diff --git a/examples/javascript-auth/index.js b/examples/javascript-auth/index.js
index 0387054d2c7..efc0e7442b4 100644
--- a/examples/javascript-auth/index.js
+++ b/examples/javascript-auth/index.js
@@ -27,7 +27,7 @@ const signUpSubmitted = (event) => {
supabase.auth
.signUp({ email, password })
.then((response) => {
- response.error ? alert(response.error.message) : alert('Confirmation Email Sent')
+ response.error ? alert(response.error.message) : setToken(response)
})
.catch((err) => {
alert(err.response.text)
@@ -42,11 +42,7 @@ const logInSubmitted = (event) => {
supabase.auth
.signIn({ email, password })
.then((response) => {
- response.error
- ? alert(response.error.message)
- : (document.querySelector('#access-token').value = response.data.access_token)
- document.querySelector('#refresh-token').value = response.data.refresh_token
- alert('Logged in as ' + response.user.email)
+ response.error ? alert(response.error.message) : setToken(response)
})
.catch((err) => {
alert(err.response.text)
@@ -71,3 +67,13 @@ const logoutSubmitted = (event) => {
alert(err.response.text)
})
}
+
+function setToken(response) {
+ if (response.data.confirmation_sent_at && !response.data.access_token) {
+ alert('Confirmation Email Sent')
+ } else {
+ document.querySelector('#access-token').value = response.data.access_token
+ document.querySelector('#refresh-token').value = response.data.refresh_token
+ alert('Logged in as ' + response.user.email)
+ }
+}
diff --git a/web/docs/guides/client-libraries.mdx b/web/docs/guides/client-libraries.mdx
index c6f7b68b7a1..5dbd781a9ba 100755
--- a/web/docs/guides/client-libraries.mdx
+++ b/web/docs/guides/client-libraries.mdx
@@ -14,7 +14,8 @@ The [Supabase Client](/docs/reference/javascript/supabase-client) makes it simpl
## Auth
-Create new users using [`signUp()`](/docs/reference/javascript/auth-signup). By default, the user will need to verify their email address before logging in.
+Create new users using [`signUp()`](/docs/reference/javascript/auth-signup). By default, the user will need to verify their email address before logging in.
+If confirmations are disabled the response will contain an access token and also a confirmed_at value, otherwise it will just contain a confirmation_sent_at attribute.