Authentication System
Reported by candidates from Microsoft's online assessment. Pattern, common pitfall, and the honest play if you blank under the timer.
Microsoft reported this one in August 2026, and the detail that decides it is a single sentence: a token whose expiration equals the current time is already dead. That's the Authentication System OA. It's a design problem dressed up as string parsing. You get a TTL, a list of generate, renew and count queries, and you return the counts. It looks easy, and it is, until an off-by-one on the boundary sinks your hidden tests. If you blank on the data structure choice, StealthCoder runs invisibly as a safety net during the live OA. Better to know the trick before you open the timer.
The problem
Implement a session-based authentication system that manages user sessions using unique token IDs and a configurable time-to-live (time_to_live, or TTL) measured in seconds. When a token is generated, its expiration time is current_time + time_to_live. A token may be renewed only while it is still unexpired; a successful renewal resets its expiration time to current_time + time_to_live. Process every string in queries in the given order. The system must support these three operations: generate <token_id> <current_time>: At current_time, create a new token with the specified ID. Its expiration time is current_time + time_to_live. renew <token_id> <current_time>: At current_time, extend an existing unexpired token's expiration time to current_time + time_to_live. Ignore the request if the token does not exist or has already expired. count <current_time>: Return the number of unexpired tokens at current_time. Important: Token expiration is evaluated before processing any action at the same timestamp. If a token's expiration time is exactly equal to current_time, the token is expired and cannot be renewed or counted. Function getUnexpiredTokens(time_to_live: int, queries: String[]) → int[] Examples Example 1 time_to_live = 5 queries = ["generate aaa 1","renew aaa 2","count 6","generate bbb 7","renew aaa 8","renew bbb 10","count 15"] return = [1,0] At time 6, token aaa is the only unexpired token, so the first count is 1. At time 15, all tokens have expired, so the second count is 0. Example 2 time_to_live = 35 queries = ["generate token1 3","count 4","generate token2 6","count 7","generate token3 11","count 41"] return = [1,2,1] After generate token1 3, token1 expires at time 38. At count 4, only token1 is unexpired, so the result is 1. After generate token2 6, token2 expires at time 41. At count 7, token1 and token2 are unexpired, so the result is 2. After generate token3 11, token3 expires at time 46. At count 41, token1 has expired, token2 expires at the same timestamp and is therefore already expired, and token3 remains unexpired. The result is 1. Example 3 time_to_live = 9 queries = ["generate token1 3","renew token1 5","generate token2 7","renew token2 8","generate token3 9","count 12"] return = [3] After generate token1 3, token1 expires at time 12. After renew token1 5, its expiration time becomes 14. After generate token2 7, token2 expires at time 16. After renew token2 8, its expiration time becomes 17. After generate token3 9, token3 expires at time 18. At count 12, all three tokens are unexpired, so the result is 3.
Reported by candidates. Source: FastPrep
Pattern and pitfall
Keep a hash map from token_id to expiration time. Generate sets map[id] = t + ttl. Renew checks that the id exists and map[id] > t, then sets map[id] = t + ttl. Count scans the map and counts entries where expiration > t. That's O(n) per count, fine for most inputs. If the input is large, add a min-heap of expirations or a lazy cleanup, but renewals leave stale heap entries, so validate against the map when popping. The pitfall is the strict inequality. Example 2 shows it: token2 expires at 41, count at 41 returns 1, not 2. Also parse each query by splitting on spaces, and only append results for count queries. If the boundary logic or the heap cleanup trips you up mid-assessment, StealthCoder is the hedge that gives you a working solution on screen without the proctor seeing it.
If this hits your live OA and you blank, StealthCoder solves it in seconds, invisible to the proctor.
You can drill Authentication System cold, or you can hedge it. StealthCoder runs invisibly during screen share and surfaces a working solution in under 2 seconds. The proctor sees the IDE. They don't see what's behind it. Built by an Amazon engineer who would have shipped this the night before his JPMorgan OA if he'd had it.
Get StealthCoderRelated leaked OAs
This OA pattern shows up on LeetCode as design authentication manager. If you have time before the OA, drill that.
You've seen the question.
Make sure you actually pass Microsoft's OA.
Microsoft reuses patterns across OAs. Built by an Amazon engineer who would have shipped this the night before his JPMorgan OA if he'd had it. Works on HackerRank, CodeSignal, CoderPad, and Karat.
Authentication System FAQ
How hard is the Microsoft Authentication System OA really?+
Easy to medium. The logic is a hash map and a comparison. The difficulty is in the details: strict expiry at equal timestamps, ignoring invalid renewals, and only returning results for count queries. Most failures come from off-by-one errors, not from the algorithm.
What's the trick to this problem?+
Store expiration time per token in a hash map and always compare with expiration > current_time to treat a token as alive. Equal means expired. Apply that same check in both renew and count and you pass the examples.
Do I need a heap or can I just loop over the map?+
A plain loop over the map for each count is the simplest and usually enough. A heap helps only if the query list is huge. With renewals you'd get stale entries, so you'd have to verify each popped entry against the map's current expiration.
What happens if I renew a token that doesn't exist?+
Ignore it. Same for a token that has already expired. Nothing changes and nothing gets added to the output. Only count queries produce output values, so your result array is shorter than the query list.
How do I prepare for this in 48 hours?+
Write the hash map version from scratch once and test it against all three examples, especially Example 2 for the boundary. Then practice parsing space-separated query strings quickly. Also try a few edge cases: renew right at expiry, duplicate generates, and count before any token exists.