Skip to content
Databasezy

Auth Live

Auth for your app's users, in your own database

Email and password, magic links and one-time codes, rotating sessions, CAPTCHA and leaked-password checks. Users live in the auth schema of your project's Postgres, so row-level security policies can use auth.uid() and your backups include them.

Auth, step by step

  1. Step 01

    Pick a primary database

    Mark one Postgres instance as the project's primary. The auth schema and the anon, authenticated and service_role roles are created in it.

  2. Step 02

    Turn Auth on

    Set the site URL, redirect URLs, password rules, CAPTCHA and rate limits in the portal or through the API.

  3. Step 03

    Use a Supabase client

    supabase-js and the other Supabase clients work against your project endpoint with a publishable key.

  4. Step 04

    Protect rows with policies

    Sessions are ES256 JWTs signed with your project's key. Postgres enforces policies such as auth.uid() = owner_id.

What you get

  • Email, password and magic links

    Sign-up with confirmation, password reset, magic links and email one-time codes. Use your own SMTP server or our sender.

    Live
  • Rotating sessions

    Short-lived access tokens and refresh tokens that rotate on every use. Reusing an old refresh token revokes the whole session.

    Live
  • CAPTCHA and leaked passwords

    hCaptcha or Cloudflare Turnstile on sign-up and sign-in, minimum length and character rules, and a k-anonymity check against known leaked passwords.

    Live
  • Rate limits

    Per-endpoint limits for sign-in, sign-up, emails and token refresh, with brute-force attempts recorded as security events.

    Live
  • Social sign-in

    GitHub, Google, Apple, Microsoft and other OAuth providers, plus any OpenID Connect provider.

    Coming soon
  • MFA and SAML single sign-on

    Time-based one-time codes for your users, and SAML 2.0 for the companies that buy your product.

    Coming soon

Live today and coming next

Every part of this service and where it stands. The list changes as each piece ships, and the changelog announces it.

  • Email and password sign-up and sign-in Live
  • Magic links and email one-time codes Live
  • Sessions with refresh-token rotation and reuse detection Live
  • CAPTCHA with hCaptcha or Cloudflare Turnstile Live
  • Password rules and leaked-password protection Live
  • Rate limits and brute-force protection Live
  • OAuth and social sign-in providers Coming soon
  • Multi-factor authentication Coming soon
  • SAML 2.0 single sign-on for your users Coming soon
  • Third-party auth (Clerk, Auth0, Firebase, Cognito, WorkOS) Coming soon
  • Anonymous sign-in and phone codes Coming soon
  • User management in the portal Coming soon
  • Import users from Supabase with their password hashes and ids Coming soon
  • Server-side auth helpers (@supabase/ssr cookies, PKCE) Coming soon
  • OAuth 2.1 / OpenID Connect provider: sign in with your app, MCP clients Coming soon

Live: available on the platform today. Coming soon: being built now; prices and plan limits are already published. See every service on the platform overview.

Try it

Sign a user up with supabase-js, or call the endpoint directly.

supabase-js
import { createClient } from "@supabase/supabase-js";

// Your project's endpoint and publishable key, from Project settings in the portal.
const supabase = createClient("https://<ref>.us-east.databasezy.com:8443", "<publishable-key>");

const { data, error } = await supabase.auth.signUp({
  email: "[email protected]",
  password: "a-long-password",
});
curl
curl -X POST "https://<ref>.us-east.databasezy.com:8443/auth/v1/signup" \
  -H "apikey: <publishable-key>" \
  -H "Content-Type: application/json" \
  -d '{"email":"[email protected]","password":"a-long-password"}'

Plan availability

Generated from the same plan catalogue that billing and the API use.

  • Free

    $0 /mo
    Included

    10,000 monthly active users included

  • Solo

    $25 /mo
    Included

    50,000 monthly active users included

  • Team

    $599 /mo
    Included

    100,000 monthly active users included

  • Enterprise

    Custom
    Included

    Allowance set in your contract

Above the allowance, $0.003 per MAU. On Free the allowance is a hard limit. OAuth and social sign-in providers, multi-factor authentication and sAML 2.0 single sign-on for your users are coming soon.

Compare every plan on the pricing page

Questions

Where are my users stored?

In the auth schema of your project's primary Postgres instance: your database, in your region, covered by your backups. Our staff cannot read it without a time-limited support grant that you issue.

Do my Supabase policies and client code work?

The auth schema, the anon, authenticated and service_role roles and the JWT claims follow the Supabase layout, so policies that use auth.uid() and auth.jwt() port over, and supabase-js talks to your project endpoint unchanged. The compatibility notes list the differences.

Can I send auth emails from my own domain?

Yes. Add your SMTP server in the Auth settings. Without one, emails go through our sender, capped per project and day (50 a day on Free).

What does Auth cost?

Every plan includes monthly active users (see the table above). Above the allowance it is $0.003 per MAU, billed with the rest of your usage. On Free the allowance is a hard limit.

Create your first database

A free instance, no card. Upgrade when you outgrow it; nothing converts silently.