Problem
Client apps need predictable authentication and error responses across several banking workflows. Duplicated OTP handling and inconsistent validation make changes harder to maintain.
My contribution
Unified OTP handling across login and registration using a common provider interface. Implemented structured domain errors, English and Arabic messages, and consistent validation responses. Also worked on account and registration webhook behavior.
Engineering decisions
- A shared OTP interface keeps authentication and registration callers separate from provider-specific behavior.
- Domain error codes are separate from English and Arabic display messages.
- A common exception and validation layer gives clients a predictable response shape.
- Account and registration workflows integrate with other banking services.
Outcome
Authentication and registration can use the same OTP API, while client applications receive structured errors instead of handling unrelated response formats.
What I learned
Stable contracts matter at failure boundaries too: provider changes and validation errors should not force every client to change.