p/monocloud-for-startups-free-for-1-year
by
Riya Pariyar
most teams spend a lot of time thinking about user authentication. who can log in, how, with what credentials.
and then the services behind the scenes just... trust each other. because they're on the same network. because they're in the same VPC. because nobody questioned it when the architecture was first drawn up.
30
112
Shivangi Tripathi
I was thinking about this because it sounds like such a small product decision, but I don t think it actually is.
Someone signs up with Google. Six months later they are on their iPhone and tap Sign in with Apple. Same person, different identity provider. And if they use Hide My Email, you may not even get the same email address.
So what should the product do?
Creating a new account feels wrong because now their history, billing, settings, or subscription can end up split across two profiles. But automatically linking accounts based on email also feels risky, because now you are assuming that matching email addresses are enough proof that both identities belong to the same person. And then Apple makes it even messier because the emails may not match at all.
19
35
p/vibecoding
SYEF SID ALI BENKRIEF
Genuine question for people shipping with Lovable, Bolt, v0 or Cursor. Building fast is the whole point, but the same few problems keep showing up on freshly shipped apps when you look at them from the outside: admin or debug routes left reachable, API endpoints that return another user's data if you change an ID in the URL, Supabase or Firebase tables readable without logging in, and API keys sitting in the frontend JavaScript. None of these need a hacker to find, just someone curious with a browser. So how do you handle it? Do you have a checklist before launch, rely on the platform's defaults, ask the AI to review its own code, or ship and fix later? And which of these has actually bitten you? Disclosure: I work on external recon at Xseth, so this is my day job, but I'd really like to hear what works for people here, with or without tools.
7
2
p/general
A big part of my week is spent talking to early-stage founders about how they handle login, access, and identity, and there is a pattern I keep noticing that I want to understand better.
Almost everyone puts auth off at the start, which honestly makes sense when you are still trying to prove the product matters at all.
11
Lu Karina
Curious what the community is running for authentication/authorization in their apps (e.g. Auth0, Supabase Auth, Clerk, Firebase Auth, Cognito, etc.)
A few things I'd love to hear your take on:
What provider are you using and what's your primary stack? (e.g. Next.js + Clerk, Go + Auth0, etc.)
What's the one thing that surprised you , good or bad ?
Would you make the same call today? Especially curious if you've hit scaling pain.
For context: I'm building a B2C application with my own database layer, and currently in the process of evaluating which authentication provider best fits the architecture. Trying to understand how others are handling the auth <> database relationship and what influenced your final decision.
6
Harsh Gupta
13
Ghost Kitty
Hey there, Manuel from Nomadful here. In preparation for our upcoming launch, I wanted to open up the conversation with this simple question, all ideas welcome! I'll start with a couple of things I wish my ID could do/have:
Personalisation: It's 2025, and it's hard to think of a future where personalisation isn't key. What if I could control what I want my ID to show based on the current situation. (For example, if I need to confirm my age to access a concert venue, do I really want security staff checking on my address or nationality?)
Universal usage: Why can't we just use one ID for multiple things? Wouldn't it be useful to have some utility help you login or autofill data online based on that same ID?
Privacy: What if IDs could really be bulletproof, and never leave your phone? If stolen, that sensitive data would be gone so no one could use it against you. (Although we would still need some kind of physical copy for backups).
While I can't just yet reveal the final product, I can assure you we're building something towards these goals: a privacy-focused, digital medical ID that will definitely change the health industry for years. But we're also scaling these product to developers, restaurants and venues, to make a comprehensive authentication system.What's your take on this?
Taus Noor
49
53