Choose how your React app will handle identity, sessions, and permissions. This page compares approaches and providers. Once you have chosen an approach, use Implement Authentication in React for the application workflow.
Build your own authentication system using TanStack Start's server functions and session management. Start with the Authentication Server Primitives guide — it covers session cookies (HttpOnly/Secure/SameSite/__Host-), session lookup as middleware, OAuth state + PKCE, password-reset enumeration defense, CSRF, rate limiting, and session rotation, with the WRONG/CORRECT patterns that catch the common mistakes.
Full Control: Complete customization over authentication flow
Use HTTPS in production and set a strong session secret.
Store sessions in HttpOnly, Secure, SameSite cookies. Do not store session tokens in localStorage or sessionStorage.
Enforce auth in every server function, server route, or API endpoint that reads or writes private user, tenant, or account data. Use beforeLoad for page UX, not as the data boundary.
Use .validator() on every server function that accepts input.
Hash passwords with bcrypt, scrypt, or Argon2. For missing users, verify against a dummy hash and return the same login/reset message.
Rate limit login, registration, and password-reset endpoints.
Use CSRF or same-origin protections for non-GET server functions and server routes.
Log authentication events and monitor failures.
Test direct unauthenticated calls to protected server functions; they should reject before returning data.