Email and password
Email and password sign-in is on by default. The Allow new sign-ups setting controls whether new users can register.
// sign up: returns a session, or { user } when email verification is requiredconst { data, error } = await base.auth.signUp({ email, password })
// sign in (alias: base.auth.signIn)const { data: session } = await base.auth.signInWithPassword({ email, password })
// password reset emailawait base.auth.resetPasswordForEmail(email, { redirectTo: "https://app.example.com/reset" })Email verification
Section titled “Email verification”When the project requires verification, sign-in answers 403 email_not_confirmed until the user opens the verification link.
Password reset
Section titled “Password reset”resetPasswordForEmail sends a single-use link to the redirectTo address, which must pass the redirect allowlist. Emails are sent through your project’s SMTP settings or the platform default. Customize them with email templates.
If MFA is enabled
Section titled “If MFA is enabled”signInWithPassword returns { user: null, session: null, mfaRequired, ticket, factors } for users who enrolled a second factor. Finish with auth.mfa.challenge. See MFA.
Limits
Section titled “Limits”| What | Limit |
|---|---|
| sign-in per IP | 10 per minute |
| failed attempts per account | 5, then a 15 minute lock that doubles on repeat (max 24 h) |
| sign-up per IP | 5 per hour |
| reset emails | 10 per hour per IP, 3 per hour per email |
The lock gives the same answer whether or not the account exists.