ReimeiTech
REIMEITECH.
← Security Engineering
Authentication Systems

Auth done right — once.

MFA, SSO, session management, account recovery, and the messy edge cases — built on Clerk, Auth0, or WorkOS, or custom when there's a real reason. The part of your product everyone touches and nobody should have to think about.

MFA + passkeys/SSO (OIDC, SAML)/SCIM provisioning/sessions + recovery
One identity, one account, every way in.
01The idea

Auth is easy to get working and hard to get right.

A login form takes an afternoon. The rest is the iceberg: MFA that people will actually use, an SSO connection per enterprise tenant, sessions you can revoke the instant something looks wrong, a recovery flow that helps the locked-out user without becoming an attacker's front door. Then the edge cases nobody scopes — the user who changes their email, the person who signed up with a password and later logs in with Google under the same address. We build the whole system, not the form: the factors, the flows, the lifecycle, and the awkward cases, on a provider when one fits and custom when one genuinely doesn't.

02The signs

Auth went from “it works” to “it's in the way”.

Each prompt has the same answer — a system built for the hard parts, not just the login.

  • 01

    Enterprise prospects are asking for SSO

    SAML and OIDC per tenant, so a big customer onboards without a code change.

  • 02

    Account recovery is a frequent ticket

    A recovery flow redesigned to unstick users without becoming a backdoor.

  • 03

    MFA is on the roadmap

    TOTP and passkeys added without forcing them on everyone overnight.

  • 04

    Sessions can't be revoked cleanly

    A token strategy where 'kill this session now' actually works.

  • 05

    Duplicate accounts keep appearing

    Explicit linking and merge rules, so one person ends up with one account.

03What we build

The whole system, not just the login.

A provider where it fits, custom where it has to be.

Provider or custom build
01

Provider or custom build

Clerk, Auth0, or WorkOS — or a custom build when there's a real reason.

MFA + recovery flows
02

MFA + recovery flows

TOTP, passkeys, backup codes, and a recovery path that isn't a backdoor.

SSO setup
03

SSO setup

OIDC and SAML per tenant, so enterprise customers bring their own IdP.

Account lifecycle
04

Account lifecycle

Sessions, tokens, SCIM provisioning, and clean revocation.

04Defense in depth

Five stages, each a place an attacker shouldn't get through.

  1. 1Identify
  2. 2Verify
  3. 3MFA
  4. 4Session
  5. 5Recover

No single stage carries the whole weight. A stolen password fails at the second factor; a compromised session can be revoked; and recovery — the stage attackers love most — is hardened so it's never an easier way in than the front door.

05Provider or custom

The right foundation for your roadmap.

Most teams are best served by a provider, and the choice matters: Clerk for fast product-led setups, Auth0 when you need deep customisation, WorkOS when enterprise SSO and SCIM lead. We pick from your roadmap and your constraints, and we build custom only when there's a genuine reason — unusual data-residency rules, a flow no provider supports, or costs that turn against you at scale.

  • Clerk, Auth0, or WorkOS, matched to your needs
  • Custom build only when there's a real reason
  • Chosen from roadmap, not from preference
  • A foundation you won't have to redo in a year
Choosing an authentication provider
Enterprise single sign-on and provisioning
06SSO + SCIM for enterprise

Let big customers bring their own identity.

Enterprise buyers want to log in through Okta, Azure AD, or Google Workspace over SAML or OIDC, with their IT team in control. We set up SSO so each tenant can be configured without a code change, handle just-in-time user creation, and add SCIM so adding or removing a person in their IdP flows straight into your app — the difference between closing the deal and not.

  • SAML and OIDC, per enterprise tenant
  • Onboard a customer without shipping code
  • Just-in-time user creation and mapping
  • SCIM provisioning for automated lifecycle
07Sessions, tokens + recovery

The lifecycle, including the awkward parts.

We decide session and token strategy up front — lifetimes, refresh and rotation, and revocation that actually works — then build the flows around it. MFA with TOTP and passkeys, recovery that unsticks the locked-out user without becoming a backdoor, and the edge cases that quietly break auth: email change, account merge, and 'log out everywhere'.

  • Token and session strategy, decided early
  • Revocation and 'log out everywhere' that work
  • Recovery hardened against takeover
  • Email change and account merge handled explicitly
Session management and account recovery
A team building authentication carefully
Easy to get working. Built to get right.
08How we work

From login form to full system.

01

Map the requirements

We map who logs in, how, and what they're protecting — and the enterprise and lifecycle needs on the horizon.

02

Choose the foundation

Provider selection — Clerk, Auth0, or WorkOS — or a scoped custom build when there's a real reason.

03

Build the core flows

Sign-up, login, MFA, and recovery, on a session and token strategy chosen for your architecture.

04

Add enterprise + lifecycle

SSO per tenant, SCIM provisioning, and the edge cases: email change, account merge, revocation.

05

Migrate and harden

Move off the old system with zero forced logouts, then tune recovery and sessions against abuse.

09Right when

Auth stopped being a checkbox.

  • Enterprise deals need SSO and SCIM

    A prospect's security team wants their own IdP and automated provisioning, and the deal is waiting on it.

  • Account recovery is a support drain

    Locked-out users are a steady stream of tickets, and you'd rather fix the flow than keep firefighting it.

  • MFA is on the roadmap

    You know you need a second factor — TOTP, passkeys — and want it added without alienating your users.

A developer building login flows
Authentication and identity at work
10The toolkit

The right tools, used with judgement.

Providers
Clerk/Auth0/WorkOS/Custom
Protocols
OIDC/SAML/OAuth/SCIM
Factors
TOTP/Passkeys/WebAuthn/Email
Lifecycle
Sessions/Recovery/Account merge/Revocation
11Questions

The things teams ask first.

For most teams, a provider is the right call — it gets you password handling, MFA, and a hosted login that you don't have to keep patching. We help you pick the one that fits: Clerk for fast product-led setups, Auth0 when you need deep customisation, WorkOS when enterprise SSO and SCIM are the priority. We build custom only when there's a real reason — unusual data-residency rules, a login flow no provider supports, or a cost curve that genuinely turns against you at your scale. The decision should come from your roadmap, not from a preference for writing auth code.

Get auth right the first time.

Tell us how people log in today and what's forcing the focus — an enterprise deal, a pile of recovery tickets, or MFA on the roadmap. We'll pick the right foundation, build the flows and the lifecycle, and handle the edge cases before they handle you.