Browse documentation

Additional tools

Security concepts

How route protection and role guards should behave.

Mark which parts of the application require sign-in and which roles may reach them. Nodlume generates the matching auth wiring and role guards for the pages and routes you protect, so access rules are expressed on the canvas rather than bolted on afterward.

Protected pages guard the whole route; protected API routes answer with a 403 instead of redirecting, matching how each is meant to behave.

We'd like to use Google cookies to understand how Nodlume is used and to measure our advertising. Nothing loads until you choose, and declining does not affect anything in the app.