Implement or review secure authentication and session/token handling — password storage, login flows, session cookies, JWTs, refresh/rotation, MFA, and logout — use when building or auditing sign-in, session management, API tokens, OAuth/OIDC integration, or password reset, or when hardening an existing auth system defensively.