credential storage, and session management.

Functional requirements

  • Sign up with email/password; verify the email.
  • Log in and receive a session credential.
  • Log out; invalidate the session (single device and all devices).
  • Reset a forgotten password.
  • Protect against brute-force and credential-stuffing attacks.

Non-functional requirements

  • ~50M registered users; ~5M logins/day -> ~60/sec average, ~500/sec at morning peak.
  • Login p99 < 500 ms — dominated deliberately by the password hash, which must be slow.
  • Password hashing tuned to ~100-250 ms per verification (bcrypt cost ~12, or argon2id at ~64 MB). At 500 logins/sec that is a real capacity input (~50-125 CPU-seconds/sec), so size the auth tier accordingly.
  • Session validation runs on every authenticated request: ~50k QPS, p99 < 10 ms.
  • 99.99% availability — if auth is down, the entire product is down.

Areas to go deep

  • Credential storage and the choice of password KDF.
  • Session strategy: server-side sessions vs JWTs and revocation.
  • Brute-force mitigation without creating a DoS vector; enumeration/timing attacks; cookie flags; password-reset safety.
asked …
LeaderboardSalaryAccount