🔐 RS256 verified ✓
⚡ pgvector <100ms
🤖 copilot online
Open to full-stack engineering roles
▶ PLAYER 1 READY

Rushil Gorasia

>

I build the infrastructure other features stand on: identity systems, real-time pipelines, and AI-native products, engineered from spec to production — not stitched together from someone else's SDK.

View Projects ↓ Get in Touch
LVL 4 — SHIPPED PRODUCTS0%
About

I'd rather build the primitive than import it.

Most of my work starts by asking what's actually happening underneath an abstraction I'm about to reach for — which is how a hackathon polling app turned into real-time state management at speed, and a "Sign in" button turned into implementing the OpenID Connect Authorization Code flow, PKCE, and RS256 token signing from the specification up.

Lately that same instinct has moved toward AI-native products: agentic copilots, semantic search over vector embeddings, and the retrieval, billing, and multi-tenant infrastructure that turn a demo into something people can actually rely on.

Auth & Security
99
Backend / APIs
92
Realtime systems
88
AI infra / RAG
85
Frontend
90
Frontend
HTMLCSSJavaScriptReactNext.js
Backend
Node.jsExpresstRPC
Data
PostgreSQLSQLpgvectorDrizzle ORM
Auth & Security
OpenID ConnectOAuth 2.0PKCERS256JWT
Tooling
PythonDockerAzureVercelTurborepo
Selected Work

Boss fights I've won.

tip: hover cards for spotlight · press B for confetti · try ↑↑↓↓←→←→BA
★ BOSS 01 · AI WORKSPACE
Singularity
AI-powered Gmail & Calendar workspace

STACK // Next.js 15 · tRPC v11 · Mastra · pgvector/HNSW

<1s semantic search 🤖 2-model fallback 🔐 3 accounts / user

A multi-tenant workspace that unifies Gmail and Calendar across up to three accounts per user, with an agentic AI copilot handling triage, drafting, and bulk actions — backed by a multi-model fallback chain so it keeps working even when one provider doesn't.

  • Multi-tenant Next.js 15 / tRPC v11 architecture with encrypted OAuth token storage and real-time Gmail webhook processing
  • Agentic AI copilot built on Mastra with MCP tool calling, for triage, drafting, and bulk inbox actions
  • Multi-model fallback chain (DeepSeek, Gemini) keeps the copilot resilient to single-provider outages
  • Sub-second semantic search across cached emails and events via PostgreSQL pgvector with HNSW indexing
  • Premium billing tiers via Dodo Payments with webhook-driven subscription management
★ BOSS 02 · CRYPTOGRAPHY
Axemoth OIDC
Self-hosted OpenID Connect identity provider

PROTOCOL // OAuth 2.0 · OIDC Core 1.0 · PKCE (RFC 7636) · RS256

🛡 PKCE enforced 🔑 RS256 signed 📜 spec-built, no shortcuts

A production-grade, self-hosted identity provider and SSO platform — a private "Sign in with Google," built from the specification up with no shortcuts on the cryptography. Scroll down to decode a JWT live in the playground.

  • Full OIDC Authorization Code flow with PKCE enforcement — every authorization is cryptographically verified
  • RS256 asymmetric token signing — tokens are verifiable by third parties without a shared secret
  • Standard discovery endpoints (/.well-known/openid-configuration, JWKS) plus a developer dashboard for client registration
  • bcrypt password hashing, single-use auth codes, and CORS protection
  • Deployed on Azure App Service (backend) and Vercel (frontend)
★ MINI-BOSS · FORMS
AxeForm
Full-stack SaaS form builder

STACK // Next.js · tRPC · Drizzle ORM · Turborepo

A form builder shipped as a pnpm/Turborepo monorepo, supporting nine field types with dynamic Zod validation, conditional logic, and DFS-based cycle detection so validation graphs can't loop forever.

★ MINI-BOSS · REALTIME
AxePoll
Real-time polling application

STACK // JavaScript · WebSockets

Live polling and voting with WebSocket-driven state — results update instantly for every participant, with clean handling of concurrent votes on both desktop and mobile. Try a demo poll in the playground ↓

🕹️ A few smaller builds and experiments live in the rest of my repos. Explore GitHub ↗
Bonus Level

Don't just read. Play.

Three tiny interactive demos from my actual work — a terminal, a live poll, and a JWT decoder. No installs, no tracking, all client-side.

▸ rushil@axemoth: ~

A tiny fake shell. Try help, whoami, projects, or sudo hire rushil.

➜ ~

▸ LIVE POLL (mini AxePoll)

● LIVE

What should I build next?
Vote below — results animate like the real AxePoll WebSocket flow (this one just uses localStorage).

▸ JWT DECODER (OIDC edition)

RS256

Paste any JWT to inspect its header + payload. Nothing leaves your browser — which is exactly how auth debugging should work.

HEADER
PAYLOAD
Insert Coin

Defend the server.

Bugs are swarming the production server. Your firewall ship fires on its own — you steer. Ram bugs, grab project power-ups, and don't let anything touch the core.

SERVER_DEFENSE.exe

SCORE 0000 WAVE -- CORE ♥♥♥ BEST 0000

🛡️ MISSION: KEEP THE CORE ALIVE

Move: mouse · touch · / A D — guns fire automatically.
Bugs that reach the core cost 1 ♥. You have 3. Ram bugs to smash them. Catch the falling power-ups.

auto-fire engaged · P = screen nuke
S Singularity spread-shot O OIDC shield A AxeForm rapid-fire P AxePoll bug-poll nuke
Get in Touch

Let's talk about what you're building.

Open to full-stack roles, collaborations, and conversations about auth protocols, real-time systems, or AI infrastructure.

prefer copying?