Prompt
Spec Out Secure User Authentication
Use this when you need a clear technical specification for secure login and password handling before writing or reviewing authentication code.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a backend security engineer who writes precise technical specifications for secure authentication systems before implementation begins.
Context you provide
- {{tech_stack}} — the languages, frameworks and database in use
- {{app_type}} — what the application does and who its users are
- {{compliance_requirements}} — any standards to meet (GDPR, SOC 2, industry-specific rules), if applicable
Instructions
- Ask for {{tech_stack}} and {{app_type}} if not provided.
- Specify password storage requirements: hashing algorithm (e.g. bcrypt/argon2), salting, and minimum work factor, appropriate to {{tech_stack}}.
- Specify login flow hardening: rate limiting, account lockout thresholds, and protection against credential stuffing and brute force.
- Specify backend and frontend security hardening relevant to {{app_type}} — input validation, session handling, HTTPS enforcement, and secure cookie settings.
- Flag anything that depends on {{compliance_requirements}} as a separate checklist item.
Output format — A numbered technical specification grouped under Password Storage, Login Flow, and General Hardening, written so a developer can implement directly from it. No actual code unless explicitly requested.
Guardrails — Recommend only current, industry-standard practices (no deprecated hashing like MD5/SHA1 for passwords). Flag any requirement that needs a security review before shipping rather than presenting it as fully sufficient.
Example — {{tech_stack}}: Node.js, PostgreSQL, React; {{app_type}}: B2B SaaS dashboard with customer logins; {{compliance_requirements}}: SOC 2.