How are admin sign-ins protected?

Quick answer

Admin panel sign-in uses a one-time code sent to the user's email, or Sign In With Google, with no passwords to steal or reuse. Sessions use short-lived access tokens and refresh tokens that rotate on every use, so a stolen refresh token that is replayed is rejected. API keys are separate, scoped and revocable.

Detailed answer

The panel avoids the most common account risks by not having passwords at all.

Sign-in methods

  • Email and one-time code: the code expires quickly and works once.
  • Google: Google verifies the email address; PropExecutor checks the token's signature, audience and that the email is verified.

Sessions

  • Access tokens carry the firm and the user's role.
  • Refresh tokens are stored as secure, HTTP-only cookies.
  • Every refresh replaces the refresh token and revokes the old one, so a copied token stops working once the real user refreshes.

Rate limiting

Requests are rate limited, including by IP for unauthenticated routes, which slows guessing attempts.

API keys

  • Created per system with chosen scopes.
  • The token is shown once.
  • Revocable at any time.

Your side

  • Protect the email accounts your team signs in with, ideally with two-factor authentication.
  • Remove users who leave.

PropExecutor team · Updated

All 11 questions in Security, data and reliability · Every category