diff --git a/apps/docs/pages/guides/auth/auth-mfa.mdx b/apps/docs/pages/guides/auth/auth-mfa.mdx index 0591e3af52b..3365952bd57 100644 --- a/apps/docs/pages/guides/auth/auth-mfa.mdx +++ b/apps/docs/pages/guides/auth/auth-mfa.mdx @@ -687,17 +687,24 @@ json_query_path(auth.jwt(), '$.amr[0]') authentication method in the JWT. Once you have extracted the most recent entry in the array, you can compare the -`method` and `timestamp` to enforce stricter rules. +`method` and `timestamp` to enforce stricter rules. For instance, you can mandate that access will be only be granted on a table to users who have recently signed in with a password. -Currently recognized methods are: +Currently recognized authentication methods are: +- `oauth` - any OAuth based sign in (social login). - `password` - any password based sign in. - `otp` - any one-time password based sign in (email code, SMS code, magic link). -- `oauth` - any OAuth based sign in (social login). - `totp` - a TOTP additional factor. +- `sso/saml` - any Single Sign On (SAML) method. -This list will expand in the future. +The following additional claims are available when using PKCE flow: +- `invite` - any sign in via an invitation. +- `magiclink` - any sign in via magic link. Excludes logins resulting from invocation of `signUp`. +- `email/signup` - any login resulting from an email signup. +- `email_change` - any login resulting from a change in email. + +More authentication methods will be added over time as we increase the number of authentication methods supported by Supabase. export const Page = ({ children }) =>