Skip to content

Magic link and OTP

Both methods are opt-in per project. Enable them in Authentication → Settings (magic_link and email_otp).

// login page
await base.auth.signInWithMagicLink({ email, redirectTo: "https://app.example.com/auth/callback" })
// on /auth/callback
const code = new URL(location.href).searchParams.get("code")!
const { data, error } = await base.auth.exchangeCodeForSession(code)

The link goes through PKCE: the SDK stores the verifier when you request the link, so the link must be opened in the same browser.

A six digit code valid for 10 minutes.

await base.auth.signInWithOtp({ email })
const { data, error } = await base.auth.verifyOtp({ type: "email", email, token: "123456" })
  • Sends are limited to 10 per hour per IP and 3 per hour per email; extra sends are dropped silently.
  • An OTP allows 5 attempts per code, plus 10 failures per hour per address.

Customize the emails with email templates (magic_link and otp).