Understanding Authentication & Refresh Tokens
This template ships with a complete authentication flow: email/password login, role-based permissions, and secure refresh token rotation.
How it works
When a user logs in, they receive a short-lived access token used to authorize API requests, along with a refresh token used to obtain new access tokens without requiring the user to log in again. Refresh tokens are rotated on each use and stored securely, reducing the risk of token theft and replay.
Roles and permissions
Access to admin features is controlled by roles and permissions, so you can define exactly what each type of user is allowed to see and do.
Artikel Terkait
Getting Started with This Template
A quick tour of the stack — Next.js, Hono, Drizzle ORM, and PostgreSQL — and how the pieces fit together.
Why We Use Hono for the API Layer
A look at why this template pairs Next.js with Hono instead of relying solely on Next.js route handlers.