PreviewRustaBase OSS is in public preview. Build on managed PostgreSQL with APIs, authentication, storage, realtime, and server-side functions.Read the product direction

Data and users

Authentication

Let people sign up and sign in to your application with email and password, one-time codes, social accounts, and two-step verification.

Sign-in methods

  • Email and password, with email verification and password reset
  • One-time codes sent by email
  • OAuth providers such as Google, GitHub, Apple, Microsoft, and Discord
  • Multi-factor authentication (MFA) that asks for a second step after the first sign-in

Set it up

  1. Open your Project and select Authentication.
  2. Choose the auth table your users live in (users is created for you).
  3. Turn on the methods you want and set their options.
  4. For OAuth, add the client ID and secret from the provider, and add the redirect address shown in the console to the provider's settings.
  5. Set up Email under Project settings so verification and reset emails are delivered.

Sign in from your app

const users = rb.auth("users");

await users.signInWithPassword("[email protected]", "password");

const { otpId } = await users.requestOtp("[email protected]");
await users.signInWithOtp(otpId, "123456");

await users.signInWithOAuth({ provider: "google" });

await users.requestPasswordReset("[email protected]");
final users = rb.auth('users');
await users.signInWithPassword('[email protected]', 'password');
await users.requestPasswordReset('[email protected]');

After sign-in the SDK keeps the session and sends it with every request, including realtime.

Security guidance

  • Require verified email before users can use sensitive features.
  • Turn on MFA for apps that handle money or personal data.
  • Lock tables to their owners with API rules and row-level security.
  • Never put superuser credentials or API keys in browser or mobile code.

Build server-side functions

Found something wrong on this page?

Fix it yourself. The link below opens this file in GitHub's editor and forks the repository for you if you need one, and your change becomes a pull request without leaving the browser.