Auth Live
Auth for your app's users, in your own database
Email and password, magic links and one-time codes, rotating sessions, CAPTCHA and leaked-password checks. Users live in the auth schema of your project's Postgres, so row-level security policies can use auth.uid() and your backups include them.
How it works
Auth, step by step
- Step 01
Pick a primary database
Mark one Postgres instance as the project's primary. The auth schema and the anon, authenticated and service_role roles are created in it.
- Step 02
Turn Auth on
Set the site URL, redirect URLs, password rules, CAPTCHA and rate limits in the portal or through the API.
- Step 03
Use a Supabase client
supabase-js and the other Supabase clients work against your project endpoint with a publishable key.
- Step 04
Protect rows with policies
Sessions are ES256 JWTs signed with your project's key. Postgres enforces policies such as auth.uid() = owner_id.
What you get
-
Email, password and magic links
Sign-up with confirmation, password reset, magic links and email one-time codes. Use your own SMTP server or our sender.
Live -
Rotating sessions
Short-lived access tokens and refresh tokens that rotate on every use. Reusing an old refresh token revokes the whole session.
Live -
CAPTCHA and leaked passwords
hCaptcha or Cloudflare Turnstile on sign-up and sign-in, minimum length and character rules, and a k-anonymity check against known leaked passwords.
Live -
Rate limits
Per-endpoint limits for sign-in, sign-up, emails and token refresh, with brute-force attempts recorded as security events.
Live -
Social sign-in
GitHub, Google, Apple, Microsoft and other OAuth providers, plus any OpenID Connect provider.
Coming soon -
MFA and SAML single sign-on
Time-based one-time codes for your users, and SAML 2.0 for the companies that buy your product.
Coming soon
Live today and coming next
Every part of this service and where it stands. The list changes as each piece ships, and the changelog announces it.
- Email and password sign-up and sign-in Live
- Magic links and email one-time codes Live
- Sessions with refresh-token rotation and reuse detection Live
- CAPTCHA with hCaptcha or Cloudflare Turnstile Live
- Password rules and leaked-password protection Live
- Rate limits and brute-force protection Live
- OAuth and social sign-in providers Coming soon
- Multi-factor authentication Coming soon
- SAML 2.0 single sign-on for your users Coming soon
- Third-party auth (Clerk, Auth0, Firebase, Cognito, WorkOS) Coming soon
- Anonymous sign-in and phone codes Coming soon
- User management in the portal Coming soon
- Import users from Supabase with their password hashes and ids Coming soon
- Server-side auth helpers (@supabase/ssr cookies, PKCE) Coming soon
- OAuth 2.1 / OpenID Connect provider: sign in with your app, MCP clients Coming soon
Live: available on the platform today. Coming soon: being built now; prices and plan limits are already published. See every service on the platform overview.
Try it
Sign a user up with supabase-js, or call the endpoint directly.
import { createClient } from "@supabase/supabase-js";
// Your project's endpoint and publishable key, from Project settings in the portal.
const supabase = createClient("https://<ref>.us-east.databasezy.com:8443", "<publishable-key>");
const { data, error } = await supabase.auth.signUp({
email: "[email protected]",
password: "a-long-password",
});curl -X POST "https://<ref>.us-east.databasezy.com:8443/auth/v1/signup" \
-H "apikey: <publishable-key>" \
-H "Content-Type: application/json" \
-d '{"email":"[email protected]","password":"a-long-password"}'Plan availability
Generated from the same plan catalogue that billing and the API use.
- Included
Free
$0 /mo10,000 monthly active users included
- Included
Solo
$25 /mo50,000 monthly active users included
- Included
Team
$599 /mo100,000 monthly active users included
- Included
Enterprise
CustomAllowance set in your contract
Above the allowance, $0.003 per MAU. On Free the allowance is a hard limit. OAuth and social sign-in providers, multi-factor authentication and sAML 2.0 single sign-on for your users are coming soon.
Questions
Where are my users stored?
In the auth schema of your project's primary Postgres instance: your database, in your region, covered by your backups. Our staff cannot read it without a time-limited support grant that you issue.
Do my Supabase policies and client code work?
The auth schema, the anon, authenticated and service_role roles and the JWT claims follow the Supabase layout, so policies that use auth.uid() and auth.jwt() port over, and supabase-js talks to your project endpoint unchanged. The compatibility notes list the differences.
Can I send auth emails from my own domain?
Yes. Add your SMTP server in the Auth settings. Without one, emails go through our sender, capped per project and day (50 a day on Free).
What does Auth cost?
Every plan includes monthly active users (see the table above). Above the allowance it is $0.003 per MAU, billed with the rest of your usage. On Free the allowance is a hard limit.
Related features
- Live
Data API
REST and GraphQL over your Postgres tables, and SQL over HTTPS for every engine.
Learn more about Data API - Live
Database tools
Extensions, cron and queues for your Postgres from the portal, with vector search, vault and wrappers next.
Learn more about Database tools -
Secure hosting
HIPAA-ready placement you turn on per database, under a signed BAA, with dedicated nodes and per-org keys.
Learn more about Secure hosting
Start today
Create your first database
A free instance, no card. Upgrade when you outgrow it; nothing converts silently.