Java Spring Authentication and Notifications Microservices Development
Budget: €2 – €6 EUR
What we’re building
A standalone Authentication microservice with event-driven orchestration via Kafka and a separate Notifications microservice for OTP delivery (email/SMS/push). It issues short-lived access tokens and manages MFA, sessions, and security audits for a broader microservices platform.
Why it matters
Secure, reliable identity is the foundation of everything else. We’re building a clean, standards-aligned auth core that’s easy to integrate, scales horizontally, and is pleasant for developers to extend and operate.
Core components
Auth Service (REST APIs): sign-up, login, MFA, token issuance/rotation, session/device management, admin endpoints.
Kafka topics: auth events & commands; notifications commands & delivery events.
Notifications Service: templated OTP and security alerts via pluggable providers (SMTP/SMS/push).
State & cache: SQL DB for identities/sessions; Redis for short-lived artifacts (OTP, rate limiting).
Observability: structured logs, metrics, traces; correlation IDs across services.
Guiding principles
Security first: OWASP ASVS L2+, robust password hashing, strict token scopes, privacy by design.
Event-driven: Everything important emits an event; side effects handled by subscribers.
Stateless where possible: Scale via replicas; state isolated to DB/Redis/Kafka.
Clean contracts: OpenAPI for REST, AsyncAPI for events. Backward-compatible changes.
Tech you’ll touch
APIs: REST (+ webhooks optional), JWT access tokens, opaque refresh tokens with rotation.
MFA: TOTP by default, OTP via email/SMS; WebAuthn/FIDO2 optional.
Platform: Kafka, SQL (PostgreSQL/MySQL), Redis, containerized runtime, CI/CD, Prometheus/Grafana, OpenTelemetry.
Reliability targets
High availability of auth paths; OTP delivery with retries and dead-letter queues.
Clear RTO/RPO objectives, tested restoration runbooks, and immutable audit logs.
What you’ll do
Ship features in auth flows (registration, MFA UX, session management).
Extend event schemas and consumers; improve delivery guarantees.
Harden security controls and observability; reduce p95 latencies.
Evolve admin tooling (search, exports, audits) and RBAC.
What we value
Pragmatic engineering and crisp interfaces.
Testability (unit/integration/contract), measurable SLOs.
Empathy for downstream teams integrating our service.
Nice to have
Experience with identity (OAuth2/OIDC), Kafka, distributed tracing, and secure coding practices.
Familiarity with delivery pipelines, blue/green or canary releases.
Where we are & what’s next
Specs drafted; baseline schemas defined.
Next milestones: finalize contracts (OpenAPI/AsyncAPI), ship MFA flows, productionize notifications, and tighten observability.
If this sounds like your kind of work—high-impact security primitives, clear contracts, and real scale—let’s talk.
A standalone Authentication microservice with event-driven orchestration via Kafka and a separate Notifications microservice for OTP delivery (email/SMS/push). It issues short-lived access tokens and manages MFA, sessions, and security audits for a broader microservices platform.
Why it matters
Secure, reliable identity is the foundation of everything else. We’re building a clean, standards-aligned auth core that’s easy to integrate, scales horizontally, and is pleasant for developers to extend and operate.
Core components
Auth Service (REST APIs): sign-up, login, MFA, token issuance/rotation, session/device management, admin endpoints.
Kafka topics: auth events & commands; notifications commands & delivery events.
Notifications Service: templated OTP and security alerts via pluggable providers (SMTP/SMS/push).
State & cache: SQL DB for identities/sessions; Redis for short-lived artifacts (OTP, rate limiting).
Observability: structured logs, metrics, traces; correlation IDs across services.
Guiding principles
Security first: OWASP ASVS L2+, robust password hashing, strict token scopes, privacy by design.
Event-driven: Everything important emits an event; side effects handled by subscribers.
Stateless where possible: Scale via replicas; state isolated to DB/Redis/Kafka.
Clean contracts: OpenAPI for REST, AsyncAPI for events. Backward-compatible changes.
Tech you’ll touch
APIs: REST (+ webhooks optional), JWT access tokens, opaque refresh tokens with rotation.
MFA: TOTP by default, OTP via email/SMS; WebAuthn/FIDO2 optional.
Platform: Kafka, SQL (PostgreSQL/MySQL), Redis, containerized runtime, CI/CD, Prometheus/Grafana, OpenTelemetry.
Reliability targets
High availability of auth paths; OTP delivery with retries and dead-letter queues.
Clear RTO/RPO objectives, tested restoration runbooks, and immutable audit logs.
What you’ll do
Ship features in auth flows (registration, MFA UX, session management).
Extend event schemas and consumers; improve delivery guarantees.
Harden security controls and observability; reduce p95 latencies.
Evolve admin tooling (search, exports, audits) and RBAC.
What we value
Pragmatic engineering and crisp interfaces.
Testability (unit/integration/contract), measurable SLOs.
Empathy for downstream teams integrating our service.
Nice to have
Experience with identity (OAuth2/OIDC), Kafka, distributed tracing, and secure coding practices.
Familiarity with delivery pipelines, blue/green or canary releases.
Where we are & what’s next
Specs drafted; baseline schemas defined.
Next milestones: finalize contracts (OpenAPI/AsyncAPI), ship MFA flows, productionize notifications, and tighten observability.
If this sounds like your kind of work—high-impact security primitives, clear contracts, and real scale—let’s talk.