Bazar — AI-Integrated E-Commerce
An AI-assisted multi-role e-commerce marketplace I built to explore how behavioral data, generative AI, and traditional commerce systems can work together in a single product.

Overview
Purpose: Build an e-commerce marketplace where product discovery becomes more relevant through AI-assisted search, behavioral recommendations, and generated product support content.
Target users: Buyers searching and purchasing products; sellers onboarding and managing products; guest users receiving session-based recommendations.
- Buyer and seller authentication flows
- Seller onboarding
- Product catalog
- Server-backed cart and wishlist
- Order APIs
- AI product search
- Behavioral recommendation engine
- AI review and FAQ capabilities
- Password reset and OTP flows
- Role-aware authorization
Tech Stack
next-auth (^4.24.14) is listed in package.json/package-lock.json but is not imported anywhere in the actual source (grep across app/, lib/, components/, context/ found zero usage) — it appears to be a dead/unused dependency; all real auth is the hand-rolled JWT + scrypt system described above.
Frontend
- Next.js 16
- React 19
- TypeScript
- Tailwind CSS v4
- Zustand
- React Compiler
Backend
- Next.js Route Handlers
- Node.js crypto utilities
- Axios-based client communication
Database
- MongoDB
- Mongoose
- 13 domain models
Auth
- Custom HMAC-SHA256 JWT implementation
- Access and refresh tokens
- scrypt password hashing
- Cookie-based authentication
AI
- OpenAI SDK using Google's Gemini OpenAI-compatible endpoint
- Gemini 2.5 Flash Lite
- AI-assisted search, FAQ generation, review processing, and recommendations
Features
AI Product Search
I implemented an AI-assisted search layer that works alongside deterministic local keyword matching.
How: The architecture supports graceful fallback so product discovery does not become completely dependent on the model provider.
Personalization & Recommendations
Recommendations use actual behavior-related models instead of only category matching. Behavioral data includes UserEvent, UserIntent, UserPreference, RecommendationLog.
How: The recommendation layer supports authenticated users and guest sessionId flows.
Seller Onboarding & Dashboard
A multi-step seller onboarding experience collects identity and business information before entering the seller dashboard.
How: Seller and SellerInfo models separate account identity from business-specific profile data.
Server-Backed Cart & Wishlist
Cart and wishlist are persisted in MongoDB instead of depending only on browser storage.
How: This allows logged-in users to preserve shopping state across sessions and devices.
AI FAQ Generation
Product-specific FAQ generation combines AI output with persistent storage through the Faqs model.
How: This creates reusable support content rather than generating the same answers repeatedly.
Authentication & Account Recovery
Buyer login/signup, seller login/signup, access token + refresh token lifecycle, OTP-based forgotten-password flow, logged-in password reset, cookie-based session handling.
Architecture
Folder structure: AI concerns isolated in lib/ai, authentication in lib/auth and lib/jwt, and recommendation logic in lib/personalization.
Database Design
- Commerce — Product, Order, Cart, Wishlist, Review
- Accounts — User, Seller, SellerInfo
- Personalization — UserEvent, UserIntent, UserPreference, RecommendationLog
- AI Content — Faqs
The separation allows recommendation logic to grow independently from the core commerce entities.
API Documentation
| Method | URL | Purpose | Auth |
|---|---|---|---|
| POST | /api/login | Buyer login | |
| POST | /api/signup | Buyer registration | |
| POST | /api/seller-login | Seller login | |
| POST | /api/seller-signup | Seller onboarding | |
| GET | /api/me | Buyer session | |
| GET | /api/seller-me | Seller session | |
| POST | /api/refreshToken | Token rotation | |
| POST | /api/logout | Session termination | |
| POST | /api/forgot-password/send-otp | Send reset OTP | |
| POST | /api/forgot-password/reset-password | Complete OTP reset | |
| POST | /api/password-reset | Authenticated password change | |
| GET/POST/PATCH/DELETE | /api/products | Product operations | |
| GET/PATCH/DELETE | /api/cart | Cart operations | |
| GET/POST/DELETE | /api/watchList | Wishlist operations | |
| POST/GET | /api/order | Order creation and retrieval | |
| GET | /api/ai-search | AI-assisted product search | |
| POST | /api/ai-review | AI-assisted review processing | |
| GET/POST | /api/faq | FAQ persistence | |
| POST | /api/ai-faq | AI FAQ generation | |
| POST | /api/recommendations | Personalized recommendations |
Authentication Flow
login: Credentials → scrypt verification → JWT access/refresh tokens → httpOnly cookies → per-route role validation.
jwt: Custom implementation covering token signing/verification, expiry handling, refresh-token rotation, cookie lifecycle, buyer/seller role separation, and password recovery flows.
Screenshots



Challenges
Problem: Maintaining Consistent Auth Contracts — as the number of account routes grew, keeping payload and cookie conventions aligned became important.
Solution: I standardized token payload handling and authentication helpers so buyer, seller, refresh, recovery, and logout flows use the same conventions.
Problem: Moving Shopping State to the Server — the project evolved from client-only state toward persisted cart and wishlist models.
Solution: This improved cross-session behavior and made the commerce state consistent with the rest of the backend architecture.
Problem: AI Fallback Design — AI features should improve the product rather than become a single point of failure.
Solution: Search therefore combines model-assisted behavior with deterministic local matching, allowing useful results even when AI configuration changes.
Performance
- React Compiler enabled
- Turbopack
- Server-backed data access
- AI fallback paths
- API routes separated by responsibility
- MongoDB models aligned around specific workloads
Security
- scrypt password hashing
- HMAC-SHA256 signed JWTs
- Access/refresh token separation
- Cookie-based sessions
- Role-aware API access
- Password recovery flows
- Server-side ownership checks for user-specific resources
- Environment-driven credentials for database and AI services
Deployment
hosting: Structured as a production-buildable Next.js application with environment-driven MongoDB, JWT, AI, and email configuration.
Future Improvements
- More sophisticated recommendation ranking
- Seller analytics
- Production payment integrations
- Automated tests across commerce and auth lifecycles
- Richer admin tooling
Lessons Learned
- Behavioral models make personalization more extensible than hardcoded category rules.
- AI works best as an enhancement with deterministic fallback behavior.
- Auth contracts should be centralized early as the number of protected routes grows.
- Persisted cart and wishlist state produces a stronger multi-device commerce experience.
- Custom cryptographic/auth implementations are valuable learning exercises but require strict consistency and testing.
Project Metrics
Timeline
- May 2026 — Project initialized
- June 2026 — Core marketplace, seller flows, APIs, and authentication developed
- June 2026 — Audit-driven API refinement and server-backed commerce state
- July 2026 — Session/auth lifecycle improvements and stabilization
Ask about this project
Depends on the /api/chat orchestrator and MCP tool server — not built yet (see plan.md).
Recruiter Summary
Role: Solo Full-Stack Developer
- Designed a 13-model MongoDB commerce and personalization schema
- Built buyer and seller authentication
- Implemented custom JWT and scrypt-based security
- Developed product, order, cart, wishlist, and seller flows
- Integrated Gemini through the OpenAI-compatible SDK
- Built AI-assisted search, recommendations, review processing, and FAQ generation
- Produced a functional AI-assisted marketplace architecture
- Connected behavioral data directly to recommendation logic
- Implemented persistent commerce state across cart and wishlist
- Gained end-to-end experience integrating AI into conventional transactional application architecture