Reported September 2026
Appledesign

Design Authentication Manager

Reported by candidates from Apple's online assessment. Pattern, common pitfall, and the honest play if you blank under the timer.

Get StealthCoderRuns invisibly during the live Apple OA. Under 2s to a working solution.
Founder's read

The Apple OA reported in September 2026 hands you a token manager and asks for counts. The whole thing hinges on one hash map from tokenId to expiration time. It's LeetCode's Design Authentication Manager, reworded into a single function that takes an operations array. If you've seen the class version, you're most of the way there. If you haven't, the shape is simple: generate, renew, count, return only the counts. The traps are boundary conditions and output handling, not algorithms. StealthCoder sits invisible on your screen as a safety net if you blank during the live OA, but the logic below is short enough to hold in your head.

The problem

You are given a token lifetime timeToLive and an ordered array of authentication-manager operations operations.
Each operation is an array of three strings: [type, tokenId, currentTime]. The supported operation types are:
GENERATE: create the unique token tokenId at currentTime. Its expiration time becomes currentTime + timeToLive.
RENEW: if tokenId exists and is unexpired at currentTime, reset its expiration time to currentTime + timeToLive. Otherwise, ignore the operation.
COUNT: count the tokens that are unexpired at currentTime. For this operation, tokenId is the empty string.
A token is unexpired at time t exactly when its expiration time is strictly greater than t. Therefore, a token is already expired at the instant equal to its expiration time.
Return one count for every COUNT operation, preserving query order. GENERATE and RENEW operations do not add values to the returned array.

Function
countUnexpiredTokens(timeToLive: int, operations: String[][]) → int[]

Examples
Example 1
timeToLive = 5
operations = [["GENERATE","aaa","1"],["RENEW","aaa","2"],["COUNT","","6"],["GENERATE","bbb","7"],["RENEW","aaa","8"],["RENEW","bbb","10"],["COUNT","","12"]]
return = [1,1]
Token aaa first expires at time 6, then renewal at time 2 moves its expiration to 7, so the count at time 6 is 1. It is expired by time 8, so that renewal is ignored. Token bbb is renewed from expiration time 12 to 15, so the count at time 12 is also 1.
Example 2
timeToLive = 3
operations = [["GENERATE","alpha","1"],["COUNT","","3"],["COUNT","","4"]]
return = [1,0]
Token alpha expires at time 4. It is unexpired at time 3 but expired at time 4.
Example 3
timeToLive = 4
operations = [["RENEW","ghost","1"],["GENERATE","x","2"],["GENERATE","y","3"],["RENEW","x","4"],["COUNT","","5"],["COUNT","","7"],["COUNT","","8"]]
return = [2,1,0]
Renewing the missing token ghost has no effect. Renewal moves token x's expiration to time 8, while token y expires at time 7. The three counts are therefore 2, 1, and 0.

Constraints
1 <= timeToLive <= 10^8.
1 <= operations.length <= 2000.
Every operation contains exactly three strings and uses one of GENERATE, RENEW, or COUNT.
Every non-empty tokenId contains from 1 through 10 lowercase English letters.
Every token ID used by GENERATE is unique.
Operation times are decimal integers from 1 through 10^8 and are strictly increasing across the array.

Reported by candidates. Source: FastPrep

Pattern and pitfall

Keep a hash map of tokenId to expiration time. GENERATE sets map[id] = t + timeToLive. RENEW checks that the id exists and map[id] > t, then resets it to t + timeToLive. COUNT loops over the map and counts values strictly greater than t. With at most 2000 operations, that O(n) scan per count is fine, so don't build anything fancier. The classic pitfall is the boundary: a token whose expiration equals the current time is already dead, so use strictly greater, not greater-or-equal. Second pitfall: times arrive as strings, so parse them to integers before comparing, or you'll compare lexicographically and fail quietly. Third: only COUNT appends to the result. Example 2 tests the boundary directly. If you freeze on the live OA, StealthCoder can hand you this map logic fast, but you can write it in ten lines.

StealthCoder is the hedge for the one pattern you didn't drill. It runs invisibly during the screen share.

If this hits your live OA

You can drill Design Authentication Manager cold, or you can hedge it. StealthCoder runs invisibly during screen share and surfaces a working solution in under 2 seconds. The proctor sees the IDE. They don't see what's behind it. If you're reading this with an OA window open, you're who this was built for.

Get StealthCoder

Related leaked OAs

⏵ Practice the LeetCode equivalent

This OA pattern shows up on LeetCode as design authentication manager. If you have time before the OA, drill that.

⏵ The honest play

You've seen the question. Make sure you actually pass Apple's OA.

Apple reuses patterns across OAs. If you're reading this with an OA window open, you're who this was built for. Works on HackerRank, CodeSignal, CoderPad, and Karat.

Design Authentication Manager FAQ

How hard is the Apple Design Authentication Manager OA question really?+

Easy to medium. There's no clever algorithm, just a hash map and careful boundary handling. Candidates lose points on the strictly-greater comparison and on parsing string times. If you write it cleanly and test Example 2, you're done quickly.

What's the trick to solving this?+

Store expiration time per token in a hash map. For RENEW, check existence and that expiration is strictly greater than the current time. For COUNT, scan the map and count expirations greater than the current time. Don't add anything to the output except COUNT results.

Do I need a heap or ordered structure for efficiency?+

No. With at most 2000 operations, scanning the map on each COUNT is at most about 4 million checks in the worst case, which is fine. A heap or sorted structure adds bug surface without helping here. Reach for it only if the constraints were far larger.

What edge cases should I test before submitting?+

Test a count at the exact expiration instant, which must return 0 for that token. Test renewing a missing token like ghost, and renewing an already expired token, both of which do nothing. Also check that expired tokens stay expired even if a later renew targets them.

How do I prepare for this in 48 hours?+

Write the class version of Design Authentication Manager once from scratch, then rewrite it as a single function over a string array. Practice parsing the time strings to ints. That covers it. Spend leftover time on other design-style problems using hash maps.

Problem reported by candidates from a real Online Assessment. Sourced from a publicly-available candidate-aggregated repository. Not affiliated with Apple.

OA at Apple?
Invisible during screen share
Get it