HN-DB Identity & Authauth.hn-db.fun
Single sign-on and session authority for every application in the HN-DB network.
Visit live websiteInterface gallery

Executive summary & purpose
auth.hn-db.fun is the trust anchor of the infrastructure: one identity, one session, one role model shared by all 23 network domains.
The challenge
Every product carried its own login, its own password rules and its own role table — users had to re-register per app and admins had no unified view of access.
The HN Group solution
HN Group consolidated identity into a single OAuth2/OIDC provider with row-level-security-backed roles, magic links, Google sign-in and refresh-token rotation, live on its own domain within 24 hours.
Technical features
- OAuth2 / OIDC single sign-on
- Google and email magic-link providers
- Refresh-token rotation and device sessions
- Role-based access with database row-level security
- Password reset and email verification flows
- Audit log of every authentication event
API specifications
- POST /auth/v1/token — password, refresh and PKCE grants
- GET /auth/v1/authorize — OIDC authorization endpoint
- GET /auth/v1/userinfo — claims and role payload
- POST /auth/v1/logout — global session revocation
- JWKS at /.well-known/jwks.json
Technology stack
- React
- Supabase Auth
- PostgreSQL
- RLS
- TanStack Start
- Tailwind
Impact & results
Sign-up friction down 62%, support tickets about lost logins eliminated, and every new subdomain inherits auth in minutes.
Need an enterprise-grade web application or custom infrastructure like this built for your company?
Request your build now on hnsite24.online — production-ready in 24–48 hours, custom domain included.
Request your build now