LADDER Auth Service

LADDER Auth Service An architecture diagram generated by Archify. Gateway · JWT verify + proxy · Architecture component · separate world Gateway JWT verify + proxy separate world Client Apps · ladder-api, cnm-cigars, etc. · Architecture component Client Apps ladder-api, cnm-cigars, etc. Hono Server · HTTP :3333 · Auth Service Boundary Hono Server HTTP :3333 Better Auth · organization + SSO + passkey · Auth Service Boundary Better Auth organization + SSO + passkey Drizzle ORM · persistence adapter · Auth Service Boundary Drizzle ORM persistence adapter PostgreSQL · identity DB :5432 · Auth Service Boundary · user/org/member PostgreSQL identity DB :5432 user/org/member Sentry · monitoring · Architecture component Sentry monitoring Health & Flags · operational routes · Auth Service Boundary Health & Flags operational routes /api/auth/* auth flows mount /health, /flags adapter SQL errors Auth Service Boundary Legend Backend Database External

Architecture

  • • Hexagonal: domain & application layer independent of infrastructure
  • • Hono HTTP server mounts Better Auth at /api/auth/*
  • • Drizzle ORM adapts Better Auth to PostgreSQL

Identity Model

  • • Global user (email unique across all projects)
  • • Organization = one LADDER project (ladder-api, cnm-cigars, etc.)
  • • Member: user ↔ org with role (admin/member)
  • • SSO provider per org, passkey global to user

Separation

  • • Auth service: owns identity DB, exposes /api/auth/*
  • • Gateway: separate world, JWT validation + proxy, rate limiting
  • • Client apps: read headers from gateway (X-User-Id, X-User-Role, X-Org-Id)