Skip to main content
FLEXORA

Building our own authentication instead of using an external provider

Control sessions, revocation, and the signup flow internally without depending on an external authentication provider.

Last updated: 2026-09-18 · Owner: Flexora engineering team

Alternatives considered

Discarded
Delegate authentication to an external provider.
Chosen
Keep authentication in-house.

Decision made

Build in-house authentication with protected sessions, self-service signup, secure recovery, and session revocation.

Rationale

Full control over sessions, revocation, and signup was prioritized, accepting that those capabilities have to be maintained internally.

Frequently asked questions

What did Pymerce decide about "building our own authentication instead of using an external provider"?
Build in-house authentication with protected sessions, self-service signup, secure recovery, and session revocation.
Why not just use Auth0 or another external provider?
We looked at it, but it means handing session control, revocation, and signup to a third party. Pymerce chose to keep that control in-house, accepting the cost of building and maintaining that layer ourselves.
Is it safe to run your own authentication?
It can be, if you implement it with the right practices — protected sessions, secure recovery, and session revocation, which is exactly what Pymerce built. The real trade-off is that this security surface becomes your own responsibility instead of being outsourced.
What does Pymerce control by not depending on an external provider?
Protected sessions, self-service signup, secure account recovery, and session revocation — all handled internally, without depending on an external provider's uptime or terms of service.

Need to weigh whether building your own authentication makes sense for your system?

A technology assessment helps you weigh the control you gain against the security maintenance you take on, before you decide.