Why this ranks here. Every bank interview goes here. Token issuance,
verification, key rotation, ACL evaluation, and service-to-service identity
are the security-critical distributed-systems surface, and this has all of
them behind a schema-first protobuf contract.
Issue, verify, rotate, the surface every bank interview goes to
RS256 rather than a shared secret, so verification needs only the public JWKS and a leaked service credential cannot mint tokens. 24 authored protobuf contracts define the service-to-service surface; entitlement is a claim, never a request field.
What it is
The identity and authorization plane for a multi-mode platform: login,
registration, token issuance and refresh, ACL, per-mode entitlement sync,
billing servicers, and an identity store with a sink and adapters.
Structure
Component
Role
auth_gateway.go, bootstrap.go
Service composition and lifecycle
auth_connect_server.go, connect_adapters.go
ConnectRPC surface (gRPC + HTTP/JSON from one definition)
Generated Swift gateway templates and view-model templates are checked in, so
the mobile clients are compiled against the same contract the server serves.
One schema, three languages, generated — this is the answer to "how do you
keep clients and servers in sync" and it is already built.
The RS256 story
Asymmetric signing (RS256) rather than shared-secret HMAC means verifiers never
hold signing material. This pattern was later carried into the Billboard
Workers — [F-2] split auth into four tiers and bound identity to the
token — which shows the same security
model applied consistently across two very different runtimes.
Interview surface this opens
JWT: RS256 vs HS256, JWKS distribution, key rotation without downtime
Token revocation in a stateless-token system, and cache invalidation
ACL evaluation latency and where you cache authorization decisions
gRPC vs ConnectRPC vs REST, and generating polyglot clients from one schema
Service-to-service identity (mTLS vs signed tokens)