Design Authentication Infrastructure for mobile apps

Last updated: January 10, 2026

Quick Overview

Design a multi-tenant authentication system that handles millions of requests. Discuss trade-offs in consistency, availability, and performance.

Stripe
System Design
Software Engineer
Stripe
January 10, 2026
Software Engineer
Onsite
System Design
Hard

75

2

597 solved


Design a multi-tenant authentication system that handles millions of requests. Discuss trade-offs in consistency, availability, and performance.

System design interviews at Stripe typically last 45-60 minutes. You are expected to drive the conversation, starting from requirements gathering through to a detailed architecture. The interviewer will evaluate your ability to handle ambiguity and make practical engineering decisions.

What the Interviewer Expects
  • Drive the design discussion proactively with minimal interviewer guidance
  • Perform detailed capacity estimation and use it to inform design decisions
  • Design for global scale with multi-region deployment and data consistency
  • Deep dive into 2-3 critical components with implementation-level detail
  • Address complex trade-offs: CAP theorem, eventual consistency, conflict resolution
  • Discuss operational excellence: deployment strategy, chaos engineering, SLOs/SLIs
  • Propose a phased rollout plan from MVP to full-scale system
Key Topics to Cover
API design and rate limiting
Consistency models and replication
Failure handling and fault tolerance
High-level architecture and component design
How to Approach This
  1. Start by clarifying functional and non-functional requirements with the interviewer.
  2. Estimate the scale: QPS, storage, bandwidth. This drives your design decisions.
  3. Draw a high-level architecture first, then deep dive into 1-2 critical components.
  4. Discuss trade-offs explicitly (e.g., consistency vs availability, SQL vs NoSQL).
  5. Address failure scenarios, monitoring, and how the system handles 10x traffic spikes.
Possible Follow-up Questions
  • What monitoring and alerting would you set up on day one?
  • How would you implement rate limiting to protect the system?
  • How would you handle a region-wide outage?
  • How would you optimize costs as the system scales?
Practice a Similar Problem on Codemia

Solve a related problem with our interactive workspace, get AI feedback, and view detailed solutions.

Solve on Codemia
Sample Answer
Requirements

Functional Requirements

  1. User Authentication: Support login, registration, password reset, and multi-factor authentication (MFA).
  2. API Rate Limiting: Implement rate limiting to prevent...
Capacity Estimation

Back-of-Envelope Calculations

  1. User Base: Assume 1 million active users with 3 authentication requests per user per day.
  2. Total Requests: 1,000,000 users * 3 requests = 3,000,000 reque...

Submit Your Answer
Markdown supported

Related Questions