shipanysaas
Documentation
Back
  • Getting started
    • Install and run
    • Project structure
    • Configuration
    • Commands
  • Coding agents
    • Agent skills
  • Authentication
    • Email sign-in
    • OAuth providers
    • Two-step sign-in and passkeys
  • Database
    • Migrations
    • Row-level security
    • Database tests
    • Reading and writing data
  • Features
    • Teams and invitations
    • Email
    • File uploads
    • Blog, docs and changelog
  • Billing
    • Stripe and Lemon Squeezy
    • Pricing plans
    • Webhooks
  • Live demo
  • Email sign-in

    Password, magic link and one-time code sign-in, email confirmation, password reset and the Supabase Auth email templates.

    Three email-based methods ship. Turn on any combination in apps/web/.env (or your host's environment settings):

    NEXT_PUBLIC_AUTH_PASSWORD=true     # email and password (on by default)
    NEXT_PUBLIC_AUTH_MAGIC_LINK=false  # a sign-in link by email
    NEXT_PUBLIC_AUTH_OTP=false         # a one-time code by email
    

    Email and password

    • Passwords need at least 8 characters. Set NEXT_PUBLIC_PASSWORD_REQUIRE_UPPERCASE, NEXT_PUBLIC_PASSWORD_REQUIRE_NUMBERS or NEXT_PUBLIC_PASSWORD_REQUIRE_SPECIAL_CHARS to true for stricter rules (packages/features/auth/src/schemas/password.schema.ts).
    • The local stack requires email confirmation before the first sign-in (enable_confirmations = true in apps/web/supabase/config.toml). Set the same in your hosted Supabase project.
    • Forgotten passwords: /auth/password-reset sends a reset email; the link opens /update-password.
    • Signed-in users change their password and email in account settings. An email change has to be confirmed on both the old and the new address locally (double_confirm_changes = true).

    Magic link and one-time code

    Both send an email through Supabase Auth. The magic link signs the user in when clicked and returns through /auth/callback. The one-time code is typed into the sign-in page instead, which also works when the email is opened on another device.

    When either is on, invited team members can join with their email alone. When both are off, a new member who joins through an invitation is asked to set up a password or another sign-in method afterwards (/identities).

    Auth email templates

    Supabase Auth sends its own emails (confirmation, password reset, email change, magic link, invitation). The kit's HTML for them is in apps/web/supabase/templates/:

    FileEmail
    confirm-email.htmlConfirm your email
    reset-password.htmlReset your password
    change-email-address.htmlConfirm an email change
    magic-link.htmlSign-in email with both the link and the code
    invite-user.htmlSupabase's own user invitation
    otp.htmlA code-only sign-in email (not mapped in config.toml)

    config.toml points the local stack at the first five. A hosted Supabase project does not read config.toml on its own: set the templates and subjects in the project's Auth email settings. Set up your own SMTP server there too: Supabase's built-in sender only delivers to members of your Supabase organisation.

    Locally, every Auth email lands in Mailpit at http://localhost:54324.

    Team invitations, one-time codes for sensitive actions and the contact form are sent by the app itself, not by Supabase Auth. See Email.