Authentication

WorkOS AuthKit login, signed rustume_session cookies, and the Cloud account boundary.

Connected deployments use WorkOS AuthKit for sign-in and a server-side session stored in PostgreSQL. Rustume Cloud configures this for hosted users; open-source operators can configure the same login flow.

Authentication flow

MethodPathDescription
GET/auth/loginCreates OAuth state cookie and redirects to WorkOS
GET/auth/callbackValidates OAuth state, exchanges the code, upserts user, sets session cookie
POST/auth/logoutDeletes session and clears cookie
GET/auth/meReturns the authenticated account record

The rustume_session cookie is signed, HttpOnly, and SameSite=Lax. It is marked Secure when the configured redirect URL uses HTTPS. OAuth state is kept in a short-lived cookie and checked during callback.

Account data stored by Rustume

WorkOS AuthKit requires an email address for every user and may receive first/last name from the identity provider (Google, GitHub, SAML SSO, etc.). Rustume syncs these fields into its own database on each sign-in so the account UI can greet the user by name.

FieldSourceStored in Rustume DBShown in UI
workos_idWorkOSYesNo
emailWorkOSYesYes
first_nameWorkOS / IdPYes (when available)Yes
last_nameWorkOS / IdPYes (when available)Yes
planPaddle / internalYesYes

WorkOS itself also retains these fields in its User Management dashboard. Deployment operators with WorkOS dashboard access can view and manage user profiles there.

What is not stored as account data

OAuth tokens, passwords, and WorkOS session metadata are never persisted by Rustume. The session cookie references an opaque server-side session ID — not identity claims.

Resume data boundary

Resume data is separate from account identity: a saved document can contain contact and employment information authored by the user. Read Cloud Storage and Encryption before operating a connected deployment.

End-to-end encryption of resume content is planned for a future release.

Operator configuration

RUSTUME_CLOUD=true
DATABASE_URL=postgres://...
WORKOS_CLIENT_ID=client_...
WORKOS_API_KEY=sk_...
WORKOS_REDIRECT_URI=https://your-domain.example/auth/callback
SESSION_SECRET=<at-least-32-characters>

If the app is behind a trusted proxy, TRUSTED_PROXY=true permits forwarding the client IP to WorkOS. Do not enable that setting for untrusted proxy headers.