Architect a scalable Authentication Engine

Last updated: April 28, 2026

Quick Overview

Design a scalable authentication system that handles millions of requests. Discuss trade-offs in consistency, availability, and performance.

Booking.com
System Design
Software Engineer
Booking.com
April 28, 2026
Software Engineer
Technical Screen
System Design
Hard

8

12

388 solved


Design a scalable authentication system that handles millions of requests. Discuss trade-offs in consistency, availability, and performance.

Booking.com asks this during the Technical Screen to assess your architectural thinking. They want to see how you decompose a complex problem, choose appropriate technologies, and reason about failure modes. Strong candidates proactively discuss monitoring, alerting, and operational concerns.

What the Interviewer Expects
  • Drive the design discussion proactively with minimal interviewer guidance
  • Perform detailed capacity estimation and use it to inform design decisions
  • Design for global scale with multi-region deployment and data consistency
  • Deep dive into 2-3 critical components with implementation-level detail
  • Address complex trade-offs: CAP theorem, eventual consistency, conflict resolution
  • Discuss operational excellence: deployment strategy, chaos engineering, SLOs/SLIs
  • Propose a phased rollout plan from MVP to full-scale system
Key Topics to Cover
Partitioning and sharding strategies
High-level architecture and component design
Message queues and async processing
API design and rate limiting
Security and authentication
Requirements gathering and capacity estimation
How to Approach This
  1. Start by clarifying functional and non-functional requirements with the interviewer.
  2. Estimate the scale: QPS, storage, bandwidth. This drives your design decisions.
  3. Draw a high-level architecture first, then deep dive into 1-2 critical components.
  4. Discuss trade-offs explicitly (e.g., consistency vs availability, SQL vs NoSQL).
  5. Address failure scenarios, monitoring, and how the system handles 10x traffic spikes.
Possible Follow-up Questions
  • How would you implement rate limiting to protect the system?
  • How would you optimize costs as the system scales?
  • What would the deployment pipeline look like for this system?
  • How do you ensure data consistency across multiple services?
Practice a Similar Problem on Codemia

Solve a related problem with our interactive workspace, get AI feedback, and view detailed solutions.

Solve on Codemia
Sample Answer
Requirements
  • Functional Requirements:
    • User registration, login, and logout functionalities.
    • Support for multi-factor authentication (MFA) and password reset flows.
    • OAuth 2.0 support for third-par...
Capacity Estimation
  • User Base: Assume 200 million registered users.
  • Daily Requests: Estimate 10 million login requests daily, translating to about 115 requests per second on average. During peak hours, this c...

Submit Your Answer
Markdown supported

Related Questions