Qubase Logo
Security & Access Control

Authentication, Identity & Authorization

Manage user accounts, secure authentication flows, profile settings, and enforce granular Role-Based Access Control (RBAC) across workspaces and projects.

Identity & Security

Secure Auth Workflow

Comprehensive, production-ready authentication mechanisms ensuring secure account creation, identity verification, session invalidation, and credential management.

Sign Up

Allow users to create a new account using name, email, and secure password.

Login

Allow users to securely sign in using their registered email and password.

Logout

Allow users to safely sign out and invalidate session tokens instantly.

Forgot Password

Allow users to request a secure password reset link or OTP via email.

Reset Password

Create a new password following verification with confirm matching.

Change Password

Authenticated user password updates validating current and new credentials.

Email Verification

Verify ownership of the user's email address during initial registration.

Live Preview
Encrypted

Reset Password Form

Interactive prototype of the current authorization flow.

Token Expire: 15mRate Limit: 5 req/m
Account Dashboard
Interactive
QU

Qubase Developer

user@qubase.io

Profile Settings

User Governance

Identity & Profile Management

Flexible profile management providing users full control over account settings, avatar customization, verified email updates, and data governance.

Centralized Workspace Hub

Access personal diagrams, shared team resources, and active workspace configurations from a unified navigation drawer.

Profile Customization

Seamlessly update avatar images, display names, custom handles, and time zone preferences.

Secure Email Management

Update primary email credentials safely through multi-step verification code confirmations.

Data Governance & Deletion

Self-serve permanent account removal backed by secondary password verification and safety confirmations.

Granular Security Architecture

Role-Based Access Control (RBAC)

Multi-layered permission hierarchy guaranteeing precise authorization across platform levels, workspace environments, and individual projects.

ApplicationFull Control

ROLE_ADMIN

Full management authority over platform settings, user provisioning, billing, and system logs.

Capabilities
READWRITEDELETEADMIN
ApplicationStandard

ROLE_USER

Standard user identity capable of launching personal workspaces and participating in invited teams.

Capabilities
CREATE_WORKSPACEJOIN_PROJECT
WorkspaceCreator

WORKSPACE_MEMBER

Can spin up new projects within the workspace and is automatically granted Owner privileges for created assets.

Capabilities
CREATE_PROJECTINVITE_MEMBERS
ProjectRead / Write

PROJECT_EDITOR

Full edit access to project schemas, ERDs, migration scripts, and database templates.

Capabilities
EDIT_SCHEMAEXECUTE_SQLMANAGE_ERD
ProjectRead Only

PROJECT_VIEWER

Strictly read-only access to inspect database schemas, view documentation, and review ERDs.

Capabilities
VIEW_SCHEMAEXPORT_DOCS
Inheritance rule: Project roles inherit permissions from Workspace scope.
Security Audit Docs