Skip to content

Application


Email & Password

Akilibot uses a Passport.js-based authentication system with JWT tokens stored in secure HTTP-only cookies. When a user logs in, the system validates their email/password against the database using bcrypt hash comparison, then generates two JWT tokens: a short-lived access token (default 60 minutes) and a long-lived refresh token (default 90 days). These tokens are stored as secure cookies. For subsequent requests, the system extracts the JWT from cookies, validates the signature and claims using Passport's JWT strategy, and checks that the user session still exists. The system also supports automatic token refresh when the access token expires, and maintains sessions using Redis or database storage.

What clients manage vs. what the platform manages

AKILIBOT is a hosted, managed platform. Application-level access control is operated for you:

  • Accounts, sessions, and token lifecycle are handled by the platform. Clients manage users and roles inside their workspace — see Workspaces and Flows (chatflow-level authorization).
  • Deployment-level security settings — JWT secrets, SMTP email delivery for password resets, token expiry, and password-hashing parameters — are configured and rotated by the AKILI TECH SERVICES platform team. Clients never handle these secrets.

If you need a change to your organization's authentication posture (custom session expiry, SSO, dedicated SMTP sender, or forced logout), contact hello@akilibot.dev and the platform team will apply it to your workspace.

  • Flows — API-key protection for individual chatflows and the Prediction API
  • Workspaces — RBAC, roles, and user invitations