07 · Identity · Notion + Miro/PDF
Auth Architecture
The application could not complete /logout in Okta and therefore could not reliably close the Okta session. The proposed design keeps Okta as the user-management source of truth, changes existing flows minimally and avoids storing passwords.
Project context — organizations, products, and platforms evidenced in the source
MRGAOAdmitONE Original
OOkta
AAdmitOne
- Role
- Solutions Architect · Front-End · Back-End · Dev Ops
- Domain
- Identity
- Sources
- Notion + Miro/PDF
- Published artifacts
- 6
Evidence archiveEnd-to-end AdmitONE / Okta identity-provider, validation and audit-session architecture.

Context
The problem and its boundary.
Federated identity and user-creation journey connecting AdmitOne and Okta.
The authenticated board is in Alexsandro's corpus and was last modified by him; no explicit in-frame role credit was observed.
Decisions & deliverables
- Initial modular user-management architecture sketch
- Next-Auth provider design for Google, Okta and Facebook
- Application-database user existence validation
- Okta user existence validation and API-based creation
- Provider-to-user linkage validation
- Okta activation-email flow
- Audit-session model for login, logout, signup and modify events
- Frontend/backend architecture and SSO integration work declared in the responsibilities section
- Components and endpoints declared in the responsibilities section
- identity federation
- user provisioning
- creation journey
Technology
- TypeScript
- MongoDB
- ReactJS
- Next.js
- Mongoose ODM
- JavaScript
Evidence archive
Real diagrams, interfaces and documents.
Open any artifact to inspect the full local image.
Public references
AdmitONE Original ↗What this archive can prove
Published authorship. Claims proportional to the source.
- The page calls the design an initial sketch; it does not prove delivery or production deployment.
- No repository, implementation metrics, date, scale or post-launch result is present.
- The responsibilities list includes broad components/endpoints but does not connect each one to this authentication proposal.




