Security facts
The facts on password storage, rate limiting and lockout, token lifetime, and revocation semantics.
This page states PandaAuth’s security mechanisms and their exact parameters, for integrators and security reviews. Parameter changes are recorded per release in the changelog.
Password storage and verification
- Hashing uses Argon2id with the OWASP baseline parameters: 19456 KiB of memory, 2 iterations, degree of parallelism 1; hashes are stored as PHC-standard format strings and verified with a constant-time comparison.
- Password policy: at least 10 characters, including uppercase, lowercase, a digit, and a non-alphanumeric character.
- Too many failed sign-ins triggers a temporary lockout: 5 consecutive failures lock the account for 5 minutes.
Anti-enumeration and rate limiting
- Sign-in runs equally expensive validation paths for “unknown account” and “wrong password”, eliminating the response-time side channel.
- Forgot-password follows the same issuance path and returns the same response whether or not the account exists; only real, enabled accounts actually receive an email.
- Sign-in is rate limited in memory along both IP and account dimensions; email verification codes are limited to 1 per minute and 5 per hour, with a 15-minute lockout after 5 consecutive failed verifications; codes are valid for 5 minutes and never stored in plaintext (only a hash).
Token lifetime
- Access tokens last 10 minutes; refresh tokens are issued per the client
registration (
offline_access). - Tokens support the standard revocation endpoint (
/connect/revoke). - Revocation semantics: administrative actions such as freeze/unfreeze, password reset, role changes, profile changes, 2FA reset, and account deletion immediately revoke all valid tokens for the account and refresh its security stamp — a frozen or deleted account loses access at the token level right away, rather than waiting for natural expiry.
Audit and compliance
- Administrative actions (mutations only) and administrator sign-in events are audited separately, recording the actor, the target, the source IP, and details.
- The audit log never records plaintext passwords or verification codes.
Reporting security issues
Please do not submit vulnerability details publicly; contact us via the private channel.