WorkOS AuthKit & Keys
Memron utilizes WorkOS AuthKit for seamless authentication (SSO, OAuth, Magic Links, Passkeys) combined with SHA-256 API key authentication for agent clients.
WorkOS AuthKit Flow
Users authenticate via the Next.js frontend at /login or /sign-up. WorkOS delivers verified session credentials which are encrypted into secure HTTP-only cookies (wos-session). User profiles are synced into PostgreSQL and linked to workspace organizations.
Agent API Key Authentication
Agent clients authorize against /mcp using standard HTTP Bearer tokens: Authorization: Bearer mm_live_<hash>. The server extracts the token, computes SHA256(token), checks the in-memory authorization cache (5-minute TTL), and queries api_keys on cache miss with sub-5ms total latency.