Hash passwords with bcrypt (never store plaintext) - Generate a cryptographically secure email verification token - Rate limit: suggest middleware approach - Return 201 Created on success (do not echo the password back)