Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)
    1. Docs
    2. /API
    3. /Authentication

    Updated Jul 20, 20262 min listen

    Ring Platform Logo

    Завантаження документації...

    Підготовка контенту платформи Ring

    1. Docs
    2. /API
    3. /Authentication

    Updated Jul 20, 20262 min listen

    Ring Platform Logo

    Завантаження документації...

    Підготовка контенту платформи Ring

    1. Docs
    2. /API
    3. /Authentication

    Updated Jul 20, 20262 min listen

    Ring Platform Logo

    Завантаження документації...

    Підготовка контенту платформи Ring

    Authentication API

    Use Founder / Developer tabs in the docs sidebar to filter this page.

    Ring uses Auth.js v5 for sessions and multi-provider sign-in. Product overview: Authentication. Architecture: Authentication Architecture.

    Supported providers (shipped)

    ProviderNotes
    GoogleOAuth redirect + One Tap
    Telegram (web)OIDC via oauth.telegram.org when AUTH_TELEGRAM_* set
    Telegram Mini AppCredentials telegram-miniapp — WebAppData HMAC on initData
    AppleSign in with Apple
    Ring MailerOTP / magic link / password Credentials
    Crypto walletNonce + signature Credentials

    What this API means for operators

    • Members authenticate through the login UI; you configure provider secrets, not custom REST “login” payloads.
    • Session cookies are httpOnly; browsers never hold the Auth.js AUTH_SECRET.
    • Telegram Login needs BotFather Web Login Allowed URLs — see the checklist on Authentication.
    • Mini App auth needs a bot API token (TELEGRAM_MINI_APP_BOT_TOKEN preferred); there is no stock platform Mini App shell page.
    • Admin Telegram chat control is a different surface: Manage via Telegram.

    Auth.js endpoints

    Handlers: app/api/auth/[...nextauth]/route.ts.

    Method / pathRole
    Auth.js sign-in / callback / CSRFProvider redirects and token exchange
    GET /api/auth/sessionCurrent session JSON for useSession / client
    POST /api/auth/signoutInvalidate session cookie
    GET /api/auth/callback/telegramTelegram OIDC callback (Auth.js)
    GET /api/auth/telegram/callbackProfile linking Login Widget (requires session)

    Server-side gate

    Client-side session

    Telegram client triggers

    Prefer features/auth/components/telegram-signin-button.tsx for locale-safe OIDC callbacks.

    Role hierarchy

    Related documentation

    Related documentation

    Authentication

    Prerequisite: which providers ship and how Telegram Login + Mini App are enabled.

    Authentication Architecture

    Deep-dive: adapters, OIDC + Mini App modules, and env wiring.

    Authentication Examples

    Next-step: code samples for signIn and SessionProvider.

    SubscriptionConductor

    See-also: telegram_stars membership invoices share the Mini App bot token.

    Authentication API

    Use Founder / Developer tabs in the docs sidebar to filter this page.

    Ring uses Auth.js v5 for sessions and multi-provider sign-in. Product overview: Authentication. Architecture: Authentication Architecture.

    Supported providers (shipped)

    ProviderNotes
    GoogleOAuth redirect + One Tap
    Telegram (web)OIDC via oauth.telegram.org when AUTH_TELEGRAM_* set
    Telegram Mini AppCredentials telegram-miniapp — WebAppData HMAC on initData
    AppleSign in with Apple
    Ring MailerOTP / magic link / password Credentials
    Crypto walletNonce + signature Credentials

    What this API means for operators

    • Members authenticate through the login UI; you configure provider secrets, not custom REST “login” payloads.
    • Session cookies are httpOnly; browsers never hold the Auth.js AUTH_SECRET.
    • Telegram Login needs BotFather Web Login Allowed URLs — see the checklist on Authentication.
    • Mini App auth needs a bot API token (TELEGRAM_MINI_APP_BOT_TOKEN preferred); there is no stock platform Mini App shell page.
    • Admin Telegram chat control is a different surface: Manage via Telegram.

    Auth.js endpoints

    Handlers: app/api/auth/[...nextauth]/route.ts.

    Method / pathRole
    Auth.js sign-in / callback / CSRFProvider redirects and token exchange
    GET /api/auth/sessionCurrent session JSON for useSession / client
    POST /api/auth/signoutInvalidate session cookie
    GET /api/auth/callback/telegramTelegram OIDC callback (Auth.js)
    GET /api/auth/telegram/callbackProfile linking Login Widget (requires session)

    Server-side gate

    Client-side session

    Telegram client triggers

    Prefer features/auth/components/telegram-signin-button.tsx for locale-safe OIDC callbacks.

    Role hierarchy

    Related documentation

    Related documentation

    Authentication

    Prerequisite: which providers ship and how Telegram Login + Mini App are enabled.

    Authentication Architecture

    Deep-dive: adapters, OIDC + Mini App modules, and env wiring.

    Authentication Examples

    Next-step: code samples for signIn and SessionProvider.

    SubscriptionConductor

    See-also: telegram_stars membership invoices share the Mini App bot token.

    Authentication API

    Use Founder / Developer tabs in the docs sidebar to filter this page.

    Ring uses Auth.js v5 for sessions and multi-provider sign-in. Product overview: Authentication. Architecture: Authentication Architecture.

    Supported providers (shipped)

    ProviderNotes
    GoogleOAuth redirect + One Tap
    Telegram (web)OIDC via oauth.telegram.org when AUTH_TELEGRAM_* set
    Telegram Mini AppCredentials telegram-miniapp — WebAppData HMAC on initData
    AppleSign in with Apple
    Ring MailerOTP / magic link / password Credentials
    Crypto walletNonce + signature Credentials

    What this API means for operators

    • Members authenticate through the login UI; you configure provider secrets, not custom REST “login” payloads.
    • Session cookies are httpOnly; browsers never hold the Auth.js AUTH_SECRET.
    • Telegram Login needs BotFather Web Login Allowed URLs — see the checklist on Authentication.
    • Mini App auth needs a bot API token (TELEGRAM_MINI_APP_BOT_TOKEN preferred); there is no stock platform Mini App shell page.
    • Admin Telegram chat control is a different surface: Manage via Telegram.

    Auth.js endpoints

    Handlers: app/api/auth/[...nextauth]/route.ts.

    Method / pathRole
    Auth.js sign-in / callback / CSRFProvider redirects and token exchange
    GET /api/auth/sessionCurrent session JSON for useSession / client
    POST /api/auth/signoutInvalidate session cookie
    GET /api/auth/callback/telegramTelegram OIDC callback (Auth.js)
    GET /api/auth/telegram/callbackProfile linking Login Widget (requires session)

    Server-side gate

    Client-side session

    Telegram client triggers

    Prefer features/auth/components/telegram-signin-button.tsx for locale-safe OIDC callbacks.

    Role hierarchy

    Related documentation

    Related documentation

    Authentication

    Prerequisite: which providers ship and how Telegram Login + Mini App are enabled.

    Authentication Architecture

    Deep-dive: adapters, OIDC + Mini App modules, and env wiring.

    Authentication Examples

    Next-step: code samples for signIn and SessionProvider.

    SubscriptionConductor

    See-also: telegram_stars membership invoices share the Mini App bot token.

    Canonical labels live in features/auth/user-role.ts (visitor → subscriber → member → confidential → admin → superadmin). Prefer useAuth() / hasRole helpers over hard-coding string compares in UI.

    Security notes

    • JWT session strategy; __Secure- cookie prefix in production
    • CSRF protection via Auth.js
    • Telegram OIDC: PKCE + state; widget linking: SHA256(bot_token) HMAC; Mini App: WebAppData HMAC — never mix the three
    • Do not log bot tokens, client secrets, raw id_tokens, or raw initData

    Manage via Telegram

    See-also: admin bot — not member OIDC or Mini App Credentials.

    Admin API

    See-also: admin HTTP surfaces after session + role checks.

    Canonical labels live in features/auth/user-role.ts (visitor → subscriber → member → confidential → admin → superadmin). Prefer useAuth() / hasRole helpers over hard-coding string compares in UI.

    Security notes

    • JWT session strategy; __Secure- cookie prefix in production
    • CSRF protection via Auth.js
    • Telegram OIDC: PKCE + state; widget linking: SHA256(bot_token) HMAC; Mini App: WebAppData HMAC — never mix the three
    • Do not log bot tokens, client secrets, raw id_tokens, or raw initData

    Manage via Telegram

    See-also: admin bot — not member OIDC or Mini App Credentials.

    Admin API

    See-also: admin HTTP surfaces after session + role checks.

    Canonical labels live in features/auth/user-role.ts (visitor → subscriber → member → confidential → admin → superadmin). Prefer useAuth() / hasRole helpers over hard-coding string compares in UI.

    Security notes

    • JWT session strategy; __Secure- cookie prefix in production
    • CSRF protection via Auth.js
    • Telegram OIDC: PKCE + state; widget linking: SHA256(bot_token) HMAC; Mini App: WebAppData HMAC — never mix the three
    • Do not log bot tokens, client secrets, raw id_tokens, or raw initData

    Manage via Telegram

    See-also: admin bot — not member OIDC or Mini App Credentials.

    Admin API

    See-also: admin HTTP surfaces after session + role checks.