currently using hardcoded pw https://github.com/async-la/thin-auth/blob/master/packages/server/src/scope/auth/index.js#L18