# Authentication

Passwords use Argon2id. Access tokens expire after 15 minutes by default.
Refresh tokens are opaque, SHA-256 hashed at rest and rotated on every refresh.
Sessions can be revoked without changing user credentials. HttpOnly, SameSite
cookies are Secure in production. Login and registration are rate limited.

Roles map to extensible permissions, with optional membership-specific additions.
All authorization is repeated server-side.
