This clever bunny did something very similar.. (but self hosted)
https://xeiaso.net/blog/2025/anubis/
I love the approach.. If I could be arsed blogging I'd probably set it up myself.
https://xeiaso.net/blog/2025/anubis/
I love the approach.. If I could be arsed blogging I'd probably set it up myself.
I recently implemented a very similar thing to its obfuscation via proof-of-work (https://altcha.org/docs/obfuscation/) in my C++ REST backend and flutter front-end, and use it for rate-limiting on APIs that allow creation of a new account or sending sign-up e-mails.
I have an authentication token that's then wrapped with AES-GCM using a random IV and the client is given the key, IV stem and a maximum count for the IV.