Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Ring Oracle
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Profile Account Widgets
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Vertical Presets (SSOT)
    Ringization playbook
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel Deployment
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Backend Services
    Firebase Integration
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Ring Oracle
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Profile Account Widgets
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Vertical Presets (SSOT)
    Ringization playbook
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel Deployment
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Backend Services
    Firebase Integration
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Ring Oracle
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Profile Account Widgets
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Vertical Presets (SSOT)
    Ringization playbook
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel Deployment
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Backend Services
    Firebase Integration
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)
    Ring Platform Logo

    Loading documentation...

    Preparing Ring Platform content

    Ring Platform Logo

    Loading documentation...

    Preparing Ring Platform content

    Ring Platform Logo

    Loading documentation...

    Preparing Ring Platform content

    Authentication

    Use Founder / Developer tabs in the docs sidebar to filter this page.

    Executive summary

    Ring uses Auth.js v5 for JWT sessions and OAuth. Members can sign in with Ring Mailer (OTP / magic link / password), Google, Telegram (web OIDC or Mini App initData), Apple, or a crypto wallet. Email is not Resend — see Ring Mailer & RingdomX Mail.

    Protection model

    LayerRole
    proxy.tsLocale rewrite + optimistic redirect to ROUTES.LOGIN(locale) (cookie presence only)
    proxy.ts soft-gateIf JWT needsOnboarding === true, redirect to /{locale}/login/onboarding (exempt: /login*, /auth*, /register*, home /)
    (authenticated)/[locale]/layout.tsxawait auth() — canonical session gate
    (admin)/[locale]/layout.tsxRole check (admin / superadmin)
    /loginLoginAuthenticatedRedirect — client useSession bounce (skips during OAuth callback params)
    /registerRedirects to /login (password signup demoted; OTP/magic is the product surface)
    API routesPer-handler auth()

    OAuth callbacks live under /api/auth/* (excluded from intl middleware). See Proxy and intl.

    Login path SSOT: ROUTES.LOGIN(locale) with unified from / callbackUrl / returnTo (features/auth/components/login-authenticated-redirect.tsx).

    Vitals onboarding gate

    After first sign-in, some providers require profile vitals (name, etc.) before the rest of the app. isVitalsGatedProvider() in features/auth/lib/vitals-onboarding.ts includes:

    Provider idGated?
    google, google-one-tap, appleYes
    email-otp, email-magic, telegram, crypto-walletYes
    OthersNot in the shared gate set

    Incomplete vitals set JWT/session needsOnboarding. Client redirects (email-login-form, verify-client, wallet-connect) and the proxy soft-gate both honor it. Own profile Avatar uses editable={true} so members can finish photo vitals on /profile.

    Providers (shipped)

    ProviderHow members sign in
    Ring MailerOTP, magic link (/verify#token=…), or password — Credentials email-otp / email-magic / credentials
    GoogleOAuth redirect + Google One Tap (GIS JWT verified server-side)
    Telegram (web)OIDC Authorization Code + PKCE at oauth.telegram.org — signIn('telegram')
    Telegram Mini AppCredentials telegram-miniapp — signIn('telegram-miniapp', { initData, redirect: false })
    AppleSign in with Apple OAuth
    Crypto walletNonce + signature (crypto-wallet Credentials)

    GitHub/Discord OAuth are not in the default auth.ts provider list.

    Telegram surfaces (do not mix crypto)

    SurfacePurposeCrypto / secret
    Login via Telegram (web)Unauthenticated member opens a Ring session in the browserOIDC id_token — AUTH_TELEGRAM_ID / AUTH_TELEGRAM_SECRET
    Mini App initDataSilent session inside a Telegram WebApp clientHMAC with secret key WebAppData — bot API token (TELEGRAM_MINI_APP_BOT_TOKEN preferred)
    Link Telegram (profile)Already logged-in member binds Telegram idLogin Widget HMAC SHA256(bot_token) — ADMIN_BOT_TOKEN / TELEGRAM_LOGIN_BOT_TOKEN
    Admin botPlatform admins moderate from chatBot API + whitelist — Manage via Telegram

    Do not reuse Mini App initData (WebAppData) HMAC for Login Widget linking, and do not use Login Widget SHA256(bot_token) math for Mini App auth.

    Ring Mailer & RingdomX

    SMTP setup, Ethereal, calculator mail add-on, token migration 038.

    Architecture

    Adapter selection, JWT callbacks, Telegram OIDC modules.

    Examples

    Integrator snippets for providers and mailer flows.

    What operators need

    • At least one working sign-in path for testers (Google, Telegram, Apple, or Ring Mailer SMTP / Ethereal).
    • For white-label production, prefer domain-branded auth mail via Ring Mailer or RingdomX Mail.
    • Sessions are platform UUIDs (users.id); email can link accounts across providers when Auth.js linking is enabled. Telegram-only users may have an empty email (allowed by the partial unique index).

    Enable Telegram Login — web OIDC (BotFather checklist)

    1. Open @BotFather → your bot → Bot Settings → Web Login.
    2. Add Allowed URLs: site origin (e.g. https://your.domain) and OIDC callback https://your.domain/api/auth/callback/telegram.
    3. Copy Client ID and Client Secret into cluster secrets / .env.local as AUTH_TELEGRAM_ID / AUTH_TELEGRAM_SECRET.
    4. Keep the bot API token (ADMIN_BOT_TOKEN or TELEGRAM_LOGIN_BOT_TOKEN) for profile “Link Telegram” widget hash — it is not the OIDC client secret.
    5. Confirm login page shows Continue with Telegram and a successful redirect lands on profile (or your from URL).

    Enable Telegram Mini App auth (operator view)

    1. Create or reuse a bot that hosts the Mini App (can be the same bot as admin/login, or a dedicated one).
    2. Set TELEGRAM_MINI_APP_BOT_TOKEN to that bot’s API token (preferred). Fallbacks used by getTelegramMiniAppBotToken(): TELEGRAM_BOT_TOKEN → ADMIN_BOT_TOKEN → TELEGRAM_LOGIN_BOT_TOKEN → N9LIFE_BOT_TOKEN.
    3. Your Mini App client must call with — platform ships the Credentials provider; a stock shell page is on the main platform clone (white-labels may add their own).

    Auth.js layout

    FileRole
    auth.config.tsEdge-safe config (minimal callbacks; no providers)
    auth.tsFull providers + adapter + JWT/session/signIn callbacks
    lib/auth/telegram-oidc.tsTelegramOidcProvider, claim map, lazy JWKS verify
    lib/auth/telegram-miniapp-initdata.tsWebAppData HMAC parse/verify + getTelegramMiniAppBotToken
    lib/auth/telegram-login-widget-hash.tsLegacy widget HMAC + auth_date window
    features/auth/services/user-resolve.tsresolveOrCreateTelegramUser, syncUserTelegramCommunication, unlinkTelegramCommunication
    features/auth/components/telegram-signin-button.tsx

    Related documentation

    Related documentation

    Authentication Architecture

    Deep-dive: Auth.js file split, adapters, OIDC + Mini App modules.

    Authentication Examples

    Next-step: copy-paste signIn('telegram') and signIn('telegram-miniapp') snippets.

    Ring Mailer & RingdomX Mail

    Same-workflow: email OTP / magic link when members skip social login.

    Email AI-CRM

    See-also: community inbox SMTP is a separate plane from Auth Ring Mailer.

    Authentication

    Use Founder / Developer tabs in the docs sidebar to filter this page.

    Executive summary

    Ring uses Auth.js v5 for JWT sessions and OAuth. Members can sign in with Ring Mailer (OTP / magic link / password), Google, Telegram (web OIDC or Mini App initData), Apple, or a crypto wallet. Email is not Resend — see Ring Mailer & RingdomX Mail.

    Protection model

    LayerRole
    proxy.tsLocale rewrite + optimistic redirect to ROUTES.LOGIN(locale) (cookie presence only)
    proxy.ts soft-gateIf JWT needsOnboarding === true, redirect to /{locale}/login/onboarding (exempt: /login*, /auth*, /register*, home /)
    (authenticated)/[locale]/layout.tsxawait auth() — canonical session gate
    (admin)/[locale]/layout.tsxRole check (admin / superadmin)
    /loginLoginAuthenticatedRedirect — client useSession bounce (skips during OAuth callback params)
    /registerRedirects to /login (password signup demoted; OTP/magic is the product surface)
    API routesPer-handler auth()

    OAuth callbacks live under /api/auth/* (excluded from intl middleware). See Proxy and intl.

    Login path SSOT: ROUTES.LOGIN(locale) with unified from / callbackUrl / returnTo (features/auth/components/login-authenticated-redirect.tsx).

    Vitals onboarding gate

    After first sign-in, some providers require profile vitals (name, etc.) before the rest of the app. isVitalsGatedProvider() in features/auth/lib/vitals-onboarding.ts includes:

    Provider idGated?
    google, google-one-tap, appleYes
    email-otp, email-magic, telegram, crypto-walletYes
    OthersNot in the shared gate set

    Incomplete vitals set JWT/session needsOnboarding. Client redirects (email-login-form, verify-client, wallet-connect) and the proxy soft-gate both honor it. Own profile Avatar uses editable={true} so members can finish photo vitals on /profile.

    Providers (shipped)

    ProviderHow members sign in
    Ring MailerOTP, magic link (/verify#token=…), or password — Credentials email-otp / email-magic / credentials
    GoogleOAuth redirect + Google One Tap (GIS JWT verified server-side)
    Telegram (web)OIDC Authorization Code + PKCE at oauth.telegram.org — signIn('telegram')
    Telegram Mini AppCredentials telegram-miniapp — signIn('telegram-miniapp', { initData, redirect: false })
    AppleSign in with Apple OAuth
    Crypto walletNonce + signature (crypto-wallet Credentials)

    GitHub/Discord OAuth are not in the default auth.ts provider list.

    Telegram surfaces (do not mix crypto)

    SurfacePurposeCrypto / secret
    Login via Telegram (web)Unauthenticated member opens a Ring session in the browserOIDC id_token — AUTH_TELEGRAM_ID / AUTH_TELEGRAM_SECRET
    Mini App initDataSilent session inside a Telegram WebApp clientHMAC with secret key WebAppData — bot API token (TELEGRAM_MINI_APP_BOT_TOKEN preferred)
    Link Telegram (profile)Already logged-in member binds Telegram idLogin Widget HMAC SHA256(bot_token) — ADMIN_BOT_TOKEN / TELEGRAM_LOGIN_BOT_TOKEN
    Admin botPlatform admins moderate from chatBot API + whitelist — Manage via Telegram

    Do not reuse Mini App initData (WebAppData) HMAC for Login Widget linking, and do not use Login Widget SHA256(bot_token) math for Mini App auth.

    Ring Mailer & RingdomX

    SMTP setup, Ethereal, calculator mail add-on, token migration 038.

    Architecture

    Adapter selection, JWT callbacks, Telegram OIDC modules.

    Examples

    Integrator snippets for providers and mailer flows.

    What operators need

    • At least one working sign-in path for testers (Google, Telegram, Apple, or Ring Mailer SMTP / Ethereal).
    • For white-label production, prefer domain-branded auth mail via Ring Mailer or RingdomX Mail.
    • Sessions are platform UUIDs (users.id); email can link accounts across providers when Auth.js linking is enabled. Telegram-only users may have an empty email (allowed by the partial unique index).

    Enable Telegram Login — web OIDC (BotFather checklist)

    1. Open @BotFather → your bot → Bot Settings → Web Login.
    2. Add Allowed URLs: site origin (e.g. https://your.domain) and OIDC callback https://your.domain/api/auth/callback/telegram.
    3. Copy Client ID and Client Secret into cluster secrets / .env.local as AUTH_TELEGRAM_ID / AUTH_TELEGRAM_SECRET.
    4. Keep the bot API token (ADMIN_BOT_TOKEN or TELEGRAM_LOGIN_BOT_TOKEN) for profile “Link Telegram” widget hash — it is not the OIDC client secret.
    5. Confirm login page shows Continue with Telegram and a successful redirect lands on profile (or your from URL).

    Enable Telegram Mini App auth (operator view)

    1. Create or reuse a bot that hosts the Mini App (can be the same bot as admin/login, or a dedicated one).
    2. Set TELEGRAM_MINI_APP_BOT_TOKEN to that bot’s API token (preferred). Fallbacks used by getTelegramMiniAppBotToken(): TELEGRAM_BOT_TOKEN → ADMIN_BOT_TOKEN → TELEGRAM_LOGIN_BOT_TOKEN → N9LIFE_BOT_TOKEN.
    3. Your Mini App client must call with — platform ships the Credentials provider; a stock shell page is on the main platform clone (white-labels may add their own).

    Auth.js layout

    FileRole
    auth.config.tsEdge-safe config (minimal callbacks; no providers)
    auth.tsFull providers + adapter + JWT/session/signIn callbacks
    lib/auth/telegram-oidc.tsTelegramOidcProvider, claim map, lazy JWKS verify
    lib/auth/telegram-miniapp-initdata.tsWebAppData HMAC parse/verify + getTelegramMiniAppBotToken
    lib/auth/telegram-login-widget-hash.tsLegacy widget HMAC + auth_date window
    features/auth/services/user-resolve.tsresolveOrCreateTelegramUser, syncUserTelegramCommunication, unlinkTelegramCommunication
    features/auth/components/telegram-signin-button.tsx

    Related documentation

    Related documentation

    Authentication Architecture

    Deep-dive: Auth.js file split, adapters, OIDC + Mini App modules.

    Authentication Examples

    Next-step: copy-paste signIn('telegram') and signIn('telegram-miniapp') snippets.

    Ring Mailer & RingdomX Mail

    Same-workflow: email OTP / magic link when members skip social login.

    Email AI-CRM

    See-also: community inbox SMTP is a separate plane from Auth Ring Mailer.

    Authentication

    Use Founder / Developer tabs in the docs sidebar to filter this page.

    Executive summary

    Ring uses Auth.js v5 for JWT sessions and OAuth. Members can sign in with Ring Mailer (OTP / magic link / password), Google, Telegram (web OIDC or Mini App initData), Apple, or a crypto wallet. Email is not Resend — see Ring Mailer & RingdomX Mail.

    Protection model

    LayerRole
    proxy.tsLocale rewrite + optimistic redirect to ROUTES.LOGIN(locale) (cookie presence only)
    proxy.ts soft-gateIf JWT needsOnboarding === true, redirect to /{locale}/login/onboarding (exempt: /login*, /auth*, /register*, home /)
    (authenticated)/[locale]/layout.tsxawait auth() — canonical session gate
    (admin)/[locale]/layout.tsxRole check (admin / superadmin)
    /loginLoginAuthenticatedRedirect — client useSession bounce (skips during OAuth callback params)
    /registerRedirects to /login (password signup demoted; OTP/magic is the product surface)
    API routesPer-handler auth()

    OAuth callbacks live under /api/auth/* (excluded from intl middleware). See Proxy and intl.

    Login path SSOT: ROUTES.LOGIN(locale) with unified from / callbackUrl / returnTo (features/auth/components/login-authenticated-redirect.tsx).

    Vitals onboarding gate

    After first sign-in, some providers require profile vitals (name, etc.) before the rest of the app. isVitalsGatedProvider() in features/auth/lib/vitals-onboarding.ts includes:

    Provider idGated?
    google, google-one-tap, appleYes
    email-otp, email-magic, telegram, crypto-walletYes
    OthersNot in the shared gate set

    Incomplete vitals set JWT/session needsOnboarding. Client redirects (email-login-form, verify-client, wallet-connect) and the proxy soft-gate both honor it. Own profile Avatar uses editable={true} so members can finish photo vitals on /profile.

    Providers (shipped)

    ProviderHow members sign in
    Ring MailerOTP, magic link (/verify#token=…), or password — Credentials email-otp / email-magic / credentials
    GoogleOAuth redirect + Google One Tap (GIS JWT verified server-side)
    Telegram (web)OIDC Authorization Code + PKCE at oauth.telegram.org — signIn('telegram')
    Telegram Mini AppCredentials telegram-miniapp — signIn('telegram-miniapp', { initData, redirect: false })
    AppleSign in with Apple OAuth
    Crypto walletNonce + signature (crypto-wallet Credentials)

    GitHub/Discord OAuth are not in the default auth.ts provider list.

    Telegram surfaces (do not mix crypto)

    SurfacePurposeCrypto / secret
    Login via Telegram (web)Unauthenticated member opens a Ring session in the browserOIDC id_token — AUTH_TELEGRAM_ID / AUTH_TELEGRAM_SECRET
    Mini App initDataSilent session inside a Telegram WebApp clientHMAC with secret key WebAppData — bot API token (TELEGRAM_MINI_APP_BOT_TOKEN preferred)
    Link Telegram (profile)Already logged-in member binds Telegram idLogin Widget HMAC SHA256(bot_token) — ADMIN_BOT_TOKEN / TELEGRAM_LOGIN_BOT_TOKEN
    Admin botPlatform admins moderate from chatBot API + whitelist — Manage via Telegram

    Do not reuse Mini App initData (WebAppData) HMAC for Login Widget linking, and do not use Login Widget SHA256(bot_token) math for Mini App auth.

    Ring Mailer & RingdomX

    SMTP setup, Ethereal, calculator mail add-on, token migration 038.

    Architecture

    Adapter selection, JWT callbacks, Telegram OIDC modules.

    Examples

    Integrator snippets for providers and mailer flows.

    What operators need

    • At least one working sign-in path for testers (Google, Telegram, Apple, or Ring Mailer SMTP / Ethereal).
    • For white-label production, prefer domain-branded auth mail via Ring Mailer or RingdomX Mail.
    • Sessions are platform UUIDs (users.id); email can link accounts across providers when Auth.js linking is enabled. Telegram-only users may have an empty email (allowed by the partial unique index).

    Enable Telegram Login — web OIDC (BotFather checklist)

    1. Open @BotFather → your bot → Bot Settings → Web Login.
    2. Add Allowed URLs: site origin (e.g. https://your.domain) and OIDC callback https://your.domain/api/auth/callback/telegram.
    3. Copy Client ID and Client Secret into cluster secrets / .env.local as AUTH_TELEGRAM_ID / AUTH_TELEGRAM_SECRET.
    4. Keep the bot API token (ADMIN_BOT_TOKEN or TELEGRAM_LOGIN_BOT_TOKEN) for profile “Link Telegram” widget hash — it is not the OIDC client secret.
    5. Confirm login page shows Continue with Telegram and a successful redirect lands on profile (or your from URL).

    Enable Telegram Mini App auth (operator view)

    1. Create or reuse a bot that hosts the Mini App (can be the same bot as admin/login, or a dedicated one).
    2. Set TELEGRAM_MINI_APP_BOT_TOKEN to that bot’s API token (preferred). Fallbacks used by getTelegramMiniAppBotToken(): TELEGRAM_BOT_TOKEN → ADMIN_BOT_TOKEN → TELEGRAM_LOGIN_BOT_TOKEN → N9LIFE_BOT_TOKEN.
    3. Your Mini App client must call with — platform ships the Credentials provider; a stock shell page is on the main platform clone (white-labels may add their own).

    Auth.js layout

    FileRole
    auth.config.tsEdge-safe config (minimal callbacks; no providers)
    auth.tsFull providers + adapter + JWT/session/signIn callbacks
    lib/auth/telegram-oidc.tsTelegramOidcProvider, claim map, lazy JWKS verify
    lib/auth/telegram-miniapp-initdata.tsWebAppData HMAC parse/verify + getTelegramMiniAppBotToken
    lib/auth/telegram-login-widget-hash.tsLegacy widget HMAC + auth_date window
    features/auth/services/user-resolve.tsresolveOrCreateTelegramUser, syncUserTelegramCommunication, unlinkTelegramCommunication
    features/auth/components/telegram-signin-button.tsx

    Related documentation

    Related documentation

    Authentication Architecture

    Deep-dive: Auth.js file split, adapters, OIDC + Mini App modules.

    Authentication Examples

    Next-step: copy-paste signIn('telegram') and signIn('telegram-miniapp') snippets.

    Ring Mailer & RingdomX Mail

    Same-workflow: email OTP / magic link when members skip social login.

    Email AI-CRM

    See-also: community inbox SMTP is a separate plane from Auth Ring Mailer.

    Stars membership
    Recurring / one-shot XTR invoice via SubscriptionConductor
    Same Mini App bot token family — SubscriptionConductor
    signIn('telegram-miniapp', { initData, redirect: false })
    Telegram.WebApp.initData
    /tg-mini-app
    not
  1. Same resolver as OIDC: members get a platform UUID via resolveOrCreateTelegramUser (accounts + communication.telegramId).
  2. Privacy copy

    Soft-launch OIDC scopes are openid profile — Ring reads Telegram id, name, username, and photo. Phone is not requested until you opt into the phone scope later. Mini App auth only uses fields present in verified initData (no phone by default).

    Resend removed

    Do not create a Resend API key. AUTH_RESEND_KEY is deprecated. Configure Auth SMTP_* or EMAIL_MODE=ethereal instead. CRM inbox SMTP is a separate channel plane — see Email AI-CRM.

    /register retired

    Bookmarks to /register land on /login (locale + from / callbackUrl preserved). EmailSignupForm is removed from the auth barrel — use OTP / magic on the login form.

    Typical scenarios

    Stars membership
    Recurring / one-shot XTR invoice via SubscriptionConductor
    Same Mini App bot token family — SubscriptionConductor
    signIn('telegram-miniapp', { initData, redirect: false })
    Telegram.WebApp.initData
    /tg-mini-app
    not
  3. Same resolver as OIDC: members get a platform UUID via resolveOrCreateTelegramUser (accounts + communication.telegramId).
  4. Privacy copy

    Soft-launch OIDC scopes are openid profile — Ring reads Telegram id, name, username, and photo. Phone is not requested until you opt into the phone scope later. Mini App auth only uses fields present in verified initData (no phone by default).

    Resend removed

    Do not create a Resend API key. AUTH_RESEND_KEY is deprecated. Configure Auth SMTP_* or EMAIL_MODE=ethereal instead. CRM inbox SMTP is a separate channel plane — see Email AI-CRM.

    /register retired

    Bookmarks to /register land on /login (locale + from / callbackUrl preserved). EmailSignupForm is removed from the auth barrel — use OTP / magic on the login form.

    Typical scenarios

    Stars membership
    Recurring / one-shot XTR invoice via SubscriptionConductor
    Same Mini App bot token family — SubscriptionConductor
    signIn('telegram-miniapp', { initData, redirect: false })
    Telegram.WebApp.initData
    /tg-mini-app
    not
  5. Same resolver as OIDC: members get a platform UUID via resolveOrCreateTelegramUser (accounts + communication.telegramId).
  6. Privacy copy

    Soft-launch OIDC scopes are openid profile — Ring reads Telegram id, name, username, and photo. Phone is not requested until you opt into the phone scope later. Mini App auth only uses fields present in verified initData (no phone by default).

    Resend removed

    Do not create a Resend API key. AUTH_RESEND_KEY is deprecated. Configure Auth SMTP_* or EMAIL_MODE=ethereal instead. CRM inbox SMTP is a separate channel plane — see Email AI-CRM.

    /register retired

    Bookmarks to /register land on /login (locale + from / callbackUrl preserved). EmailSignupForm is removed from the auth barrel — use OTP / magic on the login form.

    Typical scenarios