Skip to content

Email and password

Email and password sign-in is on by default. The Allow new sign-ups setting controls whether new users can register.

// sign up: returns a session, or { user } when email verification is required
const { data, error } = await base.auth.signUp({ email, password })
// sign in (alias: base.auth.signIn)
const { data: session } = await base.auth.signInWithPassword({ email, password })
// password reset email
await base.auth.resetPasswordForEmail(email, { redirectTo: "https://app.example.com/reset" })

When the project requires verification, sign-in answers 403 email_not_confirmed until the user opens the verification link.

resetPasswordForEmail sends a single-use link to the redirectTo address, which must pass the redirect allowlist. Emails are sent through your project’s SMTP settings or the platform default. Customize them with email templates.

signInWithPassword returns { user: null, session: null, mfaRequired, ticket, factors } for users who enrolled a second factor. Finish with auth.mfa.challenge. See MFA.

What Limit
sign-in per IP 10 per minute
failed attempts per account 5, then a 15 minute lock that doubles on repeat (max 24 h)
sign-up per IP 5 per hour
reset emails 10 per hour per IP, 3 per hour per email

The lock gives the same answer whether or not the account exists.