Velora
Log in.
Continue with Google, or the email you already use. We do not ask your age again.
Google and X use OAuth2. You approve the sign-in there. Velora only receives your name and email, never that password.
or email
Age is confirmed once and stored on your file. Coming back does not ask again. Your data
Code examples
Start Google or X
Authorization code. The broker sends them to Google or X. Velora never sees that password.
import { signIn } from "@/lib/auth/client";
await signIn("grok-google", {
callbackURL: "/verify",
errorCallbackURL: "/login",
});
await signIn("grok-x", {
callbackURL: "/verify",
errorCallbackURL: "/login",
});What comes back
A code and state hit this app. A session is issued, then the member lands on verification.
GET /api/auth/oauth2/callback/grok-google
?code=...
&state=...
# denied consent returns here instead
GET /login?error=access_deniedEmail seat, then log out
Email is this app’s own login. Log out clears the session and returns to the door.
import { authClient, signOut } from "@/lib/auth/client";
await authClient.signIn.email({
email,
password,
callbackURL: "/verify",
});
await signOut("/");Refresh the seat
The refresh token stays on the server. A live access token waits. A dead refresh token means sign in again.
import { refreshSeat } from "@/lib/auth/refresh-seat";
const seat = await refreshSeat();
// "wait" access token still good
// "refreshed" new access token; refresh token rotated when the broker sends one
// "reauth" refresh token is dead
// "skip" email seat, nothing to refresh