What protects every request

What protects every request A sequence diagram generated by Archify. request too many /api/ calls: refused here the rest pass on maintenance flag (memory copy, refreshed in background) MAINTENANCE_MODE=1 is read from the environment alone and needs none of this 503 maintenance page unless approved admin /, /try, /admin: who is it + approval row /admin: 404 unless admin; / to /today if signed in everyday tap or prefetch: cookie refreshed, no Auth call getViewer(): verify ES256 signature (cached JWKS) + expiry any failure = signed out (fail closed) one query: email, approval, admin, set-up row (none = account gone) Viewer, then gate: /pending, /setup, or in queries scoped to viewer.id; admin pages 404 paid AI: aiGate() + per-user rate windows allowed, or refused (fail closed) direct table call with the public key no privilege at all (migration 042) response + CSP, frame, HSTS headers Edge Proxy Who is asking Data + spend Closed doors Browser · page or action · Sequence participant Browser page or action Firewall · Vercel, /api/ per IP · Sequence participant Firewall Vercel, /api/ per IP proxy.ts · gate + session · Sequence participant proxy.ts gate + session Page / action · server code · Sequence participant Page / action server code getViewer · ES256 + JWKS · Sequence participant getViewer ES256 + JWKS Postgres · server only · Sequence participant Postgres server only Upstash Redis · flags, limits, AI · Sequence participant Upstash Redis flags, limits, AI Legend main request return security async trace message