About Neuctra Authix

Auth and user data, without a backend

Neuctra Authix is a hosted API that handles signing users up, signing them in, and storing their data — so a small team can ship a real product without first building an auth service and a database layer behind it.

Why we built it

Every project starts the same way: a login form, a users table, password hashing, a session, a password reset that has to invalidate old sessions, then a place to put the data those users create. It is a fortnight of work before the first feature, and it is the same fortnight every time — with the security-critical parts easy to get subtly wrong.

Neuctra Authix is that fortnight, already done and reused.

Who it's for

Indie developers, small teams and agencies shipping web and mobile apps — the people for whom a dedicated backend is overhead rather than an asset. It suits a SaaS MVP, an internal tool, a client project or a Flutter app that needs accounts and somewhere to keep their data.

If you need SAML, an audit certification or a signed uptime commitment, we would rather tell you now than after you have built on us.

How it works

Four steps, and the whole model fits in them.

  1. 1

    Create an app

    One app per product or environment. Each has its own users, isolated from every other app on your account.

  2. 2

    Take your keys

    An API key for client code, an API key for your server. Shown once, stored only as a hash.

  3. 3

    Call the SDK

    Sign up, sign in, check the session. The server sets an HttpOnly cookie and verifies it on every request.

  4. 4

    Store their data

    Write JSON per user or per app. Search it, page through it, update it safely with versions.

What makes it different

One account API key

An API key is pinned by the server to the signed-in user's own data, so shipping it in a mobile app or a browser bundle is safe by design. API keys stay on your server. Every key is stored only as a hash.

Auth and data in one place

Most auth services hand you an identity and stop. Neuctra Authix also stores your users' records — schemaless JSON with search, pagination, optimistic versioning and atomic batches — so a small app needs one backend, not two.

Sessions without a session table

A session is a signed token in an HttpOnly cookie, verified on every request. Nothing to look up, nothing to clean up — and “sign out everywhere” works by invalidating every token at once.

Four SDKs, one API

JavaScript and TypeScript, Python, Dart and Flutter, plus pre-built React components. The same concepts and the same error codes in every one, so switching platforms is not relearning the product.

What Neuctra Authix does, and doesn't

You are going to find out either way. Better here than three weeks into an integration.

It does

  • Email and password sign-up, sign-in and email verification
  • Password reset, with every existing session revoked
  • HttpOnly cookie sessions with server-side revocation
  • Unified API keys, hashed at rest
  • Per-user and app-wide JSON storage
  • Keyset pagination, indexed search, versioning and batch writes
  • Usage tracking and plan limits you can see in the dashboard

It doesn't

  • Social and enterprise sign-in (OAuth, SAML, Google, GitHub)
  • Multi-factor authentication for your end users
  • Passwordless, magic-link or biometric sign-in
  • Self-hosting — Neuctra Authix is a hosted service only
  • A compliance certification (SOC 2, ISO 27001, HIPAA)
  • A contractual uptime guarantee on any plan

What it runs on

Neuctra Authix is hosted on Vercel with a PostgreSQL database on Neon in AWS US East. There is one database region, not several — so if you serve users far from the United States, expect the round trip to reflect that. We would rather you plan for it than be surprised by it. The full list of providers is in the privacy policy.

Start on the free plan

Two apps, a hundred users each, no card required. Enough to build something real and decide for yourself.