Building our own authentication instead of using an external provider
Control sessions, revocation, and the signup flow internally without depending on an external authentication provider.
Last updated: 2026-09-18 · Owner: Flexora engineering team
Alternatives considered
- Discarded
- Delegate authentication to an external provider.
- Chosen
- Keep authentication in-house.
Decision made
Build in-house authentication with protected sessions, self-service signup, secure recovery, and session revocation.
Rationale
Full control over sessions, revocation, and signup was prioritized, accepting that those capabilities have to be maintained internally.
Frequently asked questions
- What did Pymerce decide about "building our own authentication instead of using an external provider"?
- Build in-house authentication with protected sessions, self-service signup, secure recovery, and session revocation.
- Why not just use Auth0 or another external provider?
- We looked at it, but it means handing session control, revocation, and signup to a third party. Pymerce chose to keep that control in-house, accepting the cost of building and maintaining that layer ourselves.
- Is it safe to run your own authentication?
- It can be, if you implement it with the right practices — protected sessions, secure recovery, and session revocation, which is exactly what Pymerce built. The real trade-off is that this security surface becomes your own responsibility instead of being outsourced.
- What does Pymerce control by not depending on an external provider?
- Protected sessions, self-service signup, secure account recovery, and session revocation — all handled internally, without depending on an external provider's uptime or terms of service.
Need to weigh whether building your own authentication makes sense for your system?
A technology assessment helps you weigh the control you gain against the security maintenance you take on, before you decide.