Authentication & sessions
Sessions, CSRF protection, login flows, API tokens and rate limiting all slot into your request pipeline as composable steps. You can see exactly how every route is protected in one place, instead of hunting through handlers.

