From 20d09b4a727829aa0a611facb7dba91526b89aba Mon Sep 17 00:00:00 2001 From: Wen Bo Xie Date: Thu, 17 Sep 2026 10:49:36 +0800 Subject: [PATCH] docs(auth): clarify OAuth 2.1 server pricing is included in Auth MAUs (#49753) OAuth 2.1 server had a single pricing statement anywhere, and it said the feature is free during beta. This states the actual model everywhere the feature is documented or sold: there is no separate charge, and users who sign in through the OAuth server count toward Auth MAUs. - docs getting started: replace the "free during beta" sentence with the MAU-based pricing statement - docs overview: add a Pricing section linking to the MAU usage guide and the pricing page - docs MCP authentication: note that agents authenticate as existing users, and MAUs count per distinct user, so multiple agents for one user count once - www pricing comparison table: add an "OAuth 2.1 Server" row (included on all plans) with a tooltip, and extend the MAU tooltip to cover OAuth server sign-ins ## Summary by CodeRabbit * **Documentation** * Clarified that OAuth 2.1 Server is available on all plans without a separate charge. * Explained that OAuth sign-ins count toward Monthly Active Users (MAUs), with multiple agents for one user counted once. * Added links to MAU and pricing guidance. * **Pricing** * Added OAuth 2.1 Server as a plan feature and updated billing descriptions for greater clarity. --- apps/docs/content/guides/auth/oauth-server.mdx | 4 ++++ .../guides/auth/oauth-server/getting-started.mdx | 2 +- .../guides/auth/oauth-server/mcp-authentication.mdx | 6 ++++++ apps/www/components/Pricing/PricingTableRow.tsx | 11 +++++++---- packages/shared-data/pricing.ts | 12 ++++++++++++ 5 files changed, 30 insertions(+), 5 deletions(-) diff --git a/apps/docs/content/guides/auth/oauth-server.mdx b/apps/docs/content/guides/auth/oauth-server.mdx index 66c7790d320..9dc9aab3b30 100644 --- a/apps/docs/content/guides/auth/oauth-server.mdx +++ b/apps/docs/content/guides/auth/oauth-server.mdx @@ -19,6 +19,10 @@ There are several reasons why you might want to enable OAuth 2.1 Server in your - **Enterprise SSO**: Provide OpenID Connect (OIDC) authentication for enterprise customers who need standards-compliant identity federation across multiple services. +## Pricing + +There is no separate charge for OAuth 2.1 Server. Users who sign in through your OAuth server count toward your project's [Monthly Active Users (MAUs)](/docs/guides/platform/manage-your-usage/monthly-active-users). See the [pricing page](/pricing) for the MAU quota on each plan. + ## Overview Supabase Auth implements the OAuth 2.1 authorization code flow with PKCE (Proof Key for Code Exchange). When a third-party application wants to access user data: diff --git a/apps/docs/content/guides/auth/oauth-server/getting-started.mdx b/apps/docs/content/guides/auth/oauth-server/getting-started.mdx index 1e5eea02e55..94c67088a55 100644 --- a/apps/docs/content/guides/auth/oauth-server/getting-started.mdx +++ b/apps/docs/content/guides/auth/oauth-server/getting-started.mdx @@ -31,7 +31,7 @@ Testing OAuth flows is often easier on a Supabase project since it's already acc ## Enable OAuth 2.1 server -OAuth 2.1 server is currently in beta and free to use during the beta period on all Supabase plans. +OAuth 2.1 server is in beta and available on all Supabase plans. It has no separate charge. Users who sign in through your OAuth server count toward your project's [Monthly Active Users (MAUs)](/docs/guides/platform/manage-your-usage/monthly-active-users). + +MCP authentication has no separate charge. AI agents authenticate as your existing users, so their sign-ins count toward your project's [Monthly Active Users (MAUs)](/docs/guides/platform/manage-your-usage/monthly-active-users). Supabase counts MAUs per distinct user, so multiple agents or MCP clients acting for the same user count as one MAU. + + + ## Prerequisites Before setting up MCP authentication: diff --git a/apps/www/components/Pricing/PricingTableRow.tsx b/apps/www/components/Pricing/PricingTableRow.tsx index 440d380edeb..a6e2b06a5fd 100644 --- a/apps/www/components/Pricing/PricingTableRow.tsx +++ b/apps/www/components/Pricing/PricingTableRow.tsx @@ -49,13 +49,16 @@ export const pricingTooltips: PricingTooltips = { main: 'The maximum number of users your project can have', }, 'auth.maus': { - main: 'Users who log in or refresh their token count towards MAU.\nBilling is based on the sum of distinct users requesting your API throughout the billing period. Resets every billing cycle.', + main: 'Users who log in or refresh their token count toward MAU. This includes users who sign in through your OAuth 2.1 server.\nBilling is based on the sum of distinct users requesting your API throughout the billing period. Resets every billing cycle.', + }, + 'auth.oauthServer': { + main: 'Use your project as an OAuth 2.1 and OpenID Connect identity provider. There is no separate charge. Users who sign in through your OAuth server count toward MAU.', }, 'auth.userDataOwnership': { main: 'Full ownership and access to the underlying user data including encrypted passwords.', }, 'auth.anonSignIns': { - main: 'Anonymous user requests count towards MAU, just like a permanent user.', + main: 'Anonymous user requests count toward MAU, just like a permanent user.', }, 'auth.basicMFA': { @@ -85,13 +88,13 @@ export const pricingTooltips: PricingTooltips = { main: 'Billing is based on the sum of all invocations, independent of response status, throughout your billing period.', }, 'realtime.concurrentConnections': { - main: 'Total number of successful connections. Connections attempts are not counted towards usage.\nBilling is based on the maximum amount of concurrent peak connections throughout your billing period.', + main: 'Total number of successful connections. Connections attempts are not counted toward usage.\nBilling is based on the maximum amount of concurrent peak connections throughout your billing period.', }, 'realtime.messagesPerMonth': { main: "Count of messages going through Realtime. Includes database changes, broadcast and presence. \nUsage example: If you do a database change and 5 clients listen to that change via Realtime, that's 5 messages. If you broadcast a message and 4 clients listen to that, that's 5 messages (1 message sent, 4 received).\nBilling is based on the total amount of messages throughout your billing period.", }, 'security.logDrain': { - main: 'Only events processed and sent to destinations are counted. Egress required to export logs count towards usage.\nEgress through Log Drains is rolled up into the unified egress and benefits from the unified egress quota.', + main: 'Only events processed and sent to destinations are counted. Egress required to export logs count toward usage.\nEgress through Log Drains is rolled up into the unified egress and benefits from the unified egress quota.', }, 'security.hipaa': { main: 'Available as a paid add-on on Team Plan and above.', diff --git a/packages/shared-data/pricing.ts b/packages/shared-data/pricing.ts index 532a5df56a9..682be686c6a 100644 --- a/packages/shared-data/pricing.ts +++ b/packages/shared-data/pricing.ts @@ -43,6 +43,7 @@ export type FeatureKey = | 'auth.userDataOwnership' | 'auth.anonSignIns' | 'auth.socialOAuthProviders' + | 'auth.oauthServer' | 'auth.customSMTPServer' | 'auth.removeSupabaseBranding' | 'auth.auditLogs' @@ -275,6 +276,17 @@ export const pricing: Pricing = { }, usage_based: false, }, + { + key: 'auth.oauthServer', + title: 'OAuth 2.1 Server', + plans: { + free: true, + pro: true, + team: true, + enterprise: true, + }, + usage_based: false, + }, { key: 'auth.customSMTPServer', title: 'Custom SMTP server',