The problem
Secure OTP auth for microservices
Python • gRPC • MongoDB • Redis • RabbitMQ • Docker
Constraints
What had to be proven
- gRPC auth boundary
- secure OTP
- refresh rotation
- role-based access
- async SMS delivery
- production deployment path
Solution shape
Service architecture
Code organization
Clean architecture layers
Auth flow
OTP without storing plaintext codes
Token safety
Refresh token rotation
Extensibility
Selectable SMS providers
Deployment
Only Caddy is public
Reliability
What makes it reviewable
- Mocked SMS providers
- gRPC tests
- RBAC coverage
- Compose validation
- Health checks
- Postman guide
Outcome
Interview-ready microservice demo
A focused auth service with clean boundaries, secure OTP, async messaging, provider strategy, and production deployment posture.