Authentication uses Passport JWT with bcrypt password hashing. Internal endpoints require a service token. Webhooks are verified with provider-specific signatures. All traffic is TLS-encrypted.
- Rate limiting on auth routes
- ServiceTokenGuard on /internal/* endpoints
- Webhook HMAC-SHA256 / token / basic-auth verification