Playground API
DocsStatsBlogStudio
Documentation Tree
Technical BlogFeature Deep Dives
  • Introduction
  • Quickstart
    5 min
  • How It Works
  • Recipes & Cookbooks
  • Platform Comparisons
  • Real-World Showcase
  • Interactive Studio
    Studio
  • GraphiQL IDE
    IDE
  • Session Quotas & Activity
  • Network Chaos Simulator
  • Atomic Sandbox Reset
  • Overview & Models
    Hub
  • Users Resource
  • Posts Resource
  • Comments Resource
  • Todos Resource
  • Custom Collections
    Custom
  • Multipart File Uploads
    Upload
  • Dynamic SVG Avatars
    SVG
  • Image Thumbnails
    CDN
  • Relational Filtering
  • Full-Text Search
  • Dynamic Sorting
  • Offset Pagination
  • Cursor Pagination
    Scroll
  • CSV & Excel Export & Import
    IO
  • Custom Collections
    CRUD
  • Overview & Architecture
    Hub
  • JWT Auth Flow
  • Refresh Token Rotation
    Mutex
  • RBAC Permission Matrix
    Roles
  • Expiry Simulation
  • Clock Skew Drift
  • Password Recovery Loop
  • Dual-Mode Sandboxing
  • GraphiQL IDE
    IDE
  • Relational Queries
  • Stateful Mutations
  • Realtime Subscriptions
  • Overview & Flowcharts
    Hub
  • Hosted Checkout
    Stripe
  • Payment Intents API
  • 3DS Challenge Modal
    Modal
  • Customers Vault
  • Charges & Refunds
  • Test Cards Catalog
  • Overview & Channels
    Hub
  • Virtual Email Mailbox
    Mailtrap
  • Virtual SMS Terminal
    Phone
  • In-App Notifications
  • Message Dispatcher
  • Realtime Studio
    Studio
  • Native WebSocket (/ws)
  • Socket.io Gateway
  • Presence & Echo Bot
  • Server-Sent Events (SSE)
    SSE
  • Analytics Telemetry
  • Webhook Subscriptions
  • HMAC SHA-256 Signatures
  • Delivery Logs
  • Manual Retry Simulator
  • Network Latency Delay
  • HTTP Status Codes
  • Rate-Limit Simulator
    429
  • Flaky Network & Jitter
    Chaos
  • Session Quotas & Activity
  • JSON Snapshots
    JSON
  • Headless CI/CD Testing
    CI
  • Mobile QR Code Sync
  • System Metrics & Health
  • Atomic Sandbox Reset
  • Official TypeScript SDK
  • Multi-Language Generators
  • DevTools Extension
  • OpenAPI 3.1 Spec
    JSON
  • Postman Collection v2.1
  • Bruno Collection
  • Insomnia Workspace
  • TypeScript .d.ts
    .d.ts
  • AI Prompt Rules
    Rules
  • Context Index (llms.txt)
  • Full Schema (llms-full.txt)
  • Manifest (product.json)
  • All Feature Articles
    Blog
  • React CRUD Without Backend
    Deep Dive
  • Why Static APIs Fail
  • Mocking Stateful Auth
  • WebSockets & SSE Guide
Technical Blog
Articles

In-depth articles explaining stateful mock APIs, WebSockets, payments, and frontend resilience.

Read Articles
PreviousCustom Collections
NextJWT Auth Flow
Auth & Security Architecture

Authentication & Cryptographic Security

Production-grade mock authentication loops with HMAC-SHA256 signed JWTs, copy-on-write profile updates, atomic token rotation with reuse detection, and 4-tier RBAC permission enforcement.

Signature Algorithm

HS256

HMAC-SHA256 tamper-evident
Token Lifetimes

15m / 7d

Access vs Refresh TTL
RBAC Tiers

4 Roles

Admin, Editor, Viewer, Guest
Rotation Security

Atomic

Automatic reuse invalidation
JWT Authentication & Refresh Token Rotation Loop
Security Lifecycle
Playground API JWT Authentication and Refresh Token Rotation Workflow Diagram
Click to expand full architecture
Dual-token lifecycle: Access token expiry triggers client mutex locks and atomic refresh token family rotation.Interactive High-Resolution Flowchart
1Dual Token

Login & Token Issuance

Submitting credentials issues a 15-minute access token and a 7-day refresh token pair.

2Bearer Auth

Protected API Access

Client sends Bearer token. When expired, API responds with 401 Unauthorized.

3Mutex Rotation

Mutex Lock & Token Rotation

Client queues parallel requests, calls /auth/refresh, rotates token family, and retries.

Authentication Modules & Test Guides

Select a specialized security guide below to explore interactive testing playgrounds, token decoders, and code interceptors:

HS256

JWT Authentication Flow

Dual-token access & refresh authentication flow. Issue HMAC-SHA256 signed access tokens with custom TTLs, verify claims, and authenticate protected routes.

POST /api/v1/auth/login
Mutex Lock

Refresh Token Rotation

Silent token refresh with automatic rotation. Guards against token reuse attacks and handles parallel 401 request storms with concurrency mutex locks.

POST /api/v1/auth/refresh
4 Roles

RBAC Permission Matrix

Role-Based Access Control and granular scope matching. Test Admin, Editor, Viewer, and Guest personas with simulation headers and 403 Forbidden checks.

GET /api/v1/auth/roles
TTL Control

Expiry Simulation

Simulate instant or ultra-short token lifetimes (5s, 10s, 1m) without waiting. Test frontend auto-refresh interceptors and session timeout UX.

Header: X-Simulate-JWT-Expiry
NTP Drift

Clock Skew Drift

Model distributed clock drift (+120s, -60s) between client devices and authentication servers to validate token acceptance tolerance windows.

Header: X-Simulate-Clock-Skew
OTP & Inbox

Password Recovery Loop

Full password reset workflow. Trigger forgot-password requests, inspect single-use recovery tokens in your virtual email inbox, and submit new passwords.

POST /api/v1/auth/forgot-password
Isolation

Dual-Mode Sandboxing

Understand how Playground API combines visitor session sandboxes with user-level overlays for multi-tenant simulation without seed cross-talk.

Cookie: pg_identity

Built-in Personas & Test Credentials

Use these built-in test personas to immediately test authentication, token issuance, and RBAC authorization without registering custom accounts:

Role TierUsernameEmailPasswordDefault ScopesCapabilities
adminadminadmin@example.comPassword@123*Unrestricted full access to all resources and destructive operations
editoreditoreditor@example.comPassword@123*:read, *:writeCan read, create, and update records; 403 Forbidden on delete and reset
viewerviewerviewer@example.comPassword@123*:readStrict read-only permissions; 403 Forbidden on any POST, PUT, PATCH, DELETE
guestanonymousguest@example.com-public:readUnauthenticated public visitor; 401 Unauthorized on protected resources

REST Authentication API Reference

Complete specification of all available authentication, profile management, and RBAC discovery routes:

Method & PathRequired AuthOperationDescription
POST/api/v1/auth/loginNone (Public)Authenticate & Receive TokensAuthenticate with username/email & password. Returns 15-minute access token and 7-day refresh token. Supports token_ttl and simulation headers.
POST/api/v1/auth/registerNone (Public)Register Custom Mock UserCreate a new user record in your session overlay and receive immediate signed JWT auth tokens for testing signup workflows.
POST/api/v1/auth/refreshRefresh TokenRotate Refresh & Access TokensExchange a valid refresh token for a fresh access token. Employs token family rotation; consumed tokens trigger REFRESH_TOKEN_REUSED (401).
GET/api/v1/auth/meBearer <token>Get Current User ProfileVerifies the Bearer JWT access token and returns the current authenticated user profile, assigned role, and granular scopes.
PATCH/api/v1/auth/meBearer <token>Update Current User ProfileApplies partial profile updates (name, email, bio, website) for the authenticated user. Diffs persist within your session overlay.
GET/api/v1/auth/rolesNone (Public)Get Supported Roles & PersonasDiscovery endpoint returning all built-in RBAC roles (admin, editor, viewer, guest), persona credentials, and default capability scopes.
GET/api/v1/auth/permissionsNone (Public)Get Granular Permission MatrixReturns the system permission matrix, allowed HTTP verbs per role, and wildcard matching syntax (*:read, posts:*).
POST/api/v1/auth/forgot-passwordNone (Public)Request Password Reset LinkDispatches a password recovery token and branded HTML reset link to the simulated virtual mailbox (/inbox/messages).
POST/api/v1/auth/reset-passwordReset TokenConfirm New PasswordSubmits a recovery token with the new password. Invalidates previous tokens and confirms updated password credentials.

Interactive Auth Request Runner

Execute live requests directly against the authentication endpoints:

POST

Register New Mock User (/auth/register)

Registers a brand-new user in your session sandbox overlay and returns immediate access & refresh JWTs:

Register Mock User

POST
response.json
1
{
2
// Click "Send" above to execute this request against the live server.
3
}
PATCH

Update Authenticated Profile (/auth/me)

Apply partial attribute updates for the authenticated user. Pass your issued token in the Authorization header or rely on your active session cookie:

Update Profile Attributes

PATCH
response.json
1
{
2
// Click "Send" above to execute this request against the live server.
3
}
GET

Roles Discovery (/auth/roles)

Inspect built-in personas, descriptions, and default scope arrays:

Query Supported Roles

GET
response.json
1
{
2
// Click "Send" above to execute this request against the live server.
3
}
GET

Permission Matrix (/auth/permissions)

Retrieve the full granular action matrix and wildcard scope definitions:

Query Permission Matrix

GET
response.json
1
{
2
// Click "Send" above to execute this request against the live server.
3
}