← Back to all projects

07 · Identity · Notion + Miro/PDF

Auth Architecture

The application could not complete /logout in Okta and therefore could not reliably close the Okta session. The proposed design keeps Okta as the user-management source of truth, changes existing flows minimally and avoids storing passwords.

Project context — organizations, products, and platforms evidenced in the source

MRG logoMRG
AOAdmitONE Original
OOkta
AAdmitOne
Role
Solutions Architect · Front-End · Back-End · Dev Ops
Domain
Identity
Sources
Notion + Miro/PDF
Published artifacts
6
Evidence archiveEnd-to-end AdmitONE / Okta identity-provider, validation and audit-session architecture.
End-to-end AdmitONE / Okta identity-provider, validation and audit-session architecture.
End-to-end AdmitONE / Okta identity-provider, validation and audit-session architecture.

Context

The problem and its boundary.

Federated identity and user-creation journey connecting AdmitOne and Okta.

The authenticated board is in Alexsandro's corpus and was last modified by him; no explicit in-frame role credit was observed.

Treat as project evidence, not as proof of exclusive implementation.

Decisions & deliverables

  1. Initial modular user-management architecture sketch
  2. Next-Auth provider design for Google, Okta and Facebook
  3. Application-database user existence validation
  4. Okta user existence validation and API-based creation
  5. Provider-to-user linkage validation
  6. Okta activation-email flow
  7. Audit-session model for login, logout, signup and modify events
  8. Frontend/backend architecture and SSO integration work declared in the responsibilities section
  9. Components and endpoints declared in the responsibilities section
  10. identity federation
  11. user provisioning
  12. creation journey

Technology

  • TypeScript
  • MongoDB
  • ReactJS
  • Next.js
  • Mongoose ODM
  • JavaScript

What this archive can prove

Published authorship. Claims proportional to the source.

  • The page calls the design an initial sketch; it does not prove delivery or production deployment.
  • No repository, implementation metrics, date, scale or post-launch result is present.
  • The responsibilities list includes broad components/endpoints but does not connect each one to this authentication proposal.