Gapido Backend Challenge

The problem

Secure OTP auth for microservices

Python • gRPC • MongoDB • Redis • RabbitMQ • Docker

Constraints

What had to be proven

Solution shape

Service architecture

Service architecture

Code organization

Clean architecture layers

Clean architecture layers

Auth flow

OTP without storing plaintext codes

OTP login flow

Token safety

Refresh token rotation

Refresh token rotation

Extensibility

Selectable SMS providers

SMS provider strategy

Deployment

Only Caddy is public

Production deployment

Reliability

What makes it reviewable

Outcome

Interview-ready microservice demo

A focused auth service with clean boundaries, secure OTP, async messaging, provider strategy, and production deployment posture.