From fe40cae142e814eca7cc2c315efbe042d91a995c Mon Sep 17 00:00:00 2001 From: Jeremias Menichelli Date: Thu, 23 Apr 2026 14:49:39 +0200 Subject: [PATCH] feat: Support config.json file --- .../docs/features/docs/GuidesMdx.template.tsx | 22 +- apps/docs/features/ui/guide/GuideHeader.tsx | 5 +- apps/docs/lib/docs.ts | 2 + apps/docs/scripts/generate-tsdoc-mdx.ts | 23 +- apps/docs/scripts/process-tsdoc.ts | 31 +- .../spec/enrichments/tsdoc_v2/config.json | 16 + .../spec/enrichments/tsdoc_v2/processed.json | 97127 +++++++--------- 7 files changed, 44582 insertions(+), 52644 deletions(-) create mode 100644 apps/docs/spec/enrichments/tsdoc_v2/config.json diff --git a/apps/docs/features/docs/GuidesMdx.template.tsx b/apps/docs/features/docs/GuidesMdx.template.tsx index 68885811bb6..d66b5d2ee7a 100644 --- a/apps/docs/features/docs/GuidesMdx.template.tsx +++ b/apps/docs/features/docs/GuidesMdx.template.tsx @@ -1,4 +1,4 @@ -import { ExternalLink } from 'lucide-react' +import { ExternalLink, Github } from 'lucide-react' import { type ReactNode } from 'react' import ReactMarkdown from 'react-markdown' @@ -62,7 +62,7 @@ type GuideTemplateProps = const GuideTemplate = ({ meta, content, children, editLink, mdxOptions }: GuideTemplateProps) => { const hideToc = meta?.hideToc || meta?.hide_table_of_contents - + console.log('GuideMDX.template.tsx', meta) return (
@@ -83,10 +83,24 @@ const GuideTemplate = ({ meta, content, children, editLink, mdxOptions }: GuideT

{meta?.title || 'Supabase Docs'}

+ {meta?.referenceLink && ( +
+ {meta.referenceLinkLabel} + + View on GitHub + + +
+ )} {meta?.subtitle && ( -

+
{meta.subtitle} -

+
)}
diff --git a/apps/docs/features/ui/guide/GuideHeader.tsx b/apps/docs/features/ui/guide/GuideHeader.tsx index 034adb0eed0..57c8fcaf585 100644 --- a/apps/docs/features/ui/guide/GuideHeader.tsx +++ b/apps/docs/features/ui/guide/GuideHeader.tsx @@ -9,16 +9,15 @@ interface GuideHeaderProps { export function GuideHeader({ className }: GuideHeaderProps) { const { meta } = useGuide() - return (

{meta?.title || 'Supabase Docs'}

{meta?.subtitle && ( -

+

{meta.subtitle} -

+

)}
diff --git a/apps/docs/lib/docs.ts b/apps/docs/lib/docs.ts index 89873b51407..47b6cbcdb1a 100644 --- a/apps/docs/lib/docs.ts +++ b/apps/docs/lib/docs.ts @@ -29,6 +29,8 @@ export type GuideFrontmatter = { /** @deprecated */ hide_table_of_contents?: boolean tocVideo?: string + referenceLink?: string + referenceLinkLabel?: string } /** diff --git a/apps/docs/scripts/generate-tsdoc-mdx.ts b/apps/docs/scripts/generate-tsdoc-mdx.ts index 27e1ccef5c2..d04dd3a5760 100644 --- a/apps/docs/scripts/generate-tsdoc-mdx.ts +++ b/apps/docs/scripts/generate-tsdoc-mdx.ts @@ -1,10 +1,18 @@ -import { mkdirSync, writeFileSync } from 'fs' +import { mkdirSync, readFileSync, writeFileSync } from 'fs' import { join, dirname, resolve } from 'path' import { fileURLToPath } from 'url' import { processSpec } from './process-tsdoc.js' const __dirname = dirname(fileURLToPath(import.meta.url)) +const CONFIG_PATH = join(__dirname, '../spec/enrichments/tsdoc_v2/config.json') +const config: { + title?: string + subtitle?: string + referenceLink?: string + referenceLinkLabel?: string +} = JSON.parse(readFileSync(CONFIG_PATH, 'utf-8')) + function escapeMdxProse(text: string): string { // Escape { and } outside code blocks/spans so MDX doesn't treat them as JSX. // Match fenced code blocks first (```...```), then inline code (`...`), leave both untouched. @@ -79,7 +87,18 @@ function generateExamplesBlock(examples: any[]): string[] { } function generateMdx(categories: ReturnType): string { - const lines: string[] = ['---', 'title: JavaScript Client library', '---', '', ''] + const fmVal = (v: string) => `"${v.replace(/"/g, '\\"')}"` + const frontmatter = [ + '---', + `title: ${fmVal(config.title ?? 'Reference')}`, + ...(config.subtitle ? [`subtitle: ${fmVal(config.subtitle)}`] : []), + ...(config.referenceLink ? [`referenceLink: ${fmVal(config.referenceLink)}`] : []), + ...(config.referenceLinkLabel ? [`referenceLinkLabel: ${fmVal(config.referenceLinkLabel)}`] : []), + '---', + '', + '', + ] + const lines: string[] = frontmatter for (let i = 0; i < categories.length; i++) { const { category, definitions } = categories[i] diff --git a/apps/docs/scripts/process-tsdoc.ts b/apps/docs/scripts/process-tsdoc.ts index ef88f5a5945..d0a99279025 100644 --- a/apps/docs/scripts/process-tsdoc.ts +++ b/apps/docs/scripts/process-tsdoc.ts @@ -216,6 +216,17 @@ const SOURCE_FILES = [ export function processSpec() { const specDir = join(__dirname, '../spec/enrichments/tsdoc_v2') + + const config: { ignoreDefinitions?: string[]; categoryOrder?: string[] } = (() => { + try { + return JSON.parse(readFileSync(join(specDir, 'config.json'), 'utf-8')) + } catch { + return {} + } + })() + const ignoredNames = new Set(config.ignoreDefinitions ?? []) + const categoryOrder = config.categoryOrder ?? [] + const roots = SOURCE_FILES.map((f) => JSON.parse(readFileSync(join(specDir, f), 'utf-8'))) // Build a per-file targetMap so IDs from different packages don't collide @@ -239,6 +250,8 @@ export function processSpec() { const remarkTags = blockTags.filter((t) => t.tag === '@remarks') const examples = parseExamples(blockTags) + if (ignoredNames.has(decl.name)) continue + const definition: any = { name: decl.name, description: contentToMd(decl.comment?.summary ?? []), @@ -253,10 +266,20 @@ export function processSpec() { categoryMap.get(category)!.push(definition) } - const result = Array.from(categoryMap.entries()).map(([category, definitions]) => ({ - category, - definitions, - })) + const result = Array.from(categoryMap.entries()) + .map(([category, definitions]) => ({ category, definitions })) + .sort((a, b) => { + const ai = categoryOrder.indexOf(a.category) + const bi = categoryOrder.indexOf(b.category) + // Both in order list: sort by position + if (ai !== -1 && bi !== -1) return ai - bi + // Only a is in list: a goes first + if (ai !== -1) return -1 + // Only b is in list: b goes first + if (bi !== -1) return 1 + // Neither in list: preserve insertion order + return 0 + }) console.log(result) diff --git a/apps/docs/spec/enrichments/tsdoc_v2/config.json b/apps/docs/spec/enrichments/tsdoc_v2/config.json new file mode 100644 index 00000000000..34432a95a5c --- /dev/null +++ b/apps/docs/spec/enrichments/tsdoc_v2/config.json @@ -0,0 +1,16 @@ +{ + "title":"JavaScript Client library", +"subtitle": "Use the `supabase-js` package to interact with your Postgres database, listen to database changes, invoke Deno Edge Functions, build login and user management functionality, and manage large files.", +"referenceLink": "https://github.com/supabase/supabase-js", +"referenceLinkLabel": "@supabase/supabase-js", + "versions": [ + "v1", + "v2" + ], + "isLatestVersion": true, + "version": "v2", + "ignoreDefinitions": [ + "constructor" + ], + "categoryOrder": [ "Initializing", "Database", "Auth", "Functions", "Realtime", "Storage" ] +} \ No newline at end of file diff --git a/apps/docs/spec/enrichments/tsdoc_v2/processed.json b/apps/docs/spec/enrichments/tsdoc_v2/processed.json index 91053b72698..af8f1b0eb53 100644 --- a/apps/docs/spec/enrichments/tsdoc_v2/processed.json +++ b/apps/docs/spec/enrichments/tsdoc_v2/processed.json @@ -1,44315 +1,7 @@ [ - { - "category": "Functions", - "definitions": [ - { - "name": "constructor", - "description": "Creates a new Functions client bound to an Edge Functions URL.", - "parameters": [ - { - "name": "url", - "type": "string" - }, - { - "name": "__namedParameters", - "type": { - "kind": "object", - "properties": [ - { - "name": "customFetch", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": true, - "type": { - "kind": "reference", - "name": "Record", - "typeArguments": ["string", "string"] - } - }, - { - "name": "region", - "optional": true, - "type": { - "kind": "reference", - "name": "FunctionRegion" - } - } - ] - } - } - ], - "returnType": { - "kind": "object", - "name": "FunctionsClient", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "fetch", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": false, - "type": { - "kind": "reference", - "name": "Record", - "typeArguments": ["string", "string"] - } - }, - { - "name": "region", - "optional": false, - "type": { - "kind": "reference", - "name": "FunctionRegion" - } - }, - { - "name": "url", - "optional": false, - "type": "string" - }, - { - "name": "invoke", - "optional": false, - "type": null - }, - { - "name": "setAuth", - "optional": false, - "type": null - } - ] - }, - "examples": [ - { - "title": "Example 1", - "code": "import { FunctionsClient, FunctionRegion } from '@supabase/functions-js'\n\nconst functions = new FunctionsClient('https://xyzcompany.supabase.co/functions/v1', {\n headers: { apikey: 'public-anon-key' },\n region: FunctionRegion.UsEast1,\n})" - }, - { - "title": "Creating a Functions client", - "code": "import { FunctionsClient, FunctionRegion } from '@supabase/functions-js'\n\nconst functions = new FunctionsClient('https://xyzcompany.supabase.co/functions/v1', {\n headers: { apikey: 'public-anon-key' },\n region: FunctionRegion.UsEast1,\n})" - } - ] - }, - { - "name": "invoke", - "description": "Invokes a function", - "remarks": [ - "- Requires an Authorization header. - Invoke params generally match the [Fetch API](https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API) spec. - When you pass in a body to your function, we automatically attach the Content-Type header for `Blob`, `ArrayBuffer`, `File`, `FormData` and `String`. If it doesn't match any of these types we assume the payload is `json`, serialize it and attach the `Content-Type` header as `application/json`. You can override this behavior by passing in a `Content-Type` header of your own. - Responses are automatically parsed as `json`, `blob` and `form-data` depending on the `Content-Type` header sent by your function. Responses are parsed as `text` by default." - ], - "parameters": [ - { - "name": "functionName", - "description": "The name of the Function to invoke.", - "type": "string" - }, - { - "name": "options", - "description": "Options for invoking the Function.", - "type": { - "kind": "object", - "properties": [ - { - "name": "body", - "optional": true, - "description": "The body of the request.", - "type": { - "kind": "union", - "types": [ - { - "kind": "reference", - "name": "File" - }, - { - "kind": "reference", - "name": "Blob" - }, - { - "kind": "reference", - "name": "ArrayBuffer" - }, - { - "kind": "reference", - "name": "FormData" - }, - { - "kind": "reference", - "name": "ReadableStream", - "typeArguments": [ - { - "kind": "reference", - "name": "Uint8Array" - } - ] - }, - { - "kind": "reference", - "name": "Record", - "typeArguments": ["string", "any"] - }, - "string" - ] - } - }, - { - "name": "headers", - "optional": true, - "description": "Object representing the headers to send with the request.", - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "method", - "optional": true, - "description": "The HTTP verb of the request", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "POST" - }, - { - "kind": "literal", - "value": "GET" - }, - { - "kind": "literal", - "value": "PUT" - }, - { - "kind": "literal", - "value": "PATCH" - }, - { - "kind": "literal", - "value": "DELETE" - } - ] - } - }, - { - "name": "region", - "optional": true, - "description": "The Region to invoke the function in.", - "type": { - "kind": "reference", - "name": "FunctionRegion" - } - }, - { - "name": "signal", - "optional": true, - "description": "The AbortSignal to use for the request.", - "type": { - "kind": "reference", - "name": "AbortSignal" - } - }, - { - "name": "timeout", - "optional": true, - "description": "The timeout for the request in milliseconds. If the function takes longer than this, the request will be aborted.", - "type": "number" - } - ], - "name": "FunctionInvokeOptions" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "reference", - "name": "FunctionsResponseSuccess", - "typeArguments": [ - { - "kind": "typeParam", - "name": "T" - } - ] - }, - { - "kind": "reference", - "name": "FunctionsResponseFailure" - } - ] - } - ] - }, - "examples": [ - { - "title": "Example 1", - "code": "const { data, error } = await functions.invoke('hello-world', {\n body: { name: 'Ada' },\n})", - "notes": "Error handling\nA `FunctionsHttpError` error is returned if your function throws an error, `FunctionsRelayError` if the Supabase Relay has an error processing your function and `FunctionsFetchError` if there is a network error in calling your function." - }, - { - "title": "Basic invocation", - "code": "const { data, error } = await supabase.functions.invoke('hello', {\n body: { foo: 'bar' }\n})", - "notes": "Passing custom headers\nYou can pass custom headers to your function. Note: supabase-js automatically passes the `Authorization` header with the signed in user's JWT." - }, - { - "title": "Error handling", - "code": "import { FunctionsHttpError, FunctionsRelayError, FunctionsFetchError } from \"@supabase/supabase-js\";\n\nconst { data, error } = await supabase.functions.invoke('hello', {\n headers: {\n \"my-custom-header\": 'my-custom-header-value'\n },\n body: { foo: 'bar' }\n})\n\nif (error instanceof FunctionsHttpError) {\n const errorMessage = await error.context.json()\n console.log('Function returned an error', errorMessage)\n} else if (error instanceof FunctionsRelayError) {\n console.log('Relay error:', error.message)\n} else if (error instanceof FunctionsFetchError) {\n console.log('Fetch error:', error.message)\n}", - "notes": "A `FunctionsHttpError` error is returned if your function throws an error, `FunctionsRelayError` if the Supabase Relay has an error processing your function and `FunctionsFetchError` if there is a network error in calling your function." - }, - { - "title": "Passing custom headers", - "code": "const { data, error } = await supabase.functions.invoke('hello', {\n headers: {\n \"my-custom-header\": 'my-custom-header-value'\n },\n body: { foo: 'bar' }\n})", - "notes": "You can pass custom headers to your function. Note: supabase-js automatically passes the `Authorization` header with the signed in user's JWT." - }, - { - "title": "Calling with DELETE HTTP verb", - "code": "const { data, error } = await supabase.functions.invoke('hello', {\n headers: {\n \"my-custom-header\": 'my-custom-header-value'\n },\n body: { foo: 'bar' },\n method: 'DELETE'\n})", - "notes": "You can also set the HTTP verb to `DELETE` when calling your Edge Function." - }, - { - "title": "Invoking a Function in the UsEast1 region", - "code": "import { createClient, FunctionRegion } from '@supabase/supabase-js'\n\nconst { data, error } = await supabase.functions.invoke('hello', {\n body: { foo: 'bar' },\n region: FunctionRegion.UsEast1\n})", - "notes": "Here are the available regions:\n- `FunctionRegion.Any`\n- `FunctionRegion.ApNortheast1`\n- `FunctionRegion.ApNortheast2`\n- `FunctionRegion.ApSouth1`\n- `FunctionRegion.ApSoutheast1`\n- `FunctionRegion.ApSoutheast2`\n- `FunctionRegion.CaCentral1`\n- `FunctionRegion.EuCentral1`\n- `FunctionRegion.EuWest1`\n- `FunctionRegion.EuWest2`\n- `FunctionRegion.EuWest3`\n- `FunctionRegion.SaEast1`\n- `FunctionRegion.UsEast1`\n- `FunctionRegion.UsWest1`\n- `FunctionRegion.UsWest2`" - }, - { - "title": "Calling with GET HTTP verb", - "code": "const { data, error } = await supabase.functions.invoke('hello', {\n headers: {\n \"my-custom-header\": 'my-custom-header-value'\n },\n method: 'GET'\n})", - "notes": "You can also set the HTTP verb to `GET` when calling your Edge Function." - }, - { - "title": "Example 7", - "code": "const { data, error } = await functions.invoke('hello-world', {\n body: { name: 'Ada' },\n})" - } - ] - }, - { - "name": "setAuth", - "description": "Updates the authorization header", - "parameters": [ - { - "name": "token", - "description": "the new jwt token sent in the authorisation header", - "type": "string" - } - ], - "returnType": "void", - "examples": [ - { - "title": "Setting the authorization header", - "code": "functions.setAuth(session.access_token)" - } - ] - } - ] - }, - { - "category": "Auth", - "definitions": [ - { - "name": "createUser", - "description": "Creates a new user. This function should only be called on a server. Never expose your `service_role` key in the browser.", - "remarks": [ - "- To confirm the user's email address or phone number, set `email_confirm` or `phone_confirm` to true. Both arguments default to false. - `createUser()` will not send a confirmation email to the user. You can use [`inviteUserByEmail()`](/docs/reference/javascript/auth-admin-inviteuserbyemail) if you want to send them an email invite instead. - If you are sure that the created user's email or phone number is legitimate and verified, you can set the `email_confirm` or `phone_confirm` param to `true`." - ], - "parameters": [ - { - "name": "attributes", - "type": { - "kind": "object", - "name": "AdminUserAttributes", - "properties": [ - { - "name": "app_metadata", - "optional": true, - "description": "A custom data object to store the user's application specific metadata. This maps to the `auth.users.app_metadata` column.\nOnly a service role can modify.\nThe `app_metadata` should be a JSON object that includes app-specific info, such as identity providers, roles, and other access control information.", - "type": "object" - }, - { - "name": "ban_duration", - "optional": true, - "description": "Determines how long a user is banned for.\nThe format for the ban duration follows a strict sequence of decimal numbers with a unit suffix. Valid time units are \"ns\", \"us\" (or \"µs\"), \"ms\", \"s\", \"m\", \"h\".\nFor example, some possible durations include: '300ms', '2h45m'.\nSetting the ban duration to 'none' lifts the ban on the user.", - "type": "string" - }, - { - "name": "current_password", - "optional": true, - "description": "The user's current password\nThis is only ever present when the user is resetting their password and GOTRUE_SECURITY_UPDATE_PASSWORD_REQUIRE_CURRENT_PASSWORD is true.", - "type": "string" - }, - { - "name": "email", - "optional": true, - "description": "The user's email.", - "type": "string" - }, - { - "name": "email_confirm", - "optional": true, - "description": "Sets the user's email as confirmed when true, or unconfirmed when false.\nOnly a service role can modify.", - "type": "boolean" - }, - { - "name": "id", - "optional": true, - "description": "The `id` for the user.\nAllows you to overwrite the default `id` set for the user.", - "type": "string" - }, - { - "name": "nonce", - "optional": true, - "description": "The nonce sent for reauthentication if the user's password is to be updated.\nCall reauthenticate() to obtain the nonce first.", - "type": "string" - }, - { - "name": "password", - "optional": true, - "description": "The user's password.", - "type": "string" - }, - { - "name": "password_hash", - "optional": true, - "description": "The `password_hash` for the user's password.\nAllows you to specify a password hash for the user. This is useful for migrating a user's password hash from another service.\nSupports bcrypt, scrypt (firebase), and argon2 password hashes.", - "type": "string" - }, - { - "name": "phone", - "optional": true, - "description": "The user's phone.", - "type": "string" - }, - { - "name": "phone_confirm", - "optional": true, - "description": "Sets the user's phone as confirmed when true, or unconfirmed when false.\nOnly a service role can modify.", - "type": "boolean" - }, - { - "name": "role", - "optional": true, - "description": "The `role` claim set in the user's access token JWT.\nWhen a user signs up, this role is set to `authenticated` by default. You should only modify the `role` if you need to provision several levels of admin access that have different permissions on individual columns in your database.\nSetting this role to `service_role` is not recommended as it grants the user admin privileges.", - "type": "string" - }, - { - "name": "user_metadata", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `user_metadata` should be a JSON object that includes user-specific info, such as their first and last name.\nNote: When using the GoTrueAdminApi and wanting to modify a user's metadata, this attribute is used instead of UserAttributes data.", - "type": "object" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "With custom user metadata", - "code": "const { data, error } = await supabase.auth.admin.createUser({\n email: 'user@email.com',\n password: 'password',\n user_metadata: { name: 'Yoda' }\n})", - "response": "{\n data: {\n user: {\n id: '1',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {},\n user_metadata: {},\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"1\",\n \"user_id\": \"1\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"phone_verified\": false,\n \"sub\": \"1\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false,\n }\n }\n error: null\n}" - }, - { - "title": "Auto-confirm the user's email", - "code": "const { data, error } = await supabase.auth.admin.createUser({\n email: 'user@email.com',\n email_confirm: true\n})" - }, - { - "title": "Auto-confirm the user's phone number", - "code": "const { data, error } = await supabase.auth.admin.createUser({\n phone: '1234567890',\n phone_confirm: true\n})" - } - ] - }, - { - "name": "deleteUser", - "description": "Delete a user. Requires a `service_role` key.", - "remarks": [ - "- The `deleteUser()` method requires the user's ID, which maps to the `auth.users.id` column." - ], - "parameters": [ - { - "name": "id", - "description": "The user id you want to remove.", - "type": "string" - }, - { - "name": "shouldSoftDelete", - "description": "If true, then the user will be soft-deleted from the auth schema. Soft deletion allows user identification from the hashed user ID but is not reversible. Defaults to false for backward compatibility.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "type": "boolean" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Removes a user", - "code": "const { data, error } = await supabase.auth.admin.deleteUser(\n '715ed5db-f090-4b8c-a067-640ecee36aa0'\n)", - "response": "{\n \"data\": {\n \"user\": {}\n },\n \"error\": null\n}" - } - ] - }, - { - "name": "generateLink", - "description": "Generates email links and OTPs to be sent via a custom email provider.", - "remarks": [ - "- The following types can be passed into `generateLink()`: `signup`, `magiclink`, `invite`, `recovery`, `email_change_current`, `email_change_new`, `phone_change`. - `generateLink()` only generates the email link for `email_change_email` if the **Secure email change** is enabled in your project's [email auth provider settings](/dashboard/project/_/auth/providers). - `generateLink()` handles the creation of the user for `signup`, `invite` and `magiclink`." - ], - "parameters": [ - { - "name": "params", - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "email", - "optional": false, - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "reference", - "name": "Pick", - "typeArguments": [ - { - "kind": "object", - "name": "GenerateLinkOptions", - "properties": [ - { - "name": "data", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", - "type": "object" - }, - { - "name": "redirectTo", - "optional": true, - "description": "The URL which will be appended to the email link generated.", - "type": "string" - } - ] - }, - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "data" - }, - { - "kind": "literal", - "value": "redirectTo" - } - ] - } - ] - } - }, - { - "name": "password", - "optional": false, - "type": "string" - }, - { - "name": "type", - "optional": false, - "type": { - "kind": "literal", - "value": "signup" - } - } - ], - "name": "GenerateSignupLinkParams" - }, - { - "kind": "object", - "properties": [ - { - "name": "email", - "optional": false, - "description": "The user's email", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "reference", - "name": "Pick", - "typeArguments": [ - { - "kind": "object", - "name": "GenerateLinkOptions", - "properties": [ - { - "name": "data", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", - "type": "object" - }, - { - "name": "redirectTo", - "optional": true, - "description": "The URL which will be appended to the email link generated.", - "type": "string" - } - ] - }, - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "data" - }, - { - "kind": "literal", - "value": "redirectTo" - } - ] - } - ] - } - }, - { - "name": "type", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "invite" - }, - { - "kind": "literal", - "value": "magiclink" - } - ] - } - } - ], - "name": "GenerateInviteOrMagiclinkParams" - }, - { - "kind": "object", - "properties": [ - { - "name": "email", - "optional": false, - "description": "The user's email", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "reference", - "name": "Pick", - "typeArguments": [ - { - "kind": "object", - "name": "GenerateLinkOptions", - "properties": [ - { - "name": "data", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", - "type": "object" - }, - { - "name": "redirectTo", - "optional": true, - "description": "The URL which will be appended to the email link generated.", - "type": "string" - } - ] - }, - { - "kind": "literal", - "value": "redirectTo" - } - ] - } - }, - { - "name": "type", - "optional": false, - "type": { - "kind": "literal", - "value": "recovery" - } - } - ], - "name": "GenerateRecoveryLinkParams" - }, - { - "kind": "object", - "properties": [ - { - "name": "email", - "optional": false, - "description": "The user's email", - "type": "string" - }, - { - "name": "newEmail", - "optional": false, - "description": "The user's new email. Only required if type is 'email_change_current' or 'email_change_new'.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "reference", - "name": "Pick", - "typeArguments": [ - { - "kind": "object", - "name": "GenerateLinkOptions", - "properties": [ - { - "name": "data", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", - "type": "object" - }, - { - "name": "redirectTo", - "optional": true, - "description": "The URL which will be appended to the email link generated.", - "type": "string" - } - ] - }, - { - "kind": "literal", - "value": "redirectTo" - } - ] - } - }, - { - "name": "type", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "email_change_current" - }, - { - "kind": "literal", - "value": "email_change_new" - } - ] - } - } - ], - "name": "GenerateEmailChangeLinkParams" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "properties", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "action_link", - "optional": false, - "description": "The email link to send to the user. The action_link follows the following format: auth/v1/verify?type={verification_type}&token={hashed_token}&redirect_to={redirect_to}", - "type": "string" - }, - { - "name": "email_otp", - "optional": false, - "description": "The raw email OTP. You should send this in the email if you want your users to verify using an OTP instead of the action link.", - "type": "string" - }, - { - "name": "hashed_token", - "optional": false, - "description": "The hashed token appended to the action link.", - "type": "string" - }, - { - "name": "redirect_to", - "optional": false, - "description": "The URL appended to the action link.", - "type": "string" - }, - { - "name": "verification_type", - "optional": false, - "description": "The verification type that the email link is associated to.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "signup" - }, - { - "kind": "literal", - "value": "invite" - }, - { - "kind": "literal", - "value": "magiclink" - }, - { - "kind": "literal", - "value": "recovery" - }, - { - "kind": "literal", - "value": "email_change_current" - }, - { - "kind": "literal", - "value": "email_change_new" - } - ] - } - } - ], - "name": "GenerateLinkProperties" - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Generate a signup link", - "code": "const { data, error } = await supabase.auth.admin.generateLink({\n type: 'signup',\n email: 'email@example.com',\n password: 'secret'\n})", - "response": "{\n \"data\": {\n \"properties\": {\n \"action_link\": \"\",\n \"email_otp\": \"999999\",\n \"hashed_token\": \"\",\n \"verification_type\": \"signup\"\n },\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"email@example.com\",\n \"phone\": \"\",\n \"confirmation_sent_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"email@example.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" - }, - { - "title": "Generate an invite link", - "code": "const { data, error } = await supabase.auth.admin.generateLink({\n type: 'invite',\n email: 'email@example.com'\n})" - }, - { - "title": "Generate a magic link", - "code": "const { data, error } = await supabase.auth.admin.generateLink({\n type: 'magiclink',\n email: 'email@example.com'\n})" - }, - { - "title": "Generate a recovery link", - "code": "const { data, error } = await supabase.auth.admin.generateLink({\n type: 'recovery',\n email: 'email@example.com'\n})" - }, - { - "title": "Generate links to change current email address", - "code": "// generate an email change link to be sent to the current email address\nconst { data, error } = await supabase.auth.admin.generateLink({\n type: 'email_change_current',\n email: 'current.email@example.com',\n newEmail: 'new.email@example.com'\n})\n\n// generate an email change link to be sent to the new email address\nconst { data, error } = await supabase.auth.admin.generateLink({\n type: 'email_change_new',\n email: 'current.email@example.com',\n newEmail: 'new.email@example.com'\n})" - } - ] - }, - { - "name": "getUserById", - "description": "Get user by id.", - "remarks": [ - "- Fetches the user object from the database based on the user's id. - The `getUserById()` method requires the user's id which maps to the `auth.users.id` column." - ], - "parameters": [ - { - "name": "uid", - "description": "The user's unique identifier\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "type": "string" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Fetch the user object using the access_token jwt", - "code": "const { data, error } = await supabase.auth.admin.getUserById(1)", - "response": "{\n data: {\n user: {\n id: '1',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {},\n user_metadata: {},\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"1\",\n \"user_id\": \"1\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"phone_verified\": false,\n \"sub\": \"1\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false,\n }\n }\n error: null\n}" - } - ] - }, - { - "name": "inviteUserByEmail", - "description": "Sends an invite link to an email address.", - "remarks": [ - "- Sends an invite link to the user's email address. - The `inviteUserByEmail()` method is typically used by administrators to invite users to join the application. - Note that PKCE is not supported when using `inviteUserByEmail`. This is because the browser initiating the invite is often different from the browser accepting the invite which makes it difficult to provide the security guarantees required of the PKCE flow." - ], - "parameters": [ - { - "name": "email", - "description": "The email address of the user.", - "type": "string" - }, - { - "name": "options", - "description": "Additional options to be included when inviting.", - "type": { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": true, - "description": "A custom data object to store additional metadata about the user. This maps to the `auth.users.user_metadata` column.", - "type": "object" - }, - { - "name": "redirectTo", - "optional": true, - "description": "The URL which will be appended to the email link sent to the user's email address. Once clicked the user will end up on this URL.", - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Invite a user", - "code": "const { data, error } = await supabase.auth.admin.inviteUserByEmail('email@example.com')", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"invited_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmation_sent_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" - } - ] - }, - { - "name": "listUsers", - "description": "Get a list of users.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "remarks": ["- Defaults to return 50 users per page."], - "parameters": [ - { - "name": "params", - "optional": true, - "description": "An object which supports `page` and `perPage` as numbers, to alter the paginated results.", - "type": { - "kind": "object", - "properties": [ - { - "name": "page", - "optional": true, - "description": "The page number", - "type": "number" - }, - { - "name": "perPage", - "optional": true, - "description": "Number of items returned per page", - "type": "number" - } - ], - "name": "PageParams" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "intersection", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "users", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "lastPage", - "optional": false, - "type": "number" - }, - { - "name": "nextPage", - "optional": false, - "type": { - "kind": "union", - "types": [ - "number", - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "total", - "optional": false, - "type": "number" - } - ], - "name": "Pagination" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "users", - "optional": false, - "type": { - "kind": "tuple", - "elements": [] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Get a page of users", - "code": "const { data: { users }, error } = await supabase.auth.admin.listUsers()" - }, - { - "title": "Paginated list of users", - "code": "const { data: { users }, error } = await supabase.auth.admin.listUsers({\n page: 1,\n perPage: 1000\n})" - } - ] - }, - { - "name": "signOut", - "description": "Removes a logged-in session.", - "parameters": [ - { - "name": "jwt", - "description": "A valid, logged-in JWT.", - "type": "string" - }, - { - "name": "scope", - "description": "The logout sope.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "global" - }, - { - "kind": "literal", - "value": "local" - }, - { - "kind": "literal", - "value": "others" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - ] - } - } - ] - } - ] - } - }, - { - "name": "updateUserById", - "description": "Updates the user data. Changes are applied directly without confirmation flows.", - "remarks": [ - "**Important:** This is a server-side operation and does **not** trigger client-side `onAuthStateChange` listeners. The admin API has no connection to client state.\nTo sync changes to the client after calling this method: 1. On the client, call `supabase.auth.refreshSession()` to fetch the updated user data 2. This will trigger the `TOKEN_REFRESHED` event and notify all listeners" - ], - "parameters": [ - { - "name": "uid", - "description": "The user's unique identifier", - "type": "string" - }, - { - "name": "attributes", - "description": "The data you want to update.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "type": { - "kind": "object", - "name": "AdminUserAttributes", - "properties": [ - { - "name": "app_metadata", - "optional": true, - "description": "A custom data object to store the user's application specific metadata. This maps to the `auth.users.app_metadata` column.\nOnly a service role can modify.\nThe `app_metadata` should be a JSON object that includes app-specific info, such as identity providers, roles, and other access control information.", - "type": "object" - }, - { - "name": "ban_duration", - "optional": true, - "description": "Determines how long a user is banned for.\nThe format for the ban duration follows a strict sequence of decimal numbers with a unit suffix. Valid time units are \"ns\", \"us\" (or \"µs\"), \"ms\", \"s\", \"m\", \"h\".\nFor example, some possible durations include: '300ms', '2h45m'.\nSetting the ban duration to 'none' lifts the ban on the user.", - "type": "string" - }, - { - "name": "current_password", - "optional": true, - "description": "The user's current password\nThis is only ever present when the user is resetting their password and GOTRUE_SECURITY_UPDATE_PASSWORD_REQUIRE_CURRENT_PASSWORD is true.", - "type": "string" - }, - { - "name": "email", - "optional": true, - "description": "The user's email.", - "type": "string" - }, - { - "name": "email_confirm", - "optional": true, - "description": "Sets the user's email as confirmed when true, or unconfirmed when false.\nOnly a service role can modify.", - "type": "boolean" - }, - { - "name": "id", - "optional": true, - "description": "The `id` for the user.\nAllows you to overwrite the default `id` set for the user.", - "type": "string" - }, - { - "name": "nonce", - "optional": true, - "description": "The nonce sent for reauthentication if the user's password is to be updated.\nCall reauthenticate() to obtain the nonce first.", - "type": "string" - }, - { - "name": "password", - "optional": true, - "description": "The user's password.", - "type": "string" - }, - { - "name": "password_hash", - "optional": true, - "description": "The `password_hash` for the user's password.\nAllows you to specify a password hash for the user. This is useful for migrating a user's password hash from another service.\nSupports bcrypt, scrypt (firebase), and argon2 password hashes.", - "type": "string" - }, - { - "name": "phone", - "optional": true, - "description": "The user's phone.", - "type": "string" - }, - { - "name": "phone_confirm", - "optional": true, - "description": "Sets the user's phone as confirmed when true, or unconfirmed when false.\nOnly a service role can modify.", - "type": "boolean" - }, - { - "name": "role", - "optional": true, - "description": "The `role` claim set in the user's access token JWT.\nWhen a user signs up, this role is set to `authenticated` by default. You should only modify the `role` if you need to provision several levels of admin access that have different permissions on individual columns in your database.\nSetting this role to `service_role` is not recommended as it grants the user admin privileges.", - "type": "string" - }, - { - "name": "user_metadata", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `user_metadata` should be a JSON object that includes user-specific info, such as their first and last name.\nNote: When using the GoTrueAdminApi and wanting to modify a user's metadata, this attribute is used instead of UserAttributes data.", - "type": "object" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Example 1", - "code": "// Server-side (Edge Function)\nconst { data, error } = await supabase.auth.admin.updateUserById(\n userId,\n { user_metadata: { preferences: { theme: 'dark' } } }\n)\n\n// Client-side (to sync the changes)\nconst { data, error } = await supabase.auth.refreshSession()\n// onAuthStateChange listeners will now be notified with updated user", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"new@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"recovery_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" - }, - { - "title": "Updates a user's email", - "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '11111111-1111-1111-1111-111111111111',\n { email: 'new@email.com' }\n)", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"new@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"recovery_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" - }, - { - "title": "Updates a user's password", - "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { password: 'new_password' }\n)" - }, - { - "title": "Updates a user's metadata", - "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { user_metadata: { hello: 'world' } }\n)" - }, - { - "title": "Updates a user's app_metadata", - "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { app_metadata: { plan: 'trial' } }\n)" - }, - { - "title": "Confirms a user's email address", - "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { email_confirm: true }\n)" - }, - { - "title": "Confirms a user's phone number", - "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { phone_confirm: true }\n)" - }, - { - "title": "Ban a user for 100 years", - "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { ban_duration: '876000h' }\n)" - } - ] - }, - { - "name": "exchangeCodeForSession", - "description": "Log in an existing user by exchanging an Auth Code issued during the PKCE flow.", - "remarks": ["- Used when `flowType` is set to `pkce` in client options."], - "parameters": [ - { - "name": "authCode", - "type": "string" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "object", - "name": "Session", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Exchange Auth Code", - "code": "supabase.auth.exchangeCodeForSession('34e770dd-9ff9-416c-87fa-43b31d7ef225')", - "response": "{\n \"data\": {\n session: {\n access_token: '',\n token_type: 'bearer',\n expires_in: 3600,\n expires_at: 1700000000,\n refresh_token: '',\n user: {\n id: '11111111-1111-1111-1111-111111111111',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com'\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {\n \"provider\": \"email\",\n \"providers\": [\n \"email\",\n \"\"\n ]\n },\n user_metadata: {\n email: 'email@email.com',\n email_verified: true,\n full_name: 'User Name',\n iss: '',\n name: 'User Name',\n phone_verified: false,\n provider_id: '',\n sub: ''\n },\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n {\n \"identity_id\": \"33333333-3333-3333-3333-333333333333\",\n \"id\": \"\",\n \"user_id\": \"\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"full_name\": \"User Name\",\n \"iss\": \"\",\n \"name\": \"User Name\",\n \"phone_verified\": false,\n \"provider_id\": \"\",\n \"sub\": \"\"\n },\n \"provider\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false\n },\n provider_token: '',\n provider_refresh_token: ''\n },\n user: {\n id: '11111111-1111-1111-1111-111111111111',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {\n provider: 'email',\n providers: [\n \"email\",\n \"\"\n ]\n },\n user_metadata: {\n email: 'email@email.com',\n email_verified: true,\n full_name: 'User Name',\n iss: '',\n name: 'User Name',\n phone_verified: false,\n provider_id: '',\n sub: ''\n },\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n {\n \"identity_id\": \"33333333-3333-3333-3333-333333333333\",\n \"id\": \"\",\n \"user_id\": \"\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"full_name\": \"User Name\",\n \"iss\": \"\",\n \"name\": \"User Name\",\n \"phone_verified\": false,\n \"provider_id\": \"\",\n \"sub\": \"\"\n },\n \"provider\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false\n },\n redirectType: null\n },\n \"error\": null\n}" - } - ] - }, - { - "name": "getClaims", - "description": "Extracts the JWT claims present in the access token by first verifying the JWT against the server's JSON Web Key Set endpoint `/.well-known/jwks.json` which is often cached, resulting in significantly faster responses. Prefer this method over #getUser which always sends a request to the Auth server for each JWT.\nIf the project is not using an asymmetric JWT signing key (like ECC or RSA) it always sends a request to the Auth server (similar to #getUser) to verify the JWT.", - "remarks": [ - "- Parses the user's [access token](/docs/guides/auth/sessions#access-token-jwt-claims) as a [JSON Web Token (JWT)](/docs/guides/auth/jwts) and returns its components if valid and not expired. - If your project is using asymmetric JWT signing keys, then the verification is done locally usually without a network request using the [WebCrypto API](https://developer.mozilla.org/en-US/docs/Web/API/Web_Crypto_API). - A network request is sent to your project's JWT signing key discovery endpoint `https://project-id.supabase.co/auth/v1/.well-known/jwks.json`, which is cached locally. If your environment is ephemeral, such as a Lambda function that is destroyed after every request, a network request will be sent for each new invocation. Supabase provides a network-edge cache providing fast responses for these situations. - If the user's access token is about to expire when calling this function, the user's session will first be refreshed before validating the JWT. - If your project is using a symmetric secret to sign the JWT, it always sends a request similar to `getUser()` to validate the JWT at the server before returning the decoded token. This is also used if the WebCrypto API is not available in the environment. Make sure you polyfill it in such situations. - The returned claims can be customized per project using the [Custom Access Token Hook](/docs/guides/auth/auth-hooks/custom-access-token-hook)." - ], - "parameters": [ - { - "name": "jwt", - "optional": true, - "description": "An optional specific JWT you wish to verify, not the one you can obtain from #getSession.", - "type": "string" - }, - { - "name": "options", - "description": "Various additional options that allow you to customize the behavior of this method.", - "type": { - "kind": "object", - "properties": [ - { - "name": "allowExpired", - "optional": true, - "description": "If set to `true` the `exp` claim will not be validated against the current time.", - "type": "boolean" - }, - { - "name": "jwks", - "optional": true, - "description": "If set, this JSON Web Key Set is going to have precedence over the cached value available on the server.", - "type": { - "kind": "object", - "properties": [ - { - "name": "keys", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "JWK", - "properties": [ - { - "name": "alg", - "optional": true, - "type": "string" - }, - { - "name": "key_ops", - "optional": false, - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "kid", - "optional": true, - "type": "string" - }, - { - "name": "kty", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "RSA" - }, - { - "kind": "literal", - "value": "EC" - }, - { - "kind": "literal", - "value": "oct" - } - ] - } - } - ] - } - } - } - ] - } - }, - { - "name": "keys", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "JWK", - "properties": [ - { - "name": "alg", - "optional": true, - "type": "string" - }, - { - "name": "key_ops", - "optional": false, - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "kid", - "optional": true, - "type": "string" - }, - { - "name": "kty", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "RSA" - }, - { - "kind": "literal", - "value": "EC" - }, - { - "kind": "literal", - "value": "oct" - } - ] - } - } - ] - } - } - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "claims", - "optional": false, - "type": { - "kind": "object", - "name": "JwtPayload", - "properties": [ - { - "name": "aal", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "aal1" - }, - { - "kind": "literal", - "value": "aal2" - } - ] - } - }, - { - "name": "amr", - "optional": true, - "description": "Authentication Method References. Supports both RFC-8176 compliant format (string[]) and detailed format (AMREntry[]). - String format: ['password', 'otp'] - RFC-8176 compliant - Object format: [{ method: 'password', timestamp: 1234567890 }] - includes timestamps", - "type": { - "kind": "union", - "types": [ - { - "kind": "array", - "elementType": "string" - }, - { - "kind": "array", - "elementType": { - "kind": "object", - "name": "AMREntry", - "properties": [ - { - "name": "method", - "optional": false, - "description": "Authentication method name.", - "type": { - "kind": "union", - "types": [ - { - "kind": "indexedAccess", - "objectType": { - "kind": "query" - }, - "indexType": null - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "timestamp", - "optional": false, - "description": "Timestamp when the method was successfully used. Represents number of seconds since 1st January 1970 (UNIX epoch) in UTC.", - "type": "number" - } - ] - } - } - ] - } - }, - { - "name": "app_metadata", - "optional": true, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": { - "kind": "union", - "types": [ - "string", - { - "kind": "array", - "elementType": "string" - } - ] - } - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "exp", - "optional": false, - "type": "number" - }, - { - "name": "iat", - "optional": false, - "type": "number" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "iss", - "optional": false, - "type": "string" - }, - { - "name": "jti", - "optional": true, - "type": "string" - }, - { - "name": "nbf", - "optional": true, - "type": "number" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "ref", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": false, - "type": "string" - }, - { - "name": "session_id", - "optional": false, - "type": "string" - }, - { - "name": "sub", - "optional": false, - "type": "string" - }, - { - "name": "user_metadata", - "optional": true, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - }, - { - "name": "header", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "alg", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "RS256" - }, - { - "kind": "literal", - "value": "ES256" - }, - { - "kind": "literal", - "value": "HS256" - } - ] - } - }, - { - "name": "kid", - "optional": false, - "type": "string" - }, - { - "name": "typ", - "optional": false, - "type": "string" - } - ], - "name": "JwtHeader" - } - }, - { - "name": "signature", - "optional": false, - "type": { - "kind": "reference", - "name": "Uint8Array" - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Get JWT claims, header and signature", - "code": "const { data, error } = await supabase.auth.getClaims()", - "response": "{\n \"data\": {\n \"claims\": {\n \"aal\": \"aal1\",\n \"amr\": [{\n \"method\": \"email\",\n \"timestamp\": 1715766000\n }],\n \"app_metadata\": {},\n \"aud\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"exp\": 1715769600,\n \"iat\": 1715766000,\n \"is_anonymous\": false,\n \"iss\": \"https://project-id.supabase.co/auth/v1\",\n \"phone\": \"+13334445555\",\n \"role\": \"authenticated\",\n \"session_id\": \"11111111-1111-1111-1111-111111111111\",\n \"sub\": \"11111111-1111-1111-1111-111111111111\",\n \"user_metadata\": {}\n },\n \"header\": {\n \"alg\": \"RS256\",\n \"typ\": \"JWT\",\n \"kid\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"signature\": [/** Uint8Array */],\n },\n \"error\": null\n}" - } - ] - }, - { - "name": "getSession", - "description": "Returns the session, refreshing it if necessary.\nThe session returned can be null if the session is not detected which can happen in the event a user is not signed-in or has logged out.\n**IMPORTANT:** This method loads values directly from the storage attached to the client. If that storage is based on request cookies for example, the values in it may not be authentic and therefore it's strongly advised against using this method and its results in such circumstances. A warning will be emitted if this is detected. Use #getUser() instead.", - "remarks": [ - "- Since the introduction of [asymmetric JWT signing keys](/docs/guides/auth/signing-keys), this method is considered low-level and we encourage you to use `getClaims()` or `getUser()` instead. - Retrieves the current [user session](/docs/guides/auth/sessions) from the storage medium (local storage, cookies). - The session contains an access token (signed JWT), a refresh token and the user object. - If the session's access token is expired or is about to expire, this method will use the refresh token to refresh the session. - When using in a browser, or you've called `startAutoRefresh()` in your environment (React Native, etc.) this function always returns a valid access token without refreshing the session itself, as this is done in the background. This function returns very fast. - **IMPORTANT SECURITY NOTICE:** If using an insecure storage medium, such as cookies or request headers, the user object returned by this function **must not be trusted**. Always verify the JWT using `getClaims()` or your own JWT verification library to securely establish the user's identity and access. You can also use `getUser()` to fetch the user object directly from the Auth server for this purpose. - When using in a browser, this function is synchronized across all tabs using the [LockManager](https://developer.mozilla.org/en-US/docs/Web/API/LockManager) API. In other environments make sure you've defined a proper `lock` property, if necessary, to make sure there are no race conditions while the session is being refreshed." - ], - "parameters": [], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "object", - "name": "Session", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Get the session data", - "code": "const { data, error } = await supabase.auth.getSession()", - "response": "{\n \"data\": {\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n }\n },\n \"error\": null\n}" - } - ] - }, - { - "name": "getUser", - "description": "Gets the current user details if there is an existing session. This method performs a network request to the Supabase Auth server, so the returned value is authentic and can be used to base authorization rules on.", - "remarks": [ - "- This method fetches the user object from the database instead of local session. - This method is useful for checking if the user is authorized because it validates the user's access token JWT on the server. - Should always be used when checking for user authorization on the server. On the client, you can instead use `getSession().session.user` for faster results. `getSession` is insecure on the server." - ], - "parameters": [ - { - "name": "jwt", - "optional": true, - "description": "Takes in an optional access token JWT. If no JWT is provided, the JWT from the current session is used.", - "type": "string" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Get the logged in user with the current existing session", - "code": "const { data: { user } } = await supabase.auth.getUser()", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" - }, - { - "title": "Get the logged in user with a custom access token jwt", - "code": "const { data: { user } } = await supabase.auth.getUser(jwt)" - } - ] - }, - { - "name": "getUserIdentities", - "description": "Gets all the identities linked to a user.", - "remarks": ["- The user needs to be signed in to call `getUserIdentities()`."], - "parameters": [], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "identities", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Returns a list of identities linked to the user", - "code": "const { data, error } = await supabase.auth.getUserIdentities()", - "response": "{\n \"data\": {\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"2024-01-01T00:00:00Z\",\n \"user_id\": \"2024-01-01T00:00:00Z\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ]\n },\n \"error\": null\n}" - } - ] - }, - { - "name": "initialize", - "description": "Initializes the client session either from the url or from storage. This method is automatically called when instantiating the client, but should also be called manually when checking for an error from an auth redirect (oauth, magiclink, password recovery, etc).", - "parameters": [], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "object", - "properties": [ - { - "name": "error", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - } - ], - "name": "InitializeResult" - } - ] - } - }, - { - "name": "linkIdentity", - "description": "", - "remarks": [ - "- The **Enable Manual Linking** option must be enabled from your [project's authentication settings](/dashboard/project/_/auth/providers). - The user needs to be signed in to call `linkIdentity()`. - If the candidate identity is already linked to the existing user or another user, `linkIdentity()` will fail. - If `linkIdentity` is run in the browser, the user is automatically redirected to the returned URL. On the server, you should handle the redirect." - ], - "parameters": [ - { - "name": "credentials", - "type": { - "kind": "object", - "properties": [ - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "queryParams", - "optional": true, - "description": "An object of query params", - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "redirectTo", - "optional": true, - "description": "A URL to send the user to after they are confirmed.", - "type": "string" - }, - { - "name": "scopes", - "optional": true, - "description": "A space-separated list of scopes granted to the OAuth application.", - "type": "string" - }, - { - "name": "skipBrowserRedirect", - "optional": true, - "description": "If set to true does not immediately redirect the current browser context to visit the OAuth authorization page for the provider.", - "type": "boolean" - } - ] - } - }, - { - "name": "provider", - "optional": false, - "description": "One of the providers supported by GoTrue.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "apple" - }, - { - "kind": "literal", - "value": "azure" - }, - { - "kind": "literal", - "value": "bitbucket" - }, - { - "kind": "literal", - "value": "discord" - }, - { - "kind": "literal", - "value": "facebook" - }, - { - "kind": "literal", - "value": "figma" - }, - { - "kind": "literal", - "value": "github" - }, - { - "kind": "literal", - "value": "gitlab" - }, - { - "kind": "literal", - "value": "google" - }, - { - "kind": "literal", - "value": "kakao" - }, - { - "kind": "literal", - "value": "keycloak" - }, - { - "kind": "literal", - "value": "linkedin" - }, - { - "kind": "literal", - "value": "linkedin_oidc" - }, - { - "kind": "literal", - "value": "notion" - }, - { - "kind": "literal", - "value": "slack" - }, - { - "kind": "literal", - "value": "slack_oidc" - }, - { - "kind": "literal", - "value": "spotify" - }, - { - "kind": "literal", - "value": "twitch" - }, - { - "kind": "literal", - "value": "twitter" - }, - { - "kind": "literal", - "value": "x" - }, - { - "kind": "literal", - "value": "workos" - }, - { - "kind": "literal", - "value": "zoom" - }, - { - "kind": "literal", - "value": "fly" - }, - { - "kind": "templateLiteral" - } - ] - } - } - ], - "name": "SignInWithOAuthCredentials" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "provider", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "apple" - }, - { - "kind": "literal", - "value": "azure" - }, - { - "kind": "literal", - "value": "bitbucket" - }, - { - "kind": "literal", - "value": "discord" - }, - { - "kind": "literal", - "value": "facebook" - }, - { - "kind": "literal", - "value": "figma" - }, - { - "kind": "literal", - "value": "github" - }, - { - "kind": "literal", - "value": "gitlab" - }, - { - "kind": "literal", - "value": "google" - }, - { - "kind": "literal", - "value": "kakao" - }, - { - "kind": "literal", - "value": "keycloak" - }, - { - "kind": "literal", - "value": "linkedin" - }, - { - "kind": "literal", - "value": "linkedin_oidc" - }, - { - "kind": "literal", - "value": "notion" - }, - { - "kind": "literal", - "value": "slack" - }, - { - "kind": "literal", - "value": "slack_oidc" - }, - { - "kind": "literal", - "value": "spotify" - }, - { - "kind": "literal", - "value": "twitch" - }, - { - "kind": "literal", - "value": "twitter" - }, - { - "kind": "literal", - "value": "x" - }, - { - "kind": "literal", - "value": "workos" - }, - { - "kind": "literal", - "value": "zoom" - }, - { - "kind": "literal", - "value": "fly" - }, - { - "kind": "templateLiteral" - } - ] - } - }, - { - "name": "url", - "optional": false, - "type": "string" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "provider", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "apple" - }, - { - "kind": "literal", - "value": "azure" - }, - { - "kind": "literal", - "value": "bitbucket" - }, - { - "kind": "literal", - "value": "discord" - }, - { - "kind": "literal", - "value": "facebook" - }, - { - "kind": "literal", - "value": "figma" - }, - { - "kind": "literal", - "value": "github" - }, - { - "kind": "literal", - "value": "gitlab" - }, - { - "kind": "literal", - "value": "google" - }, - { - "kind": "literal", - "value": "kakao" - }, - { - "kind": "literal", - "value": "keycloak" - }, - { - "kind": "literal", - "value": "linkedin" - }, - { - "kind": "literal", - "value": "linkedin_oidc" - }, - { - "kind": "literal", - "value": "notion" - }, - { - "kind": "literal", - "value": "slack" - }, - { - "kind": "literal", - "value": "slack_oidc" - }, - { - "kind": "literal", - "value": "spotify" - }, - { - "kind": "literal", - "value": "twitch" - }, - { - "kind": "literal", - "value": "twitter" - }, - { - "kind": "literal", - "value": "x" - }, - { - "kind": "literal", - "value": "workos" - }, - { - "kind": "literal", - "value": "zoom" - }, - { - "kind": "literal", - "value": "fly" - }, - { - "kind": "templateLiteral" - } - ] - } - }, - { - "name": "url", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Link an identity to a user", - "code": "const { data, error } = await supabase.auth.linkIdentity({\n provider: 'github'\n})", - "response": "{\n data: {\n provider: 'github',\n url: \n },\n error: null\n}" - } - ] - }, - { - "name": "onAuthStateChange", - "description": "", - "remarks": [ - "- Subscribes to important events occurring on the user's session. - Use on the frontend/client. It is less useful on the server. - Events are emitted across tabs to keep your application's UI up-to-date. Some events can fire very frequently, based on the number of tabs open. Use a quick and efficient callback function, and defer or debounce as many operations as you can to be performed outside of the callback. - **Important:** A callback can be an `async` function and it runs synchronously during the processing of the changes causing the event. You can easily create a dead-lock by using `await` on a call to another method of the Supabase library. - Avoid using `async` functions as callbacks. - Limit the number of `await` calls in `async` callbacks. - Do not use other Supabase functions in the callback function. If you must, dispatch the functions once the callback has finished executing. Use this as a quick way to achieve this: ```js supabase.auth.onAuthStateChange((event, session) => { setTimeout(async () => { // await on other Supabase function here // this runs right after the callback has finished }, 0) }) ``` - Emitted events: - `INITIAL_SESSION` - Emitted right after the Supabase client is constructed and the initial session from storage is loaded. - `SIGNED_IN` - Emitted each time a user session is confirmed or re-established, including on user sign in and when refocusing a tab. - Avoid making assumptions as to when this event is fired, this may occur even when the user is already signed in. Instead, check the user object attached to the event to see if a new user has signed in and update your application's UI. - This event can fire very frequently depending on the number of tabs open in your application. - `SIGNED_OUT` - Emitted when the user signs out. This can be after: - A call to `supabase.auth.signOut()`. - After the user's session has expired for any reason: - User has signed out on another device. - The session has reached its timebox limit or inactivity timeout. - User has signed in on another device with single session per user enabled. - Check the [User Sessions](/docs/guides/auth/sessions) docs for more information. - Use this to clean up any local storage your application has associated with the user. - `TOKEN_REFRESHED` - Emitted each time a new access and refresh token are fetched for the signed in user. - It's best practice and highly recommended to extract the access token (JWT) and store it in memory for further use in your application. - Avoid frequent calls to `supabase.auth.getSession()` for the same purpose. - There is a background process that keeps track of when the session should be refreshed so you will always receive valid tokens by listening to this event. - The frequency of this event is related to the JWT expiry limit configured on your project. - `USER_UPDATED` - Emitted each time the `supabase.auth.updateUser()` method finishes successfully. Listen to it to update your application's UI based on new profile information. - `PASSWORD_RECOVERY` - Emitted instead of the `SIGNED_IN` event when the user lands on a page that includes a password recovery link in the URL. - Use it to show a UI to the user where they can [reset their password](/docs/guides/auth/passwords#resetting-a-users-password-forgot-password)." - ], - "parameters": [ - { - "name": "callback", - "description": "A callback function to be invoked when an auth event happens.", - "type": { - "kind": "object", - "properties": [] - } - } - ], - "returnType": { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "subscription", - "optional": false, - "type": { - "kind": "object", - "name": "Subscription", - "properties": [ - { - "name": "callback", - "optional": false, - "description": "The function to call every time there is an event. eg: (eventName) => {}", - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "id", - "optional": false, - "description": "A unique identifier for this subscription, set by the client. This is an internal identifier used for managing callbacks and should not be relied upon by application code. Use the unsubscribe() method to remove listeners.", - "type": { - "kind": "union", - "types": ["string", "symbol"] - } - }, - { - "name": "unsubscribe", - "optional": false, - "description": "Call this to remove the listener.", - "type": { - "kind": "object", - "properties": [] - } - } - ] - } - } - ] - } - } - ] - }, - "examples": [ - { - "title": "Listen to auth changes", - "code": "const { data } = supabase.auth.onAuthStateChange((event, session) => {\n console.log(event, session)\n\n if (event === 'INITIAL_SESSION') {\n // handle initial session\n } else if (event === 'SIGNED_IN') {\n // handle sign in event\n } else if (event === 'SIGNED_OUT') {\n // handle sign out event\n } else if (event === 'PASSWORD_RECOVERY') {\n // handle password recovery event\n } else if (event === 'TOKEN_REFRESHED') {\n // handle token refreshed event\n } else if (event === 'USER_UPDATED') {\n // handle user updated event\n }\n})\n\n// call unsubscribe to remove the callback\ndata.subscription.unsubscribe()", - "notes": "Listen to sign out\nMake sure you clear out any local data, such as local and session storage, after the client library has detected the user's sign out." - }, - { - "title": "Listen to sign out", - "code": "supabase.auth.onAuthStateChange((event, session) => {\n if (event === 'SIGNED_OUT') {\n console.log('SIGNED_OUT', session)\n\n // clear local and session storage\n [\n window.localStorage,\n window.sessionStorage,\n ].forEach((storage) => {\n Object.entries(storage)\n .forEach(([key]) => {\n storage.removeItem(key)\n })\n })\n }\n})", - "notes": "Make sure you clear out any local data, such as local and session storage, after the client library has detected the user's sign out." - }, - { - "title": "Store OAuth provider tokens on sign in", - "code": "// Register this immediately after calling createClient!\n// Because signInWithOAuth causes a redirect, you need to fetch the\n// provider tokens from the callback.\nsupabase.auth.onAuthStateChange((event, session) => {\n if (session && session.provider_token) {\n window.localStorage.setItem('oauth_provider_token', session.provider_token)\n }\n\n if (session && session.provider_refresh_token) {\n window.localStorage.setItem('oauth_provider_refresh_token', session.provider_refresh_token)\n }\n\n if (event === 'SIGNED_OUT') {\n window.localStorage.removeItem('oauth_provider_token')\n window.localStorage.removeItem('oauth_provider_refresh_token')\n }\n})", - "notes": "When using [OAuth (Social Login)](/docs/guides/auth/social-login) you sometimes wish to get access to the provider's access token and refresh token, in order to call provider APIs in the name of the user.\n\nFor example, if you are using [Sign in with Google](/docs/guides/auth/social-login/auth-google) you may want to use the provider token to call Google APIs on behalf of the user. Supabase Auth does not keep track of the provider access and refresh token, but does return them for you once, immediately after sign in. You can use the `onAuthStateChange` method to listen for the presence of the provider tokens and store them in local storage. You can further send them to your server's APIs for use on the backend.\n\nFinally, make sure you remove them from local storage on the `SIGNED_OUT` event. If the OAuth provider supports token revocation, make sure you call those APIs either from the frontend or schedule them to be called on the backend." - }, - { - "title": "Use React Context for the User's session", - "code": "const SessionContext = React.createContext(null)\n\nfunction main() {\n const [session, setSession] = React.useState(null)\n\n React.useEffect(() => {\n const {data: { subscription }} = supabase.auth.onAuthStateChange(\n (event, session) => {\n if (event === 'SIGNED_OUT') {\n setSession(null)\n } else if (session) {\n setSession(session)\n }\n })\n\n return () => {\n subscription.unsubscribe()\n }\n }, [])\n\n return (\n \n \n \n )\n}", - "notes": "Instead of relying on `supabase.auth.getSession()` within your React components, you can use a [React Context](https://react.dev/reference/react/createContext) to store the latest session information from the `onAuthStateChange` callback and access it that way." - }, - { - "title": "Listen to password recovery events", - "code": "supabase.auth.onAuthStateChange((event, session) => {\n if (event === 'PASSWORD_RECOVERY') {\n console.log('PASSWORD_RECOVERY', session)\n // show screen to update user's password\n showPasswordResetScreen(true)\n }\n})" - }, - { - "title": "Listen to sign in", - "code": "supabase.auth.onAuthStateChange((event, session) => {\n if (event === 'SIGNED_IN') console.log('SIGNED_IN', session)\n})" - }, - { - "title": "Listen to token refresh", - "code": "supabase.auth.onAuthStateChange((event, session) => {\n if (event === 'TOKEN_REFRESHED') console.log('TOKEN_REFRESHED', session)\n})" - }, - { - "title": "Listen to user updates", - "code": "supabase.auth.onAuthStateChange((event, session) => {\n if (event === 'USER_UPDATED') console.log('USER_UPDATED', session)\n})" - } - ] - }, - { - "name": "reauthenticate", - "description": "Sends a reauthentication OTP to the user's email or phone number. Requires the user to be signed-in.", - "remarks": [ - "- This method is used together with `updateUser()` when a user's password needs to be updated. - If you require your user to reauthenticate before updating their password, you need to enable the **Secure password change** option in your [project's email provider settings](/dashboard/project/_/auth/providers). - A user is only require to reauthenticate before updating their password if **Secure password change** is enabled and the user **hasn't recently signed in**. A user is deemed recently signed in if the session was created in the last 24 hours. - This method will send a nonce to the user's email. If the user doesn't have a confirmed email address, the method will send the nonce to the user's confirmed phone number instead. - After receiving the OTP, include it as the `nonce` in your `updateUser()` call to finalize the password change." - ], - "parameters": [], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "Session", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Send reauthentication nonce", - "code": "const { error } = await supabase.auth.reauthenticate()", - "notes": "Sends a reauthentication nonce to the user's email or phone number." - } - ] - }, - { - "name": "refreshSession", - "description": "Returns a new session, regardless of expiry status. Takes in an optional current session. If not passed in, then refreshSession() will attempt to retrieve it from getSession(). If the current session's refresh token is invalid, an error will be thrown.", - "remarks": [ - "- This method will refresh and return a new session whether the current one is expired or not." - ], - "parameters": [ - { - "name": "currentSession", - "optional": true, - "description": "The current session. If passed in, it must contain a refresh token.", - "type": { - "kind": "object", - "properties": [ - { - "name": "refresh_token", - "optional": false, - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "Session", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Refresh session using the current session", - "code": "const { data, error } = await supabase.auth.refreshSession()\nconst { session, user } = data", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n }\n },\n \"error\": null\n}" - }, - { - "title": "Refresh session using a refresh token", - "code": "const { data, error } = await supabase.auth.refreshSession({ refresh_token })\nconst { session, user } = data" - } - ] - }, - { - "name": "resend", - "description": "Resends an existing signup confirmation email, email change email, SMS OTP or phone change OTP.", - "remarks": [ - "- Resends a signup confirmation, email change or phone change email to the user. - Passwordless sign-ins can be resent by calling the `signInWithOtp()` method again. - Password recovery emails can be resent by calling the `resetPasswordForEmail()` method again. - This method will only resend an email or phone OTP to the user if there was an initial signup, email change or phone change request being made(note: For existing users signing in with OTP, you should use `signInWithOtp()` again to resend the OTP). - You can specify a redirect url when you resend an email link using the `emailRedirectTo` option." - ], - "parameters": [ - { - "name": "credentials", - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "email", - "optional": false, - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "emailRedirectTo", - "optional": true, - "description": "A URL to send the user to after they have signed-in.", - "type": "string" - } - ] - } - }, - { - "name": "type", - "optional": false, - "type": { - "kind": "reference", - "name": "Extract", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "signup" - }, - { - "kind": "literal", - "value": "invite" - }, - { - "kind": "literal", - "value": "magiclink" - }, - { - "kind": "literal", - "value": "recovery" - }, - { - "kind": "literal", - "value": "email_change" - }, - { - "kind": "literal", - "value": "email" - } - ] - }, - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "signup" - }, - { - "kind": "literal", - "value": "email_change" - } - ] - } - ] - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - } - ] - } - }, - { - "name": "phone", - "optional": false, - "type": "string" - }, - { - "name": "type", - "optional": false, - "type": { - "kind": "reference", - "name": "Extract", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "sms" - }, - { - "kind": "literal", - "value": "phone_change" - } - ] - }, - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "sms" - }, - { - "kind": "literal", - "value": "phone_change" - } - ] - } - ] - } - } - ] - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "messageId", - "optional": true, - "type": { - "kind": "union", - "types": [ - "string", - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "session", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Resend an email signup confirmation", - "code": "const { error } = await supabase.auth.resend({\n type: 'signup',\n email: 'email@example.com',\n options: {\n emailRedirectTo: 'https://example.com/welcome'\n }\n})", - "notes": "Resends the email signup confirmation to the user" - }, - { - "title": "Resend a phone signup confirmation", - "code": "const { error } = await supabase.auth.resend({\n type: 'sms',\n phone: '1234567890'\n})", - "notes": "Resends the phone signup confirmation email to the user" - }, - { - "title": "Resend email change email", - "code": "const { error } = await supabase.auth.resend({\n type: 'email_change',\n email: 'email@example.com'\n})", - "notes": "Resends the email change email to the user" - }, - { - "title": "Resend phone change OTP", - "code": "const { error } = await supabase.auth.resend({\n type: 'phone_change',\n phone: '1234567890'\n})", - "notes": "Resends the phone change OTP to the user" - } - ] - }, - { - "name": "resetPasswordForEmail", - "description": "Sends a password reset request to an email address. This method supports the PKCE flow.", - "remarks": [ - "- The password reset flow consist of 2 broad steps: (i) Allow the user to login via the password reset link; (ii) Update the user's password. - The `resetPasswordForEmail()` only sends a password reset link to the user's email. To update the user's password, see [`updateUser()`](/docs/reference/javascript/auth-updateuser). - A `PASSWORD_RECOVERY` event will be emitted when the password recovery link is clicked. You can use [`onAuthStateChange()`](/docs/reference/javascript/auth-onauthstatechange) to listen and invoke a callback function on these events. - When the user clicks the reset link in the email they are redirected back to your application. You can configure the URL that the user is redirected to with the `redirectTo` parameter. See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project. - After the user has been redirected successfully, prompt them for a new password and call `updateUser()`: ```js const { data, error } = await supabase.auth.updateUser({ password: new_password }) ```" - ], - "parameters": [ - { - "name": "email", - "description": "The email address of the user.", - "type": "string" - }, - { - "name": "options", - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "redirectTo", - "optional": true, - "description": "The URL to send the user to after they click the password reset link.", - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Reset password", - "code": "const { data, error } = await supabase.auth.resetPasswordForEmail(email, {\n redirectTo: 'https://example.com/update-password',\n})", - "response": "{\n data: {}\n error: null\n}" - }, - { - "title": "Reset password (React)", - "code": "/**\n * Step 1: Send the user an email to get a password reset token.\n * This email contains a link which sends the user back to your application.\n */\nconst { data, error } = await supabase.auth\n .resetPasswordForEmail('user@email.com')\n\n/**\n * Step 2: Once the user is redirected back to your application,\n * ask the user to reset their password.\n */\n useEffect(() => {\n supabase.auth.onAuthStateChange(async (event, session) => {\n if (event == \"PASSWORD_RECOVERY\") {\n const newPassword = prompt(\"What would you like your new password to be?\");\n const { data, error } = await supabase.auth\n .updateUser({ password: newPassword })\n\n if (data) alert(\"Password updated successfully!\")\n if (error) alert(\"There was an error updating your password.\")\n }\n })\n }, [])" - } - ] - }, - { - "name": "setSession", - "description": "Sets the session data from the current session. If the current session is expired, setSession will take care of refreshing it to obtain a new session. If the refresh token or access token in the current session is invalid, an error will be thrown.", - "remarks": [ - "- This method sets the session using an `access_token` and `refresh_token`. - If successful, a `SIGNED_IN` event is emitted." - ], - "parameters": [ - { - "name": "currentSession", - "description": "The current session that minimally contains an access token and refresh token.", - "type": { - "kind": "object", - "properties": [ - { - "name": "access_token", - "optional": false, - "type": "string" - }, - { - "name": "refresh_token", - "optional": false, - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "Session", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Set the session", - "code": "const { data, error } = await supabase.auth.setSession({\n access_token,\n refresh_token\n })", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n },\n \"session\": {\n \"access_token\": \"\",\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"11111111-1111-1111-1111-111111111111\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"2024-01-01T00:00:00Z\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n },\n \"token_type\": \"bearer\",\n \"expires_in\": 3500,\n \"expires_at\": 1700000000\n }\n },\n \"error\": null\n}", - "notes": "Sets the session data from an access_token and refresh_token, then returns an auth response or error." - } - ] - }, - { - "name": "signInAnonymously", - "description": "Creates a new anonymous user.", - "remarks": [ - "- Returns an anonymous user - It is recommended to set up captcha for anonymous sign-ins to prevent abuse. You can pass in the captcha token in the `options` param." - ], - "parameters": [ - { - "name": "credentials", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "data", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", - "type": "object" - } - ] - } - } - ], - "name": "SignInAnonymouslyCredentials" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "Session", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Create an anonymous user", - "code": "const { data, error } = await supabase.auth.signInAnonymously({\n options: {\n captchaToken\n }\n});", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {},\n \"user_metadata\": {},\n \"identities\": [],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": true\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {},\n \"user_metadata\": {},\n \"identities\": [],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": true\n }\n }\n },\n \"error\": null\n}" - }, - { - "title": "Create an anonymous user with custom user metadata", - "code": "const { data, error } = await supabase.auth.signInAnonymously({\n options: {\n data\n }\n})" - } - ] - }, - { - "name": "signInWithIdToken", - "description": "Allows signing in with an OIDC ID token. The authentication provider used should be enabled and configured.", - "remarks": [ - "- Use an ID token to sign in. - Especially useful when implementing sign in using native platform dialogs in mobile or desktop apps using Sign in with Apple or Sign in with Google on iOS and Android. - You can also use Google's [One Tap](https://developers.google.com/identity/gsi/web/guides/display-google-one-tap) and [Automatic sign-in](https://developers.google.com/identity/gsi/web/guides/automatic-sign-in-sign-out) via this API." - ], - "parameters": [ - { - "name": "credentials", - "type": { - "kind": "object", - "properties": [ - { - "name": "access_token", - "optional": true, - "description": "If the ID token contains an `at_hash` claim, then the hash of this value is compared to the value in the ID token.", - "type": "string" - }, - { - "name": "nonce", - "optional": true, - "description": "If the ID token contains a `nonce` claim, then the hash of this value is compared to the value in the ID token.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - } - ] - } - }, - { - "name": "provider", - "optional": false, - "description": "Provider name or OIDC `iss` value identifying which provider should be used to verify the provided token. Supported names: `google`, `apple`, `azure`, `facebook`, `kakao`. Use the `custom:` prefix for custom OIDC providers (e.g. `custom:my-oidc-provider`).", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "google" - }, - { - "kind": "literal", - "value": "apple" - }, - { - "kind": "literal", - "value": "azure" - }, - { - "kind": "literal", - "value": "facebook" - }, - { - "kind": "literal", - "value": "kakao" - }, - { - "kind": "templateLiteral" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "token", - "optional": false, - "description": "OIDC ID token issued by the specified provider. The `iss` claim in the ID token must match the supplied provider. Some ID tokens contain an `at_hash` which require that you provide an `access_token` value to be accepted properly. If the token contains a `nonce` claim you must supply the nonce used to obtain the ID token.", - "type": "string" - } - ], - "name": "SignInWithIdTokenCredentials" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "object", - "name": "Session", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Sign In using ID Token", - "code": "const { data, error } = await supabase.auth.signInWithIdToken({\n provider: 'google',\n token: 'your-id-token'\n})", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n ...\n },\n \"user_metadata\": {\n ...\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"provider\": \"google\",\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n ...\n },\n \"user_metadata\": {\n ...\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"provider\": \"google\",\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n }\n }\n },\n \"error\": null\n}" - } - ] - }, - { - "name": "signInWithOAuth", - "description": "Log in an existing user via a third-party provider. This method supports the PKCE flow.", - "remarks": [ - "- This method is used for signing in using [Social Login (OAuth) providers](/docs/guides/auth#configure-third-party-providers). - It works by redirecting your application to the provider's authorization screen, before bringing back the user to your app." - ], - "parameters": [ - { - "name": "credentials", - "type": { - "kind": "object", - "properties": [ - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "queryParams", - "optional": true, - "description": "An object of query params", - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "redirectTo", - "optional": true, - "description": "A URL to send the user to after they are confirmed.", - "type": "string" - }, - { - "name": "scopes", - "optional": true, - "description": "A space-separated list of scopes granted to the OAuth application.", - "type": "string" - }, - { - "name": "skipBrowserRedirect", - "optional": true, - "description": "If set to true does not immediately redirect the current browser context to visit the OAuth authorization page for the provider.", - "type": "boolean" - } - ] - } - }, - { - "name": "provider", - "optional": false, - "description": "One of the providers supported by GoTrue.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "apple" - }, - { - "kind": "literal", - "value": "azure" - }, - { - "kind": "literal", - "value": "bitbucket" - }, - { - "kind": "literal", - "value": "discord" - }, - { - "kind": "literal", - "value": "facebook" - }, - { - "kind": "literal", - "value": "figma" - }, - { - "kind": "literal", - "value": "github" - }, - { - "kind": "literal", - "value": "gitlab" - }, - { - "kind": "literal", - "value": "google" - }, - { - "kind": "literal", - "value": "kakao" - }, - { - "kind": "literal", - "value": "keycloak" - }, - { - "kind": "literal", - "value": "linkedin" - }, - { - "kind": "literal", - "value": "linkedin_oidc" - }, - { - "kind": "literal", - "value": "notion" - }, - { - "kind": "literal", - "value": "slack" - }, - { - "kind": "literal", - "value": "slack_oidc" - }, - { - "kind": "literal", - "value": "spotify" - }, - { - "kind": "literal", - "value": "twitch" - }, - { - "kind": "literal", - "value": "twitter" - }, - { - "kind": "literal", - "value": "x" - }, - { - "kind": "literal", - "value": "workos" - }, - { - "kind": "literal", - "value": "zoom" - }, - { - "kind": "literal", - "value": "fly" - }, - { - "kind": "templateLiteral" - } - ] - } - } - ], - "name": "SignInWithOAuthCredentials" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "provider", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "apple" - }, - { - "kind": "literal", - "value": "azure" - }, - { - "kind": "literal", - "value": "bitbucket" - }, - { - "kind": "literal", - "value": "discord" - }, - { - "kind": "literal", - "value": "facebook" - }, - { - "kind": "literal", - "value": "figma" - }, - { - "kind": "literal", - "value": "github" - }, - { - "kind": "literal", - "value": "gitlab" - }, - { - "kind": "literal", - "value": "google" - }, - { - "kind": "literal", - "value": "kakao" - }, - { - "kind": "literal", - "value": "keycloak" - }, - { - "kind": "literal", - "value": "linkedin" - }, - { - "kind": "literal", - "value": "linkedin_oidc" - }, - { - "kind": "literal", - "value": "notion" - }, - { - "kind": "literal", - "value": "slack" - }, - { - "kind": "literal", - "value": "slack_oidc" - }, - { - "kind": "literal", - "value": "spotify" - }, - { - "kind": "literal", - "value": "twitch" - }, - { - "kind": "literal", - "value": "twitter" - }, - { - "kind": "literal", - "value": "x" - }, - { - "kind": "literal", - "value": "workos" - }, - { - "kind": "literal", - "value": "zoom" - }, - { - "kind": "literal", - "value": "fly" - }, - { - "kind": "templateLiteral" - } - ] - } - }, - { - "name": "url", - "optional": false, - "type": "string" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "provider", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "apple" - }, - { - "kind": "literal", - "value": "azure" - }, - { - "kind": "literal", - "value": "bitbucket" - }, - { - "kind": "literal", - "value": "discord" - }, - { - "kind": "literal", - "value": "facebook" - }, - { - "kind": "literal", - "value": "figma" - }, - { - "kind": "literal", - "value": "github" - }, - { - "kind": "literal", - "value": "gitlab" - }, - { - "kind": "literal", - "value": "google" - }, - { - "kind": "literal", - "value": "kakao" - }, - { - "kind": "literal", - "value": "keycloak" - }, - { - "kind": "literal", - "value": "linkedin" - }, - { - "kind": "literal", - "value": "linkedin_oidc" - }, - { - "kind": "literal", - "value": "notion" - }, - { - "kind": "literal", - "value": "slack" - }, - { - "kind": "literal", - "value": "slack_oidc" - }, - { - "kind": "literal", - "value": "spotify" - }, - { - "kind": "literal", - "value": "twitch" - }, - { - "kind": "literal", - "value": "twitter" - }, - { - "kind": "literal", - "value": "x" - }, - { - "kind": "literal", - "value": "workos" - }, - { - "kind": "literal", - "value": "zoom" - }, - { - "kind": "literal", - "value": "fly" - }, - { - "kind": "templateLiteral" - } - ] - } - }, - { - "name": "url", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Sign in using a third-party provider", - "code": "const { data, error } = await supabase.auth.signInWithOAuth({\n provider: 'github'\n})", - "response": "{\n data: {\n provider: 'github',\n url: \n },\n error: null\n}", - "notes": "with redirect\n- When the OAuth provider successfully authenticates the user, they are redirected to the URL specified in the `redirectTo` parameter. This parameter defaults to the [`SITE_URL`](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls). It does not redirect the user immediately after invoking this method.\n- See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project." - }, - { - "title": "Sign in using a third-party provider with redirect", - "code": "const { data, error } = await supabase.auth.signInWithOAuth({\n provider: 'github',\n options: {\n redirectTo: 'https://example.com/welcome'\n }\n})", - "notes": "- When the OAuth provider successfully authenticates the user, they are redirected to the URL specified in the `redirectTo` parameter. This parameter defaults to the [`SITE_URL`](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls). It does not redirect the user immediately after invoking this method.\n- See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project." - }, - { - "title": "Sign in with scopes and access provider tokens", - "code": "// Register this immediately after calling createClient!\n// Because signInWithOAuth causes a redirect, you need to fetch the\n// provider tokens from the callback.\nsupabase.auth.onAuthStateChange((event, session) => {\n if (session && session.provider_token) {\n window.localStorage.setItem('oauth_provider_token', session.provider_token)\n }\n\n if (session && session.provider_refresh_token) {\n window.localStorage.setItem('oauth_provider_refresh_token', session.provider_refresh_token)\n }\n\n if (event === 'SIGNED_OUT') {\n window.localStorage.removeItem('oauth_provider_token')\n window.localStorage.removeItem('oauth_provider_refresh_token')\n }\n})\n\n// Call this on your Sign in with GitHub button to initiate OAuth\n// with GitHub with the requested elevated scopes.\nawait supabase.auth.signInWithOAuth({\n provider: 'github',\n options: {\n scopes: 'repo gist notifications'\n }\n})", - "notes": "If you need additional access from an OAuth provider, in order to access provider specific APIs in the name of the user, you can do this by passing in the scopes the user should authorize for your application. Note that the `scopes` option takes in **a space-separated list** of scopes.\n\nBecause OAuth sign-in often includes redirects, you should register an `onAuthStateChange` callback immediately after you create the Supabase client. This callback will listen for the presence of `provider_token` and `provider_refresh_token` properties on the `session` object and store them in local storage. The client library will emit these values **only once** immediately after the user signs in. You can then access them by looking them up in local storage, or send them to your backend servers for further processing.\n\nFinally, make sure you remove them from local storage on the `SIGNED_OUT` event. If the OAuth provider supports token revocation, make sure you call those APIs either from the frontend or schedule them to be called on the backend." - } - ] - }, - { - "name": "signInWithOtp", - "description": "Log in a user using magiclink or a one-time password (OTP).\nIf the `{{ .ConfirmationURL }}` variable is specified in the email template, a magiclink will be sent. If the `{{ .Token }}` variable is specified in the email template, an OTP will be sent. If you're using phone sign-ins, only an OTP will be sent. You won't be able to send a magiclink for phone sign-ins.\nBe aware that you may get back an error message that will not distinguish between the cases where the account does not exist or, that the account can only be accessed via social login.\nDo note that you will need to configure a Whatsapp sender on Twilio if you are using phone sign in with the 'whatsapp' channel. The whatsapp channel is not supported on other providers at this time. This method supports PKCE when an email is passed.", - "remarks": [ - "- Requires either an email or phone number. - This method is used for passwordless sign-ins where a OTP is sent to the user's email or phone number. - If the user doesn't exist, `signInWithOtp()` will signup the user instead. To restrict this behavior, you can set `shouldCreateUser` in `SignInWithPasswordlessCredentials.options` to `false`. - If you're using an email, you can configure whether you want the user to receive a magiclink or a OTP. - If you're using phone, you can configure whether you want the user to receive a OTP. - The magic link's destination URL is determined by the [`SITE_URL`](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls). - See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project. - Magic links and OTPs share the same implementation. To send users a one-time code instead of a magic link, [modify the magic link email template](/dashboard/project/_/auth/templates) to include `{{ .Token }}` instead of `{{ .ConfirmationURL }}`. - See our [Twilio Phone Auth Guide](/docs/guides/auth/phone-login?showSMSProvider=Twilio) for details about configuring WhatsApp sign in." - ], - "parameters": [ - { - "name": "credentials", - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "email", - "optional": false, - "description": "The user's email address.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "data", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", - "type": "object" - }, - { - "name": "emailRedirectTo", - "optional": true, - "description": "The redirect url embedded in the email link", - "type": "string" - }, - { - "name": "shouldCreateUser", - "optional": true, - "description": "If set to false, this method will not create a new user. Defaults to true.", - "type": "boolean" - } - ] - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "channel", - "optional": true, - "description": "Messaging channel to use (e.g. whatsapp or sms)", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "sms" - }, - { - "kind": "literal", - "value": "whatsapp" - } - ] - } - }, - { - "name": "data", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", - "type": "object" - }, - { - "name": "shouldCreateUser", - "optional": true, - "description": "If set to false, this method will not create a new user. Defaults to true.", - "type": "boolean" - } - ] - } - }, - { - "name": "phone", - "optional": false, - "description": "The user's phone number.", - "type": "string" - } - ] - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "messageId", - "optional": true, - "type": { - "kind": "union", - "types": [ - "string", - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "session", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Sign in with email", - "code": "const { data, error } = await supabase.auth.signInWithOtp({\n email: 'example@email.com',\n options: {\n emailRedirectTo: 'https://example.com/welcome'\n }\n})", - "response": "{\n \"data\": {\n \"user\": null,\n \"session\": null\n },\n \"error\": null\n}", - "notes": "The user will be sent an email which contains either a magiclink or a OTP or both. By default, a given user can only request a OTP once every 60 seconds." - }, - { - "title": "Sign in with SMS OTP", - "code": "const { data, error } = await supabase.auth.signInWithOtp({\n phone: '+13334445555',\n})", - "notes": "The user will be sent a SMS which contains a OTP. By default, a given user can only request a OTP once every 60 seconds." - }, - { - "title": "Sign in with WhatsApp OTP", - "code": "const { data, error } = await supabase.auth.signInWithOtp({\n phone: '+13334445555',\n options: {\n channel:'whatsapp',\n }\n})", - "notes": "The user will be sent a WhatsApp message which contains a OTP. By default, a given user can only request a OTP once every 60 seconds. Note that a user will need to have a valid WhatsApp account that is linked to Twilio in order to use this feature." - } - ] - }, - { - "name": "signInWithPassword", - "description": "Log in an existing user with an email and password or phone and password.\nBe aware that you may get back an error message that will not distinguish between the cases where the account does not exist or that the email/phone and password combination is wrong or that the account can only be accessed via social login.", - "remarks": ["- Requires either an email and password or a phone number and password."], - "parameters": [ - { - "name": "credentials", - "type": { - "kind": "intersection", - "types": [ - { - "kind": "reference", - "name": "PasswordCredentialsBase" - }, - { - "kind": "object", - "properties": [ - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "type": "string" - } - ] - } - } - ] - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "object", - "name": "Session", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - }, - { - "name": "weakPassword", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "message", - "optional": false, - "type": "string" - }, - { - "name": "reasons", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "indexedAccess", - "objectType": { - "kind": "query" - }, - "indexType": null - } - } - } - ], - "name": "WeakPassword" - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Sign in with email and password", - "code": "const { data, error } = await supabase.auth.signInWithPassword({\n email: 'example@email.com',\n password: 'example-password',\n})", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n }\n }\n },\n \"error\": null\n}" - }, - { - "title": "Sign in with phone and password", - "code": "const { data, error } = await supabase.auth.signInWithPassword({\n phone: '+13334445555',\n password: 'some-password',\n})" - } - ] - }, - { - "name": "signInWithSSO", - "description": "Attempts a single-sign on using an enterprise Identity Provider. A successful SSO attempt will redirect the current page to the identity provider authorization page. The redirect URL is implementation and SSO protocol specific.\nYou can use it by providing a SSO domain. Typically you can extract this domain by asking users for their email address. If this domain is registered on the Auth instance the redirect will use that organization's currently active SSO Identity Provider for the login.\nIf you have built an organization-specific login page, you can use the organization's SSO Identity Provider UUID directly instead.", - "remarks": [ - "- Before you can call this method you need to [establish a connection](/docs/guides/auth/sso/auth-sso-saml#managing-saml-20-connections) to an identity provider. Use the [CLI commands](/docs/reference/cli/supabase-sso) to do this. - If you've associated an email domain to the identity provider, you can use the `domain` property to start a sign-in flow. - In case you need to use a different way to start the authentication flow with an identity provider, you can use the `providerId` property. For example: - Mapping specific user email addresses with an identity provider. - Using different hints to identity the identity provider to be used by the user, like a company-specific page, IP address or other tracking information." - ], - "parameters": [ - { - "name": "params", - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "redirectTo", - "optional": true, - "description": "A URL to send the user to after they have signed-in.", - "type": "string" - }, - { - "name": "skipBrowserRedirect", - "optional": true, - "description": "If set to true, the redirect will not happen on the client side. This parameter is used when you wish to handle the redirect yourself. Defaults to false.", - "type": "boolean" - } - ] - } - }, - { - "name": "providerId", - "optional": false, - "description": "UUID of the SSO provider to invoke single-sign on to.", - "type": "string" - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "domain", - "optional": false, - "description": "Domain name of the organization for which to invoke single-sign on.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "redirectTo", - "optional": true, - "description": "A URL to send the user to after they have signed-in.", - "type": "string" - }, - { - "name": "skipBrowserRedirect", - "optional": true, - "description": "If set to true, the redirect will not happen on the client side. This parameter is used when you wish to handle the redirect yourself. Defaults to false.", - "type": "boolean" - } - ] - } - } - ] - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "url", - "optional": false, - "description": "URL to open in a browser which will complete the sign-in flow by taking the user to the identity provider's authentication flow.\nOn browsers you can set the URL to `window.location.href` to take the user to the authentication flow.", - "type": "string" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Sign in with email domain", - "code": "// You can extract the user's email domain and use it to trigger the\n // authentication flow with the correct identity provider.\n\n const { data, error } = await supabase.auth.signInWithSSO({\n domain: 'company.com'\n })\n\n if (data?.url) {\n // redirect the user to the identity provider's authentication flow\n window.location.href = data.url\n }" - }, - { - "title": "Sign in with provider UUID", - "code": "// Useful when you need to map a user's sign in request according\n // to different rules that can't use email domains.\n\n const { data, error } = await supabase.auth.signInWithSSO({\n providerId: '21648a9d-8d5a-4555-a9d1-d6375dc14e92'\n })\n\n if (data?.url) {\n // redirect the user to the identity provider's authentication flow\n window.location.href = data.url\n }" - } - ] - }, - { - "name": "signInWithWeb3", - "description": "Signs in a user by verifying a message signed by the user's private key. Supports Ethereum (via Sign-In-With-Ethereum) & Solana (Sign-In-With-Solana) standards, both of which derive from the EIP-4361 standard With slight variation on Solana's side.", - "remarks": [ - "- Uses a Web3 (Ethereum, Solana) wallet to sign a user in. - Read up on the [potential for abuse](/docs/guides/auth/auth-web3#potential-for-abuse) before using it." - ], - "parameters": [ - { - "name": "credentials", - "type": { - "kind": "union", - "types": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "chain", - "optional": false, - "type": { - "kind": "literal", - "value": "solana" - } - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "signInWithSolana", - "optional": true, - "type": { - "kind": "reference", - "name": "Partial", - "typeArguments": [ - { - "kind": "reference", - "name": "Omit", - "typeArguments": [ - { - "kind": "reference", - "name": "SolanaSignInInput" - }, - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "version" - }, - { - "kind": "literal", - "value": "chain" - }, - { - "kind": "literal", - "value": "domain" - }, - { - "kind": "literal", - "value": "uri" - }, - { - "kind": "literal", - "value": "statement" - } - ] - } - ] - } - ] - } - }, - { - "name": "url", - "optional": true, - "description": "URL to use with the wallet interface. Some wallets do not allow signing a message for URLs different from the current page.", - "type": "string" - } - ] - } - }, - { - "name": "statement", - "optional": true, - "description": "Optional statement to include in the Sign in with Solana message. Must not include new line characters. Most wallets like Phantom **require specifying a statement!**", - "type": "string" - }, - { - "name": "wallet", - "optional": true, - "description": "Wallet interface to use. If not specified will default to `window.solana`.", - "type": { - "kind": "object", - "properties": [ - { - "name": "publicKey", - "optional": true, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "toBase58", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "signIn", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "signMessage", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - } - ], - "name": "SolanaWallet" - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "chain", - "optional": false, - "type": { - "kind": "literal", - "value": "solana" - } - }, - { - "name": "message", - "optional": false, - "description": "Sign in with Solana compatible message. Must include `Issued At`, `URI` and `Version`.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - } - ] - } - }, - { - "name": "signature", - "optional": false, - "description": "Ed25519 signature of the message.", - "type": { - "kind": "reference", - "name": "Uint8Array" - } - } - ] - } - ] - }, - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "chain", - "optional": false, - "type": { - "kind": "literal", - "value": "ethereum" - } - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "signInWithEthereum", - "optional": true, - "type": { - "kind": "reference", - "name": "Partial", - "typeArguments": [ - { - "kind": "reference", - "name": "Omit", - "typeArguments": [ - { - "kind": "reference", - "name": "EthereumSignInInput" - }, - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "version" - }, - { - "kind": "literal", - "value": "domain" - }, - { - "kind": "literal", - "value": "uri" - }, - { - "kind": "literal", - "value": "statement" - } - ] - } - ] - } - ] - } - }, - { - "name": "url", - "optional": true, - "description": "URL to use with the wallet interface. Some wallets do not allow signing a message for URLs different from the current page.", - "type": "string" - } - ] - } - }, - { - "name": "statement", - "optional": true, - "description": "Optional statement to include in the Sign in with Ethereum message. Must not include new line characters. Most wallets like Phantom **require specifying a statement!**", - "type": "string" - }, - { - "name": "wallet", - "optional": true, - "description": "Wallet interface to use. If not specified will default to `window.ethereum`.", - "type": { - "kind": "reference", - "name": "EIP1193Provider" - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "chain", - "optional": false, - "type": { - "kind": "literal", - "value": "ethereum" - } - }, - { - "name": "message", - "optional": false, - "description": "Sign in with Ethereum compatible message. Must include `Issued At`, `URI` and `Version`.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - } - ] - } - }, - { - "name": "signature", - "optional": false, - "description": "Ethereum curve (secp256k1) signature of the message.", - "type": { - "kind": "reference", - "name": "Hex" - } - } - ] - } - ] - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "object", - "name": "Session", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Sign in with Solana or Ethereum (Window API)", - "code": "// uses window.ethereum for the wallet\n const { data, error } = await supabase.auth.signInWithWeb3({\n chain: 'ethereum',\n statement: 'I accept the Terms of Service at https://example.com/tos'\n })\n\n // uses window.solana for the wallet\n const { data, error } = await supabase.auth.signInWithWeb3({\n chain: 'solana',\n statement: 'I accept the Terms of Service at https://example.com/tos'\n })" - }, - { - "title": "Sign in with Ethereum (Message and Signature)", - "code": "const { data, error } = await supabase.auth.signInWithWeb3({\n chain: 'ethereum',\n message: '',\n signature: '',\n })" - }, - { - "title": "Sign in with Solana (Brave)", - "code": "const { data, error } = await supabase.auth.signInWithWeb3({\n chain: 'solana',\n statement: 'I accept the Terms of Service at https://example.com/tos',\n wallet: window.braveSolana\n })" - }, - { - "title": "Sign in with Solana (Wallet Adapter)", - "code": "function SignInButton() {\n const wallet = useWallet()\n\n return (\n <>\n {wallet.connected ? (\n {\n supabase.auth.signInWithWeb3({\n chain: 'solana',\n statement: 'I accept the Terms of Service at https://example.com/tos',\n wallet,\n })\n }}\n >\n Sign in with Solana\n \n ) : (\n \n )}\n \n )\n}\n\nfunction App() {\n const endpoint = clusterApiUrl('devnet')\n const wallets = useMemo(() => [], [])\n\n return (\n \n \n \n \n \n \n \n )\n}" - } - ] - }, - { - "name": "signOut", - "description": "Inside a browser context, `signOut()` will remove the logged in user from the browser session and log them out - removing all items from localstorage and then trigger a `\"SIGNED_OUT\"` event.\nFor server-side management, you can revoke all refresh tokens for a user by passing a user's JWT through to `auth.api.signOut(JWT: string)`. There is no way to revoke a user's access token jwt until it expires. It is recommended to set a shorter expiry on the jwt for this reason.\nIf using `others` scope, no `SIGNED_OUT` event is fired!", - "remarks": [ - "- In order to use the `signOut()` method, the user needs to be signed in first. - By default, `signOut()` uses the global scope, which signs out all other sessions that the user is logged into as well. Customize this behavior by passing a scope parameter. - Since Supabase Auth uses JWTs for authentication, the access token JWT will be valid until it's expired. When the user signs out, Supabase revokes the refresh token and deletes the JWT from the client-side. This does not revoke the JWT and it will still be valid until it expires." - ], - "parameters": [ - { - "name": "options", - "type": { - "kind": "object", - "properties": [ - { - "name": "scope", - "optional": true, - "description": "Determines which sessions should be logged out. Global means all sessions by this account. Local means only this session. Others means all other sessions except the current one. When using others, there is no sign-out event fired on the current session!", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "global" - }, - { - "kind": "literal", - "value": "local" - }, - { - "kind": "literal", - "value": "others" - } - ] - } - } - ], - "name": "SignOut" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "object", - "properties": [ - { - "name": "error", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - ] - } - } - ] - } - ] - }, - "examples": [ - { - "title": "Sign out (all sessions)", - "code": "const { error } = await supabase.auth.signOut()" - }, - { - "title": "Sign out (current session)", - "code": "const { error } = await supabase.auth.signOut({ scope: 'local' })" - }, - { - "title": "Sign out (other sessions)", - "code": "const { error } = await supabase.auth.signOut({ scope: 'others' })" - } - ] - }, - { - "name": "signUp", - "description": "Creates a new user.\nBe aware that if a user account exists in the system you may get back an error message that attempts to hide this information from the user. This method has support for PKCE via email signups. The PKCE flow cannot be used when autoconfirm is enabled.", - "remarks": [ - "- By default, the user needs to verify their email address before logging in. To turn this off, disable **Confirm email** in [your project](/dashboard/project/_/auth/providers). - **Confirm email** determines if users need to confirm their email address after signing up. - If **Confirm email** is enabled, a `user` is returned but `session` is null. - If **Confirm email** is disabled, both a `user` and a `session` are returned. - When the user confirms their email address, they are redirected to the [`SITE_URL`](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) by default. You can modify your `SITE_URL` or add additional redirect URLs in [your project](/dashboard/project/_/auth/url-configuration). - If signUp() is called for an existing confirmed user: - When both **Confirm email** and **Confirm phone** (even when phone provider is disabled) are enabled in [your project](/dashboard/project/_/auth/providers), an obfuscated/fake user object is returned. - When either **Confirm email** or **Confirm phone** (even when phone provider is disabled) is disabled, the error message, `User already registered` is returned. - To fetch the currently logged-in user, refer to [`getUser()`](/docs/reference/javascript/auth-getuser)." - ], - "parameters": [ - { - "name": "credentials", - "type": { - "kind": "conditional" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "Session", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Sign up with an email and password", - "code": "const { data, error } = await supabase.auth.signUp({\n email: 'example@email.com',\n password: 'example-password',\n})", - "response": "// Some fields may be null if \"confirm email\" is enabled.\n{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n }\n }\n },\n \"error\": null\n}", - "notes": "Sign up with a phone number and password (whatsapp)\nThe user will be sent a WhatsApp message which contains a OTP. By default, a given user can only request a OTP once every 60 seconds. Note that a user will need to have a valid WhatsApp account that is linked to Twilio in order to use this feature." - }, - { - "title": "Sign up with a phone number and password (SMS)", - "code": "const { data, error } = await supabase.auth.signUp({\n phone: '123456789',\n password: 'example-password',\n options: {\n channel: 'sms'\n }\n})", - "notes": "Sign up with a redirect URL\n- See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project." - }, - { - "title": "Sign up with a phone number and password (whatsapp)", - "code": "const { data, error } = await supabase.auth.signUp({\n phone: '123456789',\n password: 'example-password',\n options: {\n channel: 'whatsapp'\n }\n})", - "notes": "The user will be sent a WhatsApp message which contains a OTP. By default, a given user can only request a OTP once every 60 seconds. Note that a user will need to have a valid WhatsApp account that is linked to Twilio in order to use this feature." - }, - { - "title": "Sign up with additional user metadata", - "code": "const { data, error } = await supabase.auth.signUp(\n {\n email: 'example@email.com',\n password: 'example-password',\n options: {\n data: {\n first_name: 'John',\n age: 27,\n }\n }\n }\n)" - }, - { - "title": "Sign up with a redirect URL", - "code": "const { data, error } = await supabase.auth.signUp(\n {\n email: 'example@email.com',\n password: 'example-password',\n options: {\n emailRedirectTo: 'https://example.com/welcome'\n }\n }\n)", - "notes": "- See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project." - } - ] - }, - { - "name": "startAutoRefresh", - "description": "Starts an auto-refresh process in the background. The session is checked every few seconds. Close to the time of expiration a process is started to refresh the session. If refreshing fails it will be retried for as long as necessary.\nIf you set the GoTrueClientOptions#autoRefreshToken you don't need to call this function, it will be called for you.\nOn browsers the refresh process works only when the tab/window is in the foreground to conserve resources as well as prevent race conditions and flooding auth with requests. If you call this method any managed visibility change callback will be removed and you must manage visibility changes on your own.\nOn non-browser platforms the refresh process works *continuously* in the background, which may not be desirable. You should hook into your platform's foreground indication mechanism and call these methods appropriately to conserve resources.\n#stopAutoRefresh", - "remarks": [ - "- Only useful in non-browser environments such as React Native or Electron. - The Supabase Auth library automatically starts and stops proactively refreshing the session when a tab is focused or not. - On non-browser platforms, such as mobile or desktop apps built with web technologies, the library is not able to effectively determine whether the application is _focused_ or not. - To give this hint to the application, you should be calling this method when the app is in focus and calling `supabase.auth.stopAutoRefresh()` when it's out of focus." - ], - "parameters": [], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": ["void"] - }, - "examples": [ - { - "title": "Start and stop auto refresh in React Native", - "code": "import { AppState } from 'react-native'\n\n// make sure you register this only once!\nAppState.addEventListener('change', (state) => {\n if (state === 'active') {\n supabase.auth.startAutoRefresh()\n } else {\n supabase.auth.stopAutoRefresh()\n }\n})" - } - ] - }, - { - "name": "stopAutoRefresh", - "description": "Stops an active auto refresh process running in the background (if any).\nIf you call this method any managed visibility change callback will be removed and you must manage visibility changes on your own.\nSee #startAutoRefresh for more details.", - "remarks": [ - "- Only useful in non-browser environments such as React Native or Electron. - The Supabase Auth library automatically starts and stops proactively refreshing the session when a tab is focused or not. - On non-browser platforms, such as mobile or desktop apps built with web technologies, the library is not able to effectively determine whether the application is _focused_ or not. - When your application goes in the background or out of focus, call this method to stop the proactive refreshing of the session." - ], - "parameters": [], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": ["void"] - }, - "examples": [ - { - "title": "Start and stop auto refresh in React Native", - "code": "import { AppState } from 'react-native'\n\n// make sure you register this only once!\nAppState.addEventListener('change', (state) => {\n if (state === 'active') {\n supabase.auth.startAutoRefresh()\n } else {\n supabase.auth.stopAutoRefresh()\n }\n})" - } - ] - }, - { - "name": "unlinkIdentity", - "description": "Unlinks an identity from a user by deleting it. The user will no longer be able to sign in with that identity once it's unlinked.", - "remarks": [ - "- The **Enable Manual Linking** option must be enabled from your [project's authentication settings](/dashboard/project/_/auth/providers). - The user needs to be signed in to call `unlinkIdentity()`. - The user must have at least 2 identities in order to unlink an identity. - The identity to be unlinked must belong to the user." - ], - "parameters": [ - { - "name": "identity", - "type": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Unlink an identity", - "code": "// retrieve all identities linked to a user\nconst identities = await supabase.auth.getUserIdentities()\n\n// find the google identity\nconst googleIdentity = identities.find(\n identity => identity.provider === 'google'\n)\n\n// unlink the google identity\nconst { error } = await supabase.auth.unlinkIdentity(googleIdentity)" - } - ] - }, - { - "name": "updateUser", - "description": "Updates user data for a logged in user.", - "remarks": [ - "- In order to use the `updateUser()` method, the user needs to be signed in first. - By default, email updates sends a confirmation link to both the user's current and new email. To only send a confirmation link to the user's new email, disable **Secure email change** in your project's [email auth provider settings](/dashboard/project/_/auth/providers)." - ], - "parameters": [ - { - "name": "attributes", - "type": { - "kind": "object", - "name": "UserAttributes", - "properties": [ - { - "name": "current_password", - "optional": true, - "description": "The user's current password\nThis is only ever present when the user is resetting their password and GOTRUE_SECURITY_UPDATE_PASSWORD_REQUIRE_CURRENT_PASSWORD is true.", - "type": "string" - }, - { - "name": "data", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", - "type": "object" - }, - { - "name": "email", - "optional": true, - "description": "The user's email.", - "type": "string" - }, - { - "name": "nonce", - "optional": true, - "description": "The nonce sent for reauthentication if the user's password is to be updated.\nCall reauthenticate() to obtain the nonce first.", - "type": "string" - }, - { - "name": "password", - "optional": true, - "description": "The user's password.", - "type": "string" - }, - { - "name": "phone", - "optional": true, - "description": "The user's phone.", - "type": "string" - } - ] - } - }, - { - "name": "options", - "type": { - "kind": "object", - "properties": [ - { - "name": "emailRedirectTo", - "optional": true, - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Update the email for an authenticated user", - "code": "const { data, error } = await supabase.auth.updateUser({\n email: 'new@email.com'\n})", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"new_email\": \"new@email.com\",\n \"email_change_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}", - "notes": "Sends a \"Confirm Email Change\" email to the new address. If **Secure Email Change** is enabled (default), confirmation is also required from the **old email** before the change is applied. To skip dual confirmation and apply the change after only the new email is verified, disable **Secure Email Change** in the [Email Auth Provider settings](/dashboard/project/_/auth/providers?provider=Email)." - }, - { - "title": "Update the phone number for an authenticated user", - "code": "const { data, error } = await supabase.auth.updateUser({\n phone: '123456789'\n})", - "notes": "Sends a one-time password (OTP) to the new phone number." - }, - { - "title": "Update the password for an authenticated user", - "code": "const { data, error } = await supabase.auth.updateUser({\n password: 'new password'\n})", - "notes": "Update the user's metadata\nUpdates the user's custom metadata.\n\n**Note**: The `data` field maps to the `auth.users.raw_user_meta_data` column in your Supabase database. When calling `getUser()`, the data will be available as `user.user_metadata`." - }, - { - "title": "Update the user's metadata", - "code": "const { data, error } = await supabase.auth.updateUser({\n data: { hello: 'world' }\n})", - "notes": "Updates the user's custom metadata.\n\n**Note**: The `data` field maps to the `auth.users.raw_user_meta_data` column in your Supabase database. When calling `getUser()`, the data will be available as `user.user_metadata`." - }, - { - "title": "Update the user's password with a nonce", - "code": "const { data, error } = await supabase.auth.updateUser({\n password: 'new password',\n nonce: '123456'\n})", - "notes": "If **Secure password change** is enabled in your [project's email provider settings](/dashboard/project/_/auth/providers), updating the user's password would require a nonce if the user **hasn't recently signed in**. The nonce is sent to the user's email or phone number. A user is deemed recently signed in if the session was created in the last 24 hours." - } - ] - }, - { - "name": "verifyOtp", - "description": "Log in a user given a User supplied OTP or TokenHash received through mobile or email.", - "remarks": [ - "- The `verifyOtp` method takes in different verification types. - If a phone number is used, the type can either be: 1. `sms` – Used when verifying a one-time password (OTP) sent via SMS during sign-up or sign-in. 2. `phone_change` – Used when verifying an OTP sent to a new phone number during a phone number update process. - If an email address is used, the type can be one of the following (note: `signup` and `magiclink` types are deprecated): 1. `email` – Used when verifying an OTP sent to the user's email during sign-up or sign-in. 2. `recovery` – Used when verifying an OTP sent for account recovery, typically after a password reset request. 3. `invite` – Used when verifying an OTP sent as part of an invitation to join a project or organization. 4. `email_change` – Used when verifying an OTP sent to a new email address during an email update process. - The verification type used should be determined based on the corresponding auth method called before `verifyOtp` to sign up / sign-in a user. - The `TokenHash` is contained in the [email templates](/docs/guides/auth/auth-email-templates) and can be used to sign in. You may wish to use the hash for the PKCE flow for Server Side Auth. Read [the Password-based Auth guide](/docs/guides/auth/passwords) for more details." - ], - "parameters": [ - { - "name": "params", - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "VerifyMobileOtpParams", - "properties": [ - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "redirectTo", - "optional": true, - "description": "A URL to send the user to after they are confirmed.", - "type": "string" - } - ] - } - }, - { - "name": "phone", - "optional": false, - "description": "The user's phone number.", - "type": "string" - }, - { - "name": "token", - "optional": false, - "description": "The otp sent to the user's phone number.", - "type": "string" - }, - { - "name": "type", - "optional": false, - "description": "The user's verification type.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "sms" - }, - { - "kind": "literal", - "value": "phone_change" - } - ] - } - } - ] - }, - { - "kind": "object", - "name": "VerifyEmailOtpParams", - "properties": [ - { - "name": "email", - "optional": false, - "description": "The user's email address.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "redirectTo", - "optional": true, - "description": "A URL to send the user to after they are confirmed.", - "type": "string" - } - ] - } - }, - { - "name": "token", - "optional": false, - "description": "The otp sent to the user's email address.", - "type": "string" - }, - { - "name": "type", - "optional": false, - "description": "The user's verification type.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "signup" - }, - { - "kind": "literal", - "value": "invite" - }, - { - "kind": "literal", - "value": "magiclink" - }, - { - "kind": "literal", - "value": "recovery" - }, - { - "kind": "literal", - "value": "email_change" - }, - { - "kind": "literal", - "value": "email" - } - ] - } - } - ] - }, - { - "kind": "object", - "name": "VerifyTokenHashParams", - "properties": [ - { - "name": "token_hash", - "optional": false, - "description": "The token hash used in an email link", - "type": "string" - }, - { - "name": "type", - "optional": false, - "description": "The user's verification type.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "signup" - }, - { - "kind": "literal", - "value": "invite" - }, - { - "kind": "literal", - "value": "magiclink" - }, - { - "kind": "literal", - "value": "recovery" - }, - { - "kind": "literal", - "value": "email_change" - }, - { - "kind": "literal", - "value": "email" - } - ] - } - } - ] - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "Session", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Verify Signup One-Time Password (OTP)", - "code": "const { data, error } = await supabase.auth.verifyOtp({ email, token, type: 'email'})", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"recovery_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"recovery_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n }\n },\n \"error\": null\n}" - }, - { - "title": "Verify SMS One-Time Password (OTP)", - "code": "const { data, error } = await supabase.auth.verifyOtp({ phone, token, type: 'sms'})" - }, - { - "title": "Verify Email Auth (Token Hash)", - "code": "const { data, error } = await supabase.auth.verifyOtp({ token_hash: tokenHash, type: 'email'})" - } - ] - }, - { - "name": "approveAuthorization", - "description": "Approves an OAuth authorization request. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nAfter approval, the user's consent is stored and an authorization code is generated. The response contains a complete redirect URL with the authorization code and state.", - "parameters": [ - { - "name": "authorizationId", - "description": "The authorization ID to approve", - "type": "string" - }, - { - "name": "options", - "optional": true, - "description": "Optional parameters", - "type": { - "kind": "object", - "properties": [ - { - "name": "skipBrowserRedirect", - "optional": true, - "description": "If false (default), automatically redirects the browser to the OAuth client. If true, returns the redirect_url without automatic redirect (useful for custom handling).", - "type": "boolean" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "redirect_url", - "optional": false, - "description": "Complete redirect URL with authorization code and state parameters (e.g., \"https://app.com/callback?code=xxx&state=yyy\")", - "type": "string" - } - ], - "name": "OAuthRedirect" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "denyAuthorization", - "description": "Denies an OAuth authorization request. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nAfter denial, the response contains a redirect URL with an OAuth error (access_denied) to inform the OAuth client that the user rejected the request.", - "parameters": [ - { - "name": "authorizationId", - "description": "The authorization ID to deny", - "type": "string" - }, - { - "name": "options", - "optional": true, - "description": "Optional parameters", - "type": { - "kind": "object", - "properties": [ - { - "name": "skipBrowserRedirect", - "optional": true, - "description": "If false (default), automatically redirects the browser to the OAuth client. If true, returns the redirect_url without automatic redirect (useful for custom handling).", - "type": "boolean" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "redirect_url", - "optional": false, - "description": "Complete redirect URL with authorization code and state parameters (e.g., \"https://app.com/callback?code=xxx&state=yyy\")", - "type": "string" - } - ], - "name": "OAuthRedirect" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "getAuthorizationDetails", - "description": "Retrieves details about an OAuth authorization request. Used to display consent information to the user. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis method returns one of two response types: - `OAuthAuthorizationDetails`: User needs to consent - show consent page with client info - `OAuthRedirect`: User already consented - redirect immediately to the OAuth client\nUse type narrowing to distinguish between the responses: ```typescript if ('authorization_id' in data) { // Show consent page } else { // Redirect to data.redirect_url } ```", - "parameters": [ - { - "name": "authorizationId", - "description": "The authorization ID from the authorization request", - "type": "string" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "authorization_id", - "optional": false, - "description": "The authorization ID used to approve or deny the request", - "type": "string" - }, - { - "name": "client", - "optional": false, - "description": "OAuth client requesting authorization", - "type": { - "kind": "object", - "properties": [ - { - "name": "id", - "optional": false, - "description": "Unique identifier for the OAuth client (UUID)", - "type": "string" - }, - { - "name": "logo_uri", - "optional": false, - "description": "URI of the OAuth client's logo", - "type": "string" - }, - { - "name": "name", - "optional": false, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "uri", - "optional": false, - "description": "URI of the OAuth client's website", - "type": "string" - } - ], - "name": "OAuthAuthorizationClient" - } - }, - { - "name": "redirect_uri", - "optional": false, - "description": "The OAuth client's registered redirect URI (base URI without query parameters)", - "type": "string" - }, - { - "name": "scope", - "optional": false, - "description": "Space-separated list of requested scopes (e.g., \"openid profile email\")", - "type": "string" - }, - { - "name": "user", - "optional": false, - "description": "User object associated with the authorization", - "type": { - "kind": "object", - "properties": [ - { - "name": "email", - "optional": false, - "description": "User email", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "User ID (UUID)", - "type": "string" - } - ] - } - } - ], - "name": "OAuthAuthorizationDetails" - }, - { - "kind": "object", - "properties": [ - { - "name": "redirect_url", - "optional": false, - "description": "Complete redirect URL with authorization code and state parameters (e.g., \"https://app.com/callback?code=xxx&state=yyy\")", - "type": "string" - } - ], - "name": "OAuthRedirect" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "listGrants", - "description": "Lists all OAuth grants that the authenticated user has authorized. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.", - "parameters": [], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "properties": [ - { - "name": "client", - "optional": false, - "description": "OAuth client information", - "type": { - "kind": "object", - "properties": [ - { - "name": "id", - "optional": false, - "description": "Unique identifier for the OAuth client (UUID)", - "type": "string" - }, - { - "name": "logo_uri", - "optional": false, - "description": "URI of the OAuth client's logo", - "type": "string" - }, - { - "name": "name", - "optional": false, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "uri", - "optional": false, - "description": "URI of the OAuth client's website", - "type": "string" - } - ], - "name": "OAuthAuthorizationClient" - } - }, - { - "name": "granted_at", - "optional": false, - "description": "Timestamp when the grant was created (ISO 8601 date-time)", - "type": "string" - }, - { - "name": "scopes", - "optional": false, - "description": "Array of scopes granted to this client", - "type": { - "kind": "array", - "elementType": "string" - } - } - ], - "name": "OAuthGrant" - } - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "revokeGrant", - "description": "Revokes a user's OAuth grant for a specific client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nRevocation marks consent as revoked, deletes active sessions for that OAuth client, and invalidates associated refresh tokens.", - "parameters": [ - { - "name": "options", - "description": "Revocation options", - "type": { - "kind": "object", - "properties": [ - { - "name": "clientId", - "optional": false, - "description": "The OAuth client identifier (UUID) to revoke access for", - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "deleteFactor", - "description": "Deletes a factor on a user. This will log the user out of all active sessions if the deleted factor was verified.", - "parameters": [ - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "id", - "optional": false, - "description": "ID of the MFA factor to delete.", - "type": "string" - }, - { - "name": "userId", - "optional": false, - "description": "ID of the user whose factor is being deleted.", - "type": "string" - } - ], - "name": "AuthMFAAdminDeleteFactorParams" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "id", - "optional": false, - "description": "ID of the factor that was successfully deleted.", - "type": "string" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Delete a factor for a user", - "code": "const { data, error } = await supabase.auth.admin.mfa.deleteFactor({\n id: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n userId: 'a89baba7-b1b7-440f-b4bb-91026967f66b',\n})", - "response": "{\n data: {\n id: '34e770dd-9ff9-416c-87fa-43b31d7ef225'\n },\n error: null\n}" - } - ] - }, - { - "name": "listFactors", - "description": "Lists all factors associated to a user.", - "parameters": [ - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "userId", - "optional": false, - "description": "ID of the user.", - "type": "string" - } - ], - "name": "AuthMFAAdminListFactorsParams" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "factors", - "optional": false, - "description": "All factors attached to the user.", - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "typeParam", - "name": "Type" - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "typeParam", - "name": "Status" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "List all factors for a user", - "code": "const { data, error } = await supabase.auth.admin.mfa.listFactors()", - "response": "{\n data: {\n factors: Factor[\n {\n id: '',\n friendly_name: 'Auth App Factor',\n factor_type: 'totp',\n status: 'verified',\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z'\n }\n ]\n },\n error: null\n}" - } - ] - }, - { - "name": "createClient", - "description": "Creates a new OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "parameters": [ - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "client_name", - "optional": false, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "client_uri", - "optional": true, - "description": "URI of the OAuth client", - "type": "string" - }, - { - "name": "grant_types", - "optional": true, - "description": "Array of allowed grant types (optional, defaults to authorization_code and refresh_token)", - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "authorization_code" - }, - { - "kind": "literal", - "value": "refresh_token" - } - ] - } - } - }, - { - "name": "redirect_uris", - "optional": false, - "description": "Array of allowed redirect URIs", - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "response_types", - "optional": true, - "description": "Array of allowed response types (optional, defaults to code)", - "type": { - "kind": "array", - "elementType": { - "kind": "literal", - "value": "code" - } - } - }, - { - "name": "scope", - "optional": true, - "description": "Scope of the OAuth client", - "type": "string" - }, - { - "name": "token_endpoint_auth_method", - "optional": true, - "description": "Token endpoint authentication method (defaults to server default if not specified)", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "none" - }, - { - "kind": "literal", - "value": "client_secret_basic" - }, - { - "kind": "literal", - "value": "client_secret_post" - } - ] - } - } - ], - "name": "CreateOAuthClientParams" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "client_id", - "optional": false, - "description": "Unique identifier for the OAuth client", - "type": "string" - }, - { - "name": "client_name", - "optional": false, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "client_secret", - "optional": true, - "description": "Client secret (only returned on registration and regeneration)", - "type": "string" - }, - { - "name": "client_type", - "optional": false, - "description": "Type of OAuth client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "public" - }, - { - "kind": "literal", - "value": "confidential" - } - ] - } - }, - { - "name": "client_uri", - "optional": true, - "description": "URI of the OAuth client", - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "description": "Timestamp when the client was created", - "type": "string" - }, - { - "name": "grant_types", - "optional": false, - "description": "Array of allowed grant types", - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "authorization_code" - }, - { - "kind": "literal", - "value": "refresh_token" - } - ] - } - } - }, - { - "name": "logo_uri", - "optional": true, - "description": "URI of the OAuth client's logo", - "type": "string" - }, - { - "name": "redirect_uris", - "optional": false, - "description": "Array of allowed redirect URIs", - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "registration_type", - "optional": false, - "description": "Registration type of the client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "dynamic" - }, - { - "kind": "literal", - "value": "manual" - } - ] - } - }, - { - "name": "response_types", - "optional": false, - "description": "Array of allowed response types", - "type": { - "kind": "array", - "elementType": { - "kind": "literal", - "value": "code" - } - } - }, - { - "name": "scope", - "optional": true, - "description": "Scope of the OAuth client", - "type": "string" - }, - { - "name": "token_endpoint_auth_method", - "optional": false, - "description": "Token endpoint authentication method", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "none" - }, - { - "kind": "literal", - "value": "client_secret_basic" - }, - { - "kind": "literal", - "value": "client_secret_post" - } - ] - } - }, - { - "name": "updated_at", - "optional": false, - "description": "Timestamp when the client was last updated", - "type": "string" - } - ], - "name": "OAuthClient" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "deleteClient", - "description": "Deletes an OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "parameters": [ - { - "name": "clientId", - "type": "string" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - ] - } - } - ] - } - ] - } - }, - { - "name": "getClient", - "description": "Gets details of a specific OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "parameters": [ - { - "name": "clientId", - "type": "string" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "client_id", - "optional": false, - "description": "Unique identifier for the OAuth client", - "type": "string" - }, - { - "name": "client_name", - "optional": false, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "client_secret", - "optional": true, - "description": "Client secret (only returned on registration and regeneration)", - "type": "string" - }, - { - "name": "client_type", - "optional": false, - "description": "Type of OAuth client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "public" - }, - { - "kind": "literal", - "value": "confidential" - } - ] - } - }, - { - "name": "client_uri", - "optional": true, - "description": "URI of the OAuth client", - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "description": "Timestamp when the client was created", - "type": "string" - }, - { - "name": "grant_types", - "optional": false, - "description": "Array of allowed grant types", - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "authorization_code" - }, - { - "kind": "literal", - "value": "refresh_token" - } - ] - } - } - }, - { - "name": "logo_uri", - "optional": true, - "description": "URI of the OAuth client's logo", - "type": "string" - }, - { - "name": "redirect_uris", - "optional": false, - "description": "Array of allowed redirect URIs", - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "registration_type", - "optional": false, - "description": "Registration type of the client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "dynamic" - }, - { - "kind": "literal", - "value": "manual" - } - ] - } - }, - { - "name": "response_types", - "optional": false, - "description": "Array of allowed response types", - "type": { - "kind": "array", - "elementType": { - "kind": "literal", - "value": "code" - } - } - }, - { - "name": "scope", - "optional": true, - "description": "Scope of the OAuth client", - "type": "string" - }, - { - "name": "token_endpoint_auth_method", - "optional": false, - "description": "Token endpoint authentication method", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "none" - }, - { - "kind": "literal", - "value": "client_secret_basic" - }, - { - "kind": "literal", - "value": "client_secret_post" - } - ] - } - }, - { - "name": "updated_at", - "optional": false, - "description": "Timestamp when the client was last updated", - "type": "string" - } - ], - "name": "OAuthClient" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "listClients", - "description": "Lists all OAuth clients with optional pagination. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "parameters": [ - { - "name": "params", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "page", - "optional": true, - "description": "The page number", - "type": "number" - }, - { - "name": "perPage", - "optional": true, - "description": "Number of items returned per page", - "type": "number" - } - ], - "name": "PageParams" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "intersection", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "clients", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "properties": [ - { - "name": "client_id", - "optional": false, - "description": "Unique identifier for the OAuth client", - "type": "string" - }, - { - "name": "client_name", - "optional": false, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "client_secret", - "optional": true, - "description": "Client secret (only returned on registration and regeneration)", - "type": "string" - }, - { - "name": "client_type", - "optional": false, - "description": "Type of OAuth client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "public" - }, - { - "kind": "literal", - "value": "confidential" - } - ] - } - }, - { - "name": "client_uri", - "optional": true, - "description": "URI of the OAuth client", - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "description": "Timestamp when the client was created", - "type": "string" - }, - { - "name": "grant_types", - "optional": false, - "description": "Array of allowed grant types", - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "authorization_code" - }, - { - "kind": "literal", - "value": "refresh_token" - } - ] - } - } - }, - { - "name": "logo_uri", - "optional": true, - "description": "URI of the OAuth client's logo", - "type": "string" - }, - { - "name": "redirect_uris", - "optional": false, - "description": "Array of allowed redirect URIs", - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "registration_type", - "optional": false, - "description": "Registration type of the client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "dynamic" - }, - { - "kind": "literal", - "value": "manual" - } - ] - } - }, - { - "name": "response_types", - "optional": false, - "description": "Array of allowed response types", - "type": { - "kind": "array", - "elementType": { - "kind": "literal", - "value": "code" - } - } - }, - { - "name": "scope", - "optional": true, - "description": "Scope of the OAuth client", - "type": "string" - }, - { - "name": "token_endpoint_auth_method", - "optional": false, - "description": "Token endpoint authentication method", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "none" - }, - { - "kind": "literal", - "value": "client_secret_basic" - }, - { - "kind": "literal", - "value": "client_secret_post" - } - ] - } - }, - { - "name": "updated_at", - "optional": false, - "description": "Timestamp when the client was last updated", - "type": "string" - } - ], - "name": "OAuthClient" - } - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "lastPage", - "optional": false, - "type": "number" - }, - { - "name": "nextPage", - "optional": false, - "type": { - "kind": "union", - "types": [ - "number", - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "total", - "optional": false, - "type": "number" - } - ], - "name": "Pagination" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "clients", - "optional": false, - "type": { - "kind": "tuple", - "elements": [] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - } - }, - { - "name": "regenerateClientSecret", - "description": "Regenerates the secret for an OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "parameters": [ - { - "name": "clientId", - "type": "string" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "client_id", - "optional": false, - "description": "Unique identifier for the OAuth client", - "type": "string" - }, - { - "name": "client_name", - "optional": false, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "client_secret", - "optional": true, - "description": "Client secret (only returned on registration and regeneration)", - "type": "string" - }, - { - "name": "client_type", - "optional": false, - "description": "Type of OAuth client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "public" - }, - { - "kind": "literal", - "value": "confidential" - } - ] - } - }, - { - "name": "client_uri", - "optional": true, - "description": "URI of the OAuth client", - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "description": "Timestamp when the client was created", - "type": "string" - }, - { - "name": "grant_types", - "optional": false, - "description": "Array of allowed grant types", - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "authorization_code" - }, - { - "kind": "literal", - "value": "refresh_token" - } - ] - } - } - }, - { - "name": "logo_uri", - "optional": true, - "description": "URI of the OAuth client's logo", - "type": "string" - }, - { - "name": "redirect_uris", - "optional": false, - "description": "Array of allowed redirect URIs", - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "registration_type", - "optional": false, - "description": "Registration type of the client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "dynamic" - }, - { - "kind": "literal", - "value": "manual" - } - ] - } - }, - { - "name": "response_types", - "optional": false, - "description": "Array of allowed response types", - "type": { - "kind": "array", - "elementType": { - "kind": "literal", - "value": "code" - } - } - }, - { - "name": "scope", - "optional": true, - "description": "Scope of the OAuth client", - "type": "string" - }, - { - "name": "token_endpoint_auth_method", - "optional": false, - "description": "Token endpoint authentication method", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "none" - }, - { - "kind": "literal", - "value": "client_secret_basic" - }, - { - "kind": "literal", - "value": "client_secret_post" - } - ] - } - }, - { - "name": "updated_at", - "optional": false, - "description": "Timestamp when the client was last updated", - "type": "string" - } - ], - "name": "OAuthClient" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "updateClient", - "description": "Updates an existing OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "parameters": [ - { - "name": "clientId", - "type": "string" - }, - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "client_name", - "optional": true, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "client_uri", - "optional": true, - "description": "URI of the OAuth client", - "type": "string" - }, - { - "name": "grant_types", - "optional": true, - "description": "Array of allowed grant types", - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "authorization_code" - }, - { - "kind": "literal", - "value": "refresh_token" - } - ] - } - } - }, - { - "name": "logo_uri", - "optional": true, - "description": "URI of the OAuth client's logo", - "type": "string" - }, - { - "name": "redirect_uris", - "optional": true, - "description": "Array of allowed redirect URIs", - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "token_endpoint_auth_method", - "optional": true, - "description": "Token endpoint authentication method", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "none" - }, - { - "kind": "literal", - "value": "client_secret_basic" - }, - { - "kind": "literal", - "value": "client_secret_post" - } - ] - } - } - ], - "name": "UpdateOAuthClientParams" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "client_id", - "optional": false, - "description": "Unique identifier for the OAuth client", - "type": "string" - }, - { - "name": "client_name", - "optional": false, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "client_secret", - "optional": true, - "description": "Client secret (only returned on registration and regeneration)", - "type": "string" - }, - { - "name": "client_type", - "optional": false, - "description": "Type of OAuth client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "public" - }, - { - "kind": "literal", - "value": "confidential" - } - ] - } - }, - { - "name": "client_uri", - "optional": true, - "description": "URI of the OAuth client", - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "description": "Timestamp when the client was created", - "type": "string" - }, - { - "name": "grant_types", - "optional": false, - "description": "Array of allowed grant types", - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "authorization_code" - }, - { - "kind": "literal", - "value": "refresh_token" - } - ] - } - } - }, - { - "name": "logo_uri", - "optional": true, - "description": "URI of the OAuth client's logo", - "type": "string" - }, - { - "name": "redirect_uris", - "optional": false, - "description": "Array of allowed redirect URIs", - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "registration_type", - "optional": false, - "description": "Registration type of the client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "dynamic" - }, - { - "kind": "literal", - "value": "manual" - } - ] - } - }, - { - "name": "response_types", - "optional": false, - "description": "Array of allowed response types", - "type": { - "kind": "array", - "elementType": { - "kind": "literal", - "value": "code" - } - } - }, - { - "name": "scope", - "optional": true, - "description": "Scope of the OAuth client", - "type": "string" - }, - { - "name": "token_endpoint_auth_method", - "optional": false, - "description": "Token endpoint authentication method", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "none" - }, - { - "kind": "literal", - "value": "client_secret_basic" - }, - { - "kind": "literal", - "value": "client_secret_post" - } - ] - } - }, - { - "name": "updated_at", - "optional": false, - "description": "Timestamp when the client was last updated", - "type": "string" - } - ], - "name": "OAuthClient" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "challenge", - "description": "Prepares a challenge used to verify that a user has access to a MFA factor.", - "remarks": [ - "- An [enrolled factor](/docs/reference/javascript/auth-mfa-enroll) is required before creating a challenge. - To verify a challenge, see [`mfa.verify()`](/docs/reference/javascript/auth-mfa-verify). - A phone factor sends a code to the user upon challenge. The channel defaults to `sms` unless otherwise specified." - ], - "parameters": [ - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "factorId", - "optional": false, - "description": "ID of the factor to be challenged. Returned in enroll().", - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "expires_at", - "optional": false, - "description": "Timestamp in UNIX seconds when this challenge will no longer be usable.", - "type": "number" - }, - { - "name": "id", - "optional": false, - "description": "ID of the newly created challenge.", - "type": "string" - }, - { - "name": "type", - "optional": false, - "description": "Factor Type which generated the challenge", - "type": { - "kind": "literal", - "value": "totp" - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Create a challenge for a factor", - "code": "const { data, error } = await supabase.auth.mfa.challenge({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225'\n})", - "response": "{\n data: {\n id: '',\n type: 'totp',\n expires_at: 1700000000\n },\n error: null\n}" - }, - { - "title": "Create a challenge for a phone factor", - "code": "const { data, error } = await supabase.auth.mfa.challenge({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n})", - "response": "{\n data: {\n id: '',\n type: 'phone',\n expires_at: 1700000000\n },\n error: null\n}" - }, - { - "title": "Create a challenge for a phone factor (WhatsApp)", - "code": "const { data, error } = await supabase.auth.mfa.challenge({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n channel: 'whatsapp',\n})", - "response": "{\n data: {\n id: '',\n expires_at: 1700000000\n },\n error: null\n}" - } - ] - }, - { - "name": "challengeAndVerify", - "description": "Helper method which creates a challenge and immediately uses the given code to verify against it thereafter. The verification code is provided by the user by entering a code seen in their authenticator app.", - "remarks": [ - "- Intended for use with only TOTP factors. - An [enrolled factor](/docs/reference/javascript/auth-mfa-enroll) is required before invoking `challengeAndVerify()`. - Executes [`mfa.challenge()`](/docs/reference/javascript/auth-mfa-challenge) and [`mfa.verify()`](/docs/reference/javascript/auth-mfa-verify) in a single step." - ], - "parameters": [ - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "code", - "optional": false, - "description": "Verification code provided by the user.", - "type": "string" - }, - { - "name": "factorId", - "optional": false, - "description": "ID of the factor being verified. Returned in enroll().", - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "New access token (JWT) after successful verification.", - "type": "string" - }, - { - "name": "expires_in", - "optional": false, - "description": "Number of seconds in which the access token will expire.", - "type": "number" - }, - { - "name": "refresh_token", - "optional": false, - "description": "Refresh token you can use to obtain new access tokens when expired.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "description": "Type of token, always `bearer`.", - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "Updated user profile.", - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ], - "name": "AuthMFAVerifyResponseData" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Create and verify a challenge for a factor", - "code": "const { data, error } = await supabase.auth.mfa.challengeAndVerify({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n code: '123456'\n})", - "response": "{\n data: {\n access_token: '',\n token_type: 'Bearer',\n expires_in: 3600,\n refresh_token: '',\n user: {\n id: '11111111-1111-1111-1111-111111111111',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {\n provider: 'email',\n providers: [\n \"email\",\n ]\n },\n user_metadata: {},\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false,\n factors: [\n \"id\": '',\n \"friendly_name\": 'Important Auth App',\n \"factor_type\": 'totp',\n \"status\": 'verified',\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n ]\n }\n }\n error: null\n}" - } - ] - }, - { - "name": "enroll", - "description": "Starts the enrollment process for a new Multi-Factor Authentication (MFA) factor. This method creates a new `unverified` factor. To verify a factor, present the QR code or secret to the user and ask them to add it to their authenticator app. The user has to enter the code from their authenticator app to verify it.\nUpon verifying a factor, all other sessions are logged out and the current session's authenticator level is promoted to `aal2`.", - "remarks": [ - "- Use `totp` or `phone` as the `factorType` and use the returned `id` to create a challenge. - To create a challenge, see [`mfa.challenge()`](/docs/reference/javascript/auth-mfa-challenge). - To verify a challenge, see [`mfa.verify()`](/docs/reference/javascript/auth-mfa-verify). - To create and verify a TOTP challenge in a single step, see [`mfa.challengeAndVerify()`](/docs/reference/javascript/auth-mfa-challengeandverify). - To generate a QR code for the `totp` secret in Next.js, you can do the following: ```html {data.totp.uri} ``` - The `challenge` and `verify` steps are separated when using Phone factors as the user will need time to receive and input the code obtained from the SMS in challenge." - ], - "parameters": [ - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "factorType", - "optional": false, - "description": "The type of factor being enrolled.", - "type": { - "kind": "literal", - "value": "totp" - } - }, - { - "name": "friendlyName", - "optional": true, - "description": "Human readable name assigned to the factor.", - "type": "string" - }, - { - "name": "issuer", - "optional": true, - "description": "Domain which the user is enrolled with.", - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Enroll a time-based, one-time password (TOTP) factor", - "code": "const { data, error } = await supabase.auth.mfa.enroll({\n factorType: 'totp',\n friendlyName: 'your_friendly_name'\n})\n\n// Use the id to create a challenge.\n// The challenge can be verified by entering the code generated from the authenticator app.\n// The code will be generated upon scanning the qr_code or entering the secret into the authenticator app.\nconst { id, type, totp: { qr_code, secret, uri }, friendly_name } = data\nconst challenge = await supabase.auth.mfa.challenge({ factorId: id });", - "response": "{\n data: {\n id: '',\n type: 'totp'\n totp: {\n qr_code: '',\n secret: '',\n uri: '',\n }\n friendly_name?: 'Important app'\n },\n error: null\n}" - }, - { - "title": "Enroll a Phone Factor", - "code": "const { data, error } = await supabase.auth.mfa.enroll({\n factorType: 'phone',\n friendlyName: 'your_friendly_name',\n phone: '+12345678',\n})\n\n// Use the id to create a challenge and send an SMS with a code to the user.\nconst { id, type, friendly_name, phone } = data\n\nconst challenge = await supabase.auth.mfa.challenge({ factorId: id });", - "response": "{\n data: {\n id: '',\n type: 'phone',\n friendly_name?: 'Important app',\n phone: '+5787123456'\n },\n error: null\n}" - } - ] - }, - { - "name": "getAuthenticatorAssuranceLevel", - "description": "Returns the Authenticator Assurance Level (AAL) for the active session.\n- `aal1` (or `null`) means that the user's identity has been verified only with a conventional login (email+password, OTP, magic link, social login, etc.). - `aal2` means that the user's identity has been verified both with a conventional login and at least one MFA factor.\nWhen called without a JWT parameter, this method is fairly quick (microseconds) and rarely uses the network. When a JWT is provided (useful in server-side environments like Edge Functions where no session is stored), this method will make a network request to validate the user and fetch their MFA factors.", - "remarks": [ - "- Authenticator Assurance Level (AAL) is the measure of the strength of an authentication mechanism. - In Supabase, having an AAL of `aal1` refers to having the 1st factor of authentication such as an email and password or OAuth sign-in while `aal2` refers to the 2nd factor of authentication such as a time-based, one-time-password (TOTP) or Phone factor. - If the user has a verified factor, the `nextLevel` field will return `aal2`, else, it will return `aal1`. - An optional `jwt` parameter can be passed to check the AAL level of a specific JWT instead of the current session." - ], - "parameters": [ - { - "name": "jwt", - "optional": true, - "description": "Takes in an optional access token JWT. If no JWT is provided, the JWT from the current session is used.", - "type": "string" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "currentAuthenticationMethods", - "optional": false, - "description": "A list of all authentication methods attached to this session. Use the information here to detect the last time a user verified a factor, for example if implementing a step-up scenario.\nSupports both RFC-8176 compliant format (string[]) and detailed format (AMREntry[]). - String format: ['password', 'otp'] - RFC-8176 compliant - Object format: [{ method: 'password', timestamp: 1234567890 }] - includes timestamps", - "type": { - "kind": "union", - "types": [ - { - "kind": "array", - "elementType": { - "kind": "object", - "name": "AMREntry", - "properties": [ - { - "name": "method", - "optional": false, - "description": "Authentication method name.", - "type": { - "kind": "union", - "types": [ - { - "kind": "indexedAccess", - "objectType": { - "kind": "query" - }, - "indexType": null - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "timestamp", - "optional": false, - "description": "Timestamp when the method was successfully used. Represents number of seconds since 1st January 1970 (UNIX epoch) in UTC.", - "type": "number" - } - ] - } - }, - { - "kind": "array", - "elementType": "string" - } - ] - } - }, - { - "name": "currentLevel", - "optional": false, - "description": "Current AAL level of the session.", - "type": { - "kind": "union", - "types": [ - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "aal1" - }, - { - "kind": "literal", - "value": "aal2" - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "nextLevel", - "optional": false, - "description": "Next possible AAL level for the session. If the next level is higher than the current one, the user should go through MFA.", - "type": { - "kind": "union", - "types": [ - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "aal1" - }, - { - "kind": "literal", - "value": "aal2" - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Get the AAL details of a session", - "code": "const { data, error } = await supabase.auth.mfa.getAuthenticatorAssuranceLevel()\nconst { currentLevel, nextLevel, currentAuthenticationMethods } = data", - "response": "{\n data: {\n currentLevel: 'aal1',\n nextLevel: 'aal2',\n currentAuthenticationMethods: [\n {\n method: 'password',\n timestamp: 1700000000\n }\n ]\n }\n error: null\n}" - }, - { - "title": "Get the AAL details for a specific JWT", - "code": "const { data, error } = await supabase.auth.mfa.getAuthenticatorAssuranceLevel(jwt)" - } - ] - }, - { - "name": "listFactors", - "description": "Returns the list of MFA factors enabled for this user.", - "parameters": [], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "intersection", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "all", - "optional": false, - "description": "All available factors (verified and unverified).", - "type": { - "kind": "array", - "elementType": { - "kind": "conditional" - } - } - } - ] - }, - { - "kind": "mapped" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "unenroll", - "description": "Unenroll removes a MFA factor. A user has to have an `aal2` authenticator level in order to unenroll a `verified` factor.", - "parameters": [ - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "factorId", - "optional": false, - "description": "ID of the factor being unenrolled.", - "type": "string" - } - ], - "name": "MFAUnenrollParams" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "id", - "optional": false, - "description": "ID of the factor that was successfully unenrolled.", - "type": "string" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Unenroll a factor", - "code": "const { data, error } = await supabase.auth.mfa.unenroll({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n})", - "response": "{\n data: {\n id: ''\n },\n error: null\n}" - } - ] - }, - { - "name": "verify", - "description": "Verifies a code against a challenge. The verification code is provided by the user by entering a code seen in their authenticator app.", - "remarks": [ - "- To verify a challenge, please [create a challenge](/docs/reference/javascript/auth-mfa-challenge) first." - ], - "parameters": [ - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "challengeId", - "optional": false, - "description": "ID of the challenge being verified. Returned in challenge().", - "type": "string" - }, - { - "name": "code", - "optional": false, - "description": "Verification code provided by the user.", - "type": "string" - }, - { - "name": "factorId", - "optional": false, - "description": "ID of the factor being verified. Returned in enroll().", - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "New access token (JWT) after successful verification.", - "type": "string" - }, - { - "name": "expires_in", - "optional": false, - "description": "Number of seconds in which the access token will expire.", - "type": "number" - }, - { - "name": "refresh_token", - "optional": false, - "description": "Refresh token you can use to obtain new access tokens when expired.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "description": "Type of token, always `bearer`.", - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "Updated user profile.", - "type": { - "kind": "object", - "name": "User", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - }, - { - "kind": "literal", - "value": "webauthn" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ], - "name": "AuthMFAVerifyResponseData" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Verify a challenge for a factor", - "code": "const { data, error } = await supabase.auth.mfa.verify({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n challengeId: '4034ae6f-a8ce-4fb5-8ee5-69a5863a7c15',\n code: '123456'\n})", - "response": "{\n data: {\n access_token: '',\n token_type: 'Bearer',\n expires_in: 3600,\n refresh_token: '',\n user: {\n id: '11111111-1111-1111-1111-111111111111',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {\n provider: 'email',\n providers: [\n \"email\",\n ]\n },\n user_metadata: {},\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false,\n factors: [\n \"id\": '',\n \"friendly_name\": 'Important Auth App',\n \"factor_type\": 'totp',\n \"status\": 'verified',\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n ]\n }\n }\n error: null\n}" - } - ] - }, - { - "name": "createUser", - "description": "Creates a new user. This function should only be called on a server. Never expose your `service_role` key in the browser.", - "remarks": [ - "- To confirm the user's email address or phone number, set `email_confirm` or `phone_confirm` to true. Both arguments default to false. - `createUser()` will not send a confirmation email to the user. You can use [`inviteUserByEmail()`](/docs/reference/javascript/auth-admin-inviteuserbyemail) if you want to send them an email invite instead. - If you are sure that the created user's email or phone number is legitimate and verified, you can set the `email_confirm` or `phone_confirm` param to `true`." - ], - "parameters": [ - { - "name": "attributes", - "type": { - "kind": "object", - "name": "AdminUserAttributes", - "properties": [ - { - "name": "app_metadata", - "optional": true, - "description": "A custom data object to store the user's application specific metadata. This maps to the `auth.users.app_metadata` column.\nOnly a service role can modify.\nThe `app_metadata` should be a JSON object that includes app-specific info, such as identity providers, roles, and other access control information.", - "type": "object" - }, - { - "name": "ban_duration", - "optional": true, - "description": "Determines how long a user is banned for.\nThe format for the ban duration follows a strict sequence of decimal numbers with a unit suffix. Valid time units are \"ns\", \"us\" (or \"µs\"), \"ms\", \"s\", \"m\", \"h\".\nFor example, some possible durations include: '300ms', '2h45m'.\nSetting the ban duration to 'none' lifts the ban on the user.", - "type": "string" - }, - { - "name": "current_password", - "optional": true, - "description": "The user's current password\nThis is only ever present when the user is resetting their password and GOTRUE_SECURITY_UPDATE_PASSWORD_REQUIRE_CURRENT_PASSWORD is true.", - "type": "string" - }, - { - "name": "email", - "optional": true, - "description": "The user's email.", - "type": "string" - }, - { - "name": "email_confirm", - "optional": true, - "description": "Sets the user's email as confirmed when true, or unconfirmed when false.\nOnly a service role can modify.", - "type": "boolean" - }, - { - "name": "id", - "optional": true, - "description": "The `id` for the user.\nAllows you to overwrite the default `id` set for the user.", - "type": "string" - }, - { - "name": "nonce", - "optional": true, - "description": "The nonce sent for reauthentication if the user's password is to be updated.\nCall reauthenticate() to obtain the nonce first.", - "type": "string" - }, - { - "name": "password", - "optional": true, - "description": "The user's password.", - "type": "string" - }, - { - "name": "password_hash", - "optional": true, - "description": "The `password_hash` for the user's password.\nAllows you to specify a password hash for the user. This is useful for migrating a user's password hash from another service.\nSupports bcrypt, scrypt (firebase), and argon2 password hashes.", - "type": "string" - }, - { - "name": "phone", - "optional": true, - "description": "The user's phone.", - "type": "string" - }, - { - "name": "phone_confirm", - "optional": true, - "description": "Sets the user's phone as confirmed when true, or unconfirmed when false.\nOnly a service role can modify.", - "type": "boolean" - }, - { - "name": "role", - "optional": true, - "description": "The `role` claim set in the user's access token JWT.\nWhen a user signs up, this role is set to `authenticated` by default. You should only modify the `role` if you need to provision several levels of admin access that have different permissions on individual columns in your database.\nSetting this role to `service_role` is not recommended as it grants the user admin privileges.", - "type": "string" - }, - { - "name": "user_metadata", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `user_metadata` should be a JSON object that includes user-specific info, such as their first and last name.\nNote: When using the GoTrueAdminApi and wanting to modify a user's metadata, this attribute is used instead of UserAttributes data.", - "type": "object" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "With custom user metadata", - "code": "const { data, error } = await supabase.auth.admin.createUser({\n email: 'user@email.com',\n password: 'password',\n user_metadata: { name: 'Yoda' }\n})", - "response": "{\n data: {\n user: {\n id: '1',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {},\n user_metadata: {},\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"1\",\n \"user_id\": \"1\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"phone_verified\": false,\n \"sub\": \"1\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false,\n }\n }\n error: null\n}" - }, - { - "title": "Auto-confirm the user's email", - "code": "const { data, error } = await supabase.auth.admin.createUser({\n email: 'user@email.com',\n email_confirm: true\n})" - }, - { - "title": "Auto-confirm the user's phone number", - "code": "const { data, error } = await supabase.auth.admin.createUser({\n phone: '1234567890',\n phone_confirm: true\n})" - } - ] - }, - { - "name": "deleteUser", - "description": "Delete a user. Requires a `service_role` key.", - "remarks": [ - "- The `deleteUser()` method requires the user's ID, which maps to the `auth.users.id` column." - ], - "parameters": [ - { - "name": "id", - "description": "The user id you want to remove.", - "type": "string" - }, - { - "name": "shouldSoftDelete", - "optional": true, - "description": "If true, then the user will be soft-deleted from the auth schema. Soft deletion allows user identification from the hashed user ID but is not reversible. Defaults to false for backward compatibility.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "type": "boolean" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Removes a user", - "code": "const { data, error } = await supabase.auth.admin.deleteUser(\n '715ed5db-f090-4b8c-a067-640ecee36aa0'\n)", - "response": "{\n \"data\": {\n \"user\": {}\n },\n \"error\": null\n}" - } - ] - }, - { - "name": "generateLink", - "description": "Generates email links and OTPs to be sent via a custom email provider.", - "remarks": [ - "- The following types can be passed into `generateLink()`: `signup`, `magiclink`, `invite`, `recovery`, `email_change_current`, `email_change_new`, `phone_change`. - `generateLink()` only generates the email link for `email_change_email` if the **Secure email change** is enabled in your project's [email auth provider settings](/dashboard/project/_/auth/providers). - `generateLink()` handles the creation of the user for `signup`, `invite` and `magiclink`." - ], - "parameters": [ - { - "name": "params", - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "email", - "optional": false, - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "reference", - "name": "Pick", - "typeArguments": [ - { - "kind": "object", - "name": "GenerateLinkOptions", - "properties": [ - { - "name": "data", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", - "type": "object" - }, - { - "name": "redirectTo", - "optional": true, - "description": "The URL which will be appended to the email link generated.", - "type": "string" - } - ] - }, - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "data" - }, - { - "kind": "literal", - "value": "redirectTo" - } - ] - } - ] - } - }, - { - "name": "password", - "optional": false, - "type": "string" - }, - { - "name": "type", - "optional": false, - "type": { - "kind": "literal", - "value": "signup" - } - } - ], - "name": "GenerateSignupLinkParams" - }, - { - "kind": "object", - "properties": [ - { - "name": "email", - "optional": false, - "description": "The user's email", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "reference", - "name": "Pick", - "typeArguments": [ - { - "kind": "object", - "name": "GenerateLinkOptions", - "properties": [ - { - "name": "data", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", - "type": "object" - }, - { - "name": "redirectTo", - "optional": true, - "description": "The URL which will be appended to the email link generated.", - "type": "string" - } - ] - }, - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "data" - }, - { - "kind": "literal", - "value": "redirectTo" - } - ] - } - ] - } - }, - { - "name": "type", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "invite" - }, - { - "kind": "literal", - "value": "magiclink" - } - ] - } - } - ], - "name": "GenerateInviteOrMagiclinkParams" - }, - { - "kind": "object", - "properties": [ - { - "name": "email", - "optional": false, - "description": "The user's email", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "reference", - "name": "Pick", - "typeArguments": [ - { - "kind": "object", - "name": "GenerateLinkOptions", - "properties": [ - { - "name": "data", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", - "type": "object" - }, - { - "name": "redirectTo", - "optional": true, - "description": "The URL which will be appended to the email link generated.", - "type": "string" - } - ] - }, - { - "kind": "literal", - "value": "redirectTo" - } - ] - } - }, - { - "name": "type", - "optional": false, - "type": { - "kind": "literal", - "value": "recovery" - } - } - ], - "name": "GenerateRecoveryLinkParams" - }, - { - "kind": "object", - "properties": [ - { - "name": "email", - "optional": false, - "description": "The user's email", - "type": "string" - }, - { - "name": "newEmail", - "optional": false, - "description": "The user's new email. Only required if type is 'email_change_current' or 'email_change_new'.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "reference", - "name": "Pick", - "typeArguments": [ - { - "kind": "object", - "name": "GenerateLinkOptions", - "properties": [ - { - "name": "data", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", - "type": "object" - }, - { - "name": "redirectTo", - "optional": true, - "description": "The URL which will be appended to the email link generated.", - "type": "string" - } - ] - }, - { - "kind": "literal", - "value": "redirectTo" - } - ] - } - }, - { - "name": "type", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "email_change_current" - }, - { - "kind": "literal", - "value": "email_change_new" - } - ] - } - } - ], - "name": "GenerateEmailChangeLinkParams" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "properties", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "action_link", - "optional": false, - "description": "The email link to send to the user. The action_link follows the following format: auth/v1/verify?type={verification_type}&token={hashed_token}&redirect_to={redirect_to}", - "type": "string" - }, - { - "name": "email_otp", - "optional": false, - "description": "The raw email OTP. You should send this in the email if you want your users to verify using an OTP instead of the action link.", - "type": "string" - }, - { - "name": "hashed_token", - "optional": false, - "description": "The hashed token appended to the action link.", - "type": "string" - }, - { - "name": "redirect_to", - "optional": false, - "description": "The URL appended to the action link.", - "type": "string" - }, - { - "name": "verification_type", - "optional": false, - "description": "The verification type that the email link is associated to.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "signup" - }, - { - "kind": "literal", - "value": "invite" - }, - { - "kind": "literal", - "value": "magiclink" - }, - { - "kind": "literal", - "value": "recovery" - }, - { - "kind": "literal", - "value": "email_change_current" - }, - { - "kind": "literal", - "value": "email_change_new" - } - ] - } - } - ], - "name": "GenerateLinkProperties" - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Generate a signup link", - "code": "const { data, error } = await supabase.auth.admin.generateLink({\n type: 'signup',\n email: 'email@example.com',\n password: 'secret'\n})", - "response": "{\n \"data\": {\n \"properties\": {\n \"action_link\": \"\",\n \"email_otp\": \"999999\",\n \"hashed_token\": \"\",\n \"verification_type\": \"signup\"\n },\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"email@example.com\",\n \"phone\": \"\",\n \"confirmation_sent_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"email@example.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" - }, - { - "title": "Generate an invite link", - "code": "const { data, error } = await supabase.auth.admin.generateLink({\n type: 'invite',\n email: 'email@example.com'\n})" - }, - { - "title": "Generate a magic link", - "code": "const { data, error } = await supabase.auth.admin.generateLink({\n type: 'magiclink',\n email: 'email@example.com'\n})" - }, - { - "title": "Generate a recovery link", - "code": "const { data, error } = await supabase.auth.admin.generateLink({\n type: 'recovery',\n email: 'email@example.com'\n})" - }, - { - "title": "Generate links to change current email address", - "code": "// generate an email change link to be sent to the current email address\nconst { data, error } = await supabase.auth.admin.generateLink({\n type: 'email_change_current',\n email: 'current.email@example.com',\n newEmail: 'new.email@example.com'\n})\n\n// generate an email change link to be sent to the new email address\nconst { data, error } = await supabase.auth.admin.generateLink({\n type: 'email_change_new',\n email: 'current.email@example.com',\n newEmail: 'new.email@example.com'\n})" - } - ] - }, - { - "name": "getUserById", - "description": "Get user by id.", - "remarks": [ - "- Fetches the user object from the database based on the user's id. - The `getUserById()` method requires the user's id which maps to the `auth.users.id` column." - ], - "parameters": [ - { - "name": "uid", - "description": "The user's unique identifier\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "type": "string" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Fetch the user object using the access_token jwt", - "code": "const { data, error } = await supabase.auth.admin.getUserById(1)", - "response": "{\n data: {\n user: {\n id: '1',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {},\n user_metadata: {},\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"1\",\n \"user_id\": \"1\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"phone_verified\": false,\n \"sub\": \"1\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false,\n }\n }\n error: null\n}" - } - ] - }, - { - "name": "inviteUserByEmail", - "description": "Sends an invite link to an email address.", - "remarks": [ - "- Sends an invite link to the user's email address. - The `inviteUserByEmail()` method is typically used by administrators to invite users to join the application. - Note that PKCE is not supported when using `inviteUserByEmail`. This is because the browser initiating the invite is often different from the browser accepting the invite which makes it difficult to provide the security guarantees required of the PKCE flow." - ], - "parameters": [ - { - "name": "email", - "description": "The email address of the user.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "description": "Additional options to be included when inviting.", - "type": { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": true, - "description": "A custom data object to store additional metadata about the user. This maps to the `auth.users.user_metadata` column.", - "type": "object" - }, - { - "name": "redirectTo", - "optional": true, - "description": "The URL which will be appended to the email link sent to the user's email address. Once clicked the user will end up on this URL.", - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Invite a user", - "code": "const { data, error } = await supabase.auth.admin.inviteUserByEmail('email@example.com')", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"invited_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmation_sent_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" - } - ] - }, - { - "name": "listUsers", - "description": "Get a list of users.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "remarks": ["- Defaults to return 50 users per page."], - "parameters": [ - { - "name": "params", - "optional": true, - "description": "An object which supports `page` and `perPage` as numbers, to alter the paginated results.", - "type": { - "kind": "object", - "properties": [ - { - "name": "page", - "optional": true, - "description": "The page number", - "type": "number" - }, - { - "name": "perPage", - "optional": true, - "description": "Number of items returned per page", - "type": "number" - } - ], - "name": "PageParams" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "intersection", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "users", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "lastPage", - "optional": false, - "type": "number" - }, - { - "name": "nextPage", - "optional": false, - "type": { - "kind": "union", - "types": [ - "number", - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "total", - "optional": false, - "type": "number" - } - ], - "name": "Pagination" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "users", - "optional": false, - "type": { - "kind": "tuple", - "elements": [] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Get a page of users", - "code": "const { data: { users }, error } = await supabase.auth.admin.listUsers()" - }, - { - "title": "Paginated list of users", - "code": "const { data: { users }, error } = await supabase.auth.admin.listUsers({\n page: 1,\n perPage: 1000\n})" - } - ] - }, - { - "name": "signOut", - "description": "Removes a logged-in session.", - "parameters": [ - { - "name": "jwt", - "description": "A valid, logged-in JWT.", - "type": "string" - }, - { - "name": "scope", - "optional": true, - "description": "The logout sope.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "global" - }, - { - "kind": "literal", - "value": "local" - }, - { - "kind": "literal", - "value": "others" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - ] - } - } - ] - } - ] - } - }, - { - "name": "updateUserById", - "description": "Updates the user data. Changes are applied directly without confirmation flows.", - "remarks": [ - "**Important:** This is a server-side operation and does **not** trigger client-side `onAuthStateChange` listeners. The admin API has no connection to client state.\nTo sync changes to the client after calling this method: 1. On the client, call `supabase.auth.refreshSession()` to fetch the updated user data 2. This will trigger the `TOKEN_REFRESHED` event and notify all listeners" - ], - "parameters": [ - { - "name": "uid", - "description": "The user's unique identifier", - "type": "string" - }, - { - "name": "attributes", - "description": "The data you want to update.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "type": { - "kind": "object", - "name": "AdminUserAttributes", - "properties": [ - { - "name": "app_metadata", - "optional": true, - "description": "A custom data object to store the user's application specific metadata. This maps to the `auth.users.app_metadata` column.\nOnly a service role can modify.\nThe `app_metadata` should be a JSON object that includes app-specific info, such as identity providers, roles, and other access control information.", - "type": "object" - }, - { - "name": "ban_duration", - "optional": true, - "description": "Determines how long a user is banned for.\nThe format for the ban duration follows a strict sequence of decimal numbers with a unit suffix. Valid time units are \"ns\", \"us\" (or \"µs\"), \"ms\", \"s\", \"m\", \"h\".\nFor example, some possible durations include: '300ms', '2h45m'.\nSetting the ban duration to 'none' lifts the ban on the user.", - "type": "string" - }, - { - "name": "current_password", - "optional": true, - "description": "The user's current password\nThis is only ever present when the user is resetting their password and GOTRUE_SECURITY_UPDATE_PASSWORD_REQUIRE_CURRENT_PASSWORD is true.", - "type": "string" - }, - { - "name": "email", - "optional": true, - "description": "The user's email.", - "type": "string" - }, - { - "name": "email_confirm", - "optional": true, - "description": "Sets the user's email as confirmed when true, or unconfirmed when false.\nOnly a service role can modify.", - "type": "boolean" - }, - { - "name": "id", - "optional": true, - "description": "The `id` for the user.\nAllows you to overwrite the default `id` set for the user.", - "type": "string" - }, - { - "name": "nonce", - "optional": true, - "description": "The nonce sent for reauthentication if the user's password is to be updated.\nCall reauthenticate() to obtain the nonce first.", - "type": "string" - }, - { - "name": "password", - "optional": true, - "description": "The user's password.", - "type": "string" - }, - { - "name": "password_hash", - "optional": true, - "description": "The `password_hash` for the user's password.\nAllows you to specify a password hash for the user. This is useful for migrating a user's password hash from another service.\nSupports bcrypt, scrypt (firebase), and argon2 password hashes.", - "type": "string" - }, - { - "name": "phone", - "optional": true, - "description": "The user's phone.", - "type": "string" - }, - { - "name": "phone_confirm", - "optional": true, - "description": "Sets the user's phone as confirmed when true, or unconfirmed when false.\nOnly a service role can modify.", - "type": "boolean" - }, - { - "name": "role", - "optional": true, - "description": "The `role` claim set in the user's access token JWT.\nWhen a user signs up, this role is set to `authenticated` by default. You should only modify the `role` if you need to provision several levels of admin access that have different permissions on individual columns in your database.\nSetting this role to `service_role` is not recommended as it grants the user admin privileges.", - "type": "string" - }, - { - "name": "user_metadata", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `user_metadata` should be a JSON object that includes user-specific info, such as their first and last name.\nNote: When using the GoTrueAdminApi and wanting to modify a user's metadata, this attribute is used instead of UserAttributes data.", - "type": "object" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Example 1", - "code": "// Server-side (Edge Function)\nconst { data, error } = await supabase.auth.admin.updateUserById(\n userId,\n { user_metadata: { preferences: { theme: 'dark' } } }\n)\n\n// Client-side (to sync the changes)\nconst { data, error } = await supabase.auth.refreshSession()\n// onAuthStateChange listeners will now be notified with updated user", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"new@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"recovery_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" - }, - { - "title": "Updates a user's email", - "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '11111111-1111-1111-1111-111111111111',\n { email: 'new@email.com' }\n)", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"new@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"recovery_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" - }, - { - "title": "Updates a user's password", - "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { password: 'new_password' }\n)" - }, - { - "title": "Updates a user's metadata", - "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { user_metadata: { hello: 'world' } }\n)" - }, - { - "title": "Updates a user's app_metadata", - "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { app_metadata: { plan: 'trial' } }\n)" - }, - { - "title": "Confirms a user's email address", - "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { email_confirm: true }\n)" - }, - { - "title": "Confirms a user's phone number", - "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { phone_confirm: true }\n)" - }, - { - "title": "Ban a user for 100 years", - "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { ban_duration: '876000h' }\n)" - } - ] - }, - { - "name": "exchangeCodeForSession", - "description": "Log in an existing user by exchanging an Auth Code issued during the PKCE flow.", - "remarks": ["- Used when `flowType` is set to `pkce` in client options."], - "parameters": [ - { - "name": "authCode", - "type": "string" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "object", - "name": "AuthSession", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Exchange Auth Code", - "code": "supabase.auth.exchangeCodeForSession('34e770dd-9ff9-416c-87fa-43b31d7ef225')", - "response": "{\n \"data\": {\n session: {\n access_token: '',\n token_type: 'bearer',\n expires_in: 3600,\n expires_at: 1700000000,\n refresh_token: '',\n user: {\n id: '11111111-1111-1111-1111-111111111111',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com'\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {\n \"provider\": \"email\",\n \"providers\": [\n \"email\",\n \"\"\n ]\n },\n user_metadata: {\n email: 'email@email.com',\n email_verified: true,\n full_name: 'User Name',\n iss: '',\n name: 'User Name',\n phone_verified: false,\n provider_id: '',\n sub: ''\n },\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n {\n \"identity_id\": \"33333333-3333-3333-3333-333333333333\",\n \"id\": \"\",\n \"user_id\": \"\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"full_name\": \"User Name\",\n \"iss\": \"\",\n \"name\": \"User Name\",\n \"phone_verified\": false,\n \"provider_id\": \"\",\n \"sub\": \"\"\n },\n \"provider\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false\n },\n provider_token: '',\n provider_refresh_token: ''\n },\n user: {\n id: '11111111-1111-1111-1111-111111111111',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {\n provider: 'email',\n providers: [\n \"email\",\n \"\"\n ]\n },\n user_metadata: {\n email: 'email@email.com',\n email_verified: true,\n full_name: 'User Name',\n iss: '',\n name: 'User Name',\n phone_verified: false,\n provider_id: '',\n sub: ''\n },\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n {\n \"identity_id\": \"33333333-3333-3333-3333-333333333333\",\n \"id\": \"\",\n \"user_id\": \"\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"full_name\": \"User Name\",\n \"iss\": \"\",\n \"name\": \"User Name\",\n \"phone_verified\": false,\n \"provider_id\": \"\",\n \"sub\": \"\"\n },\n \"provider\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false\n },\n redirectType: null\n },\n \"error\": null\n}" - } - ] - }, - { - "name": "getClaims", - "description": "Extracts the JWT claims present in the access token by first verifying the JWT against the server's JSON Web Key Set endpoint `/.well-known/jwks.json` which is often cached, resulting in significantly faster responses. Prefer this method over #getUser which always sends a request to the Auth server for each JWT.\nIf the project is not using an asymmetric JWT signing key (like ECC or RSA) it always sends a request to the Auth server (similar to #getUser) to verify the JWT.", - "remarks": [ - "- Parses the user's [access token](/docs/guides/auth/sessions#access-token-jwt-claims) as a [JSON Web Token (JWT)](/docs/guides/auth/jwts) and returns its components if valid and not expired. - If your project is using asymmetric JWT signing keys, then the verification is done locally usually without a network request using the [WebCrypto API](https://developer.mozilla.org/en-US/docs/Web/API/Web_Crypto_API). - A network request is sent to your project's JWT signing key discovery endpoint `https://project-id.supabase.co/auth/v1/.well-known/jwks.json`, which is cached locally. If your environment is ephemeral, such as a Lambda function that is destroyed after every request, a network request will be sent for each new invocation. Supabase provides a network-edge cache providing fast responses for these situations. - If the user's access token is about to expire when calling this function, the user's session will first be refreshed before validating the JWT. - If your project is using a symmetric secret to sign the JWT, it always sends a request similar to `getUser()` to validate the JWT at the server before returning the decoded token. This is also used if the WebCrypto API is not available in the environment. Make sure you polyfill it in such situations. - The returned claims can be customized per project using the [Custom Access Token Hook](/docs/guides/auth/auth-hooks/custom-access-token-hook)." - ], - "parameters": [ - { - "name": "jwt", - "optional": true, - "description": "An optional specific JWT you wish to verify, not the one you can obtain from #getSession.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "description": "Various additional options that allow you to customize the behavior of this method.", - "type": { - "kind": "object", - "properties": [ - { - "name": "allowExpired", - "optional": true, - "description": "If set to `true` the `exp` claim will not be validated against the current time.", - "type": "boolean" - }, - { - "name": "jwks", - "optional": true, - "description": "If set, this JSON Web Key Set is going to have precedence over the cached value available on the server.", - "type": { - "kind": "object", - "properties": [ - { - "name": "keys", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "JWK", - "properties": [ - { - "name": "alg", - "optional": true, - "type": "string" - }, - { - "name": "key_ops", - "optional": false, - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "kid", - "optional": true, - "type": "string" - }, - { - "name": "kty", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "RSA" - }, - { - "kind": "literal", - "value": "EC" - }, - { - "kind": "literal", - "value": "oct" - } - ] - } - } - ] - } - } - } - ] - } - }, - { - "name": "keys", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "JWK", - "properties": [ - { - "name": "alg", - "optional": true, - "type": "string" - }, - { - "name": "key_ops", - "optional": false, - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "kid", - "optional": true, - "type": "string" - }, - { - "name": "kty", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "RSA" - }, - { - "kind": "literal", - "value": "EC" - }, - { - "kind": "literal", - "value": "oct" - } - ] - } - } - ] - } - } - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "claims", - "optional": false, - "type": { - "kind": "object", - "name": "JwtPayload", - "properties": [ - { - "name": "aal", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "aal1" - }, - { - "kind": "literal", - "value": "aal2" - } - ] - } - }, - { - "name": "amr", - "optional": true, - "description": "Authentication Method References. Supports both RFC-8176 compliant format (string[]) and detailed format (AMREntry[]). - String format: ['password', 'otp'] - RFC-8176 compliant - Object format: [{ method: 'password', timestamp: 1234567890 }] - includes timestamps", - "type": { - "kind": "union", - "types": [ - { - "kind": "array", - "elementType": "string" - }, - { - "kind": "array", - "elementType": { - "kind": "object", - "name": "AMREntry", - "properties": [ - { - "name": "method", - "optional": false, - "description": "Authentication method name.", - "type": { - "kind": "union", - "types": [ - { - "kind": "indexedAccess", - "objectType": { - "kind": "query" - }, - "indexType": null - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "timestamp", - "optional": false, - "description": "Timestamp when the method was successfully used. Represents number of seconds since 1st January 1970 (UNIX epoch) in UTC.", - "type": "number" - } - ] - } - } - ] - } - }, - { - "name": "app_metadata", - "optional": true, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": { - "kind": "union", - "types": [ - "string", - { - "kind": "array", - "elementType": "string" - } - ] - } - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "exp", - "optional": false, - "type": "number" - }, - { - "name": "iat", - "optional": false, - "type": "number" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "iss", - "optional": false, - "type": "string" - }, - { - "name": "jti", - "optional": true, - "type": "string" - }, - { - "name": "nbf", - "optional": true, - "type": "number" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "ref", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": false, - "type": "string" - }, - { - "name": "session_id", - "optional": false, - "type": "string" - }, - { - "name": "sub", - "optional": false, - "type": "string" - }, - { - "name": "user_metadata", - "optional": true, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - }, - { - "name": "header", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "alg", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "RS256" - }, - { - "kind": "literal", - "value": "ES256" - }, - { - "kind": "literal", - "value": "HS256" - } - ] - } - }, - { - "name": "kid", - "optional": false, - "type": "string" - }, - { - "name": "typ", - "optional": false, - "type": "string" - } - ], - "name": "JwtHeader" - } - }, - { - "name": "signature", - "optional": false, - "type": { - "kind": "reference", - "name": "Uint8Array" - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Get JWT claims, header and signature", - "code": "const { data, error } = await supabase.auth.getClaims()", - "response": "{\n \"data\": {\n \"claims\": {\n \"aal\": \"aal1\",\n \"amr\": [{\n \"method\": \"email\",\n \"timestamp\": 1715766000\n }],\n \"app_metadata\": {},\n \"aud\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"exp\": 1715769600,\n \"iat\": 1715766000,\n \"is_anonymous\": false,\n \"iss\": \"https://project-id.supabase.co/auth/v1\",\n \"phone\": \"+13334445555\",\n \"role\": \"authenticated\",\n \"session_id\": \"11111111-1111-1111-1111-111111111111\",\n \"sub\": \"11111111-1111-1111-1111-111111111111\",\n \"user_metadata\": {}\n },\n \"header\": {\n \"alg\": \"RS256\",\n \"typ\": \"JWT\",\n \"kid\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"signature\": [/** Uint8Array */],\n },\n \"error\": null\n}" - } - ] - }, - { - "name": "getSession", - "description": "Returns the session, refreshing it if necessary.\nThe session returned can be null if the session is not detected which can happen in the event a user is not signed-in or has logged out.\n**IMPORTANT:** This method loads values directly from the storage attached to the client. If that storage is based on request cookies for example, the values in it may not be authentic and therefore it's strongly advised against using this method and its results in such circumstances. A warning will be emitted if this is detected. Use #getUser() instead.", - "remarks": [ - "- Since the introduction of [asymmetric JWT signing keys](/docs/guides/auth/signing-keys), this method is considered low-level and we encourage you to use `getClaims()` or `getUser()` instead. - Retrieves the current [user session](/docs/guides/auth/sessions) from the storage medium (local storage, cookies). - The session contains an access token (signed JWT), a refresh token and the user object. - If the session's access token is expired or is about to expire, this method will use the refresh token to refresh the session. - When using in a browser, or you've called `startAutoRefresh()` in your environment (React Native, etc.) this function always returns a valid access token without refreshing the session itself, as this is done in the background. This function returns very fast. - **IMPORTANT SECURITY NOTICE:** If using an insecure storage medium, such as cookies or request headers, the user object returned by this function **must not be trusted**. Always verify the JWT using `getClaims()` or your own JWT verification library to securely establish the user's identity and access. You can also use `getUser()` to fetch the user object directly from the Auth server for this purpose. - When using in a browser, this function is synchronized across all tabs using the [LockManager](https://developer.mozilla.org/en-US/docs/Web/API/LockManager) API. In other environments make sure you've defined a proper `lock` property, if necessary, to make sure there are no race conditions while the session is being refreshed." - ], - "parameters": [], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "object", - "name": "AuthSession", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Get the session data", - "code": "const { data, error } = await supabase.auth.getSession()", - "response": "{\n \"data\": {\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n }\n },\n \"error\": null\n}" - } - ] - }, - { - "name": "getUser", - "description": "Gets the current user details if there is an existing session. This method performs a network request to the Supabase Auth server, so the returned value is authentic and can be used to base authorization rules on.", - "remarks": [ - "- This method fetches the user object from the database instead of local session. - This method is useful for checking if the user is authorized because it validates the user's access token JWT on the server. - Should always be used when checking for user authorization on the server. On the client, you can instead use `getSession().session.user` for faster results. `getSession` is insecure on the server." - ], - "parameters": [ - { - "name": "jwt", - "optional": true, - "description": "Takes in an optional access token JWT. If no JWT is provided, the JWT from the current session is used.", - "type": "string" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Get the logged in user with the current existing session", - "code": "const { data: { user } } = await supabase.auth.getUser()", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" - }, - { - "title": "Get the logged in user with a custom access token jwt", - "code": "const { data: { user } } = await supabase.auth.getUser(jwt)" - } - ] - }, - { - "name": "getUserIdentities", - "description": "Gets all the identities linked to a user.", - "remarks": ["- The user needs to be signed in to call `getUserIdentities()`."], - "parameters": [], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "identities", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Returns a list of identities linked to the user", - "code": "const { data, error } = await supabase.auth.getUserIdentities()", - "response": "{\n \"data\": {\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"2024-01-01T00:00:00Z\",\n \"user_id\": \"2024-01-01T00:00:00Z\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ]\n },\n \"error\": null\n}" - } - ] - }, - { - "name": "initialize", - "description": "Initializes the client session either from the url or from storage. This method is automatically called when instantiating the client, but should also be called manually when checking for an error from an auth redirect (oauth, magiclink, password recovery, etc).", - "parameters": [], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "object", - "properties": [ - { - "name": "error", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - } - ], - "name": "InitializeResult" - } - ] - } - }, - { - "name": "reauthenticate", - "description": "Sends a reauthentication OTP to the user's email or phone number. Requires the user to be signed-in.", - "remarks": [ - "- This method is used together with `updateUser()` when a user's password needs to be updated. - If you require your user to reauthenticate before updating their password, you need to enable the **Secure password change** option in your [project's email provider settings](/dashboard/project/_/auth/providers). - A user is only require to reauthenticate before updating their password if **Secure password change** is enabled and the user **hasn't recently signed in**. A user is deemed recently signed in if the session was created in the last 24 hours. - This method will send a nonce to the user's email. If the user doesn't have a confirmed email address, the method will send the nonce to the user's confirmed phone number instead. - After receiving the OTP, include it as the `nonce` in your `updateUser()` call to finalize the password change." - ], - "parameters": [], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "AuthSession", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Send reauthentication nonce", - "code": "const { error } = await supabase.auth.reauthenticate()", - "notes": "Sends a reauthentication nonce to the user's email or phone number." - } - ] - }, - { - "name": "refreshSession", - "description": "Returns a new session, regardless of expiry status. Takes in an optional current session. If not passed in, then refreshSession() will attempt to retrieve it from getSession(). If the current session's refresh token is invalid, an error will be thrown.", - "remarks": [ - "- This method will refresh and return a new session whether the current one is expired or not." - ], - "parameters": [ - { - "name": "currentSession", - "optional": true, - "description": "The current session. If passed in, it must contain a refresh token.", - "type": { - "kind": "object", - "properties": [ - { - "name": "refresh_token", - "optional": false, - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "AuthSession", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Refresh session using the current session", - "code": "const { data, error } = await supabase.auth.refreshSession()\nconst { session, user } = data", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n }\n },\n \"error\": null\n}" - }, - { - "title": "Refresh session using a refresh token", - "code": "const { data, error } = await supabase.auth.refreshSession({ refresh_token })\nconst { session, user } = data" - } - ] - }, - { - "name": "resend", - "description": "Resends an existing signup confirmation email, email change email, SMS OTP or phone change OTP.", - "remarks": [ - "- Resends a signup confirmation, email change or phone change email to the user. - Passwordless sign-ins can be resent by calling the `signInWithOtp()` method again. - Password recovery emails can be resent by calling the `resetPasswordForEmail()` method again. - This method will only resend an email or phone OTP to the user if there was an initial signup, email change or phone change request being made(note: For existing users signing in with OTP, you should use `signInWithOtp()` again to resend the OTP). - You can specify a redirect url when you resend an email link using the `emailRedirectTo` option." - ], - "parameters": [ - { - "name": "credentials", - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "email", - "optional": false, - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "emailRedirectTo", - "optional": true, - "description": "A URL to send the user to after they have signed-in.", - "type": "string" - } - ] - } - }, - { - "name": "type", - "optional": false, - "type": { - "kind": "reference", - "name": "Extract", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "signup" - }, - { - "kind": "literal", - "value": "invite" - }, - { - "kind": "literal", - "value": "magiclink" - }, - { - "kind": "literal", - "value": "recovery" - }, - { - "kind": "literal", - "value": "email_change" - }, - { - "kind": "literal", - "value": "email" - } - ] - }, - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "signup" - }, - { - "kind": "literal", - "value": "email_change" - } - ] - } - ] - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - } - ] - } - }, - { - "name": "phone", - "optional": false, - "type": "string" - }, - { - "name": "type", - "optional": false, - "type": { - "kind": "reference", - "name": "Extract", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "sms" - }, - { - "kind": "literal", - "value": "phone_change" - } - ] - }, - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "sms" - }, - { - "kind": "literal", - "value": "phone_change" - } - ] - } - ] - } - } - ] - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "messageId", - "optional": true, - "type": { - "kind": "union", - "types": [ - "string", - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "session", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Resend an email signup confirmation", - "code": "const { error } = await supabase.auth.resend({\n type: 'signup',\n email: 'email@example.com',\n options: {\n emailRedirectTo: 'https://example.com/welcome'\n }\n})", - "notes": "Resends the email signup confirmation to the user" - }, - { - "title": "Resend a phone signup confirmation", - "code": "const { error } = await supabase.auth.resend({\n type: 'sms',\n phone: '1234567890'\n})", - "notes": "Resends the phone signup confirmation email to the user" - }, - { - "title": "Resend email change email", - "code": "const { error } = await supabase.auth.resend({\n type: 'email_change',\n email: 'email@example.com'\n})", - "notes": "Resends the email change email to the user" - }, - { - "title": "Resend phone change OTP", - "code": "const { error } = await supabase.auth.resend({\n type: 'phone_change',\n phone: '1234567890'\n})", - "notes": "Resends the phone change OTP to the user" - } - ] - }, - { - "name": "resetPasswordForEmail", - "description": "Sends a password reset request to an email address. This method supports the PKCE flow.", - "remarks": [ - "- The password reset flow consist of 2 broad steps: (i) Allow the user to login via the password reset link; (ii) Update the user's password. - The `resetPasswordForEmail()` only sends a password reset link to the user's email. To update the user's password, see [`updateUser()`](/docs/reference/javascript/auth-updateuser). - A `PASSWORD_RECOVERY` event will be emitted when the password recovery link is clicked. You can use [`onAuthStateChange()`](/docs/reference/javascript/auth-onauthstatechange) to listen and invoke a callback function on these events. - When the user clicks the reset link in the email they are redirected back to your application. You can configure the URL that the user is redirected to with the `redirectTo` parameter. See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project. - After the user has been redirected successfully, prompt them for a new password and call `updateUser()`: ```js const { data, error } = await supabase.auth.updateUser({ password: new_password }) ```" - ], - "parameters": [ - { - "name": "email", - "description": "The email address of the user.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "redirectTo", - "optional": true, - "description": "The URL to send the user to after they click the password reset link.", - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Reset password", - "code": "const { data, error } = await supabase.auth.resetPasswordForEmail(email, {\n redirectTo: 'https://example.com/update-password',\n})", - "response": "{\n data: {}\n error: null\n}" - }, - { - "title": "Reset password (React)", - "code": "/**\n * Step 1: Send the user an email to get a password reset token.\n * This email contains a link which sends the user back to your application.\n */\nconst { data, error } = await supabase.auth\n .resetPasswordForEmail('user@email.com')\n\n/**\n * Step 2: Once the user is redirected back to your application,\n * ask the user to reset their password.\n */\n useEffect(() => {\n supabase.auth.onAuthStateChange(async (event, session) => {\n if (event == \"PASSWORD_RECOVERY\") {\n const newPassword = prompt(\"What would you like your new password to be?\");\n const { data, error } = await supabase.auth\n .updateUser({ password: newPassword })\n\n if (data) alert(\"Password updated successfully!\")\n if (error) alert(\"There was an error updating your password.\")\n }\n })\n }, [])" - } - ] - }, - { - "name": "setSession", - "description": "Sets the session data from the current session. If the current session is expired, setSession will take care of refreshing it to obtain a new session. If the refresh token or access token in the current session is invalid, an error will be thrown.", - "remarks": [ - "- This method sets the session using an `access_token` and `refresh_token`. - If successful, a `SIGNED_IN` event is emitted." - ], - "parameters": [ - { - "name": "currentSession", - "description": "The current session that minimally contains an access token and refresh token.", - "type": { - "kind": "object", - "properties": [ - { - "name": "access_token", - "optional": false, - "type": "string" - }, - { - "name": "refresh_token", - "optional": false, - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "AuthSession", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Set the session", - "code": "const { data, error } = await supabase.auth.setSession({\n access_token,\n refresh_token\n })", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n },\n \"session\": {\n \"access_token\": \"\",\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"11111111-1111-1111-1111-111111111111\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"2024-01-01T00:00:00Z\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n },\n \"token_type\": \"bearer\",\n \"expires_in\": 3500,\n \"expires_at\": 1700000000\n }\n },\n \"error\": null\n}", - "notes": "Sets the session data from an access_token and refresh_token, then returns an auth response or error." - } - ] - }, - { - "name": "signInAnonymously", - "description": "Creates a new anonymous user.", - "remarks": [ - "- Returns an anonymous user - It is recommended to set up captcha for anonymous sign-ins to prevent abuse. You can pass in the captcha token in the `options` param." - ], - "parameters": [ - { - "name": "credentials", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "data", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", - "type": "object" - } - ] - } - } - ], - "name": "SignInAnonymouslyCredentials" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "AuthSession", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Create an anonymous user", - "code": "const { data, error } = await supabase.auth.signInAnonymously({\n options: {\n captchaToken\n }\n});", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {},\n \"user_metadata\": {},\n \"identities\": [],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": true\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {},\n \"user_metadata\": {},\n \"identities\": [],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": true\n }\n }\n },\n \"error\": null\n}" - }, - { - "title": "Create an anonymous user with custom user metadata", - "code": "const { data, error } = await supabase.auth.signInAnonymously({\n options: {\n data\n }\n})" - } - ] - }, - { - "name": "signInWithIdToken", - "description": "Allows signing in with an OIDC ID token. The authentication provider used should be enabled and configured.", - "remarks": [ - "- Use an ID token to sign in. - Especially useful when implementing sign in using native platform dialogs in mobile or desktop apps using Sign in with Apple or Sign in with Google on iOS and Android. - You can also use Google's [One Tap](https://developers.google.com/identity/gsi/web/guides/display-google-one-tap) and [Automatic sign-in](https://developers.google.com/identity/gsi/web/guides/automatic-sign-in-sign-out) via this API." - ], - "parameters": [ - { - "name": "credentials", - "type": { - "kind": "object", - "properties": [ - { - "name": "access_token", - "optional": true, - "description": "If the ID token contains an `at_hash` claim, then the hash of this value is compared to the value in the ID token.", - "type": "string" - }, - { - "name": "nonce", - "optional": true, - "description": "If the ID token contains a `nonce` claim, then the hash of this value is compared to the value in the ID token.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - } - ] - } - }, - { - "name": "provider", - "optional": false, - "description": "Provider name or OIDC `iss` value identifying which provider should be used to verify the provided token. Supported names: `google`, `apple`, `azure`, `facebook`, `kakao`. Use the `custom:` prefix for custom OIDC providers (e.g. `custom:my-oidc-provider`).", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "google" - }, - { - "kind": "literal", - "value": "apple" - }, - { - "kind": "literal", - "value": "azure" - }, - { - "kind": "literal", - "value": "facebook" - }, - { - "kind": "literal", - "value": "kakao" - }, - { - "kind": "templateLiteral" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "token", - "optional": false, - "description": "OIDC ID token issued by the specified provider. The `iss` claim in the ID token must match the supplied provider. Some ID tokens contain an `at_hash` which require that you provide an `access_token` value to be accepted properly. If the token contains a `nonce` claim you must supply the nonce used to obtain the ID token.", - "type": "string" - } - ], - "name": "SignInWithIdTokenCredentials" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "object", - "name": "AuthSession", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Sign In using ID Token", - "code": "const { data, error } = await supabase.auth.signInWithIdToken({\n provider: 'google',\n token: 'your-id-token'\n})", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n ...\n },\n \"user_metadata\": {\n ...\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"provider\": \"google\",\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n ...\n },\n \"user_metadata\": {\n ...\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"provider\": \"google\",\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n }\n }\n },\n \"error\": null\n}" - } - ] - }, - { - "name": "signInWithOAuth", - "description": "Log in an existing user via a third-party provider. This method supports the PKCE flow.", - "remarks": [ - "- This method is used for signing in using [Social Login (OAuth) providers](/docs/guides/auth#configure-third-party-providers). - It works by redirecting your application to the provider's authorization screen, before bringing back the user to your app." - ], - "parameters": [ - { - "name": "credentials", - "type": { - "kind": "object", - "properties": [ - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "queryParams", - "optional": true, - "description": "An object of query params", - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "redirectTo", - "optional": true, - "description": "A URL to send the user to after they are confirmed.", - "type": "string" - }, - { - "name": "scopes", - "optional": true, - "description": "A space-separated list of scopes granted to the OAuth application.", - "type": "string" - }, - { - "name": "skipBrowserRedirect", - "optional": true, - "description": "If set to true does not immediately redirect the current browser context to visit the OAuth authorization page for the provider.", - "type": "boolean" - } - ] - } - }, - { - "name": "provider", - "optional": false, - "description": "One of the providers supported by GoTrue.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "apple" - }, - { - "kind": "literal", - "value": "azure" - }, - { - "kind": "literal", - "value": "bitbucket" - }, - { - "kind": "literal", - "value": "discord" - }, - { - "kind": "literal", - "value": "facebook" - }, - { - "kind": "literal", - "value": "figma" - }, - { - "kind": "literal", - "value": "github" - }, - { - "kind": "literal", - "value": "gitlab" - }, - { - "kind": "literal", - "value": "google" - }, - { - "kind": "literal", - "value": "kakao" - }, - { - "kind": "literal", - "value": "keycloak" - }, - { - "kind": "literal", - "value": "linkedin" - }, - { - "kind": "literal", - "value": "linkedin_oidc" - }, - { - "kind": "literal", - "value": "notion" - }, - { - "kind": "literal", - "value": "slack" - }, - { - "kind": "literal", - "value": "slack_oidc" - }, - { - "kind": "literal", - "value": "spotify" - }, - { - "kind": "literal", - "value": "twitch" - }, - { - "kind": "literal", - "value": "twitter" - }, - { - "kind": "literal", - "value": "x" - }, - { - "kind": "literal", - "value": "workos" - }, - { - "kind": "literal", - "value": "zoom" - }, - { - "kind": "literal", - "value": "fly" - }, - { - "kind": "templateLiteral" - } - ] - } - } - ], - "name": "SignInWithOAuthCredentials" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "provider", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "apple" - }, - { - "kind": "literal", - "value": "azure" - }, - { - "kind": "literal", - "value": "bitbucket" - }, - { - "kind": "literal", - "value": "discord" - }, - { - "kind": "literal", - "value": "facebook" - }, - { - "kind": "literal", - "value": "figma" - }, - { - "kind": "literal", - "value": "github" - }, - { - "kind": "literal", - "value": "gitlab" - }, - { - "kind": "literal", - "value": "google" - }, - { - "kind": "literal", - "value": "kakao" - }, - { - "kind": "literal", - "value": "keycloak" - }, - { - "kind": "literal", - "value": "linkedin" - }, - { - "kind": "literal", - "value": "linkedin_oidc" - }, - { - "kind": "literal", - "value": "notion" - }, - { - "kind": "literal", - "value": "slack" - }, - { - "kind": "literal", - "value": "slack_oidc" - }, - { - "kind": "literal", - "value": "spotify" - }, - { - "kind": "literal", - "value": "twitch" - }, - { - "kind": "literal", - "value": "twitter" - }, - { - "kind": "literal", - "value": "x" - }, - { - "kind": "literal", - "value": "workos" - }, - { - "kind": "literal", - "value": "zoom" - }, - { - "kind": "literal", - "value": "fly" - }, - { - "kind": "templateLiteral" - } - ] - } - }, - { - "name": "url", - "optional": false, - "type": "string" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "provider", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "apple" - }, - { - "kind": "literal", - "value": "azure" - }, - { - "kind": "literal", - "value": "bitbucket" - }, - { - "kind": "literal", - "value": "discord" - }, - { - "kind": "literal", - "value": "facebook" - }, - { - "kind": "literal", - "value": "figma" - }, - { - "kind": "literal", - "value": "github" - }, - { - "kind": "literal", - "value": "gitlab" - }, - { - "kind": "literal", - "value": "google" - }, - { - "kind": "literal", - "value": "kakao" - }, - { - "kind": "literal", - "value": "keycloak" - }, - { - "kind": "literal", - "value": "linkedin" - }, - { - "kind": "literal", - "value": "linkedin_oidc" - }, - { - "kind": "literal", - "value": "notion" - }, - { - "kind": "literal", - "value": "slack" - }, - { - "kind": "literal", - "value": "slack_oidc" - }, - { - "kind": "literal", - "value": "spotify" - }, - { - "kind": "literal", - "value": "twitch" - }, - { - "kind": "literal", - "value": "twitter" - }, - { - "kind": "literal", - "value": "x" - }, - { - "kind": "literal", - "value": "workos" - }, - { - "kind": "literal", - "value": "zoom" - }, - { - "kind": "literal", - "value": "fly" - }, - { - "kind": "templateLiteral" - } - ] - } - }, - { - "name": "url", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Sign in using a third-party provider", - "code": "const { data, error } = await supabase.auth.signInWithOAuth({\n provider: 'github'\n})", - "response": "{\n data: {\n provider: 'github',\n url: \n },\n error: null\n}", - "notes": "with redirect\n- When the OAuth provider successfully authenticates the user, they are redirected to the URL specified in the `redirectTo` parameter. This parameter defaults to the [`SITE_URL`](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls). It does not redirect the user immediately after invoking this method.\n- See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project." - }, - { - "title": "Sign in using a third-party provider with redirect", - "code": "const { data, error } = await supabase.auth.signInWithOAuth({\n provider: 'github',\n options: {\n redirectTo: 'https://example.com/welcome'\n }\n})", - "notes": "- When the OAuth provider successfully authenticates the user, they are redirected to the URL specified in the `redirectTo` parameter. This parameter defaults to the [`SITE_URL`](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls). It does not redirect the user immediately after invoking this method.\n- See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project." - }, - { - "title": "Sign in with scopes and access provider tokens", - "code": "// Register this immediately after calling createClient!\n// Because signInWithOAuth causes a redirect, you need to fetch the\n// provider tokens from the callback.\nsupabase.auth.onAuthStateChange((event, session) => {\n if (session && session.provider_token) {\n window.localStorage.setItem('oauth_provider_token', session.provider_token)\n }\n\n if (session && session.provider_refresh_token) {\n window.localStorage.setItem('oauth_provider_refresh_token', session.provider_refresh_token)\n }\n\n if (event === 'SIGNED_OUT') {\n window.localStorage.removeItem('oauth_provider_token')\n window.localStorage.removeItem('oauth_provider_refresh_token')\n }\n})\n\n// Call this on your Sign in with GitHub button to initiate OAuth\n// with GitHub with the requested elevated scopes.\nawait supabase.auth.signInWithOAuth({\n provider: 'github',\n options: {\n scopes: 'repo gist notifications'\n }\n})", - "notes": "If you need additional access from an OAuth provider, in order to access provider specific APIs in the name of the user, you can do this by passing in the scopes the user should authorize for your application. Note that the `scopes` option takes in **a space-separated list** of scopes.\n\nBecause OAuth sign-in often includes redirects, you should register an `onAuthStateChange` callback immediately after you create the Supabase client. This callback will listen for the presence of `provider_token` and `provider_refresh_token` properties on the `session` object and store them in local storage. The client library will emit these values **only once** immediately after the user signs in. You can then access them by looking them up in local storage, or send them to your backend servers for further processing.\n\nFinally, make sure you remove them from local storage on the `SIGNED_OUT` event. If the OAuth provider supports token revocation, make sure you call those APIs either from the frontend or schedule them to be called on the backend." - } - ] - }, - { - "name": "signInWithOtp", - "description": "Log in a user using magiclink or a one-time password (OTP).\nIf the `{{ .ConfirmationURL }}` variable is specified in the email template, a magiclink will be sent. If the `{{ .Token }}` variable is specified in the email template, an OTP will be sent. If you're using phone sign-ins, only an OTP will be sent. You won't be able to send a magiclink for phone sign-ins.\nBe aware that you may get back an error message that will not distinguish between the cases where the account does not exist or, that the account can only be accessed via social login.\nDo note that you will need to configure a Whatsapp sender on Twilio if you are using phone sign in with the 'whatsapp' channel. The whatsapp channel is not supported on other providers at this time. This method supports PKCE when an email is passed.", - "remarks": [ - "- Requires either an email or phone number. - This method is used for passwordless sign-ins where a OTP is sent to the user's email or phone number. - If the user doesn't exist, `signInWithOtp()` will signup the user instead. To restrict this behavior, you can set `shouldCreateUser` in `SignInWithPasswordlessCredentials.options` to `false`. - If you're using an email, you can configure whether you want the user to receive a magiclink or a OTP. - If you're using phone, you can configure whether you want the user to receive a OTP. - The magic link's destination URL is determined by the [`SITE_URL`](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls). - See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project. - Magic links and OTPs share the same implementation. To send users a one-time code instead of a magic link, [modify the magic link email template](/dashboard/project/_/auth/templates) to include `{{ .Token }}` instead of `{{ .ConfirmationURL }}`. - See our [Twilio Phone Auth Guide](/docs/guides/auth/phone-login?showSMSProvider=Twilio) for details about configuring WhatsApp sign in." - ], - "parameters": [ - { - "name": "credentials", - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "email", - "optional": false, - "description": "The user's email address.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "data", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", - "type": "object" - }, - { - "name": "emailRedirectTo", - "optional": true, - "description": "The redirect url embedded in the email link", - "type": "string" - }, - { - "name": "shouldCreateUser", - "optional": true, - "description": "If set to false, this method will not create a new user. Defaults to true.", - "type": "boolean" - } - ] - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "channel", - "optional": true, - "description": "Messaging channel to use (e.g. whatsapp or sms)", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "sms" - }, - { - "kind": "literal", - "value": "whatsapp" - } - ] - } - }, - { - "name": "data", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", - "type": "object" - }, - { - "name": "shouldCreateUser", - "optional": true, - "description": "If set to false, this method will not create a new user. Defaults to true.", - "type": "boolean" - } - ] - } - }, - { - "name": "phone", - "optional": false, - "description": "The user's phone number.", - "type": "string" - } - ] - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "messageId", - "optional": true, - "type": { - "kind": "union", - "types": [ - "string", - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "session", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Sign in with email", - "code": "const { data, error } = await supabase.auth.signInWithOtp({\n email: 'example@email.com',\n options: {\n emailRedirectTo: 'https://example.com/welcome'\n }\n})", - "response": "{\n \"data\": {\n \"user\": null,\n \"session\": null\n },\n \"error\": null\n}", - "notes": "The user will be sent an email which contains either a magiclink or a OTP or both. By default, a given user can only request a OTP once every 60 seconds." - }, - { - "title": "Sign in with SMS OTP", - "code": "const { data, error } = await supabase.auth.signInWithOtp({\n phone: '+13334445555',\n})", - "notes": "The user will be sent a SMS which contains a OTP. By default, a given user can only request a OTP once every 60 seconds." - }, - { - "title": "Sign in with WhatsApp OTP", - "code": "const { data, error } = await supabase.auth.signInWithOtp({\n phone: '+13334445555',\n options: {\n channel:'whatsapp',\n }\n})", - "notes": "The user will be sent a WhatsApp message which contains a OTP. By default, a given user can only request a OTP once every 60 seconds. Note that a user will need to have a valid WhatsApp account that is linked to Twilio in order to use this feature." - } - ] - }, - { - "name": "signInWithPassword", - "description": "Log in an existing user with an email and password or phone and password.\nBe aware that you may get back an error message that will not distinguish between the cases where the account does not exist or that the email/phone and password combination is wrong or that the account can only be accessed via social login.", - "remarks": ["- Requires either an email and password or a phone number and password."], - "parameters": [ - { - "name": "credentials", - "type": { - "kind": "intersection", - "types": [ - { - "kind": "reference", - "name": "PasswordCredentialsBase" - }, - { - "kind": "object", - "properties": [ - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "type": "string" - } - ] - } - } - ] - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "object", - "name": "AuthSession", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - }, - { - "name": "weakPassword", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "message", - "optional": false, - "type": "string" - }, - { - "name": "reasons", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "indexedAccess", - "objectType": { - "kind": "query" - }, - "indexType": null - } - } - } - ], - "name": "WeakPassword" - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Sign in with email and password", - "code": "const { data, error } = await supabase.auth.signInWithPassword({\n email: 'example@email.com',\n password: 'example-password',\n})", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n }\n }\n },\n \"error\": null\n}" - }, - { - "title": "Sign in with phone and password", - "code": "const { data, error } = await supabase.auth.signInWithPassword({\n phone: '+13334445555',\n password: 'some-password',\n})" - } - ] - }, - { - "name": "signInWithSSO", - "description": "Attempts a single-sign on using an enterprise Identity Provider. A successful SSO attempt will redirect the current page to the identity provider authorization page. The redirect URL is implementation and SSO protocol specific.\nYou can use it by providing a SSO domain. Typically you can extract this domain by asking users for their email address. If this domain is registered on the Auth instance the redirect will use that organization's currently active SSO Identity Provider for the login.\nIf you have built an organization-specific login page, you can use the organization's SSO Identity Provider UUID directly instead.", - "remarks": [ - "- Before you can call this method you need to [establish a connection](/docs/guides/auth/sso/auth-sso-saml#managing-saml-20-connections) to an identity provider. Use the [CLI commands](/docs/reference/cli/supabase-sso) to do this. - If you've associated an email domain to the identity provider, you can use the `domain` property to start a sign-in flow. - In case you need to use a different way to start the authentication flow with an identity provider, you can use the `providerId` property. For example: - Mapping specific user email addresses with an identity provider. - Using different hints to identity the identity provider to be used by the user, like a company-specific page, IP address or other tracking information." - ], - "parameters": [ - { - "name": "params", - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "redirectTo", - "optional": true, - "description": "A URL to send the user to after they have signed-in.", - "type": "string" - }, - { - "name": "skipBrowserRedirect", - "optional": true, - "description": "If set to true, the redirect will not happen on the client side. This parameter is used when you wish to handle the redirect yourself. Defaults to false.", - "type": "boolean" - } - ] - } - }, - { - "name": "providerId", - "optional": false, - "description": "UUID of the SSO provider to invoke single-sign on to.", - "type": "string" - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "domain", - "optional": false, - "description": "Domain name of the organization for which to invoke single-sign on.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "redirectTo", - "optional": true, - "description": "A URL to send the user to after they have signed-in.", - "type": "string" - }, - { - "name": "skipBrowserRedirect", - "optional": true, - "description": "If set to true, the redirect will not happen on the client side. This parameter is used when you wish to handle the redirect yourself. Defaults to false.", - "type": "boolean" - } - ] - } - } - ] - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "url", - "optional": false, - "description": "URL to open in a browser which will complete the sign-in flow by taking the user to the identity provider's authentication flow.\nOn browsers you can set the URL to `window.location.href` to take the user to the authentication flow.", - "type": "string" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Sign in with email domain", - "code": "// You can extract the user's email domain and use it to trigger the\n // authentication flow with the correct identity provider.\n\n const { data, error } = await supabase.auth.signInWithSSO({\n domain: 'company.com'\n })\n\n if (data?.url) {\n // redirect the user to the identity provider's authentication flow\n window.location.href = data.url\n }" - }, - { - "title": "Sign in with provider UUID", - "code": "// Useful when you need to map a user's sign in request according\n // to different rules that can't use email domains.\n\n const { data, error } = await supabase.auth.signInWithSSO({\n providerId: '21648a9d-8d5a-4555-a9d1-d6375dc14e92'\n })\n\n if (data?.url) {\n // redirect the user to the identity provider's authentication flow\n window.location.href = data.url\n }" - } - ] - }, - { - "name": "signInWithWeb3", - "description": "Signs in a user by verifying a message signed by the user's private key. Supports Ethereum (via Sign-In-With-Ethereum) & Solana (Sign-In-With-Solana) standards, both of which derive from the EIP-4361 standard With slight variation on Solana's side.", - "remarks": [ - "- Uses a Web3 (Ethereum, Solana) wallet to sign a user in. - Read up on the [potential for abuse](/docs/guides/auth/auth-web3#potential-for-abuse) before using it." - ], - "parameters": [ - { - "name": "credentials", - "type": { - "kind": "union", - "types": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "chain", - "optional": false, - "type": { - "kind": "literal", - "value": "solana" - } - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "signInWithSolana", - "optional": true, - "type": { - "kind": "reference", - "name": "Partial", - "typeArguments": [ - { - "kind": "reference", - "name": "Omit", - "typeArguments": [ - { - "kind": "reference", - "name": "SolanaSignInInput" - }, - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "version" - }, - { - "kind": "literal", - "value": "chain" - }, - { - "kind": "literal", - "value": "domain" - }, - { - "kind": "literal", - "value": "uri" - }, - { - "kind": "literal", - "value": "statement" - } - ] - } - ] - } - ] - } - }, - { - "name": "url", - "optional": true, - "description": "URL to use with the wallet interface. Some wallets do not allow signing a message for URLs different from the current page.", - "type": "string" - } - ] - } - }, - { - "name": "statement", - "optional": true, - "description": "Optional statement to include in the Sign in with Solana message. Must not include new line characters. Most wallets like Phantom **require specifying a statement!**", - "type": "string" - }, - { - "name": "wallet", - "optional": true, - "description": "Wallet interface to use. If not specified will default to `window.solana`.", - "type": { - "kind": "object", - "properties": [ - { - "name": "publicKey", - "optional": true, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "toBase58", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "signIn", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "signMessage", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - } - ], - "name": "SolanaWallet" - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "chain", - "optional": false, - "type": { - "kind": "literal", - "value": "solana" - } - }, - { - "name": "message", - "optional": false, - "description": "Sign in with Solana compatible message. Must include `Issued At`, `URI` and `Version`.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - } - ] - } - }, - { - "name": "signature", - "optional": false, - "description": "Ed25519 signature of the message.", - "type": { - "kind": "reference", - "name": "Uint8Array" - } - } - ] - } - ] - }, - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "chain", - "optional": false, - "type": { - "kind": "literal", - "value": "ethereum" - } - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "signInWithEthereum", - "optional": true, - "type": { - "kind": "reference", - "name": "Partial", - "typeArguments": [ - { - "kind": "reference", - "name": "Omit", - "typeArguments": [ - { - "kind": "reference", - "name": "EthereumSignInInput" - }, - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "version" - }, - { - "kind": "literal", - "value": "domain" - }, - { - "kind": "literal", - "value": "uri" - }, - { - "kind": "literal", - "value": "statement" - } - ] - } - ] - } - ] - } - }, - { - "name": "url", - "optional": true, - "description": "URL to use with the wallet interface. Some wallets do not allow signing a message for URLs different from the current page.", - "type": "string" - } - ] - } - }, - { - "name": "statement", - "optional": true, - "description": "Optional statement to include in the Sign in with Ethereum message. Must not include new line characters. Most wallets like Phantom **require specifying a statement!**", - "type": "string" - }, - { - "name": "wallet", - "optional": true, - "description": "Wallet interface to use. If not specified will default to `window.ethereum`.", - "type": { - "kind": "reference", - "name": "EIP1193Provider" - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "chain", - "optional": false, - "type": { - "kind": "literal", - "value": "ethereum" - } - }, - { - "name": "message", - "optional": false, - "description": "Sign in with Ethereum compatible message. Must include `Issued At`, `URI` and `Version`.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - } - ] - } - }, - { - "name": "signature", - "optional": false, - "description": "Ethereum curve (secp256k1) signature of the message.", - "type": { - "kind": "reference", - "name": "Hex" - } - } - ] - } - ] - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "object", - "name": "AuthSession", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Sign in with Solana or Ethereum (Window API)", - "code": "// uses window.ethereum for the wallet\n const { data, error } = await supabase.auth.signInWithWeb3({\n chain: 'ethereum',\n statement: 'I accept the Terms of Service at https://example.com/tos'\n })\n\n // uses window.solana for the wallet\n const { data, error } = await supabase.auth.signInWithWeb3({\n chain: 'solana',\n statement: 'I accept the Terms of Service at https://example.com/tos'\n })" - }, - { - "title": "Sign in with Ethereum (Message and Signature)", - "code": "const { data, error } = await supabase.auth.signInWithWeb3({\n chain: 'ethereum',\n message: '',\n signature: '',\n })" - }, - { - "title": "Sign in with Solana (Brave)", - "code": "const { data, error } = await supabase.auth.signInWithWeb3({\n chain: 'solana',\n statement: 'I accept the Terms of Service at https://example.com/tos',\n wallet: window.braveSolana\n })" - }, - { - "title": "Sign in with Solana (Wallet Adapter)", - "code": "function SignInButton() {\n const wallet = useWallet()\n\n return (\n <>\n {wallet.connected ? (\n {\n supabase.auth.signInWithWeb3({\n chain: 'solana',\n statement: 'I accept the Terms of Service at https://example.com/tos',\n wallet,\n })\n }}\n >\n Sign in with Solana\n \n ) : (\n \n )}\n \n )\n}\n\nfunction App() {\n const endpoint = clusterApiUrl('devnet')\n const wallets = useMemo(() => [], [])\n\n return (\n \n \n \n \n \n \n \n )\n}" - } - ] - }, - { - "name": "signOut", - "description": "Inside a browser context, `signOut()` will remove the logged in user from the browser session and log them out - removing all items from localstorage and then trigger a `\"SIGNED_OUT\"` event.\nFor server-side management, you can revoke all refresh tokens for a user by passing a user's JWT through to `auth.api.signOut(JWT: string)`. There is no way to revoke a user's access token jwt until it expires. It is recommended to set a shorter expiry on the jwt for this reason.\nIf using `others` scope, no `SIGNED_OUT` event is fired!", - "remarks": [ - "- In order to use the `signOut()` method, the user needs to be signed in first. - By default, `signOut()` uses the global scope, which signs out all other sessions that the user is logged into as well. Customize this behavior by passing a scope parameter. - Since Supabase Auth uses JWTs for authentication, the access token JWT will be valid until it's expired. When the user signs out, Supabase revokes the refresh token and deletes the JWT from the client-side. This does not revoke the JWT and it will still be valid until it expires." - ], - "parameters": [ - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "scope", - "optional": true, - "description": "Determines which sessions should be logged out. Global means all sessions by this account. Local means only this session. Others means all other sessions except the current one. When using others, there is no sign-out event fired on the current session!", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "global" - }, - { - "kind": "literal", - "value": "local" - }, - { - "kind": "literal", - "value": "others" - } - ] - } - } - ], - "name": "SignOut" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "object", - "properties": [ - { - "name": "error", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - ] - } - } - ] - } - ] - }, - "examples": [ - { - "title": "Sign out (all sessions)", - "code": "const { error } = await supabase.auth.signOut()" - }, - { - "title": "Sign out (current session)", - "code": "const { error } = await supabase.auth.signOut({ scope: 'local' })" - }, - { - "title": "Sign out (other sessions)", - "code": "const { error } = await supabase.auth.signOut({ scope: 'others' })" - } - ] - }, - { - "name": "signUp", - "description": "Creates a new user.\nBe aware that if a user account exists in the system you may get back an error message that attempts to hide this information from the user. This method has support for PKCE via email signups. The PKCE flow cannot be used when autoconfirm is enabled.", - "remarks": [ - "- By default, the user needs to verify their email address before logging in. To turn this off, disable **Confirm email** in [your project](/dashboard/project/_/auth/providers). - **Confirm email** determines if users need to confirm their email address after signing up. - If **Confirm email** is enabled, a `user` is returned but `session` is null. - If **Confirm email** is disabled, both a `user` and a `session` are returned. - When the user confirms their email address, they are redirected to the [`SITE_URL`](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) by default. You can modify your `SITE_URL` or add additional redirect URLs in [your project](/dashboard/project/_/auth/url-configuration). - If signUp() is called for an existing confirmed user: - When both **Confirm email** and **Confirm phone** (even when phone provider is disabled) are enabled in [your project](/dashboard/project/_/auth/providers), an obfuscated/fake user object is returned. - When either **Confirm email** or **Confirm phone** (even when phone provider is disabled) is disabled, the error message, `User already registered` is returned. - To fetch the currently logged-in user, refer to [`getUser()`](/docs/reference/javascript/auth-getuser)." - ], - "parameters": [ - { - "name": "credentials", - "type": { - "kind": "conditional" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "AuthSession", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Sign up with an email and password", - "code": "const { data, error } = await supabase.auth.signUp({\n email: 'example@email.com',\n password: 'example-password',\n})", - "response": "// Some fields may be null if \"confirm email\" is enabled.\n{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n }\n }\n },\n \"error\": null\n}", - "notes": "Sign up with a phone number and password (whatsapp)\nThe user will be sent a WhatsApp message which contains a OTP. By default, a given user can only request a OTP once every 60 seconds. Note that a user will need to have a valid WhatsApp account that is linked to Twilio in order to use this feature." - }, - { - "title": "Sign up with a phone number and password (SMS)", - "code": "const { data, error } = await supabase.auth.signUp({\n phone: '123456789',\n password: 'example-password',\n options: {\n channel: 'sms'\n }\n})", - "notes": "Sign up with a redirect URL\n- See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project." - }, - { - "title": "Sign up with a phone number and password (whatsapp)", - "code": "const { data, error } = await supabase.auth.signUp({\n phone: '123456789',\n password: 'example-password',\n options: {\n channel: 'whatsapp'\n }\n})", - "notes": "The user will be sent a WhatsApp message which contains a OTP. By default, a given user can only request a OTP once every 60 seconds. Note that a user will need to have a valid WhatsApp account that is linked to Twilio in order to use this feature." - }, - { - "title": "Sign up with additional user metadata", - "code": "const { data, error } = await supabase.auth.signUp(\n {\n email: 'example@email.com',\n password: 'example-password',\n options: {\n data: {\n first_name: 'John',\n age: 27,\n }\n }\n }\n)" - }, - { - "title": "Sign up with a redirect URL", - "code": "const { data, error } = await supabase.auth.signUp(\n {\n email: 'example@email.com',\n password: 'example-password',\n options: {\n emailRedirectTo: 'https://example.com/welcome'\n }\n }\n)", - "notes": "- See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project." - } - ] - }, - { - "name": "startAutoRefresh", - "description": "Starts an auto-refresh process in the background. The session is checked every few seconds. Close to the time of expiration a process is started to refresh the session. If refreshing fails it will be retried for as long as necessary.\nIf you set the GoTrueClientOptions#autoRefreshToken you don't need to call this function, it will be called for you.\nOn browsers the refresh process works only when the tab/window is in the foreground to conserve resources as well as prevent race conditions and flooding auth with requests. If you call this method any managed visibility change callback will be removed and you must manage visibility changes on your own.\nOn non-browser platforms the refresh process works *continuously* in the background, which may not be desirable. You should hook into your platform's foreground indication mechanism and call these methods appropriately to conserve resources.\n#stopAutoRefresh", - "remarks": [ - "- Only useful in non-browser environments such as React Native or Electron. - The Supabase Auth library automatically starts and stops proactively refreshing the session when a tab is focused or not. - On non-browser platforms, such as mobile or desktop apps built with web technologies, the library is not able to effectively determine whether the application is _focused_ or not. - To give this hint to the application, you should be calling this method when the app is in focus and calling `supabase.auth.stopAutoRefresh()` when it's out of focus." - ], - "parameters": [], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": ["void"] - }, - "examples": [ - { - "title": "Start and stop auto refresh in React Native", - "code": "import { AppState } from 'react-native'\n\n// make sure you register this only once!\nAppState.addEventListener('change', (state) => {\n if (state === 'active') {\n supabase.auth.startAutoRefresh()\n } else {\n supabase.auth.stopAutoRefresh()\n }\n})" - } - ] - }, - { - "name": "stopAutoRefresh", - "description": "Stops an active auto refresh process running in the background (if any).\nIf you call this method any managed visibility change callback will be removed and you must manage visibility changes on your own.\nSee #startAutoRefresh for more details.", - "remarks": [ - "- Only useful in non-browser environments such as React Native or Electron. - The Supabase Auth library automatically starts and stops proactively refreshing the session when a tab is focused or not. - On non-browser platforms, such as mobile or desktop apps built with web technologies, the library is not able to effectively determine whether the application is _focused_ or not. - When your application goes in the background or out of focus, call this method to stop the proactive refreshing of the session." - ], - "parameters": [], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": ["void"] - }, - "examples": [ - { - "title": "Start and stop auto refresh in React Native", - "code": "import { AppState } from 'react-native'\n\n// make sure you register this only once!\nAppState.addEventListener('change', (state) => {\n if (state === 'active') {\n supabase.auth.startAutoRefresh()\n } else {\n supabase.auth.stopAutoRefresh()\n }\n})" - } - ] - }, - { - "name": "unlinkIdentity", - "description": "Unlinks an identity from a user by deleting it. The user will no longer be able to sign in with that identity once it's unlinked.", - "remarks": [ - "- The **Enable Manual Linking** option must be enabled from your [project's authentication settings](/dashboard/project/_/auth/providers). - The user needs to be signed in to call `unlinkIdentity()`. - The user must have at least 2 identities in order to unlink an identity. - The identity to be unlinked must belong to the user." - ], - "parameters": [ - { - "name": "identity", - "type": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Unlink an identity", - "code": "// retrieve all identities linked to a user\nconst identities = await supabase.auth.getUserIdentities()\n\n// find the google identity\nconst googleIdentity = identities.find(\n identity => identity.provider === 'google'\n)\n\n// unlink the google identity\nconst { error } = await supabase.auth.unlinkIdentity(googleIdentity)" - } - ] - }, - { - "name": "updateUser", - "description": "Updates user data for a logged in user.", - "remarks": [ - "- In order to use the `updateUser()` method, the user needs to be signed in first. - By default, email updates sends a confirmation link to both the user's current and new email. To only send a confirmation link to the user's new email, disable **Secure email change** in your project's [email auth provider settings](/dashboard/project/_/auth/providers)." - ], - "parameters": [ - { - "name": "attributes", - "type": { - "kind": "object", - "name": "UserAttributes", - "properties": [ - { - "name": "current_password", - "optional": true, - "description": "The user's current password\nThis is only ever present when the user is resetting their password and GOTRUE_SECURITY_UPDATE_PASSWORD_REQUIRE_CURRENT_PASSWORD is true.", - "type": "string" - }, - { - "name": "data", - "optional": true, - "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", - "type": "object" - }, - { - "name": "email", - "optional": true, - "description": "The user's email.", - "type": "string" - }, - { - "name": "nonce", - "optional": true, - "description": "The nonce sent for reauthentication if the user's password is to be updated.\nCall reauthenticate() to obtain the nonce first.", - "type": "string" - }, - { - "name": "password", - "optional": true, - "description": "The user's password.", - "type": "string" - }, - { - "name": "phone", - "optional": true, - "description": "The user's phone.", - "type": "string" - } - ] - } - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "emailRedirectTo", - "optional": true, - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "user", - "optional": false, - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Update the email for an authenticated user", - "code": "const { data, error } = await supabase.auth.updateUser({\n email: 'new@email.com'\n})", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"new_email\": \"new@email.com\",\n \"email_change_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}", - "notes": "Sends a \"Confirm Email Change\" email to the new address. If **Secure Email Change** is enabled (default), confirmation is also required from the **old email** before the change is applied. To skip dual confirmation and apply the change after only the new email is verified, disable **Secure Email Change** in the [Email Auth Provider settings](/dashboard/project/_/auth/providers?provider=Email)." - }, - { - "title": "Update the phone number for an authenticated user", - "code": "const { data, error } = await supabase.auth.updateUser({\n phone: '123456789'\n})", - "notes": "Sends a one-time password (OTP) to the new phone number." - }, - { - "title": "Update the password for an authenticated user", - "code": "const { data, error } = await supabase.auth.updateUser({\n password: 'new password'\n})", - "notes": "Update the user's metadata\nUpdates the user's custom metadata.\n\n**Note**: The `data` field maps to the `auth.users.raw_user_meta_data` column in your Supabase database. When calling `getUser()`, the data will be available as `user.user_metadata`." - }, - { - "title": "Update the user's metadata", - "code": "const { data, error } = await supabase.auth.updateUser({\n data: { hello: 'world' }\n})", - "notes": "Updates the user's custom metadata.\n\n**Note**: The `data` field maps to the `auth.users.raw_user_meta_data` column in your Supabase database. When calling `getUser()`, the data will be available as `user.user_metadata`." - }, - { - "title": "Update the user's password with a nonce", - "code": "const { data, error } = await supabase.auth.updateUser({\n password: 'new password',\n nonce: '123456'\n})", - "notes": "If **Secure password change** is enabled in your [project's email provider settings](/dashboard/project/_/auth/providers), updating the user's password would require a nonce if the user **hasn't recently signed in**. The nonce is sent to the user's email or phone number. A user is deemed recently signed in if the session was created in the last 24 hours." - } - ] - }, - { - "name": "verifyOtp", - "description": "Log in a user given a User supplied OTP or TokenHash received through mobile or email.", - "remarks": [ - "- The `verifyOtp` method takes in different verification types. - If a phone number is used, the type can either be: 1. `sms` – Used when verifying a one-time password (OTP) sent via SMS during sign-up or sign-in. 2. `phone_change` – Used when verifying an OTP sent to a new phone number during a phone number update process. - If an email address is used, the type can be one of the following (note: `signup` and `magiclink` types are deprecated): 1. `email` – Used when verifying an OTP sent to the user's email during sign-up or sign-in. 2. `recovery` – Used when verifying an OTP sent for account recovery, typically after a password reset request. 3. `invite` – Used when verifying an OTP sent as part of an invitation to join a project or organization. 4. `email_change` – Used when verifying an OTP sent to a new email address during an email update process. - The verification type used should be determined based on the corresponding auth method called before `verifyOtp` to sign up / sign-in a user. - The `TokenHash` is contained in the [email templates](/docs/guides/auth/auth-email-templates) and can be used to sign in. You may wish to use the hash for the PKCE flow for Server Side Auth. Read [the Password-based Auth guide](/docs/guides/auth/passwords) for more details." - ], - "parameters": [ - { - "name": "params", - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "VerifyMobileOtpParams", - "properties": [ - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "redirectTo", - "optional": true, - "description": "A URL to send the user to after they are confirmed.", - "type": "string" - } - ] - } - }, - { - "name": "phone", - "optional": false, - "description": "The user's phone number.", - "type": "string" - }, - { - "name": "token", - "optional": false, - "description": "The otp sent to the user's phone number.", - "type": "string" - }, - { - "name": "type", - "optional": false, - "description": "The user's verification type.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "sms" - }, - { - "kind": "literal", - "value": "phone_change" - } - ] - } - } - ] - }, - { - "kind": "object", - "name": "VerifyEmailOtpParams", - "properties": [ - { - "name": "email", - "optional": false, - "description": "The user's email address.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "captchaToken", - "optional": true, - "description": "Verification token received when the user completes the captcha on the site.", - "type": "string" - }, - { - "name": "redirectTo", - "optional": true, - "description": "A URL to send the user to after they are confirmed.", - "type": "string" - } - ] - } - }, - { - "name": "token", - "optional": false, - "description": "The otp sent to the user's email address.", - "type": "string" - }, - { - "name": "type", - "optional": false, - "description": "The user's verification type.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "signup" - }, - { - "kind": "literal", - "value": "invite" - }, - { - "kind": "literal", - "value": "magiclink" - }, - { - "kind": "literal", - "value": "recovery" - }, - { - "kind": "literal", - "value": "email_change" - }, - { - "kind": "literal", - "value": "email" - } - ] - } - } - ] - }, - { - "kind": "object", - "name": "VerifyTokenHashParams", - "properties": [ - { - "name": "token_hash", - "optional": false, - "description": "The token hash used in an email link", - "type": "string" - }, - { - "name": "type", - "optional": false, - "description": "The user's verification type.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "signup" - }, - { - "kind": "literal", - "value": "invite" - }, - { - "kind": "literal", - "value": "magiclink" - }, - { - "kind": "literal", - "value": "recovery" - }, - { - "kind": "literal", - "value": "email_change" - }, - { - "kind": "literal", - "value": "email" - } - ] - } - } - ] - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "session", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "AuthSession", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", - "type": "string" - }, - { - "name": "expires_at", - "optional": true, - "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "expires_in", - "optional": false, - "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", - "type": "number" - }, - { - "name": "provider_refresh_token", - "optional": true, - "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "provider_token", - "optional": true, - "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "refresh_token", - "optional": false, - "description": "A one-time used refresh token that never expires.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "When using a separate user storage, accessing properties of this object will throw an error.", - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "user", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Verify Signup One-Time Password (OTP)", - "code": "const { data, error } = await supabase.auth.verifyOtp({ email, token, type: 'email'})", - "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"recovery_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"recovery_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n }\n },\n \"error\": null\n}" - }, - { - "title": "Verify SMS One-Time Password (OTP)", - "code": "const { data, error } = await supabase.auth.verifyOtp({ phone, token, type: 'sms'})" - }, - { - "title": "Verify Email Auth (Token Hash)", - "code": "const { data, error } = await supabase.auth.verifyOtp({ token_hash: tokenHash, type: 'email'})" - } - ] - }, - { - "name": "approveAuthorization", - "description": "Approves an OAuth authorization request. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nAfter approval, the user's consent is stored and an authorization code is generated. The response contains a complete redirect URL with the authorization code and state.", - "parameters": [ - { - "name": "authorizationId", - "description": "The authorization ID to approve", - "type": "string" - }, - { - "name": "options", - "optional": true, - "description": "Optional parameters", - "type": { - "kind": "object", - "properties": [ - { - "name": "skipBrowserRedirect", - "optional": true, - "description": "If false (default), automatically redirects the browser to the OAuth client. If true, returns the redirect_url without automatic redirect (useful for custom handling).", - "type": "boolean" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "redirect_url", - "optional": false, - "description": "Complete redirect URL with authorization code and state parameters (e.g., \"https://app.com/callback?code=xxx&state=yyy\")", - "type": "string" - } - ], - "name": "OAuthRedirect" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "denyAuthorization", - "description": "Denies an OAuth authorization request. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nAfter denial, the response contains a redirect URL with an OAuth error (access_denied) to inform the OAuth client that the user rejected the request.", - "parameters": [ - { - "name": "authorizationId", - "description": "The authorization ID to deny", - "type": "string" - }, - { - "name": "options", - "optional": true, - "description": "Optional parameters", - "type": { - "kind": "object", - "properties": [ - { - "name": "skipBrowserRedirect", - "optional": true, - "description": "If false (default), automatically redirects the browser to the OAuth client. If true, returns the redirect_url without automatic redirect (useful for custom handling).", - "type": "boolean" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "redirect_url", - "optional": false, - "description": "Complete redirect URL with authorization code and state parameters (e.g., \"https://app.com/callback?code=xxx&state=yyy\")", - "type": "string" - } - ], - "name": "OAuthRedirect" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "getAuthorizationDetails", - "description": "Retrieves details about an OAuth authorization request. Used to display consent information to the user. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis method returns one of two response types: - `OAuthAuthorizationDetails`: User needs to consent - show consent page with client info - `OAuthRedirect`: User already consented - redirect immediately to the OAuth client\nUse type narrowing to distinguish between the responses: ```typescript if ('authorization_id' in data) { // Show consent page } else { // Redirect to data.redirect_url } ```", - "parameters": [ - { - "name": "authorizationId", - "description": "The authorization ID from the authorization request", - "type": "string" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "authorization_id", - "optional": false, - "description": "The authorization ID used to approve or deny the request", - "type": "string" - }, - { - "name": "client", - "optional": false, - "description": "OAuth client requesting authorization", - "type": { - "kind": "object", - "properties": [ - { - "name": "id", - "optional": false, - "description": "Unique identifier for the OAuth client (UUID)", - "type": "string" - }, - { - "name": "logo_uri", - "optional": false, - "description": "URI of the OAuth client's logo", - "type": "string" - }, - { - "name": "name", - "optional": false, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "uri", - "optional": false, - "description": "URI of the OAuth client's website", - "type": "string" - } - ], - "name": "OAuthAuthorizationClient" - } - }, - { - "name": "redirect_uri", - "optional": false, - "description": "The OAuth client's registered redirect URI (base URI without query parameters)", - "type": "string" - }, - { - "name": "scope", - "optional": false, - "description": "Space-separated list of requested scopes (e.g., \"openid profile email\")", - "type": "string" - }, - { - "name": "user", - "optional": false, - "description": "User object associated with the authorization", - "type": { - "kind": "object", - "properties": [ - { - "name": "email", - "optional": false, - "description": "User email", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "User ID (UUID)", - "type": "string" - } - ] - } - } - ], - "name": "OAuthAuthorizationDetails" - }, - { - "kind": "object", - "properties": [ - { - "name": "redirect_url", - "optional": false, - "description": "Complete redirect URL with authorization code and state parameters (e.g., \"https://app.com/callback?code=xxx&state=yyy\")", - "type": "string" - } - ], - "name": "OAuthRedirect" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "listGrants", - "description": "Lists all OAuth grants that the authenticated user has authorized. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.", - "parameters": [], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "properties": [ - { - "name": "client", - "optional": false, - "description": "OAuth client information", - "type": { - "kind": "object", - "properties": [ - { - "name": "id", - "optional": false, - "description": "Unique identifier for the OAuth client (UUID)", - "type": "string" - }, - { - "name": "logo_uri", - "optional": false, - "description": "URI of the OAuth client's logo", - "type": "string" - }, - { - "name": "name", - "optional": false, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "uri", - "optional": false, - "description": "URI of the OAuth client's website", - "type": "string" - } - ], - "name": "OAuthAuthorizationClient" - } - }, - { - "name": "granted_at", - "optional": false, - "description": "Timestamp when the grant was created (ISO 8601 date-time)", - "type": "string" - }, - { - "name": "scopes", - "optional": false, - "description": "Array of scopes granted to this client", - "type": { - "kind": "array", - "elementType": "string" - } - } - ], - "name": "OAuthGrant" - } - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "revokeGrant", - "description": "Revokes a user's OAuth grant for a specific client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nRevocation marks consent as revoked, deletes active sessions for that OAuth client, and invalidates associated refresh tokens.", - "parameters": [ - { - "name": "options", - "description": "Revocation options", - "type": { - "kind": "object", - "properties": [ - { - "name": "clientId", - "optional": false, - "description": "The OAuth client identifier (UUID) to revoke access for", - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "deleteFactor", - "description": "Deletes a factor on a user. This will log the user out of all active sessions if the deleted factor was verified.", - "parameters": [ - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "id", - "optional": false, - "description": "ID of the MFA factor to delete.", - "type": "string" - }, - { - "name": "userId", - "optional": false, - "description": "ID of the user whose factor is being deleted.", - "type": "string" - } - ], - "name": "AuthMFAAdminDeleteFactorParams" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "id", - "optional": false, - "description": "ID of the factor that was successfully deleted.", - "type": "string" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Delete a factor for a user", - "code": "const { data, error } = await supabase.auth.admin.mfa.deleteFactor({\n id: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n userId: 'a89baba7-b1b7-440f-b4bb-91026967f66b',\n})", - "response": "{\n data: {\n id: '34e770dd-9ff9-416c-87fa-43b31d7ef225'\n },\n error: null\n}" - } - ] - }, - { - "name": "listFactors", - "description": "Lists all factors associated to a user.", - "parameters": [ - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "userId", - "optional": false, - "description": "ID of the user.", - "type": "string" - } - ], - "name": "AuthMFAAdminListFactorsParams" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "factors", - "optional": false, - "description": "All factors attached to the user.", - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "typeParam", - "name": "Type" - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "typeParam", - "name": "Status" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "List all factors for a user", - "code": "const { data, error } = await supabase.auth.admin.mfa.listFactors()", - "response": "{\n data: {\n factors: Factor[\n {\n id: '',\n friendly_name: 'Auth App Factor',\n factor_type: 'totp',\n status: 'verified',\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z'\n }\n ]\n },\n error: null\n}" - } - ] - }, - { - "name": "createClient", - "description": "Creates a new OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "parameters": [ - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "client_name", - "optional": false, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "client_uri", - "optional": true, - "description": "URI of the OAuth client", - "type": "string" - }, - { - "name": "grant_types", - "optional": true, - "description": "Array of allowed grant types (optional, defaults to authorization_code and refresh_token)", - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "authorization_code" - }, - { - "kind": "literal", - "value": "refresh_token" - } - ] - } - } - }, - { - "name": "redirect_uris", - "optional": false, - "description": "Array of allowed redirect URIs", - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "response_types", - "optional": true, - "description": "Array of allowed response types (optional, defaults to code)", - "type": { - "kind": "array", - "elementType": { - "kind": "literal", - "value": "code" - } - } - }, - { - "name": "scope", - "optional": true, - "description": "Scope of the OAuth client", - "type": "string" - }, - { - "name": "token_endpoint_auth_method", - "optional": true, - "description": "Token endpoint authentication method (defaults to server default if not specified)", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "none" - }, - { - "kind": "literal", - "value": "client_secret_basic" - }, - { - "kind": "literal", - "value": "client_secret_post" - } - ] - } - } - ], - "name": "CreateOAuthClientParams" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "client_id", - "optional": false, - "description": "Unique identifier for the OAuth client", - "type": "string" - }, - { - "name": "client_name", - "optional": false, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "client_secret", - "optional": true, - "description": "Client secret (only returned on registration and regeneration)", - "type": "string" - }, - { - "name": "client_type", - "optional": false, - "description": "Type of OAuth client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "public" - }, - { - "kind": "literal", - "value": "confidential" - } - ] - } - }, - { - "name": "client_uri", - "optional": true, - "description": "URI of the OAuth client", - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "description": "Timestamp when the client was created", - "type": "string" - }, - { - "name": "grant_types", - "optional": false, - "description": "Array of allowed grant types", - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "authorization_code" - }, - { - "kind": "literal", - "value": "refresh_token" - } - ] - } - } - }, - { - "name": "logo_uri", - "optional": true, - "description": "URI of the OAuth client's logo", - "type": "string" - }, - { - "name": "redirect_uris", - "optional": false, - "description": "Array of allowed redirect URIs", - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "registration_type", - "optional": false, - "description": "Registration type of the client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "dynamic" - }, - { - "kind": "literal", - "value": "manual" - } - ] - } - }, - { - "name": "response_types", - "optional": false, - "description": "Array of allowed response types", - "type": { - "kind": "array", - "elementType": { - "kind": "literal", - "value": "code" - } - } - }, - { - "name": "scope", - "optional": true, - "description": "Scope of the OAuth client", - "type": "string" - }, - { - "name": "token_endpoint_auth_method", - "optional": false, - "description": "Token endpoint authentication method", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "none" - }, - { - "kind": "literal", - "value": "client_secret_basic" - }, - { - "kind": "literal", - "value": "client_secret_post" - } - ] - } - }, - { - "name": "updated_at", - "optional": false, - "description": "Timestamp when the client was last updated", - "type": "string" - } - ], - "name": "OAuthClient" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "deleteClient", - "description": "Deletes an OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "parameters": [ - { - "name": "clientId", - "type": "string" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - ] - } - } - ] - } - ] - } - }, - { - "name": "getClient", - "description": "Gets details of a specific OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "parameters": [ - { - "name": "clientId", - "type": "string" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "client_id", - "optional": false, - "description": "Unique identifier for the OAuth client", - "type": "string" - }, - { - "name": "client_name", - "optional": false, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "client_secret", - "optional": true, - "description": "Client secret (only returned on registration and regeneration)", - "type": "string" - }, - { - "name": "client_type", - "optional": false, - "description": "Type of OAuth client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "public" - }, - { - "kind": "literal", - "value": "confidential" - } - ] - } - }, - { - "name": "client_uri", - "optional": true, - "description": "URI of the OAuth client", - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "description": "Timestamp when the client was created", - "type": "string" - }, - { - "name": "grant_types", - "optional": false, - "description": "Array of allowed grant types", - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "authorization_code" - }, - { - "kind": "literal", - "value": "refresh_token" - } - ] - } - } - }, - { - "name": "logo_uri", - "optional": true, - "description": "URI of the OAuth client's logo", - "type": "string" - }, - { - "name": "redirect_uris", - "optional": false, - "description": "Array of allowed redirect URIs", - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "registration_type", - "optional": false, - "description": "Registration type of the client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "dynamic" - }, - { - "kind": "literal", - "value": "manual" - } - ] - } - }, - { - "name": "response_types", - "optional": false, - "description": "Array of allowed response types", - "type": { - "kind": "array", - "elementType": { - "kind": "literal", - "value": "code" - } - } - }, - { - "name": "scope", - "optional": true, - "description": "Scope of the OAuth client", - "type": "string" - }, - { - "name": "token_endpoint_auth_method", - "optional": false, - "description": "Token endpoint authentication method", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "none" - }, - { - "kind": "literal", - "value": "client_secret_basic" - }, - { - "kind": "literal", - "value": "client_secret_post" - } - ] - } - }, - { - "name": "updated_at", - "optional": false, - "description": "Timestamp when the client was last updated", - "type": "string" - } - ], - "name": "OAuthClient" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "listClients", - "description": "Lists all OAuth clients with optional pagination. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "parameters": [ - { - "name": "params", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "page", - "optional": true, - "description": "The page number", - "type": "number" - }, - { - "name": "perPage", - "optional": true, - "description": "Number of items returned per page", - "type": "number" - } - ], - "name": "PageParams" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "intersection", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "clients", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "properties": [ - { - "name": "client_id", - "optional": false, - "description": "Unique identifier for the OAuth client", - "type": "string" - }, - { - "name": "client_name", - "optional": false, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "client_secret", - "optional": true, - "description": "Client secret (only returned on registration and regeneration)", - "type": "string" - }, - { - "name": "client_type", - "optional": false, - "description": "Type of OAuth client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "public" - }, - { - "kind": "literal", - "value": "confidential" - } - ] - } - }, - { - "name": "client_uri", - "optional": true, - "description": "URI of the OAuth client", - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "description": "Timestamp when the client was created", - "type": "string" - }, - { - "name": "grant_types", - "optional": false, - "description": "Array of allowed grant types", - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "authorization_code" - }, - { - "kind": "literal", - "value": "refresh_token" - } - ] - } - } - }, - { - "name": "logo_uri", - "optional": true, - "description": "URI of the OAuth client's logo", - "type": "string" - }, - { - "name": "redirect_uris", - "optional": false, - "description": "Array of allowed redirect URIs", - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "registration_type", - "optional": false, - "description": "Registration type of the client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "dynamic" - }, - { - "kind": "literal", - "value": "manual" - } - ] - } - }, - { - "name": "response_types", - "optional": false, - "description": "Array of allowed response types", - "type": { - "kind": "array", - "elementType": { - "kind": "literal", - "value": "code" - } - } - }, - { - "name": "scope", - "optional": true, - "description": "Scope of the OAuth client", - "type": "string" - }, - { - "name": "token_endpoint_auth_method", - "optional": false, - "description": "Token endpoint authentication method", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "none" - }, - { - "kind": "literal", - "value": "client_secret_basic" - }, - { - "kind": "literal", - "value": "client_secret_post" - } - ] - } - }, - { - "name": "updated_at", - "optional": false, - "description": "Timestamp when the client was last updated", - "type": "string" - } - ], - "name": "OAuthClient" - } - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "lastPage", - "optional": false, - "type": "number" - }, - { - "name": "nextPage", - "optional": false, - "type": { - "kind": "union", - "types": [ - "number", - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "total", - "optional": false, - "type": "number" - } - ], - "name": "Pagination" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "clients", - "optional": false, - "type": { - "kind": "tuple", - "elements": [] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - } - ] - } - ] - } - }, - { - "name": "regenerateClientSecret", - "description": "Regenerates the secret for an OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "parameters": [ - { - "name": "clientId", - "type": "string" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "client_id", - "optional": false, - "description": "Unique identifier for the OAuth client", - "type": "string" - }, - { - "name": "client_name", - "optional": false, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "client_secret", - "optional": true, - "description": "Client secret (only returned on registration and regeneration)", - "type": "string" - }, - { - "name": "client_type", - "optional": false, - "description": "Type of OAuth client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "public" - }, - { - "kind": "literal", - "value": "confidential" - } - ] - } - }, - { - "name": "client_uri", - "optional": true, - "description": "URI of the OAuth client", - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "description": "Timestamp when the client was created", - "type": "string" - }, - { - "name": "grant_types", - "optional": false, - "description": "Array of allowed grant types", - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "authorization_code" - }, - { - "kind": "literal", - "value": "refresh_token" - } - ] - } - } - }, - { - "name": "logo_uri", - "optional": true, - "description": "URI of the OAuth client's logo", - "type": "string" - }, - { - "name": "redirect_uris", - "optional": false, - "description": "Array of allowed redirect URIs", - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "registration_type", - "optional": false, - "description": "Registration type of the client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "dynamic" - }, - { - "kind": "literal", - "value": "manual" - } - ] - } - }, - { - "name": "response_types", - "optional": false, - "description": "Array of allowed response types", - "type": { - "kind": "array", - "elementType": { - "kind": "literal", - "value": "code" - } - } - }, - { - "name": "scope", - "optional": true, - "description": "Scope of the OAuth client", - "type": "string" - }, - { - "name": "token_endpoint_auth_method", - "optional": false, - "description": "Token endpoint authentication method", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "none" - }, - { - "kind": "literal", - "value": "client_secret_basic" - }, - { - "kind": "literal", - "value": "client_secret_post" - } - ] - } - }, - { - "name": "updated_at", - "optional": false, - "description": "Timestamp when the client was last updated", - "type": "string" - } - ], - "name": "OAuthClient" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "updateClient", - "description": "Updates an existing OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", - "parameters": [ - { - "name": "clientId", - "type": "string" - }, - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "client_name", - "optional": true, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "client_uri", - "optional": true, - "description": "URI of the OAuth client", - "type": "string" - }, - { - "name": "grant_types", - "optional": true, - "description": "Array of allowed grant types", - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "authorization_code" - }, - { - "kind": "literal", - "value": "refresh_token" - } - ] - } - } - }, - { - "name": "logo_uri", - "optional": true, - "description": "URI of the OAuth client's logo", - "type": "string" - }, - { - "name": "redirect_uris", - "optional": true, - "description": "Array of allowed redirect URIs", - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "token_endpoint_auth_method", - "optional": true, - "description": "Token endpoint authentication method", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "none" - }, - { - "kind": "literal", - "value": "client_secret_basic" - }, - { - "kind": "literal", - "value": "client_secret_post" - } - ] - } - } - ], - "name": "UpdateOAuthClientParams" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "client_id", - "optional": false, - "description": "Unique identifier for the OAuth client", - "type": "string" - }, - { - "name": "client_name", - "optional": false, - "description": "Human-readable name of the OAuth client", - "type": "string" - }, - { - "name": "client_secret", - "optional": true, - "description": "Client secret (only returned on registration and regeneration)", - "type": "string" - }, - { - "name": "client_type", - "optional": false, - "description": "Type of OAuth client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "public" - }, - { - "kind": "literal", - "value": "confidential" - } - ] - } - }, - { - "name": "client_uri", - "optional": true, - "description": "URI of the OAuth client", - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "description": "Timestamp when the client was created", - "type": "string" - }, - { - "name": "grant_types", - "optional": false, - "description": "Array of allowed grant types", - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "authorization_code" - }, - { - "kind": "literal", - "value": "refresh_token" - } - ] - } - } - }, - { - "name": "logo_uri", - "optional": true, - "description": "URI of the OAuth client's logo", - "type": "string" - }, - { - "name": "redirect_uris", - "optional": false, - "description": "Array of allowed redirect URIs", - "type": { - "kind": "array", - "elementType": "string" - } - }, - { - "name": "registration_type", - "optional": false, - "description": "Registration type of the client", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "dynamic" - }, - { - "kind": "literal", - "value": "manual" - } - ] - } - }, - { - "name": "response_types", - "optional": false, - "description": "Array of allowed response types", - "type": { - "kind": "array", - "elementType": { - "kind": "literal", - "value": "code" - } - } - }, - { - "name": "scope", - "optional": true, - "description": "Scope of the OAuth client", - "type": "string" - }, - { - "name": "token_endpoint_auth_method", - "optional": false, - "description": "Token endpoint authentication method", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "none" - }, - { - "kind": "literal", - "value": "client_secret_basic" - }, - { - "kind": "literal", - "value": "client_secret_post" - } - ] - } - }, - { - "name": "updated_at", - "optional": false, - "description": "Timestamp when the client was last updated", - "type": "string" - } - ], - "name": "OAuthClient" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "challenge", - "description": "Prepares a challenge used to verify that a user has access to a MFA factor.", - "remarks": [ - "- An [enrolled factor](/docs/reference/javascript/auth-mfa-enroll) is required before creating a challenge. - To verify a challenge, see [`mfa.verify()`](/docs/reference/javascript/auth-mfa-verify). - A phone factor sends a code to the user upon challenge. The channel defaults to `sms` unless otherwise specified." - ], - "parameters": [ - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "factorId", - "optional": false, - "description": "ID of the factor to be challenged. Returned in enroll().", - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "object", - "name": "AuthError", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "__isAuthError", - "optional": false, - "type": "boolean" - }, - { - "name": "code", - "optional": false, - "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "reference", - "name": "ErrorCode" - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "status", - "optional": false, - "description": "HTTP status code that caused the error.", - "type": { - "kind": "union", - "types": ["undefined", "number"] - } - } - ] - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "expires_at", - "optional": false, - "description": "Timestamp in UNIX seconds when this challenge will no longer be usable.", - "type": "number" - }, - { - "name": "id", - "optional": false, - "description": "ID of the newly created challenge.", - "type": "string" - }, - { - "name": "type", - "optional": false, - "description": "Factor Type which generated the challenge", - "type": { - "kind": "literal", - "value": "totp" - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Create a challenge for a factor", - "code": "const { data, error } = await supabase.auth.mfa.challenge({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225'\n})", - "response": "{\n data: {\n id: '',\n type: 'totp',\n expires_at: 1700000000\n },\n error: null\n}" - }, - { - "title": "Create a challenge for a phone factor", - "code": "const { data, error } = await supabase.auth.mfa.challenge({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n})", - "response": "{\n data: {\n id: '',\n type: 'phone',\n expires_at: 1700000000\n },\n error: null\n}" - }, - { - "title": "Create a challenge for a phone factor (WhatsApp)", - "code": "const { data, error } = await supabase.auth.mfa.challenge({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n channel: 'whatsapp',\n})", - "response": "{\n data: {\n id: '',\n expires_at: 1700000000\n },\n error: null\n}" - } - ] - }, - { - "name": "challengeAndVerify", - "description": "Helper method which creates a challenge and immediately uses the given code to verify against it thereafter. The verification code is provided by the user by entering a code seen in their authenticator app.", - "remarks": [ - "- Intended for use with only TOTP factors. - An [enrolled factor](/docs/reference/javascript/auth-mfa-enroll) is required before invoking `challengeAndVerify()`. - Executes [`mfa.challenge()`](/docs/reference/javascript/auth-mfa-challenge) and [`mfa.verify()`](/docs/reference/javascript/auth-mfa-verify) in a single step." - ], - "parameters": [ - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "code", - "optional": false, - "description": "Verification code provided by the user.", - "type": "string" - }, - { - "name": "factorId", - "optional": false, - "description": "ID of the factor being verified. Returned in enroll().", - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "New access token (JWT) after successful verification.", - "type": "string" - }, - { - "name": "expires_in", - "optional": false, - "description": "Number of seconds in which the access token will expire.", - "type": "number" - }, - { - "name": "refresh_token", - "optional": false, - "description": "Refresh token you can use to obtain new access tokens when expired.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "description": "Type of token, always `bearer`.", - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "Updated user profile.", - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ], - "name": "AuthMFAVerifyResponseData" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Create and verify a challenge for a factor", - "code": "const { data, error } = await supabase.auth.mfa.challengeAndVerify({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n code: '123456'\n})", - "response": "{\n data: {\n access_token: '',\n token_type: 'Bearer',\n expires_in: 3600,\n refresh_token: '',\n user: {\n id: '11111111-1111-1111-1111-111111111111',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {\n provider: 'email',\n providers: [\n \"email\",\n ]\n },\n user_metadata: {},\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false,\n factors: [\n \"id\": '',\n \"friendly_name\": 'Important Auth App',\n \"factor_type\": 'totp',\n \"status\": 'verified',\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n ]\n }\n }\n error: null\n}" - } - ] - }, - { - "name": "enroll", - "description": "Starts the enrollment process for a new Multi-Factor Authentication (MFA) factor. This method creates a new `unverified` factor. To verify a factor, present the QR code or secret to the user and ask them to add it to their authenticator app. The user has to enter the code from their authenticator app to verify it.\nUpon verifying a factor, all other sessions are logged out and the current session's authenticator level is promoted to `aal2`.", - "remarks": [ - "- Use `totp` or `phone` as the `factorType` and use the returned `id` to create a challenge. - To create a challenge, see [`mfa.challenge()`](/docs/reference/javascript/auth-mfa-challenge). - To verify a challenge, see [`mfa.verify()`](/docs/reference/javascript/auth-mfa-verify). - To create and verify a TOTP challenge in a single step, see [`mfa.challengeAndVerify()`](/docs/reference/javascript/auth-mfa-challengeandverify). - To generate a QR code for the `totp` secret in Next.js, you can do the following: ```html {data.totp.uri} ``` - The `challenge` and `verify` steps are separated when using Phone factors as the user will need time to receive and input the code obtained from the SMS in challenge." - ], - "parameters": [ - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "factorType", - "optional": false, - "description": "The type of factor being enrolled.", - "type": { - "kind": "literal", - "value": "totp" - } - }, - { - "name": "friendlyName", - "optional": true, - "description": "Human readable name assigned to the factor.", - "type": "string" - }, - { - "name": "issuer", - "optional": true, - "description": "Domain which the user is enrolled with.", - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "conditional" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Enroll a time-based, one-time password (TOTP) factor", - "code": "const { data, error } = await supabase.auth.mfa.enroll({\n factorType: 'totp',\n friendlyName: 'your_friendly_name'\n})\n\n// Use the id to create a challenge.\n// The challenge can be verified by entering the code generated from the authenticator app.\n// The code will be generated upon scanning the qr_code or entering the secret into the authenticator app.\nconst { id, type, totp: { qr_code, secret, uri }, friendly_name } = data\nconst challenge = await supabase.auth.mfa.challenge({ factorId: id });", - "response": "{\n data: {\n id: '',\n type: 'totp'\n totp: {\n qr_code: '',\n secret: '',\n uri: '',\n }\n friendly_name?: 'Important app'\n },\n error: null\n}" - }, - { - "title": "Enroll a Phone Factor", - "code": "const { data, error } = await supabase.auth.mfa.enroll({\n factorType: 'phone',\n friendlyName: 'your_friendly_name',\n phone: '+12345678',\n})\n\n// Use the id to create a challenge and send an SMS with a code to the user.\nconst { id, type, friendly_name, phone } = data\n\nconst challenge = await supabase.auth.mfa.challenge({ factorId: id });", - "response": "{\n data: {\n id: '',\n type: 'phone',\n friendly_name?: 'Important app',\n phone: '+5787123456'\n },\n error: null\n}" - } - ] - }, - { - "name": "getAuthenticatorAssuranceLevel", - "description": "Returns the Authenticator Assurance Level (AAL) for the active session.\n- `aal1` (or `null`) means that the user's identity has been verified only with a conventional login (email+password, OTP, magic link, social login, etc.). - `aal2` means that the user's identity has been verified both with a conventional login and at least one MFA factor.\nWhen called without a JWT parameter, this method is fairly quick (microseconds) and rarely uses the network. When a JWT is provided (useful in server-side environments like Edge Functions where no session is stored), this method will make a network request to validate the user and fetch their MFA factors.", - "remarks": [ - "- Authenticator Assurance Level (AAL) is the measure of the strength of an authentication mechanism. - In Supabase, having an AAL of `aal1` refers to having the 1st factor of authentication such as an email and password or OAuth sign-in while `aal2` refers to the 2nd factor of authentication such as a time-based, one-time-password (TOTP) or Phone factor. - If the user has a verified factor, the `nextLevel` field will return `aal2`, else, it will return `aal1`. - An optional `jwt` parameter can be passed to check the AAL level of a specific JWT instead of the current session." - ], - "parameters": [ - { - "name": "jwt", - "optional": true, - "description": "Takes in an optional access token JWT. If no JWT is provided, the JWT from the current session is used.", - "type": "string" - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "currentAuthenticationMethods", - "optional": false, - "description": "A list of all authentication methods attached to this session. Use the information here to detect the last time a user verified a factor, for example if implementing a step-up scenario.\nSupports both RFC-8176 compliant format (string[]) and detailed format (AMREntry[]). - String format: ['password', 'otp'] - RFC-8176 compliant - Object format: [{ method: 'password', timestamp: 1234567890 }] - includes timestamps", - "type": { - "kind": "union", - "types": [ - { - "kind": "array", - "elementType": { - "kind": "object", - "name": "AMREntry", - "properties": [ - { - "name": "method", - "optional": false, - "description": "Authentication method name.", - "type": { - "kind": "union", - "types": [ - { - "kind": "indexedAccess", - "objectType": { - "kind": "query" - }, - "indexType": null - }, - { - "kind": "intersection", - "types": [ - "string", - { - "kind": "object", - "properties": [] - } - ] - } - ] - } - }, - { - "name": "timestamp", - "optional": false, - "description": "Timestamp when the method was successfully used. Represents number of seconds since 1st January 1970 (UNIX epoch) in UTC.", - "type": "number" - } - ] - } - }, - { - "kind": "array", - "elementType": "string" - } - ] - } - }, - { - "name": "currentLevel", - "optional": false, - "description": "Current AAL level of the session.", - "type": { - "kind": "union", - "types": [ - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "aal1" - }, - { - "kind": "literal", - "value": "aal2" - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - }, - { - "name": "nextLevel", - "optional": false, - "description": "Next possible AAL level for the session. If the next level is higher than the current one, the user should go through MFA.", - "type": { - "kind": "union", - "types": [ - { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "aal1" - }, - { - "kind": "literal", - "value": "aal2" - } - ] - }, - { - "kind": "literal", - "value": null - } - ] - } - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Get the AAL details of a session", - "code": "const { data, error } = await supabase.auth.mfa.getAuthenticatorAssuranceLevel()\nconst { currentLevel, nextLevel, currentAuthenticationMethods } = data", - "response": "{\n data: {\n currentLevel: 'aal1',\n nextLevel: 'aal2',\n currentAuthenticationMethods: [\n {\n method: 'password',\n timestamp: 1700000000\n }\n ]\n }\n error: null\n}" - }, - { - "title": "Get the AAL details for a specific JWT", - "code": "const { data, error } = await supabase.auth.mfa.getAuthenticatorAssuranceLevel(jwt)" - } - ] - }, - { - "name": "listFactors", - "description": "Returns the list of MFA factors enabled for this user.", - "parameters": [], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "intersection", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "all", - "optional": false, - "description": "All available factors (verified and unverified).", - "type": { - "kind": "array", - "elementType": { - "kind": "conditional" - } - } - } - ] - }, - { - "kind": "mapped" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - } - }, - { - "name": "unenroll", - "description": "Unenroll removes a MFA factor. A user has to have an `aal2` authenticator level in order to unenroll a `verified` factor.", - "parameters": [ - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "factorId", - "optional": false, - "description": "ID of the factor being unenrolled.", - "type": "string" - } - ], - "name": "MFAUnenrollParams" - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "id", - "optional": false, - "description": "ID of the factor that was successfully unenrolled.", - "type": "string" - } - ] - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Unenroll a factor", - "code": "const { data, error } = await supabase.auth.mfa.unenroll({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n})", - "response": "{\n data: {\n id: ''\n },\n error: null\n}" - } - ] - }, - { - "name": "verify", - "description": "Verifies a code against a challenge. The verification code is provided by the user by entering a code seen in their authenticator app.", - "remarks": [ - "- To verify a challenge, please [create a challenge](/docs/reference/javascript/auth-mfa-challenge) first." - ], - "parameters": [ - { - "name": "params", - "type": { - "kind": "object", - "properties": [ - { - "name": "challengeId", - "optional": false, - "description": "ID of the challenge being verified. Returned in challenge().", - "type": "string" - }, - { - "name": "code", - "optional": false, - "description": "Verification code provided by the user.", - "type": "string" - }, - { - "name": "factorId", - "optional": false, - "description": "ID of the factor being verified. Returned in enroll().", - "type": "string" - } - ] - } - } - ], - "returnType": { - "kind": "reference", - "name": "Promise", - "typeArguments": [ - { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "access_token", - "optional": false, - "description": "New access token (JWT) after successful verification.", - "type": "string" - }, - { - "name": "expires_in", - "optional": false, - "description": "Number of seconds in which the access token will expire.", - "type": "number" - }, - { - "name": "refresh_token", - "optional": false, - "description": "Refresh token you can use to obtain new access tokens when expired.", - "type": "string" - }, - { - "name": "token_type", - "optional": false, - "description": "Type of token, always `bearer`.", - "type": { - "kind": "literal", - "value": "bearer" - } - }, - { - "name": "user", - "optional": false, - "description": "Updated user profile.", - "type": { - "kind": "object", - "name": "AuthUser", - "properties": [ - { - "name": "action_link", - "optional": true, - "type": "string" - }, - { - "name": "app_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserAppMetadata", - "properties": [ - { - "name": "provider", - "optional": true, - "description": "The first provider that the user used to sign up with.", - "type": "string" - }, - { - "name": "providers", - "optional": true, - "description": "A list of all providers that the user has linked to their account.", - "type": { - "kind": "array", - "elementType": "string" - } - } - ] - } - }, - { - "name": "aud", - "optional": false, - "type": "string" - }, - { - "name": "banned_until", - "optional": true, - "type": "string" - }, - { - "name": "confirmation_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "deleted_at", - "optional": true, - "type": "string" - }, - { - "name": "email", - "optional": true, - "type": "string" - }, - { - "name": "email_change_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "email_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "factors", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "union", - "types": [ - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "verified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - }, - { - "kind": "object", - "properties": [ - { - "name": "created_at", - "optional": false, - "type": "string" - }, - { - "name": "factor_type", - "optional": false, - "description": "Type of factor. `totp` and `phone` supported with this version", - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "webauthn" - }, - { - "kind": "literal", - "value": "totp" - }, - { - "kind": "literal", - "value": "phone" - } - ] - } - }, - { - "name": "friendly_name", - "optional": true, - "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", - "type": "string" - }, - { - "name": "id", - "optional": false, - "description": "ID of the factor.", - "type": "string" - }, - { - "name": "last_challenged_at", - "optional": true, - "type": "string" - }, - { - "name": "status", - "optional": false, - "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", - "type": { - "kind": "literal", - "value": "unverified" - } - }, - { - "name": "updated_at", - "optional": false, - "type": "string" - } - ], - "name": "Factor" - } - ] - } - } - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identities", - "optional": true, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "UserIdentity", - "properties": [ - { - "name": "created_at", - "optional": true, - "type": "string" - }, - { - "name": "id", - "optional": false, - "type": "string" - }, - { - "name": "identity_data", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "identity_id", - "optional": false, - "type": "string" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "provider", - "optional": false, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_id", - "optional": false, - "type": "string" - } - ] - } - } - }, - { - "name": "invited_at", - "optional": true, - "type": "string" - }, - { - "name": "is_anonymous", - "optional": true, - "type": "boolean" - }, - { - "name": "is_sso_user", - "optional": true, - "type": "boolean" - }, - { - "name": "last_sign_in_at", - "optional": true, - "type": "string" - }, - { - "name": "new_email", - "optional": true, - "type": "string" - }, - { - "name": "new_phone", - "optional": true, - "type": "string" - }, - { - "name": "phone", - "optional": true, - "type": "string" - }, - { - "name": "phone_confirmed_at", - "optional": true, - "type": "string" - }, - { - "name": "recovery_sent_at", - "optional": true, - "type": "string" - }, - { - "name": "role", - "optional": true, - "type": "string" - }, - { - "name": "updated_at", - "optional": true, - "type": "string" - }, - { - "name": "user_metadata", - "optional": false, - "type": { - "kind": "object", - "name": "UserMetadata", - "properties": [] - } - } - ] - } - } - ], - "name": "AuthMFAVerifyResponseData" - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - } - ] - }, - { - "kind": "object", - "properties": [ - { - "name": "data", - "optional": false, - "type": { - "kind": "literal", - "value": null - } - }, - { - "name": "error", - "optional": false, - "type": { - "kind": "conditional" - } - } - ] - } - ] - } - ] - }, - "examples": [ - { - "title": "Verify a challenge for a factor", - "code": "const { data, error } = await supabase.auth.mfa.verify({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n challengeId: '4034ae6f-a8ce-4fb5-8ee5-69a5863a7c15',\n code: '123456'\n})", - "response": "{\n data: {\n access_token: '',\n token_type: 'Bearer',\n expires_in: 3600,\n refresh_token: '',\n user: {\n id: '11111111-1111-1111-1111-111111111111',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {\n provider: 'email',\n providers: [\n \"email\",\n ]\n },\n user_metadata: {},\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false,\n factors: [\n \"id\": '',\n \"friendly_name\": 'Important Auth App',\n \"factor_type\": 'totp',\n \"status\": 'verified',\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n ]\n }\n }\n error: null\n}" - } - ] - } - ] - }, { "category": "Database", "definitions": [ - { - "name": "constructor", - "description": "Creates a builder configured for a specific PostgREST request.", - "parameters": [ - { - "name": "builder", - "type": { - "kind": "object", - "properties": [ - { - "name": "body", - "optional": true, - "type": "unknown" - }, - { - "name": "fetch", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": false, - "type": { - "kind": "reference", - "name": "HeadersInit" - } - }, - { - "name": "isMaybeSingle", - "optional": true, - "type": "boolean" - }, - { - "name": "method", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "GET" - }, - { - "kind": "literal", - "value": "HEAD" - }, - { - "kind": "literal", - "value": "POST" - }, - { - "kind": "literal", - "value": "PATCH" - }, - { - "kind": "literal", - "value": "DELETE" - } - ] - } - }, - { - "name": "schema", - "optional": true, - "type": "string" - }, - { - "name": "shouldThrowOnError", - "optional": true, - "type": "boolean" - }, - { - "name": "signal", - "optional": true, - "type": { - "kind": "reference", - "name": "AbortSignal" - } - }, - { - "name": "url", - "optional": false, - "type": { - "kind": "reference", - "name": "URL" - } - }, - { - "name": "urlLengthLimit", - "optional": true, - "type": "number" - } - ] - } - } - ], - "returnType": { - "kind": "object", - "name": "PostgrestBuilder", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "body", - "optional": true, - "type": "unknown" - }, - { - "name": "fetch", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": false, - "type": { - "kind": "reference", - "name": "Headers" - } - }, - { - "name": "isMaybeSingle", - "optional": false, - "type": "boolean" - }, - { - "name": "method", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "GET" - }, - { - "kind": "literal", - "value": "HEAD" - }, - { - "kind": "literal", - "value": "POST" - }, - { - "kind": "literal", - "value": "PATCH" - }, - { - "kind": "literal", - "value": "DELETE" - } - ] - } - }, - { - "name": "schema", - "optional": true, - "type": "string" - }, - { - "name": "shouldThrowOnError", - "optional": false, - "type": "boolean" - }, - { - "name": "signal", - "optional": true, - "type": { - "kind": "reference", - "name": "AbortSignal" - } - }, - { - "name": "url", - "optional": false, - "type": { - "kind": "reference", - "name": "URL" - } - }, - { - "name": "urlLengthLimit", - "optional": false, - "type": "number" - }, - { - "name": "overrideTypes", - "optional": false, - "type": null - }, - { - "name": "returns", - "optional": false, - "type": null - }, - { - "name": "setHeader", - "optional": false, - "type": null - }, - { - "name": "then", - "optional": false, - "type": null - }, - { - "name": "throwOnError", - "optional": false, - "type": null - } - ] - }, - "examples": [ - { - "title": "Example 1", - "code": "import { PostgrestQueryBuilder } from '@supabase/postgrest-js'\n\nconst builder = new PostgrestQueryBuilder(\n new URL('https://xyzcompany.supabase.co/rest/v1/users'),\n { headers: new Headers({ apikey: 'public-anon-key' }) }\n)" - }, - { - "title": "Creating a Postgrest query builder", - "code": "import { PostgrestQueryBuilder } from '@supabase/postgrest-js'\n\nconst builder = new PostgrestQueryBuilder(\n new URL('https://xyzcompany.supabase.co/rest/v1/users'),\n { headers: new Headers({ apikey: 'public-anon-key' }) }\n)" - } - ] - }, { "name": "overrideTypes", "description": "Override the type of the returned `data` field in the response.", @@ -44923,143 +615,6 @@ ] } }, - { - "name": "constructor", - "description": "Creates a PostgREST client.", - "remarks": [ - "- A `timeout` option (in milliseconds) can be set to automatically abort requests that take too long. - A `urlLengthLimit` option (default: 8000) can be set to control when URL length warnings are included in error messages for aborted requests." - ], - "parameters": [ - { - "name": "url", - "description": "URL of the PostgREST endpoint", - "type": "string" - }, - { - "name": "options", - "description": "Named parameters", - "type": { - "kind": "object", - "properties": [ - { - "name": "fetch", - "optional": true, - "description": "Custom fetch", - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": true, - "description": "Custom headers", - "type": { - "kind": "reference", - "name": "HeadersInit" - } - }, - { - "name": "schema", - "optional": true, - "description": "Postgres schema to switch to", - "type": { - "kind": "typeParam", - "name": "SchemaName" - } - }, - { - "name": "timeout", - "optional": true, - "description": "Optional timeout in milliseconds for all requests. When set, requests will automatically abort after this duration to prevent indefinite hangs.", - "type": "number" - }, - { - "name": "urlLengthLimit", - "optional": true, - "description": "Maximum URL length in characters before warnings/errors are triggered. Defaults to 8000.", - "type": "number" - } - ] - } - } - ], - "returnType": { - "kind": "object", - "name": "PostgrestClient", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "fetch", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": false, - "type": { - "kind": "reference", - "name": "Headers" - } - }, - { - "name": "schemaName", - "optional": true, - "type": { - "kind": "typeParam", - "name": "SchemaName" - } - }, - { - "name": "url", - "optional": false, - "type": "string" - }, - { - "name": "urlLengthLimit", - "optional": false, - "type": "number" - }, - { - "name": "from", - "optional": false, - "description": "Perform a query on a table or a view.", - "type": null - }, - { - "name": "rpc", - "optional": false, - "type": null - }, - { - "name": "schema", - "optional": false, - "type": null - } - ] - }, - "examples": [ - { - "title": "Example 1", - "code": "import { PostgrestClient } from '@supabase/postgrest-js'\n\nconst postgrest = new PostgrestClient('https://xyzcompany.supabase.co/rest/v1', {\n headers: { apikey: 'public-anon-key' },\n schema: 'public',\n timeout: 30000, // 30 second timeout\n})" - }, - { - "title": "Creating a Postgrest client", - "code": "import { PostgrestClient } from '@supabase/postgrest-js'\n\nconst postgrest = new PostgrestClient('https://xyzcompany.supabase.co/rest/v1', {\n headers: { apikey: 'public-anon-key' },\n schema: 'public',\n})" - }, - { - "title": "With timeout", - "code": "import { PostgrestClient } from '@supabase/postgrest-js'\n\nconst postgrest = new PostgrestClient('https://xyzcompany.supabase.co/rest/v1', {\n headers: { apikey: 'public-anon-key' },\n schema: 'public',\n timeout: 30000, // 30 second timeout\n})" - } - ] - }, { "name": "from", "description": "Perform a query on a table or a view.", @@ -45698,483 +1253,12 @@ ] } }, - { - "name": "constructor", - "description": "Creates a builder configured for a specific PostgREST request.", - "parameters": [ - { - "name": "builder", - "type": { - "kind": "object", - "properties": [ - { - "name": "body", - "optional": true, - "type": "unknown" - }, - { - "name": "fetch", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": false, - "type": { - "kind": "reference", - "name": "HeadersInit" - } - }, - { - "name": "isMaybeSingle", - "optional": true, - "type": "boolean" - }, - { - "name": "method", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "GET" - }, - { - "kind": "literal", - "value": "HEAD" - }, - { - "kind": "literal", - "value": "POST" - }, - { - "kind": "literal", - "value": "PATCH" - }, - { - "kind": "literal", - "value": "DELETE" - } - ] - } - }, - { - "name": "schema", - "optional": true, - "type": "string" - }, - { - "name": "shouldThrowOnError", - "optional": true, - "type": "boolean" - }, - { - "name": "signal", - "optional": true, - "type": { - "kind": "reference", - "name": "AbortSignal" - } - }, - { - "name": "url", - "optional": false, - "type": { - "kind": "reference", - "name": "URL" - } - }, - { - "name": "urlLengthLimit", - "optional": true, - "type": "number" - } - ] - } - } - ], - "returnType": { - "kind": "object", - "name": "PostgrestFilterBuilder", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "body", - "optional": true, - "type": "unknown" - }, - { - "name": "fetch", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": false, - "type": { - "kind": "reference", - "name": "Headers" - } - }, - { - "name": "isMaybeSingle", - "optional": false, - "type": "boolean" - }, - { - "name": "method", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "GET" - }, - { - "kind": "literal", - "value": "HEAD" - }, - { - "kind": "literal", - "value": "POST" - }, - { - "kind": "literal", - "value": "PATCH" - }, - { - "kind": "literal", - "value": "DELETE" - } - ] - } - }, - { - "name": "schema", - "optional": true, - "type": "string" - }, - { - "name": "shouldThrowOnError", - "optional": false, - "type": "boolean" - }, - { - "name": "signal", - "optional": true, - "type": { - "kind": "reference", - "name": "AbortSignal" - } - }, - { - "name": "url", - "optional": false, - "type": { - "kind": "reference", - "name": "URL" - } - }, - { - "name": "urlLengthLimit", - "optional": false, - "type": "number" - }, - { - "name": "abortSignal", - "optional": false, - "type": null - }, - { - "name": "containedBy", - "optional": false, - "description": "Only relevant for jsonb, array, and range columns. Match only rows where every element appearing in `column` is contained by `value`.", - "type": null - }, - { - "name": "contains", - "optional": false, - "description": "Only relevant for jsonb, array, and range columns. Match only rows where `column` contains every element appearing in `value`.", - "type": null - }, - { - "name": "csv", - "optional": false, - "type": null - }, - { - "name": "eq", - "optional": false, - "type": null - }, - { - "name": "explain", - "optional": false, - "type": null - }, - { - "name": "filter", - "optional": false, - "description": "Match only rows which satisfy the filter. This is an escape hatch - you should use the specific filter methods wherever possible.\nUnlike most filters, `opearator` and `value` are used as-is and need to follow [PostgREST syntax](https://postgrest.org/en/stable/api.html#operators). You also need to make sure they are properly sanitized.", - "type": null - }, - { - "name": "geojson", - "optional": false, - "type": null - }, - { - "name": "gt", - "optional": false, - "description": "Match only rows where `column` is greater than `value`.", - "type": null - }, - { - "name": "gte", - "optional": false, - "description": "Match only rows where `column` is greater than or equal to `value`.", - "type": null - }, - { - "name": "ilike", - "optional": false, - "description": "Match only rows where `column` matches `pattern` case-insensitively.", - "type": null - }, - { - "name": "ilikeAllOf", - "optional": false, - "description": "Match only rows where `column` matches all of `patterns` case-insensitively.", - "type": null - }, - { - "name": "ilikeAnyOf", - "optional": false, - "description": "Match only rows where `column` matches any of `patterns` case-insensitively.", - "type": null - }, - { - "name": "in", - "optional": false, - "type": null - }, - { - "name": "is", - "optional": false, - "description": "Match only rows where `column` IS `value`.\nFor non-boolean columns, this is only relevant for checking if the value of `column` is NULL by setting `value` to `null`.\nFor boolean columns, you can also set `value` to `true` or `false` and it will behave the same way as `.eq()`.", - "type": null - }, - { - "name": "isDistinct", - "optional": false, - "type": null - }, - { - "name": "like", - "optional": false, - "description": "Match only rows where `column` matches `pattern` case-sensitively.", - "type": null - }, - { - "name": "likeAllOf", - "optional": false, - "description": "Match only rows where `column` matches all of `patterns` case-sensitively.", - "type": null - }, - { - "name": "likeAnyOf", - "optional": false, - "description": "Match only rows where `column` matches any of `patterns` case-sensitively.", - "type": null - }, - { - "name": "limit", - "optional": false, - "type": null - }, - { - "name": "lt", - "optional": false, - "description": "Match only rows where `column` is less than `value`.", - "type": null - }, - { - "name": "lte", - "optional": false, - "description": "Match only rows where `column` is less than or equal to `value`.", - "type": null - }, - { - "name": "match", - "optional": false, - "description": "Match only rows where each column in `query` keys is equal to its associated value. Shorthand for multiple `.eq()`s.", - "type": null - }, - { - "name": "maxAffected", - "optional": false, - "type": null - }, - { - "name": "maybeSingle", - "optional": false, - "type": null - }, - { - "name": "neq", - "optional": false, - "type": null - }, - { - "name": "not", - "optional": false, - "description": "Match only rows which doesn't satisfy the filter.\nUnlike most filters, `opearator` and `value` are used as-is and need to follow [PostgREST syntax](https://postgrest.org/en/stable/api.html#operators). You also need to make sure they are properly sanitized.", - "type": null - }, - { - "name": "notIn", - "optional": false, - "type": null - }, - { - "name": "or", - "optional": false, - "type": null - }, - { - "name": "order", - "optional": false, - "description": "Order the query result by `column`.\nYou can call this method multiple times to order by multiple columns.\nYou can order referenced tables, but it only affects the ordering of the parent table if you use `!inner` in the query.", - "type": null - }, - { - "name": "overlaps", - "optional": false, - "description": "Only relevant for array and range columns. Match only rows where `column` and `value` have an element in common.", - "type": null - }, - { - "name": "overrideTypes", - "optional": false, - "type": null - }, - { - "name": "range", - "optional": false, - "type": null - }, - { - "name": "rangeAdjacent", - "optional": false, - "description": "Only relevant for range columns. Match only rows where `column` is mutually exclusive to `range` and there can be no element between the two ranges.", - "type": null - }, - { - "name": "rangeGt", - "optional": false, - "description": "Only relevant for range columns. Match only rows where every element in `column` is greater than any element in `range`.", - "type": null - }, - { - "name": "rangeGte", - "optional": false, - "description": "Only relevant for range columns. Match only rows where every element in `column` is either contained in `range` or greater than any element in `range`.", - "type": null - }, - { - "name": "rangeLt", - "optional": false, - "description": "Only relevant for range columns. Match only rows where every element in `column` is less than any element in `range`.", - "type": null - }, - { - "name": "rangeLte", - "optional": false, - "description": "Only relevant for range columns. Match only rows where every element in `column` is either contained in `range` or less than any element in `range`.", - "type": null - }, - { - "name": "regexIMatch", - "optional": false, - "description": "Match only rows where `column` matches the PostgreSQL regex `pattern` case-insensitively (using the `~*` operator).", - "type": null - }, - { - "name": "regexMatch", - "optional": false, - "description": "Match only rows where `column` matches the PostgreSQL regex `pattern` case-sensitively (using the `~` operator).", - "type": null - }, - { - "name": "returns", - "optional": false, - "type": null - }, - { - "name": "rollback", - "optional": false, - "type": null - }, - { - "name": "select", - "optional": false, - "type": null - }, - { - "name": "setHeader", - "optional": false, - "type": null - }, - { - "name": "single", - "optional": false, - "type": null - }, - { - "name": "textSearch", - "optional": false, - "description": "Only relevant for text and tsvector columns. Match only rows where `column` matches the query string in `query`.", - "type": null - }, - { - "name": "then", - "optional": false, - "type": null - }, - { - "name": "throwOnError", - "optional": false, - "type": null - } - ] - }, - "examples": [ - { - "title": "Example 1", - "code": "import { PostgrestQueryBuilder } from '@supabase/postgrest-js'\n\nconst builder = new PostgrestQueryBuilder(\n new URL('https://xyzcompany.supabase.co/rest/v1/users'),\n { headers: new Headers({ apikey: 'public-anon-key' }) }\n)" - }, - { - "title": "Creating a Postgrest query builder", - "code": "import { PostgrestQueryBuilder } from '@supabase/postgrest-js'\n\nconst builder = new PostgrestQueryBuilder(\n new URL('https://xyzcompany.supabase.co/rest/v1/users'),\n { headers: new Headers({ apikey: 'public-anon-key' }) }\n)" - } - ] - }, { "name": "abortSignal", "description": "Set the AbortSignal for the fetch request.", - "remarks": ["You can use this to set a timeout for the request."], + "remarks": [ + "You can use this to set a timeout for the request." + ], "parameters": [ { "name": "signal", @@ -46220,7 +1304,10 @@ { "kind": "reference", "name": "Record", - "typeArguments": ["string", "unknown"] + "typeArguments": [ + "string", + "unknown" + ] }, { "kind": "typeOperator" @@ -46273,7 +1360,10 @@ { "kind": "reference", "name": "Record", - "typeArguments": ["string", "unknown"] + "typeArguments": [ + "string", + "unknown" + ] }, { "kind": "typeOperator" @@ -48222,7 +3312,9 @@ { "name": "returns", "description": "Override the type of the returned `data`.", - "remarks": ["- Deprecated: use overrideTypes method instead"], + "remarks": [ + "- Deprecated: use overrideTypes method instead" + ], "parameters": [], "returnType": { "kind": "object", @@ -49596,139 +4688,6 @@ ] } }, - { - "name": "constructor", - "description": "Creates a query builder scoped to a Postgres table or view.", - "parameters": [ - { - "name": "url", - "type": { - "kind": "reference", - "name": "URL" - } - }, - { - "name": "__namedParameters", - "type": { - "kind": "object", - "properties": [ - { - "name": "fetch", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": true, - "type": { - "kind": "reference", - "name": "HeadersInit" - } - }, - { - "name": "schema", - "optional": true, - "type": "string" - }, - { - "name": "urlLengthLimit", - "optional": true, - "type": "number" - } - ] - } - } - ], - "returnType": { - "kind": "object", - "name": "PostgrestQueryBuilder", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "fetch", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": false, - "type": { - "kind": "reference", - "name": "Headers" - } - }, - { - "name": "schema", - "optional": true, - "type": "string" - }, - { - "name": "signal", - "optional": true, - "type": { - "kind": "reference", - "name": "AbortSignal" - } - }, - { - "name": "url", - "optional": false, - "type": { - "kind": "reference", - "name": "URL" - } - }, - { - "name": "urlLengthLimit", - "optional": false, - "type": "number" - }, - { - "name": "delete", - "optional": false, - "type": null - }, - { - "name": "insert", - "optional": false, - "description": "Perform an INSERT into the table or view.\nBy default, inserted rows are not returned. To return it, chain the call with `.select()`.", - "type": null - }, - { - "name": "select", - "optional": false, - "type": null - }, - { - "name": "update", - "optional": false, - "type": null - }, - { - "name": "upsert", - "optional": false, - "description": "Perform an UPSERT on the table or view. Depending on the column(s) passed to `onConflict`, `.upsert()` allows you to perform the equivalent of `.insert()` if a row with the corresponding `onConflict` columns doesn't exist, or if it does exist, perform an alternative action depending on `ignoreDuplicates`.\nBy default, upserted rows are not returned. To return it, chain the call with `.select()`.", - "type": null - } - ] - }, - "examples": [ - { - "title": "Creating a Postgrest query builder", - "code": "import { PostgrestQueryBuilder } from '@supabase/postgrest-js'\n\nconst query = new PostgrestQueryBuilder(\n new URL('https://xyzcompany.supabase.co/rest/v1/users'),\n { headers: { apikey: 'public-anon-key' } }\n)" - } - ] - }, { "name": "delete", "description": "Perform a DELETE on the table or view.\nBy default, deleted rows are not returned. To return it, chain the call with `.select()` after filters.", @@ -51521,7 +6480,9 @@ { "name": "upsert", "description": "Perform an UPSERT on the table or view. Depending on the column(s) passed to `onConflict`, `.upsert()` allows you to perform the equivalent of `.insert()` if a row with the corresponding `onConflict` columns doesn't exist, or if it does exist, perform an alternative action depending on `ignoreDuplicates`.\nBy default, upserted rows are not returned. To return it, chain the call with `.select()`.", - "remarks": ["- Primary keys must be included in `values` to use upsert."], + "remarks": [ + "- Primary keys must be included in `values` to use upsert." + ], "parameters": [ { "name": "values", @@ -51969,303 +6930,12 @@ } ] }, - { - "name": "constructor", - "description": "Creates a builder configured for a specific PostgREST request.", - "parameters": [ - { - "name": "builder", - "type": { - "kind": "object", - "properties": [ - { - "name": "body", - "optional": true, - "type": "unknown" - }, - { - "name": "fetch", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": false, - "type": { - "kind": "reference", - "name": "HeadersInit" - } - }, - { - "name": "isMaybeSingle", - "optional": true, - "type": "boolean" - }, - { - "name": "method", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "GET" - }, - { - "kind": "literal", - "value": "HEAD" - }, - { - "kind": "literal", - "value": "POST" - }, - { - "kind": "literal", - "value": "PATCH" - }, - { - "kind": "literal", - "value": "DELETE" - } - ] - } - }, - { - "name": "schema", - "optional": true, - "type": "string" - }, - { - "name": "shouldThrowOnError", - "optional": true, - "type": "boolean" - }, - { - "name": "signal", - "optional": true, - "type": { - "kind": "reference", - "name": "AbortSignal" - } - }, - { - "name": "url", - "optional": false, - "type": { - "kind": "reference", - "name": "URL" - } - }, - { - "name": "urlLengthLimit", - "optional": true, - "type": "number" - } - ] - } - } - ], - "returnType": { - "kind": "object", - "name": "PostgrestTransformBuilder", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "body", - "optional": true, - "type": "unknown" - }, - { - "name": "fetch", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": false, - "type": { - "kind": "reference", - "name": "Headers" - } - }, - { - "name": "isMaybeSingle", - "optional": false, - "type": "boolean" - }, - { - "name": "method", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": "GET" - }, - { - "kind": "literal", - "value": "HEAD" - }, - { - "kind": "literal", - "value": "POST" - }, - { - "kind": "literal", - "value": "PATCH" - }, - { - "kind": "literal", - "value": "DELETE" - } - ] - } - }, - { - "name": "schema", - "optional": true, - "type": "string" - }, - { - "name": "shouldThrowOnError", - "optional": false, - "type": "boolean" - }, - { - "name": "signal", - "optional": true, - "type": { - "kind": "reference", - "name": "AbortSignal" - } - }, - { - "name": "url", - "optional": false, - "type": { - "kind": "reference", - "name": "URL" - } - }, - { - "name": "urlLengthLimit", - "optional": false, - "type": "number" - }, - { - "name": "abortSignal", - "optional": false, - "type": null - }, - { - "name": "csv", - "optional": false, - "type": null - }, - { - "name": "explain", - "optional": false, - "type": null - }, - { - "name": "geojson", - "optional": false, - "type": null - }, - { - "name": "limit", - "optional": false, - "type": null - }, - { - "name": "maxAffected", - "optional": false, - "type": null - }, - { - "name": "maybeSingle", - "optional": false, - "type": null - }, - { - "name": "order", - "optional": false, - "description": "Order the query result by `column`.\nYou can call this method multiple times to order by multiple columns.\nYou can order referenced tables, but it only affects the ordering of the parent table if you use `!inner` in the query.", - "type": null - }, - { - "name": "overrideTypes", - "optional": false, - "type": null - }, - { - "name": "range", - "optional": false, - "type": null - }, - { - "name": "returns", - "optional": false, - "type": null - }, - { - "name": "rollback", - "optional": false, - "type": null - }, - { - "name": "select", - "optional": false, - "type": null - }, - { - "name": "setHeader", - "optional": false, - "type": null - }, - { - "name": "single", - "optional": false, - "type": null - }, - { - "name": "then", - "optional": false, - "type": null - }, - { - "name": "throwOnError", - "optional": false, - "type": null - } - ] - }, - "examples": [ - { - "title": "Example 1", - "code": "import { PostgrestQueryBuilder } from '@supabase/postgrest-js'\n\nconst builder = new PostgrestQueryBuilder(\n new URL('https://xyzcompany.supabase.co/rest/v1/users'),\n { headers: new Headers({ apikey: 'public-anon-key' }) }\n)" - }, - { - "title": "Creating a Postgrest query builder", - "code": "import { PostgrestQueryBuilder } from '@supabase/postgrest-js'\n\nconst builder = new PostgrestQueryBuilder(\n new URL('https://xyzcompany.supabase.co/rest/v1/users'),\n { headers: new Headers({ apikey: 'public-anon-key' }) }\n)" - } - ] - }, { "name": "abortSignal", "description": "Set the AbortSignal for the fetch request.", - "remarks": ["You can use this to set a timeout for the request."], + "remarks": [ + "You can use this to set a timeout for the request." + ], "parameters": [ { "name": "signal", @@ -53346,7 +8016,9 @@ { "name": "returns", "description": "Override the type of the returned `data`.", - "remarks": ["- Deprecated: use overrideTypes method instead"], + "remarks": [ + "- Deprecated: use overrideTypes method instead" + ], "parameters": [], "returnType": { "kind": "object", @@ -54463,102 +9135,3395 @@ ] }, { - "category": "Realtime", + "category": "Auth", "definitions": [ { - "name": "constructor", - "description": "Creates a channel that can broadcast messages, sync presence, and listen to Postgres changes.\nThe topic determines which realtime stream you are subscribing to. Config options let you enable acknowledgement for broadcasts, presence tracking, or private channels.", + "name": "createUser", + "description": "Creates a new user. This function should only be called on a server. Never expose your `service_role` key in the browser.", + "remarks": [ + "- To confirm the user's email address or phone number, set `email_confirm` or `phone_confirm` to true. Both arguments default to false. - `createUser()` will not send a confirmation email to the user. You can use [`inviteUserByEmail()`](/docs/reference/javascript/auth-admin-inviteuserbyemail) if you want to send them an email invite instead. - If you are sure that the created user's email or phone number is legitimate and verified, you can set the `email_confirm` or `phone_confirm` param to `true`." + ], "parameters": [ { - "name": "topic", - "description": "Topic name can be any string.", + "name": "attributes", + "type": { + "kind": "object", + "name": "AdminUserAttributes", + "properties": [ + { + "name": "app_metadata", + "optional": true, + "description": "A custom data object to store the user's application specific metadata. This maps to the `auth.users.app_metadata` column.\nOnly a service role can modify.\nThe `app_metadata` should be a JSON object that includes app-specific info, such as identity providers, roles, and other access control information.", + "type": "object" + }, + { + "name": "ban_duration", + "optional": true, + "description": "Determines how long a user is banned for.\nThe format for the ban duration follows a strict sequence of decimal numbers with a unit suffix. Valid time units are \"ns\", \"us\" (or \"µs\"), \"ms\", \"s\", \"m\", \"h\".\nFor example, some possible durations include: '300ms', '2h45m'.\nSetting the ban duration to 'none' lifts the ban on the user.", + "type": "string" + }, + { + "name": "current_password", + "optional": true, + "description": "The user's current password\nThis is only ever present when the user is resetting their password and GOTRUE_SECURITY_UPDATE_PASSWORD_REQUIRE_CURRENT_PASSWORD is true.", + "type": "string" + }, + { + "name": "email", + "optional": true, + "description": "The user's email.", + "type": "string" + }, + { + "name": "email_confirm", + "optional": true, + "description": "Sets the user's email as confirmed when true, or unconfirmed when false.\nOnly a service role can modify.", + "type": "boolean" + }, + { + "name": "id", + "optional": true, + "description": "The `id` for the user.\nAllows you to overwrite the default `id` set for the user.", + "type": "string" + }, + { + "name": "nonce", + "optional": true, + "description": "The nonce sent for reauthentication if the user's password is to be updated.\nCall reauthenticate() to obtain the nonce first.", + "type": "string" + }, + { + "name": "password", + "optional": true, + "description": "The user's password.", + "type": "string" + }, + { + "name": "password_hash", + "optional": true, + "description": "The `password_hash` for the user's password.\nAllows you to specify a password hash for the user. This is useful for migrating a user's password hash from another service.\nSupports bcrypt, scrypt (firebase), and argon2 password hashes.", + "type": "string" + }, + { + "name": "phone", + "optional": true, + "description": "The user's phone.", + "type": "string" + }, + { + "name": "phone_confirm", + "optional": true, + "description": "Sets the user's phone as confirmed when true, or unconfirmed when false.\nOnly a service role can modify.", + "type": "boolean" + }, + { + "name": "role", + "optional": true, + "description": "The `role` claim set in the user's access token JWT.\nWhen a user signs up, this role is set to `authenticated` by default. You should only modify the `role` if you need to provision several levels of admin access that have different permissions on individual columns in your database.\nSetting this role to `service_role` is not recommended as it grants the user admin privileges.", + "type": "string" + }, + { + "name": "user_metadata", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `user_metadata` should be a JSON object that includes user-specific info, such as their first and last name.\nNote: When using the GoTrueAdminApi and wanting to modify a user's metadata, this attribute is used instead of UserAttributes data.", + "type": "object" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "With custom user metadata", + "code": "const { data, error } = await supabase.auth.admin.createUser({\n email: 'user@email.com',\n password: 'password',\n user_metadata: { name: 'Yoda' }\n})", + "response": "{\n data: {\n user: {\n id: '1',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {},\n user_metadata: {},\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"1\",\n \"user_id\": \"1\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"phone_verified\": false,\n \"sub\": \"1\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false,\n }\n }\n error: null\n}" + }, + { + "title": "Auto-confirm the user's email", + "code": "const { data, error } = await supabase.auth.admin.createUser({\n email: 'user@email.com',\n email_confirm: true\n})" + }, + { + "title": "Auto-confirm the user's phone number", + "code": "const { data, error } = await supabase.auth.admin.createUser({\n phone: '1234567890',\n phone_confirm: true\n})" + } + ] + }, + { + "name": "deleteUser", + "description": "Delete a user. Requires a `service_role` key.", + "remarks": [ + "- The `deleteUser()` method requires the user's ID, which maps to the `auth.users.id` column." + ], + "parameters": [ + { + "name": "id", + "description": "The user id you want to remove.", "type": "string" }, { - "name": "params", - "type": { - "kind": "object", - "properties": [ + "name": "shouldSoftDelete", + "description": "If true, then the user will be soft-deleted from the auth schema. Soft deletion allows user identification from the hashed user ID but is not reversible. Defaults to false for backward compatibility.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "type": "boolean" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ { - "name": "config", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "broadcast", - "optional": true, - "description": "self option enables client to receive message it broadcast ack option instructs server to acknowledge that broadcast message was received replay option instructs server to replay broadcast messages", - "type": { - "kind": "object", - "properties": [ - { - "name": "ack", - "optional": true, - "type": "boolean" - }, - { - "name": "replay", - "optional": true, - "type": { - "kind": "reference", - "name": "ReplayOption" - } - }, - { - "name": "self", - "optional": true, - "type": "boolean" + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] } - ] - } - }, - { - "name": "presence", - "optional": true, - "description": "key option is used to track presence payload across clients", - "type": { - "kind": "object", - "properties": [ - { - "name": "enabled", - "optional": true, - "type": "boolean" - }, - { - "name": "key", - "optional": true, - "type": "string" - } - ] - } - }, - { - "name": "private", - "optional": true, - "description": "defines if the channel is private or not and if RLS policies will be used to check data", - "type": "boolean" + } + ] } - ] - } - } - ], - "name": "RealtimeChannelOptions" - } - }, - { - "name": "socket", - "type": { - "kind": "object", - "name": "RealtimeClient", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] }, { - "name": "accessToken", + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Removes a user", + "code": "const { data, error } = await supabase.auth.admin.deleteUser(\n '715ed5db-f090-4b8c-a067-640ecee36aa0'\n)", + "response": "{\n \"data\": {\n \"user\": {}\n },\n \"error\": null\n}" + } + ] + }, + { + "name": "generateLink", + "description": "Generates email links and OTPs to be sent via a custom email provider.", + "remarks": [ + "- The following types can be passed into `generateLink()`: `signup`, `magiclink`, `invite`, `recovery`, `email_change_current`, `email_change_new`, `phone_change`. - `generateLink()` only generates the email link for `email_change_email` if the **Secure email change** is enabled in your project's [email auth provider settings](/dashboard/project/_/auth/providers). - `generateLink()` handles the creation of the user for `signup`, `invite` and `magiclink`." + ], + "parameters": [ + { + "name": "params", + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "email", + "optional": false, + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "reference", + "name": "Pick", + "typeArguments": [ + { + "kind": "object", + "name": "GenerateLinkOptions", + "properties": [ + { + "name": "data", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", + "type": "object" + }, + { + "name": "redirectTo", + "optional": true, + "description": "The URL which will be appended to the email link generated.", + "type": "string" + } + ] + }, + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "data" + }, + { + "kind": "literal", + "value": "redirectTo" + } + ] + } + ] + } + }, + { + "name": "password", + "optional": false, + "type": "string" + }, + { + "name": "type", + "optional": false, + "type": { + "kind": "literal", + "value": "signup" + } + } + ], + "name": "GenerateSignupLinkParams" + }, + { + "kind": "object", + "properties": [ + { + "name": "email", + "optional": false, + "description": "The user's email", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "reference", + "name": "Pick", + "typeArguments": [ + { + "kind": "object", + "name": "GenerateLinkOptions", + "properties": [ + { + "name": "data", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", + "type": "object" + }, + { + "name": "redirectTo", + "optional": true, + "description": "The URL which will be appended to the email link generated.", + "type": "string" + } + ] + }, + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "data" + }, + { + "kind": "literal", + "value": "redirectTo" + } + ] + } + ] + } + }, + { + "name": "type", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "invite" + }, + { + "kind": "literal", + "value": "magiclink" + } + ] + } + } + ], + "name": "GenerateInviteOrMagiclinkParams" + }, + { + "kind": "object", + "properties": [ + { + "name": "email", + "optional": false, + "description": "The user's email", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "reference", + "name": "Pick", + "typeArguments": [ + { + "kind": "object", + "name": "GenerateLinkOptions", + "properties": [ + { + "name": "data", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", + "type": "object" + }, + { + "name": "redirectTo", + "optional": true, + "description": "The URL which will be appended to the email link generated.", + "type": "string" + } + ] + }, + { + "kind": "literal", + "value": "redirectTo" + } + ] + } + }, + { + "name": "type", + "optional": false, + "type": { + "kind": "literal", + "value": "recovery" + } + } + ], + "name": "GenerateRecoveryLinkParams" + }, + { + "kind": "object", + "properties": [ + { + "name": "email", + "optional": false, + "description": "The user's email", + "type": "string" + }, + { + "name": "newEmail", + "optional": false, + "description": "The user's new email. Only required if type is 'email_change_current' or 'email_change_new'.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "reference", + "name": "Pick", + "typeArguments": [ + { + "kind": "object", + "name": "GenerateLinkOptions", + "properties": [ + { + "name": "data", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", + "type": "object" + }, + { + "name": "redirectTo", + "optional": true, + "description": "The URL which will be appended to the email link generated.", + "type": "string" + } + ] + }, + { + "kind": "literal", + "value": "redirectTo" + } + ] + } + }, + { + "name": "type", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "email_change_current" + }, + { + "kind": "literal", + "value": "email_change_new" + } + ] + } + } + ], + "name": "GenerateEmailChangeLinkParams" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "properties", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "action_link", + "optional": false, + "description": "The email link to send to the user. The action_link follows the following format: auth/v1/verify?type={verification_type}&token={hashed_token}&redirect_to={redirect_to}", + "type": "string" + }, + { + "name": "email_otp", + "optional": false, + "description": "The raw email OTP. You should send this in the email if you want your users to verify using an OTP instead of the action link.", + "type": "string" + }, + { + "name": "hashed_token", + "optional": false, + "description": "The hashed token appended to the action link.", + "type": "string" + }, + { + "name": "redirect_to", + "optional": false, + "description": "The URL appended to the action link.", + "type": "string" + }, + { + "name": "verification_type", + "optional": false, + "description": "The verification type that the email link is associated to.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "signup" + }, + { + "kind": "literal", + "value": "invite" + }, + { + "kind": "literal", + "value": "magiclink" + }, + { + "kind": "literal", + "value": "recovery" + }, + { + "kind": "literal", + "value": "email_change_current" + }, + { + "kind": "literal", + "value": "email_change_new" + } + ] + } + } + ], + "name": "GenerateLinkProperties" + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Generate a signup link", + "code": "const { data, error } = await supabase.auth.admin.generateLink({\n type: 'signup',\n email: 'email@example.com',\n password: 'secret'\n})", + "response": "{\n \"data\": {\n \"properties\": {\n \"action_link\": \"\",\n \"email_otp\": \"999999\",\n \"hashed_token\": \"\",\n \"verification_type\": \"signup\"\n },\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"email@example.com\",\n \"phone\": \"\",\n \"confirmation_sent_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"email@example.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" + }, + { + "title": "Generate an invite link", + "code": "const { data, error } = await supabase.auth.admin.generateLink({\n type: 'invite',\n email: 'email@example.com'\n})" + }, + { + "title": "Generate a magic link", + "code": "const { data, error } = await supabase.auth.admin.generateLink({\n type: 'magiclink',\n email: 'email@example.com'\n})" + }, + { + "title": "Generate a recovery link", + "code": "const { data, error } = await supabase.auth.admin.generateLink({\n type: 'recovery',\n email: 'email@example.com'\n})" + }, + { + "title": "Generate links to change current email address", + "code": "// generate an email change link to be sent to the current email address\nconst { data, error } = await supabase.auth.admin.generateLink({\n type: 'email_change_current',\n email: 'current.email@example.com',\n newEmail: 'new.email@example.com'\n})\n\n// generate an email change link to be sent to the new email address\nconst { data, error } = await supabase.auth.admin.generateLink({\n type: 'email_change_new',\n email: 'current.email@example.com',\n newEmail: 'new.email@example.com'\n})" + } + ] + }, + { + "name": "getUserById", + "description": "Get user by id.", + "remarks": [ + "- Fetches the user object from the database based on the user's id. - The `getUserById()` method requires the user's id which maps to the `auth.users.id` column." + ], + "parameters": [ + { + "name": "uid", + "description": "The user's unique identifier\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "type": "string" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Fetch the user object using the access_token jwt", + "code": "const { data, error } = await supabase.auth.admin.getUserById(1)", + "response": "{\n data: {\n user: {\n id: '1',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {},\n user_metadata: {},\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"1\",\n \"user_id\": \"1\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"phone_verified\": false,\n \"sub\": \"1\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false,\n }\n }\n error: null\n}" + } + ] + }, + { + "name": "inviteUserByEmail", + "description": "Sends an invite link to an email address.", + "remarks": [ + "- Sends an invite link to the user's email address. - The `inviteUserByEmail()` method is typically used by administrators to invite users to join the application. - Note that PKCE is not supported when using `inviteUserByEmail`. This is because the browser initiating the invite is often different from the browser accepting the invite which makes it difficult to provide the security guarantees required of the PKCE flow." + ], + "parameters": [ + { + "name": "email", + "description": "The email address of the user.", + "type": "string" + }, + { + "name": "options", + "description": "Additional options to be included when inviting.", + "type": { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": true, + "description": "A custom data object to store additional metadata about the user. This maps to the `auth.users.user_metadata` column.", + "type": "object" + }, + { + "name": "redirectTo", + "optional": true, + "description": "The URL which will be appended to the email link sent to the user's email address. Once clicked the user will end up on this URL.", + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Invite a user", + "code": "const { data, error } = await supabase.auth.admin.inviteUserByEmail('email@example.com')", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"invited_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmation_sent_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" + } + ] + }, + { + "name": "listUsers", + "description": "Get a list of users.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "remarks": [ + "- Defaults to return 50 users per page." + ], + "parameters": [ + { + "name": "params", + "optional": true, + "description": "An object which supports `page` and `perPage` as numbers, to alter the paginated results.", + "type": { + "kind": "object", + "properties": [ + { + "name": "page", + "optional": true, + "description": "The page number", + "type": "number" + }, + { + "name": "perPage", + "optional": true, + "description": "Number of items returned per page", + "type": "number" + } + ], + "name": "PageParams" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "intersection", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "users", + "optional": false, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "lastPage", + "optional": false, + "type": "number" + }, + { + "name": "nextPage", + "optional": false, + "type": { + "kind": "union", + "types": [ + "number", + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "total", + "optional": false, + "type": "number" + } + ], + "name": "Pagination" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "users", + "optional": false, + "type": { + "kind": "tuple", + "elements": [] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Get a page of users", + "code": "const { data: { users }, error } = await supabase.auth.admin.listUsers()" + }, + { + "title": "Paginated list of users", + "code": "const { data: { users }, error } = await supabase.auth.admin.listUsers({\n page: 1,\n perPage: 1000\n})" + } + ] + }, + { + "name": "signOut", + "description": "Removes a logged-in session.", + "parameters": [ + { + "name": "jwt", + "description": "A valid, logged-in JWT.", + "type": "string" + }, + { + "name": "scope", + "description": "The logout sope.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "global" + }, + { + "kind": "literal", + "value": "local" + }, + { + "kind": "literal", + "value": "others" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", "optional": false, "type": { "kind": "union", @@ -54569,1038 +12534,40812 @@ }, { "kind": "object", - "properties": [] - } - ] - } - }, - { - "name": "accessTokenValue", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "apiKey", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "channels", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "RealtimeChannel", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "bindings", - "optional": false, - "type": { - "kind": "reference", - "name": "Record", - "typeArguments": [ - "string", - { - "kind": "array", - "elementType": { + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { "kind": "reference", - "name": "Binding" - } - } - ] - } - }, - { - "name": "broadcastEndpointURL", - "optional": false, - "type": "string" - }, - { - "name": "params", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "config", - "optional": false, - "type": { - "kind": "object", - "properties": [ + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", { - "name": "broadcast", - "optional": true, - "description": "self option enables client to receive message it broadcast ack option instructs server to acknowledge that broadcast message was received replay option instructs server to replay broadcast messages", - "type": { - "kind": "object", - "properties": [ - { - "name": "ack", - "optional": true, - "type": "boolean" - }, - { - "name": "replay", - "optional": true, - "type": { - "kind": "reference", - "name": "ReplayOption" - } - }, - { - "name": "self", - "optional": true, - "type": "boolean" - } - ] - } - }, - { - "name": "presence", - "optional": true, - "description": "key option is used to track presence payload across clients", - "type": { - "kind": "object", - "properties": [ - { - "name": "enabled", - "optional": true, - "type": "boolean" - }, - { - "name": "key", - "optional": true, - "type": "string" - } - ] - } - }, - { - "name": "private", - "optional": true, - "description": "defines if the channel is private or not and if RLS policies will be used to check data", - "type": "boolean" + "kind": "object", + "properties": [] } ] } - } - ], - "name": "RealtimeChannelOptions" + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } } - }, - { - "name": "presence", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimePresence", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "description": "The realtime channel to bind to.", - "type": { - "kind": "reference", - "name": "RealtimeChannel" - } - }, - { - "name": "state", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "private", - "optional": false, - "type": "boolean" - }, - { - "name": "socket", - "optional": false, - "type": { - "kind": "reference", - "name": "RealtimeClient" - } - }, - { - "name": "subTopic", - "optional": false, - "type": "string" - }, - { - "name": "topic", - "optional": false, - "description": "Topic name can be any string.", - "type": "string" - }, - { - "name": "joinedOnce", - "optional": false, - "type": null - }, - { - "name": "joinPush", - "optional": false, - "type": null - }, - { - "name": "rejoinTimer", - "optional": false, - "type": null - }, - { - "name": "state", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "copyBindings", - "optional": false, - "type": null - }, - { - "name": "httpSend", - "optional": false, - "type": null - }, - { - "name": "on", - "optional": false, - "description": "Listen to realtime events on this channel.", - "type": null - }, - { - "name": "presenceState", - "optional": false, - "type": null - }, - { - "name": "send", - "optional": false, - "type": null - }, - { - "name": "subscribe", - "optional": false, - "type": null - }, - { - "name": "teardown", - "optional": false, - "type": null - }, - { - "name": "track", - "optional": false, - "type": null - }, - { - "name": "unsubscribe", - "optional": false, - "type": null - }, - { - "name": "untrack", - "optional": false, - "type": null - }, - { - "name": "updateJoinPayload", - "optional": false, - "type": null - } - ] - } + ] + } + ] } - }, + } + ] + } + ] + } + }, + { + "name": "updateUserById", + "description": "Updates the user data. Changes are applied directly without confirmation flows.", + "remarks": [ + "**Important:** This is a server-side operation and does **not** trigger client-side `onAuthStateChange` listeners. The admin API has no connection to client state.\nTo sync changes to the client after calling this method: 1. On the client, call `supabase.auth.refreshSession()` to fetch the updated user data 2. This will trigger the `TOKEN_REFRESHED` event and notify all listeners" + ], + "parameters": [ + { + "name": "uid", + "description": "The user's unique identifier", + "type": "string" + }, + { + "name": "attributes", + "description": "The data you want to update.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "type": { + "kind": "object", + "name": "AdminUserAttributes", + "properties": [ { - "name": "fetch", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", + "name": "app_metadata", "optional": true, - "type": { - "kind": "object", - "properties": [] - } + "description": "A custom data object to store the user's application specific metadata. This maps to the `auth.users.app_metadata` column.\nOnly a service role can modify.\nThe `app_metadata` should be a JSON object that includes app-specific info, such as identity providers, roles, and other access control information.", + "type": "object" }, { - "name": "httpEndpoint", - "optional": false, + "name": "ban_duration", + "optional": true, + "description": "Determines how long a user is banned for.\nThe format for the ban duration follows a strict sequence of decimal numbers with a unit suffix. Valid time units are \"ns\", \"us\" (or \"µs\"), \"ms\", \"s\", \"m\", \"h\".\nFor example, some possible durations include: '300ms', '2h45m'.\nSetting the ban duration to 'none' lifts the ban on the user.", "type": "string" }, { - "name": "logLevel", + "name": "current_password", "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } + "description": "The user's current password\nThis is only ever present when the user is resetting their password and GOTRUE_SECURITY_UPDATE_PASSWORD_REQUIRE_CURRENT_PASSWORD is true.", + "type": "string" }, { - "name": "params", + "name": "email", "optional": true, - "type": { - "kind": "object", - "properties": [] - } + "description": "The user's email.", + "type": "string" }, { - "name": "ref", - "optional": false, - "type": "number" - }, - { - "name": "serializer", - "optional": false, - "type": { - "kind": "reference", - "name": "Serializer" - } - }, - { - "name": "worker", + "name": "email_confirm", "optional": true, + "description": "Sets the user's email as confirmed when true, or unconfirmed when false.\nOnly a service role can modify.", "type": "boolean" }, { - "name": "workerRef", - "optional": true, - "type": { - "kind": "reference", - "name": "Worker" - } - }, - { - "name": "workerUrl", + "name": "id", "optional": true, + "description": "The `id` for the user.\nAllows you to overwrite the default `id` set for the user.", "type": "string" }, { - "name": "decode", - "optional": false, - "type": null + "name": "nonce", + "optional": true, + "description": "The nonce sent for reauthentication if the user's password is to be updated.\nCall reauthenticate() to obtain the nonce first.", + "type": "string" }, { - "name": "encode", - "optional": false, - "type": null + "name": "password", + "optional": true, + "description": "The user's password.", + "type": "string" }, { - "name": "endPoint", - "optional": false, - "type": null + "name": "password_hash", + "optional": true, + "description": "The `password_hash` for the user's password.\nAllows you to specify a password hash for the user. This is useful for migrating a user's password hash from another service.\nSupports bcrypt, scrypt (firebase), and argon2 password hashes.", + "type": "string" }, { - "name": "heartbeatCallback", - "optional": false, - "type": null + "name": "phone", + "optional": true, + "description": "The user's phone.", + "type": "string" }, { - "name": "heartbeatIntervalMs", - "optional": false, - "type": null + "name": "phone_confirm", + "optional": true, + "description": "Sets the user's phone as confirmed when true, or unconfirmed when false.\nOnly a service role can modify.", + "type": "boolean" }, { - "name": "heartbeatTimer", - "optional": false, - "type": null + "name": "role", + "optional": true, + "description": "The `role` claim set in the user's access token JWT.\nWhen a user signs up, this role is set to `authenticated` by default. You should only modify the `role` if you need to provision several levels of admin access that have different permissions on individual columns in your database.\nSetting this role to `service_role` is not recommended as it grants the user admin privileges.", + "type": "string" }, { - "name": "pendingHeartbeatRef", - "optional": false, - "type": null - }, - { - "name": "reconnectAfterMs", - "optional": false, - "type": null - }, - { - "name": "reconnectTimer", - "optional": false, - "type": null - }, - { - "name": "sendBuffer", - "optional": false, - "type": null - }, - { - "name": "stateChangeCallbacks", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "transport", - "optional": false, - "type": null - }, - { - "name": "vsn", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": null - }, - { - "name": "connect", - "optional": false, - "type": null - }, - { - "name": "connectionState", - "optional": false, - "type": null - }, - { - "name": "disconnect", - "optional": false, - "type": null - }, - { - "name": "endpointURL", - "optional": false, - "type": null - }, - { - "name": "getChannels", - "optional": false, - "type": null - }, - { - "name": "isConnected", - "optional": false, - "type": null - }, - { - "name": "isConnecting", - "optional": false, - "type": null - }, - { - "name": "isDisconnecting", - "optional": false, - "type": null - }, - { - "name": "log", - "optional": false, - "type": null - }, - { - "name": "onHeartbeat", - "optional": false, - "type": null - }, - { - "name": "push", - "optional": false, - "type": null - }, - { - "name": "removeAllChannels", - "optional": false, - "type": null - }, - { - "name": "removeChannel", - "optional": false, - "type": null - }, - { - "name": "sendHeartbeat", - "optional": false, - "type": null - }, - { - "name": "setAuth", - "optional": false, - "type": null + "name": "user_metadata", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `user_metadata` should be a JSON object that includes user-specific info, such as their first and last name.\nNote: When using the GoTrueAdminApi and wanting to modify a user's metadata, this attribute is used instead of UserAttributes data.", + "type": "object" } ] } } ], "returnType": { - "kind": "object", - "name": "RealtimeChannel", - "properties": [ + "kind": "reference", + "name": "Promise", + "typeArguments": [ { - "name": "constructor", - "optional": false, - "type": null - }, + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Example 1", + "code": "// Server-side (Edge Function)\nconst { data, error } = await supabase.auth.admin.updateUserById(\n userId,\n { user_metadata: { preferences: { theme: 'dark' } } }\n)\n\n// Client-side (to sync the changes)\nconst { data, error } = await supabase.auth.refreshSession()\n// onAuthStateChange listeners will now be notified with updated user", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"new@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"recovery_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" + }, + { + "title": "Updates a user's email", + "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '11111111-1111-1111-1111-111111111111',\n { email: 'new@email.com' }\n)", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"new@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"recovery_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" + }, + { + "title": "Updates a user's password", + "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { password: 'new_password' }\n)" + }, + { + "title": "Updates a user's metadata", + "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { user_metadata: { hello: 'world' } }\n)" + }, + { + "title": "Updates a user's app_metadata", + "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { app_metadata: { plan: 'trial' } }\n)" + }, + { + "title": "Confirms a user's email address", + "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { email_confirm: true }\n)" + }, + { + "title": "Confirms a user's phone number", + "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { phone_confirm: true }\n)" + }, + { + "title": "Ban a user for 100 years", + "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { ban_duration: '876000h' }\n)" + } + ] + }, + { + "name": "exchangeCodeForSession", + "description": "Log in an existing user by exchanging an Auth Code issued during the PKCE flow.", + "remarks": [ + "- Used when `flowType` is set to `pkce` in client options." + ], + "parameters": [ + { + "name": "authCode", + "type": "string" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ { - "name": "bindings", - "optional": false, - "type": { - "kind": "reference", - "name": "Record", - "typeArguments": [ - "string", - { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "object", + "name": "Session", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Exchange Auth Code", + "code": "supabase.auth.exchangeCodeForSession('34e770dd-9ff9-416c-87fa-43b31d7ef225')", + "response": "{\n \"data\": {\n session: {\n access_token: '',\n token_type: 'bearer',\n expires_in: 3600,\n expires_at: 1700000000,\n refresh_token: '',\n user: {\n id: '11111111-1111-1111-1111-111111111111',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com'\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {\n \"provider\": \"email\",\n \"providers\": [\n \"email\",\n \"\"\n ]\n },\n user_metadata: {\n email: 'email@email.com',\n email_verified: true,\n full_name: 'User Name',\n iss: '',\n name: 'User Name',\n phone_verified: false,\n provider_id: '',\n sub: ''\n },\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n {\n \"identity_id\": \"33333333-3333-3333-3333-333333333333\",\n \"id\": \"\",\n \"user_id\": \"\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"full_name\": \"User Name\",\n \"iss\": \"\",\n \"name\": \"User Name\",\n \"phone_verified\": false,\n \"provider_id\": \"\",\n \"sub\": \"\"\n },\n \"provider\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false\n },\n provider_token: '',\n provider_refresh_token: ''\n },\n user: {\n id: '11111111-1111-1111-1111-111111111111',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {\n provider: 'email',\n providers: [\n \"email\",\n \"\"\n ]\n },\n user_metadata: {\n email: 'email@email.com',\n email_verified: true,\n full_name: 'User Name',\n iss: '',\n name: 'User Name',\n phone_verified: false,\n provider_id: '',\n sub: ''\n },\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n {\n \"identity_id\": \"33333333-3333-3333-3333-333333333333\",\n \"id\": \"\",\n \"user_id\": \"\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"full_name\": \"User Name\",\n \"iss\": \"\",\n \"name\": \"User Name\",\n \"phone_verified\": false,\n \"provider_id\": \"\",\n \"sub\": \"\"\n },\n \"provider\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false\n },\n redirectType: null\n },\n \"error\": null\n}" + } + ] + }, + { + "name": "getClaims", + "description": "Extracts the JWT claims present in the access token by first verifying the JWT against the server's JSON Web Key Set endpoint `/.well-known/jwks.json` which is often cached, resulting in significantly faster responses. Prefer this method over #getUser which always sends a request to the Auth server for each JWT.\nIf the project is not using an asymmetric JWT signing key (like ECC or RSA) it always sends a request to the Auth server (similar to #getUser) to verify the JWT.", + "remarks": [ + "- Parses the user's [access token](/docs/guides/auth/sessions#access-token-jwt-claims) as a [JSON Web Token (JWT)](/docs/guides/auth/jwts) and returns its components if valid and not expired. - If your project is using asymmetric JWT signing keys, then the verification is done locally usually without a network request using the [WebCrypto API](https://developer.mozilla.org/en-US/docs/Web/API/Web_Crypto_API). - A network request is sent to your project's JWT signing key discovery endpoint `https://project-id.supabase.co/auth/v1/.well-known/jwks.json`, which is cached locally. If your environment is ephemeral, such as a Lambda function that is destroyed after every request, a network request will be sent for each new invocation. Supabase provides a network-edge cache providing fast responses for these situations. - If the user's access token is about to expire when calling this function, the user's session will first be refreshed before validating the JWT. - If your project is using a symmetric secret to sign the JWT, it always sends a request similar to `getUser()` to validate the JWT at the server before returning the decoded token. This is also used if the WebCrypto API is not available in the environment. Make sure you polyfill it in such situations. - The returned claims can be customized per project using the [Custom Access Token Hook](/docs/guides/auth/auth-hooks/custom-access-token-hook)." + ], + "parameters": [ + { + "name": "jwt", + "optional": true, + "description": "An optional specific JWT you wish to verify, not the one you can obtain from #getSession.", + "type": "string" + }, + { + "name": "options", + "description": "Various additional options that allow you to customize the behavior of this method.", + "type": { + "kind": "object", + "properties": [ + { + "name": "allowExpired", + "optional": true, + "description": "If set to `true` the `exp` claim will not be validated against the current time.", + "type": "boolean" + }, + { + "name": "jwks", + "optional": true, + "description": "If set, this JSON Web Key Set is going to have precedence over the cached value available on the server.", + "type": { + "kind": "object", + "properties": [ + { + "name": "keys", + "optional": false, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "JWK", + "properties": [ + { + "name": "alg", + "optional": true, + "type": "string" + }, + { + "name": "key_ops", + "optional": false, + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "kid", + "optional": true, + "type": "string" + }, + { + "name": "kty", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "RSA" + }, + { + "kind": "literal", + "value": "EC" + }, + { + "kind": "literal", + "value": "oct" + } + ] + } + } + ] + } + } + } + ] + } + }, + { + "name": "keys", + "optional": true, + "type": { "kind": "array", "elementType": { - "kind": "reference", - "name": "Binding" + "kind": "object", + "name": "JWK", + "properties": [ + { + "name": "alg", + "optional": true, + "type": "string" + }, + { + "name": "key_ops", + "optional": false, + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "kid", + "optional": true, + "type": "string" + }, + { + "name": "kty", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "RSA" + }, + { + "kind": "literal", + "value": "EC" + }, + { + "kind": "literal", + "value": "oct" + } + ] + } + } + ] } } - ] - } - }, + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ { - "name": "broadcastEndpointURL", - "optional": false, - "type": "string" - }, + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "claims", + "optional": false, + "type": { + "kind": "object", + "name": "JwtPayload", + "properties": [ + { + "name": "aal", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "aal1" + }, + { + "kind": "literal", + "value": "aal2" + } + ] + } + }, + { + "name": "amr", + "optional": true, + "description": "Authentication Method References. Supports both RFC-8176 compliant format (string[]) and detailed format (AMREntry[]). - String format: ['password', 'otp'] - RFC-8176 compliant - Object format: [{ method: 'password', timestamp: 1234567890 }] - includes timestamps", + "type": { + "kind": "union", + "types": [ + { + "kind": "array", + "elementType": "string" + }, + { + "kind": "array", + "elementType": { + "kind": "object", + "name": "AMREntry", + "properties": [ + { + "name": "method", + "optional": false, + "description": "Authentication method name.", + "type": { + "kind": "union", + "types": [ + { + "kind": "indexedAccess", + "objectType": { + "kind": "query" + }, + "indexType": null + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "timestamp", + "optional": false, + "description": "Timestamp when the method was successfully used. Represents number of seconds since 1st January 1970 (UNIX epoch) in UTC.", + "type": "number" + } + ] + } + } + ] + } + }, + { + "name": "app_metadata", + "optional": true, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": { + "kind": "union", + "types": [ + "string", + { + "kind": "array", + "elementType": "string" + } + ] + } + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "exp", + "optional": false, + "type": "number" + }, + { + "name": "iat", + "optional": false, + "type": "number" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "iss", + "optional": false, + "type": "string" + }, + { + "name": "jti", + "optional": true, + "type": "string" + }, + { + "name": "nbf", + "optional": true, + "type": "number" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "ref", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": false, + "type": "string" + }, + { + "name": "session_id", + "optional": false, + "type": "string" + }, + { + "name": "sub", + "optional": false, + "type": "string" + }, + { + "name": "user_metadata", + "optional": true, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + }, + { + "name": "header", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "alg", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "RS256" + }, + { + "kind": "literal", + "value": "ES256" + }, + { + "kind": "literal", + "value": "HS256" + } + ] + } + }, + { + "name": "kid", + "optional": false, + "type": "string" + }, + { + "name": "typ", + "optional": false, + "type": "string" + } + ], + "name": "JwtHeader" + } + }, + { + "name": "signature", + "optional": false, + "type": { + "kind": "reference", + "name": "Uint8Array" + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Get JWT claims, header and signature", + "code": "const { data, error } = await supabase.auth.getClaims()", + "response": "{\n \"data\": {\n \"claims\": {\n \"aal\": \"aal1\",\n \"amr\": [{\n \"method\": \"email\",\n \"timestamp\": 1715766000\n }],\n \"app_metadata\": {},\n \"aud\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"exp\": 1715769600,\n \"iat\": 1715766000,\n \"is_anonymous\": false,\n \"iss\": \"https://project-id.supabase.co/auth/v1\",\n \"phone\": \"+13334445555\",\n \"role\": \"authenticated\",\n \"session_id\": \"11111111-1111-1111-1111-111111111111\",\n \"sub\": \"11111111-1111-1111-1111-111111111111\",\n \"user_metadata\": {}\n },\n \"header\": {\n \"alg\": \"RS256\",\n \"typ\": \"JWT\",\n \"kid\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"signature\": [/** Uint8Array */],\n },\n \"error\": null\n}" + } + ] + }, + { + "name": "getSession", + "description": "Returns the session, refreshing it if necessary.\nThe session returned can be null if the session is not detected which can happen in the event a user is not signed-in or has logged out.\n**IMPORTANT:** This method loads values directly from the storage attached to the client. If that storage is based on request cookies for example, the values in it may not be authentic and therefore it's strongly advised against using this method and its results in such circumstances. A warning will be emitted if this is detected. Use #getUser() instead.", + "remarks": [ + "- Since the introduction of [asymmetric JWT signing keys](/docs/guides/auth/signing-keys), this method is considered low-level and we encourage you to use `getClaims()` or `getUser()` instead. - Retrieves the current [user session](/docs/guides/auth/sessions) from the storage medium (local storage, cookies). - The session contains an access token (signed JWT), a refresh token and the user object. - If the session's access token is expired or is about to expire, this method will use the refresh token to refresh the session. - When using in a browser, or you've called `startAutoRefresh()` in your environment (React Native, etc.) this function always returns a valid access token without refreshing the session itself, as this is done in the background. This function returns very fast. - **IMPORTANT SECURITY NOTICE:** If using an insecure storage medium, such as cookies or request headers, the user object returned by this function **must not be trusted**. Always verify the JWT using `getClaims()` or your own JWT verification library to securely establish the user's identity and access. You can also use `getUser()` to fetch the user object directly from the Auth server for this purpose. - When using in a browser, this function is synchronized across all tabs using the [LockManager](https://developer.mozilla.org/en-US/docs/Web/API/LockManager) API. In other environments make sure you've defined a proper `lock` property, if necessary, to make sure there are no race conditions while the session is being refreshed." + ], + "parameters": [], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ { - "name": "params", + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "object", + "name": "Session", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Get the session data", + "code": "const { data, error } = await supabase.auth.getSession()", + "response": "{\n \"data\": {\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n }\n },\n \"error\": null\n}" + } + ] + }, + { + "name": "getUser", + "description": "Gets the current user details if there is an existing session. This method performs a network request to the Supabase Auth server, so the returned value is authentic and can be used to base authorization rules on.", + "remarks": [ + "- This method fetches the user object from the database instead of local session. - This method is useful for checking if the user is authorized because it validates the user's access token JWT on the server. - Should always be used when checking for user authorization on the server. On the client, you can instead use `getSession().session.user` for faster results. `getSession` is insecure on the server." + ], + "parameters": [ + { + "name": "jwt", + "optional": true, + "description": "Takes in an optional access token JWT. If no JWT is provided, the JWT from the current session is used.", + "type": "string" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Get the logged in user with the current existing session", + "code": "const { data: { user } } = await supabase.auth.getUser()", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" + }, + { + "title": "Get the logged in user with a custom access token jwt", + "code": "const { data: { user } } = await supabase.auth.getUser(jwt)" + } + ] + }, + { + "name": "getUserIdentities", + "description": "Gets all the identities linked to a user.", + "remarks": [ + "- The user needs to be signed in to call `getUserIdentities()`." + ], + "parameters": [], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "identities", + "optional": false, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Returns a list of identities linked to the user", + "code": "const { data, error } = await supabase.auth.getUserIdentities()", + "response": "{\n \"data\": {\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"2024-01-01T00:00:00Z\",\n \"user_id\": \"2024-01-01T00:00:00Z\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ]\n },\n \"error\": null\n}" + } + ] + }, + { + "name": "initialize", + "description": "Initializes the client session either from the url or from storage. This method is automatically called when instantiating the client, but should also be called manually when checking for an error from an auth redirect (oauth, magiclink, password recovery, etc).", + "parameters": [], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "object", + "properties": [ + { + "name": "error", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + } + ], + "name": "InitializeResult" + } + ] + } + }, + { + "name": "linkIdentity", + "description": "", + "remarks": [ + "- The **Enable Manual Linking** option must be enabled from your [project's authentication settings](/dashboard/project/_/auth/providers). - The user needs to be signed in to call `linkIdentity()`. - If the candidate identity is already linked to the existing user or another user, `linkIdentity()` will fail. - If `linkIdentity` is run in the browser, the user is automatically redirected to the returned URL. On the server, you should handle the redirect." + ], + "parameters": [ + { + "name": "credentials", + "type": { + "kind": "object", + "properties": [ + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "queryParams", + "optional": true, + "description": "An object of query params", + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "redirectTo", + "optional": true, + "description": "A URL to send the user to after they are confirmed.", + "type": "string" + }, + { + "name": "scopes", + "optional": true, + "description": "A space-separated list of scopes granted to the OAuth application.", + "type": "string" + }, + { + "name": "skipBrowserRedirect", + "optional": true, + "description": "If set to true does not immediately redirect the current browser context to visit the OAuth authorization page for the provider.", + "type": "boolean" + } + ] + } + }, + { + "name": "provider", + "optional": false, + "description": "One of the providers supported by GoTrue.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "apple" + }, + { + "kind": "literal", + "value": "azure" + }, + { + "kind": "literal", + "value": "bitbucket" + }, + { + "kind": "literal", + "value": "discord" + }, + { + "kind": "literal", + "value": "facebook" + }, + { + "kind": "literal", + "value": "figma" + }, + { + "kind": "literal", + "value": "github" + }, + { + "kind": "literal", + "value": "gitlab" + }, + { + "kind": "literal", + "value": "google" + }, + { + "kind": "literal", + "value": "kakao" + }, + { + "kind": "literal", + "value": "keycloak" + }, + { + "kind": "literal", + "value": "linkedin" + }, + { + "kind": "literal", + "value": "linkedin_oidc" + }, + { + "kind": "literal", + "value": "notion" + }, + { + "kind": "literal", + "value": "slack" + }, + { + "kind": "literal", + "value": "slack_oidc" + }, + { + "kind": "literal", + "value": "spotify" + }, + { + "kind": "literal", + "value": "twitch" + }, + { + "kind": "literal", + "value": "twitter" + }, + { + "kind": "literal", + "value": "x" + }, + { + "kind": "literal", + "value": "workos" + }, + { + "kind": "literal", + "value": "zoom" + }, + { + "kind": "literal", + "value": "fly" + }, + { + "kind": "templateLiteral" + } + ] + } + } + ], + "name": "SignInWithOAuthCredentials" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "provider", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "apple" + }, + { + "kind": "literal", + "value": "azure" + }, + { + "kind": "literal", + "value": "bitbucket" + }, + { + "kind": "literal", + "value": "discord" + }, + { + "kind": "literal", + "value": "facebook" + }, + { + "kind": "literal", + "value": "figma" + }, + { + "kind": "literal", + "value": "github" + }, + { + "kind": "literal", + "value": "gitlab" + }, + { + "kind": "literal", + "value": "google" + }, + { + "kind": "literal", + "value": "kakao" + }, + { + "kind": "literal", + "value": "keycloak" + }, + { + "kind": "literal", + "value": "linkedin" + }, + { + "kind": "literal", + "value": "linkedin_oidc" + }, + { + "kind": "literal", + "value": "notion" + }, + { + "kind": "literal", + "value": "slack" + }, + { + "kind": "literal", + "value": "slack_oidc" + }, + { + "kind": "literal", + "value": "spotify" + }, + { + "kind": "literal", + "value": "twitch" + }, + { + "kind": "literal", + "value": "twitter" + }, + { + "kind": "literal", + "value": "x" + }, + { + "kind": "literal", + "value": "workos" + }, + { + "kind": "literal", + "value": "zoom" + }, + { + "kind": "literal", + "value": "fly" + }, + { + "kind": "templateLiteral" + } + ] + } + }, + { + "name": "url", + "optional": false, + "type": "string" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "provider", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "apple" + }, + { + "kind": "literal", + "value": "azure" + }, + { + "kind": "literal", + "value": "bitbucket" + }, + { + "kind": "literal", + "value": "discord" + }, + { + "kind": "literal", + "value": "facebook" + }, + { + "kind": "literal", + "value": "figma" + }, + { + "kind": "literal", + "value": "github" + }, + { + "kind": "literal", + "value": "gitlab" + }, + { + "kind": "literal", + "value": "google" + }, + { + "kind": "literal", + "value": "kakao" + }, + { + "kind": "literal", + "value": "keycloak" + }, + { + "kind": "literal", + "value": "linkedin" + }, + { + "kind": "literal", + "value": "linkedin_oidc" + }, + { + "kind": "literal", + "value": "notion" + }, + { + "kind": "literal", + "value": "slack" + }, + { + "kind": "literal", + "value": "slack_oidc" + }, + { + "kind": "literal", + "value": "spotify" + }, + { + "kind": "literal", + "value": "twitch" + }, + { + "kind": "literal", + "value": "twitter" + }, + { + "kind": "literal", + "value": "x" + }, + { + "kind": "literal", + "value": "workos" + }, + { + "kind": "literal", + "value": "zoom" + }, + { + "kind": "literal", + "value": "fly" + }, + { + "kind": "templateLiteral" + } + ] + } + }, + { + "name": "url", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Link an identity to a user", + "code": "const { data, error } = await supabase.auth.linkIdentity({\n provider: 'github'\n})", + "response": "{\n data: {\n provider: 'github',\n url: \n },\n error: null\n}" + } + ] + }, + { + "name": "onAuthStateChange", + "description": "", + "remarks": [ + "- Subscribes to important events occurring on the user's session. - Use on the frontend/client. It is less useful on the server. - Events are emitted across tabs to keep your application's UI up-to-date. Some events can fire very frequently, based on the number of tabs open. Use a quick and efficient callback function, and defer or debounce as many operations as you can to be performed outside of the callback. - **Important:** A callback can be an `async` function and it runs synchronously during the processing of the changes causing the event. You can easily create a dead-lock by using `await` on a call to another method of the Supabase library. - Avoid using `async` functions as callbacks. - Limit the number of `await` calls in `async` callbacks. - Do not use other Supabase functions in the callback function. If you must, dispatch the functions once the callback has finished executing. Use this as a quick way to achieve this: ```js supabase.auth.onAuthStateChange((event, session) => { setTimeout(async () => { // await on other Supabase function here // this runs right after the callback has finished }, 0) }) ``` - Emitted events: - `INITIAL_SESSION` - Emitted right after the Supabase client is constructed and the initial session from storage is loaded. - `SIGNED_IN` - Emitted each time a user session is confirmed or re-established, including on user sign in and when refocusing a tab. - Avoid making assumptions as to when this event is fired, this may occur even when the user is already signed in. Instead, check the user object attached to the event to see if a new user has signed in and update your application's UI. - This event can fire very frequently depending on the number of tabs open in your application. - `SIGNED_OUT` - Emitted when the user signs out. This can be after: - A call to `supabase.auth.signOut()`. - After the user's session has expired for any reason: - User has signed out on another device. - The session has reached its timebox limit or inactivity timeout. - User has signed in on another device with single session per user enabled. - Check the [User Sessions](/docs/guides/auth/sessions) docs for more information. - Use this to clean up any local storage your application has associated with the user. - `TOKEN_REFRESHED` - Emitted each time a new access and refresh token are fetched for the signed in user. - It's best practice and highly recommended to extract the access token (JWT) and store it in memory for further use in your application. - Avoid frequent calls to `supabase.auth.getSession()` for the same purpose. - There is a background process that keeps track of when the session should be refreshed so you will always receive valid tokens by listening to this event. - The frequency of this event is related to the JWT expiry limit configured on your project. - `USER_UPDATED` - Emitted each time the `supabase.auth.updateUser()` method finishes successfully. Listen to it to update your application's UI based on new profile information. - `PASSWORD_RECOVERY` - Emitted instead of the `SIGNED_IN` event when the user lands on a page that includes a password recovery link in the URL. - Use it to show a UI to the user where they can [reset their password](/docs/guides/auth/passwords#resetting-a-users-password-forgot-password)." + ], + "parameters": [ + { + "name": "callback", + "description": "A callback function to be invoked when an auth event happens.", + "type": { + "kind": "object", + "properties": [] + } + } + ], + "returnType": { + "kind": "object", + "properties": [ + { + "name": "data", "optional": false, "type": { "kind": "object", "properties": [ { - "name": "config", + "name": "subscription", "optional": false, "type": { "kind": "object", + "name": "Subscription", "properties": [ { - "name": "broadcast", - "optional": true, - "description": "self option enables client to receive message it broadcast ack option instructs server to acknowledge that broadcast message was received replay option instructs server to replay broadcast messages", + "name": "callback", + "optional": false, + "description": "The function to call every time there is an event. eg: (eventName) => {}", "type": { "kind": "object", - "properties": [ - { - "name": "ack", - "optional": true, - "type": "boolean" - }, - { - "name": "replay", - "optional": true, - "type": { - "kind": "reference", - "name": "ReplayOption" - } - }, - { - "name": "self", - "optional": true, - "type": "boolean" - } + "properties": [] + } + }, + { + "name": "id", + "optional": false, + "description": "A unique identifier for this subscription, set by the client. This is an internal identifier used for managing callbacks and should not be relied upon by application code. Use the unsubscribe() method to remove listeners.", + "type": { + "kind": "union", + "types": [ + "string", + "symbol" ] } }, { - "name": "presence", + "name": "unsubscribe", + "optional": false, + "description": "Call this to remove the listener.", + "type": { + "kind": "object", + "properties": [] + } + } + ] + } + } + ] + } + } + ] + }, + "examples": [ + { + "title": "Listen to auth changes", + "code": "const { data } = supabase.auth.onAuthStateChange((event, session) => {\n console.log(event, session)\n\n if (event === 'INITIAL_SESSION') {\n // handle initial session\n } else if (event === 'SIGNED_IN') {\n // handle sign in event\n } else if (event === 'SIGNED_OUT') {\n // handle sign out event\n } else if (event === 'PASSWORD_RECOVERY') {\n // handle password recovery event\n } else if (event === 'TOKEN_REFRESHED') {\n // handle token refreshed event\n } else if (event === 'USER_UPDATED') {\n // handle user updated event\n }\n})\n\n// call unsubscribe to remove the callback\ndata.subscription.unsubscribe()", + "notes": "Listen to sign out\nMake sure you clear out any local data, such as local and session storage, after the client library has detected the user's sign out." + }, + { + "title": "Listen to sign out", + "code": "supabase.auth.onAuthStateChange((event, session) => {\n if (event === 'SIGNED_OUT') {\n console.log('SIGNED_OUT', session)\n\n // clear local and session storage\n [\n window.localStorage,\n window.sessionStorage,\n ].forEach((storage) => {\n Object.entries(storage)\n .forEach(([key]) => {\n storage.removeItem(key)\n })\n })\n }\n})", + "notes": "Make sure you clear out any local data, such as local and session storage, after the client library has detected the user's sign out." + }, + { + "title": "Store OAuth provider tokens on sign in", + "code": "// Register this immediately after calling createClient!\n// Because signInWithOAuth causes a redirect, you need to fetch the\n// provider tokens from the callback.\nsupabase.auth.onAuthStateChange((event, session) => {\n if (session && session.provider_token) {\n window.localStorage.setItem('oauth_provider_token', session.provider_token)\n }\n\n if (session && session.provider_refresh_token) {\n window.localStorage.setItem('oauth_provider_refresh_token', session.provider_refresh_token)\n }\n\n if (event === 'SIGNED_OUT') {\n window.localStorage.removeItem('oauth_provider_token')\n window.localStorage.removeItem('oauth_provider_refresh_token')\n }\n})", + "notes": "When using [OAuth (Social Login)](/docs/guides/auth/social-login) you sometimes wish to get access to the provider's access token and refresh token, in order to call provider APIs in the name of the user.\n\nFor example, if you are using [Sign in with Google](/docs/guides/auth/social-login/auth-google) you may want to use the provider token to call Google APIs on behalf of the user. Supabase Auth does not keep track of the provider access and refresh token, but does return them for you once, immediately after sign in. You can use the `onAuthStateChange` method to listen for the presence of the provider tokens and store them in local storage. You can further send them to your server's APIs for use on the backend.\n\nFinally, make sure you remove them from local storage on the `SIGNED_OUT` event. If the OAuth provider supports token revocation, make sure you call those APIs either from the frontend or schedule them to be called on the backend." + }, + { + "title": "Use React Context for the User's session", + "code": "const SessionContext = React.createContext(null)\n\nfunction main() {\n const [session, setSession] = React.useState(null)\n\n React.useEffect(() => {\n const {data: { subscription }} = supabase.auth.onAuthStateChange(\n (event, session) => {\n if (event === 'SIGNED_OUT') {\n setSession(null)\n } else if (session) {\n setSession(session)\n }\n })\n\n return () => {\n subscription.unsubscribe()\n }\n }, [])\n\n return (\n \n \n \n )\n}", + "notes": "Instead of relying on `supabase.auth.getSession()` within your React components, you can use a [React Context](https://react.dev/reference/react/createContext) to store the latest session information from the `onAuthStateChange` callback and access it that way." + }, + { + "title": "Listen to password recovery events", + "code": "supabase.auth.onAuthStateChange((event, session) => {\n if (event === 'PASSWORD_RECOVERY') {\n console.log('PASSWORD_RECOVERY', session)\n // show screen to update user's password\n showPasswordResetScreen(true)\n }\n})" + }, + { + "title": "Listen to sign in", + "code": "supabase.auth.onAuthStateChange((event, session) => {\n if (event === 'SIGNED_IN') console.log('SIGNED_IN', session)\n})" + }, + { + "title": "Listen to token refresh", + "code": "supabase.auth.onAuthStateChange((event, session) => {\n if (event === 'TOKEN_REFRESHED') console.log('TOKEN_REFRESHED', session)\n})" + }, + { + "title": "Listen to user updates", + "code": "supabase.auth.onAuthStateChange((event, session) => {\n if (event === 'USER_UPDATED') console.log('USER_UPDATED', session)\n})" + } + ] + }, + { + "name": "reauthenticate", + "description": "Sends a reauthentication OTP to the user's email or phone number. Requires the user to be signed-in.", + "remarks": [ + "- This method is used together with `updateUser()` when a user's password needs to be updated. - If you require your user to reauthenticate before updating their password, you need to enable the **Secure password change** option in your [project's email provider settings](/dashboard/project/_/auth/providers). - A user is only require to reauthenticate before updating their password if **Secure password change** is enabled and the user **hasn't recently signed in**. A user is deemed recently signed in if the session was created in the last 24 hours. - This method will send a nonce to the user's email. If the user doesn't have a confirmed email address, the method will send the nonce to the user's confirmed phone number instead. - After receiving the OTP, include it as the `nonce` in your `updateUser()` call to finalize the password change." + ], + "parameters": [], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "Session", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Send reauthentication nonce", + "code": "const { error } = await supabase.auth.reauthenticate()", + "notes": "Sends a reauthentication nonce to the user's email or phone number." + } + ] + }, + { + "name": "refreshSession", + "description": "Returns a new session, regardless of expiry status. Takes in an optional current session. If not passed in, then refreshSession() will attempt to retrieve it from getSession(). If the current session's refresh token is invalid, an error will be thrown.", + "remarks": [ + "- This method will refresh and return a new session whether the current one is expired or not." + ], + "parameters": [ + { + "name": "currentSession", + "optional": true, + "description": "The current session. If passed in, it must contain a refresh token.", + "type": { + "kind": "object", + "properties": [ + { + "name": "refresh_token", + "optional": false, + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "Session", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Refresh session using the current session", + "code": "const { data, error } = await supabase.auth.refreshSession()\nconst { session, user } = data", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n }\n },\n \"error\": null\n}" + }, + { + "title": "Refresh session using a refresh token", + "code": "const { data, error } = await supabase.auth.refreshSession({ refresh_token })\nconst { session, user } = data" + } + ] + }, + { + "name": "resend", + "description": "Resends an existing signup confirmation email, email change email, SMS OTP or phone change OTP.", + "remarks": [ + "- Resends a signup confirmation, email change or phone change email to the user. - Passwordless sign-ins can be resent by calling the `signInWithOtp()` method again. - Password recovery emails can be resent by calling the `resetPasswordForEmail()` method again. - This method will only resend an email or phone OTP to the user if there was an initial signup, email change or phone change request being made(note: For existing users signing in with OTP, you should use `signInWithOtp()` again to resend the OTP). - You can specify a redirect url when you resend an email link using the `emailRedirectTo` option." + ], + "parameters": [ + { + "name": "credentials", + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "email", + "optional": false, + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "emailRedirectTo", + "optional": true, + "description": "A URL to send the user to after they have signed-in.", + "type": "string" + } + ] + } + }, + { + "name": "type", + "optional": false, + "type": { + "kind": "reference", + "name": "Extract", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "signup" + }, + { + "kind": "literal", + "value": "invite" + }, + { + "kind": "literal", + "value": "magiclink" + }, + { + "kind": "literal", + "value": "recovery" + }, + { + "kind": "literal", + "value": "email_change" + }, + { + "kind": "literal", + "value": "email" + } + ] + }, + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "signup" + }, + { + "kind": "literal", + "value": "email_change" + } + ] + } + ] + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + } + ] + } + }, + { + "name": "phone", + "optional": false, + "type": "string" + }, + { + "name": "type", + "optional": false, + "type": { + "kind": "reference", + "name": "Extract", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "sms" + }, + { + "kind": "literal", + "value": "phone_change" + } + ] + }, + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "sms" + }, + { + "kind": "literal", + "value": "phone_change" + } + ] + } + ] + } + } + ] + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "messageId", + "optional": true, + "type": { + "kind": "union", + "types": [ + "string", + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "session", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Resend an email signup confirmation", + "code": "const { error } = await supabase.auth.resend({\n type: 'signup',\n email: 'email@example.com',\n options: {\n emailRedirectTo: 'https://example.com/welcome'\n }\n})", + "notes": "Resends the email signup confirmation to the user" + }, + { + "title": "Resend a phone signup confirmation", + "code": "const { error } = await supabase.auth.resend({\n type: 'sms',\n phone: '1234567890'\n})", + "notes": "Resends the phone signup confirmation email to the user" + }, + { + "title": "Resend email change email", + "code": "const { error } = await supabase.auth.resend({\n type: 'email_change',\n email: 'email@example.com'\n})", + "notes": "Resends the email change email to the user" + }, + { + "title": "Resend phone change OTP", + "code": "const { error } = await supabase.auth.resend({\n type: 'phone_change',\n phone: '1234567890'\n})", + "notes": "Resends the phone change OTP to the user" + } + ] + }, + { + "name": "resetPasswordForEmail", + "description": "Sends a password reset request to an email address. This method supports the PKCE flow.", + "remarks": [ + "- The password reset flow consist of 2 broad steps: (i) Allow the user to login via the password reset link; (ii) Update the user's password. - The `resetPasswordForEmail()` only sends a password reset link to the user's email. To update the user's password, see [`updateUser()`](/docs/reference/javascript/auth-updateuser). - A `PASSWORD_RECOVERY` event will be emitted when the password recovery link is clicked. You can use [`onAuthStateChange()`](/docs/reference/javascript/auth-onauthstatechange) to listen and invoke a callback function on these events. - When the user clicks the reset link in the email they are redirected back to your application. You can configure the URL that the user is redirected to with the `redirectTo` parameter. See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project. - After the user has been redirected successfully, prompt them for a new password and call `updateUser()`: ```js const { data, error } = await supabase.auth.updateUser({ password: new_password }) ```" + ], + "parameters": [ + { + "name": "email", + "description": "The email address of the user.", + "type": "string" + }, + { + "name": "options", + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "redirectTo", + "optional": true, + "description": "The URL to send the user to after they click the password reset link.", + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Reset password", + "code": "const { data, error } = await supabase.auth.resetPasswordForEmail(email, {\n redirectTo: 'https://example.com/update-password',\n})", + "response": "{\n data: {}\n error: null\n}" + }, + { + "title": "Reset password (React)", + "code": "/**\n * Step 1: Send the user an email to get a password reset token.\n * This email contains a link which sends the user back to your application.\n */\nconst { data, error } = await supabase.auth\n .resetPasswordForEmail('user@email.com')\n\n/**\n * Step 2: Once the user is redirected back to your application,\n * ask the user to reset their password.\n */\n useEffect(() => {\n supabase.auth.onAuthStateChange(async (event, session) => {\n if (event == \"PASSWORD_RECOVERY\") {\n const newPassword = prompt(\"What would you like your new password to be?\");\n const { data, error } = await supabase.auth\n .updateUser({ password: newPassword })\n\n if (data) alert(\"Password updated successfully!\")\n if (error) alert(\"There was an error updating your password.\")\n }\n })\n }, [])" + } + ] + }, + { + "name": "setSession", + "description": "Sets the session data from the current session. If the current session is expired, setSession will take care of refreshing it to obtain a new session. If the refresh token or access token in the current session is invalid, an error will be thrown.", + "remarks": [ + "- This method sets the session using an `access_token` and `refresh_token`. - If successful, a `SIGNED_IN` event is emitted." + ], + "parameters": [ + { + "name": "currentSession", + "description": "The current session that minimally contains an access token and refresh token.", + "type": { + "kind": "object", + "properties": [ + { + "name": "access_token", + "optional": false, + "type": "string" + }, + { + "name": "refresh_token", + "optional": false, + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "Session", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Set the session", + "code": "const { data, error } = await supabase.auth.setSession({\n access_token,\n refresh_token\n })", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n },\n \"session\": {\n \"access_token\": \"\",\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"11111111-1111-1111-1111-111111111111\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"2024-01-01T00:00:00Z\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n },\n \"token_type\": \"bearer\",\n \"expires_in\": 3500,\n \"expires_at\": 1700000000\n }\n },\n \"error\": null\n}", + "notes": "Sets the session data from an access_token and refresh_token, then returns an auth response or error." + } + ] + }, + { + "name": "signInAnonymously", + "description": "Creates a new anonymous user.", + "remarks": [ + "- Returns an anonymous user - It is recommended to set up captcha for anonymous sign-ins to prevent abuse. You can pass in the captcha token in the `options` param." + ], + "parameters": [ + { + "name": "credentials", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "data", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", + "type": "object" + } + ] + } + } + ], + "name": "SignInAnonymouslyCredentials" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "Session", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Create an anonymous user", + "code": "const { data, error } = await supabase.auth.signInAnonymously({\n options: {\n captchaToken\n }\n});", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {},\n \"user_metadata\": {},\n \"identities\": [],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": true\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {},\n \"user_metadata\": {},\n \"identities\": [],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": true\n }\n }\n },\n \"error\": null\n}" + }, + { + "title": "Create an anonymous user with custom user metadata", + "code": "const { data, error } = await supabase.auth.signInAnonymously({\n options: {\n data\n }\n})" + } + ] + }, + { + "name": "signInWithIdToken", + "description": "Allows signing in with an OIDC ID token. The authentication provider used should be enabled and configured.", + "remarks": [ + "- Use an ID token to sign in. - Especially useful when implementing sign in using native platform dialogs in mobile or desktop apps using Sign in with Apple or Sign in with Google on iOS and Android. - You can also use Google's [One Tap](https://developers.google.com/identity/gsi/web/guides/display-google-one-tap) and [Automatic sign-in](https://developers.google.com/identity/gsi/web/guides/automatic-sign-in-sign-out) via this API." + ], + "parameters": [ + { + "name": "credentials", + "type": { + "kind": "object", + "properties": [ + { + "name": "access_token", + "optional": true, + "description": "If the ID token contains an `at_hash` claim, then the hash of this value is compared to the value in the ID token.", + "type": "string" + }, + { + "name": "nonce", + "optional": true, + "description": "If the ID token contains a `nonce` claim, then the hash of this value is compared to the value in the ID token.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + } + ] + } + }, + { + "name": "provider", + "optional": false, + "description": "Provider name or OIDC `iss` value identifying which provider should be used to verify the provided token. Supported names: `google`, `apple`, `azure`, `facebook`, `kakao`. Use the `custom:` prefix for custom OIDC providers (e.g. `custom:my-oidc-provider`).", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "google" + }, + { + "kind": "literal", + "value": "apple" + }, + { + "kind": "literal", + "value": "azure" + }, + { + "kind": "literal", + "value": "facebook" + }, + { + "kind": "literal", + "value": "kakao" + }, + { + "kind": "templateLiteral" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "token", + "optional": false, + "description": "OIDC ID token issued by the specified provider. The `iss` claim in the ID token must match the supplied provider. Some ID tokens contain an `at_hash` which require that you provide an `access_token` value to be accepted properly. If the token contains a `nonce` claim you must supply the nonce used to obtain the ID token.", + "type": "string" + } + ], + "name": "SignInWithIdTokenCredentials" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "object", + "name": "Session", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Sign In using ID Token", + "code": "const { data, error } = await supabase.auth.signInWithIdToken({\n provider: 'google',\n token: 'your-id-token'\n})", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n ...\n },\n \"user_metadata\": {\n ...\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"provider\": \"google\",\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n ...\n },\n \"user_metadata\": {\n ...\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"provider\": \"google\",\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n }\n }\n },\n \"error\": null\n}" + } + ] + }, + { + "name": "signInWithOAuth", + "description": "Log in an existing user via a third-party provider. This method supports the PKCE flow.", + "remarks": [ + "- This method is used for signing in using [Social Login (OAuth) providers](/docs/guides/auth#configure-third-party-providers). - It works by redirecting your application to the provider's authorization screen, before bringing back the user to your app." + ], + "parameters": [ + { + "name": "credentials", + "type": { + "kind": "object", + "properties": [ + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "queryParams", + "optional": true, + "description": "An object of query params", + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "redirectTo", + "optional": true, + "description": "A URL to send the user to after they are confirmed.", + "type": "string" + }, + { + "name": "scopes", + "optional": true, + "description": "A space-separated list of scopes granted to the OAuth application.", + "type": "string" + }, + { + "name": "skipBrowserRedirect", + "optional": true, + "description": "If set to true does not immediately redirect the current browser context to visit the OAuth authorization page for the provider.", + "type": "boolean" + } + ] + } + }, + { + "name": "provider", + "optional": false, + "description": "One of the providers supported by GoTrue.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "apple" + }, + { + "kind": "literal", + "value": "azure" + }, + { + "kind": "literal", + "value": "bitbucket" + }, + { + "kind": "literal", + "value": "discord" + }, + { + "kind": "literal", + "value": "facebook" + }, + { + "kind": "literal", + "value": "figma" + }, + { + "kind": "literal", + "value": "github" + }, + { + "kind": "literal", + "value": "gitlab" + }, + { + "kind": "literal", + "value": "google" + }, + { + "kind": "literal", + "value": "kakao" + }, + { + "kind": "literal", + "value": "keycloak" + }, + { + "kind": "literal", + "value": "linkedin" + }, + { + "kind": "literal", + "value": "linkedin_oidc" + }, + { + "kind": "literal", + "value": "notion" + }, + { + "kind": "literal", + "value": "slack" + }, + { + "kind": "literal", + "value": "slack_oidc" + }, + { + "kind": "literal", + "value": "spotify" + }, + { + "kind": "literal", + "value": "twitch" + }, + { + "kind": "literal", + "value": "twitter" + }, + { + "kind": "literal", + "value": "x" + }, + { + "kind": "literal", + "value": "workos" + }, + { + "kind": "literal", + "value": "zoom" + }, + { + "kind": "literal", + "value": "fly" + }, + { + "kind": "templateLiteral" + } + ] + } + } + ], + "name": "SignInWithOAuthCredentials" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "provider", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "apple" + }, + { + "kind": "literal", + "value": "azure" + }, + { + "kind": "literal", + "value": "bitbucket" + }, + { + "kind": "literal", + "value": "discord" + }, + { + "kind": "literal", + "value": "facebook" + }, + { + "kind": "literal", + "value": "figma" + }, + { + "kind": "literal", + "value": "github" + }, + { + "kind": "literal", + "value": "gitlab" + }, + { + "kind": "literal", + "value": "google" + }, + { + "kind": "literal", + "value": "kakao" + }, + { + "kind": "literal", + "value": "keycloak" + }, + { + "kind": "literal", + "value": "linkedin" + }, + { + "kind": "literal", + "value": "linkedin_oidc" + }, + { + "kind": "literal", + "value": "notion" + }, + { + "kind": "literal", + "value": "slack" + }, + { + "kind": "literal", + "value": "slack_oidc" + }, + { + "kind": "literal", + "value": "spotify" + }, + { + "kind": "literal", + "value": "twitch" + }, + { + "kind": "literal", + "value": "twitter" + }, + { + "kind": "literal", + "value": "x" + }, + { + "kind": "literal", + "value": "workos" + }, + { + "kind": "literal", + "value": "zoom" + }, + { + "kind": "literal", + "value": "fly" + }, + { + "kind": "templateLiteral" + } + ] + } + }, + { + "name": "url", + "optional": false, + "type": "string" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "provider", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "apple" + }, + { + "kind": "literal", + "value": "azure" + }, + { + "kind": "literal", + "value": "bitbucket" + }, + { + "kind": "literal", + "value": "discord" + }, + { + "kind": "literal", + "value": "facebook" + }, + { + "kind": "literal", + "value": "figma" + }, + { + "kind": "literal", + "value": "github" + }, + { + "kind": "literal", + "value": "gitlab" + }, + { + "kind": "literal", + "value": "google" + }, + { + "kind": "literal", + "value": "kakao" + }, + { + "kind": "literal", + "value": "keycloak" + }, + { + "kind": "literal", + "value": "linkedin" + }, + { + "kind": "literal", + "value": "linkedin_oidc" + }, + { + "kind": "literal", + "value": "notion" + }, + { + "kind": "literal", + "value": "slack" + }, + { + "kind": "literal", + "value": "slack_oidc" + }, + { + "kind": "literal", + "value": "spotify" + }, + { + "kind": "literal", + "value": "twitch" + }, + { + "kind": "literal", + "value": "twitter" + }, + { + "kind": "literal", + "value": "x" + }, + { + "kind": "literal", + "value": "workos" + }, + { + "kind": "literal", + "value": "zoom" + }, + { + "kind": "literal", + "value": "fly" + }, + { + "kind": "templateLiteral" + } + ] + } + }, + { + "name": "url", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Sign in using a third-party provider", + "code": "const { data, error } = await supabase.auth.signInWithOAuth({\n provider: 'github'\n})", + "response": "{\n data: {\n provider: 'github',\n url: \n },\n error: null\n}", + "notes": "with redirect\n- When the OAuth provider successfully authenticates the user, they are redirected to the URL specified in the `redirectTo` parameter. This parameter defaults to the [`SITE_URL`](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls). It does not redirect the user immediately after invoking this method.\n- See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project." + }, + { + "title": "Sign in using a third-party provider with redirect", + "code": "const { data, error } = await supabase.auth.signInWithOAuth({\n provider: 'github',\n options: {\n redirectTo: 'https://example.com/welcome'\n }\n})", + "notes": "- When the OAuth provider successfully authenticates the user, they are redirected to the URL specified in the `redirectTo` parameter. This parameter defaults to the [`SITE_URL`](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls). It does not redirect the user immediately after invoking this method.\n- See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project." + }, + { + "title": "Sign in with scopes and access provider tokens", + "code": "// Register this immediately after calling createClient!\n// Because signInWithOAuth causes a redirect, you need to fetch the\n// provider tokens from the callback.\nsupabase.auth.onAuthStateChange((event, session) => {\n if (session && session.provider_token) {\n window.localStorage.setItem('oauth_provider_token', session.provider_token)\n }\n\n if (session && session.provider_refresh_token) {\n window.localStorage.setItem('oauth_provider_refresh_token', session.provider_refresh_token)\n }\n\n if (event === 'SIGNED_OUT') {\n window.localStorage.removeItem('oauth_provider_token')\n window.localStorage.removeItem('oauth_provider_refresh_token')\n }\n})\n\n// Call this on your Sign in with GitHub button to initiate OAuth\n// with GitHub with the requested elevated scopes.\nawait supabase.auth.signInWithOAuth({\n provider: 'github',\n options: {\n scopes: 'repo gist notifications'\n }\n})", + "notes": "If you need additional access from an OAuth provider, in order to access provider specific APIs in the name of the user, you can do this by passing in the scopes the user should authorize for your application. Note that the `scopes` option takes in **a space-separated list** of scopes.\n\nBecause OAuth sign-in often includes redirects, you should register an `onAuthStateChange` callback immediately after you create the Supabase client. This callback will listen for the presence of `provider_token` and `provider_refresh_token` properties on the `session` object and store them in local storage. The client library will emit these values **only once** immediately after the user signs in. You can then access them by looking them up in local storage, or send them to your backend servers for further processing.\n\nFinally, make sure you remove them from local storage on the `SIGNED_OUT` event. If the OAuth provider supports token revocation, make sure you call those APIs either from the frontend or schedule them to be called on the backend." + } + ] + }, + { + "name": "signInWithOtp", + "description": "Log in a user using magiclink or a one-time password (OTP).\nIf the `{{ .ConfirmationURL }}` variable is specified in the email template, a magiclink will be sent. If the `{{ .Token }}` variable is specified in the email template, an OTP will be sent. If you're using phone sign-ins, only an OTP will be sent. You won't be able to send a magiclink for phone sign-ins.\nBe aware that you may get back an error message that will not distinguish between the cases where the account does not exist or, that the account can only be accessed via social login.\nDo note that you will need to configure a Whatsapp sender on Twilio if you are using phone sign in with the 'whatsapp' channel. The whatsapp channel is not supported on other providers at this time. This method supports PKCE when an email is passed.", + "remarks": [ + "- Requires either an email or phone number. - This method is used for passwordless sign-ins where a OTP is sent to the user's email or phone number. - If the user doesn't exist, `signInWithOtp()` will signup the user instead. To restrict this behavior, you can set `shouldCreateUser` in `SignInWithPasswordlessCredentials.options` to `false`. - If you're using an email, you can configure whether you want the user to receive a magiclink or a OTP. - If you're using phone, you can configure whether you want the user to receive a OTP. - The magic link's destination URL is determined by the [`SITE_URL`](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls). - See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project. - Magic links and OTPs share the same implementation. To send users a one-time code instead of a magic link, [modify the magic link email template](/dashboard/project/_/auth/templates) to include `{{ .Token }}` instead of `{{ .ConfirmationURL }}`. - See our [Twilio Phone Auth Guide](/docs/guides/auth/phone-login?showSMSProvider=Twilio) for details about configuring WhatsApp sign in." + ], + "parameters": [ + { + "name": "credentials", + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "email", + "optional": false, + "description": "The user's email address.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "data", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", + "type": "object" + }, + { + "name": "emailRedirectTo", + "optional": true, + "description": "The redirect url embedded in the email link", + "type": "string" + }, + { + "name": "shouldCreateUser", + "optional": true, + "description": "If set to false, this method will not create a new user. Defaults to true.", + "type": "boolean" + } + ] + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "channel", + "optional": true, + "description": "Messaging channel to use (e.g. whatsapp or sms)", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "sms" + }, + { + "kind": "literal", + "value": "whatsapp" + } + ] + } + }, + { + "name": "data", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", + "type": "object" + }, + { + "name": "shouldCreateUser", + "optional": true, + "description": "If set to false, this method will not create a new user. Defaults to true.", + "type": "boolean" + } + ] + } + }, + { + "name": "phone", + "optional": false, + "description": "The user's phone number.", + "type": "string" + } + ] + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "messageId", + "optional": true, + "type": { + "kind": "union", + "types": [ + "string", + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "session", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Sign in with email", + "code": "const { data, error } = await supabase.auth.signInWithOtp({\n email: 'example@email.com',\n options: {\n emailRedirectTo: 'https://example.com/welcome'\n }\n})", + "response": "{\n \"data\": {\n \"user\": null,\n \"session\": null\n },\n \"error\": null\n}", + "notes": "The user will be sent an email which contains either a magiclink or a OTP or both. By default, a given user can only request a OTP once every 60 seconds." + }, + { + "title": "Sign in with SMS OTP", + "code": "const { data, error } = await supabase.auth.signInWithOtp({\n phone: '+13334445555',\n})", + "notes": "The user will be sent a SMS which contains a OTP. By default, a given user can only request a OTP once every 60 seconds." + }, + { + "title": "Sign in with WhatsApp OTP", + "code": "const { data, error } = await supabase.auth.signInWithOtp({\n phone: '+13334445555',\n options: {\n channel:'whatsapp',\n }\n})", + "notes": "The user will be sent a WhatsApp message which contains a OTP. By default, a given user can only request a OTP once every 60 seconds. Note that a user will need to have a valid WhatsApp account that is linked to Twilio in order to use this feature." + } + ] + }, + { + "name": "signInWithPassword", + "description": "Log in an existing user with an email and password or phone and password.\nBe aware that you may get back an error message that will not distinguish between the cases where the account does not exist or that the email/phone and password combination is wrong or that the account can only be accessed via social login.", + "remarks": [ + "- Requires either an email and password or a phone number and password." + ], + "parameters": [ + { + "name": "credentials", + "type": { + "kind": "intersection", + "types": [ + { + "kind": "reference", + "name": "PasswordCredentialsBase" + }, + { + "kind": "object", + "properties": [ + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "type": "string" + } + ] + } + } + ] + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "object", + "name": "Session", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + }, + { + "name": "weakPassword", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "message", + "optional": false, + "type": "string" + }, + { + "name": "reasons", + "optional": false, + "type": { + "kind": "array", + "elementType": { + "kind": "indexedAccess", + "objectType": { + "kind": "query" + }, + "indexType": null + } + } + } + ], + "name": "WeakPassword" + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Sign in with email and password", + "code": "const { data, error } = await supabase.auth.signInWithPassword({\n email: 'example@email.com',\n password: 'example-password',\n})", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n }\n }\n },\n \"error\": null\n}" + }, + { + "title": "Sign in with phone and password", + "code": "const { data, error } = await supabase.auth.signInWithPassword({\n phone: '+13334445555',\n password: 'some-password',\n})" + } + ] + }, + { + "name": "signInWithSSO", + "description": "Attempts a single-sign on using an enterprise Identity Provider. A successful SSO attempt will redirect the current page to the identity provider authorization page. The redirect URL is implementation and SSO protocol specific.\nYou can use it by providing a SSO domain. Typically you can extract this domain by asking users for their email address. If this domain is registered on the Auth instance the redirect will use that organization's currently active SSO Identity Provider for the login.\nIf you have built an organization-specific login page, you can use the organization's SSO Identity Provider UUID directly instead.", + "remarks": [ + "- Before you can call this method you need to [establish a connection](/docs/guides/auth/sso/auth-sso-saml#managing-saml-20-connections) to an identity provider. Use the [CLI commands](/docs/reference/cli/supabase-sso) to do this. - If you've associated an email domain to the identity provider, you can use the `domain` property to start a sign-in flow. - In case you need to use a different way to start the authentication flow with an identity provider, you can use the `providerId` property. For example: - Mapping specific user email addresses with an identity provider. - Using different hints to identity the identity provider to be used by the user, like a company-specific page, IP address or other tracking information." + ], + "parameters": [ + { + "name": "params", + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "redirectTo", + "optional": true, + "description": "A URL to send the user to after they have signed-in.", + "type": "string" + }, + { + "name": "skipBrowserRedirect", + "optional": true, + "description": "If set to true, the redirect will not happen on the client side. This parameter is used when you wish to handle the redirect yourself. Defaults to false.", + "type": "boolean" + } + ] + } + }, + { + "name": "providerId", + "optional": false, + "description": "UUID of the SSO provider to invoke single-sign on to.", + "type": "string" + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "domain", + "optional": false, + "description": "Domain name of the organization for which to invoke single-sign on.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "redirectTo", + "optional": true, + "description": "A URL to send the user to after they have signed-in.", + "type": "string" + }, + { + "name": "skipBrowserRedirect", + "optional": true, + "description": "If set to true, the redirect will not happen on the client side. This parameter is used when you wish to handle the redirect yourself. Defaults to false.", + "type": "boolean" + } + ] + } + } + ] + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "url", + "optional": false, + "description": "URL to open in a browser which will complete the sign-in flow by taking the user to the identity provider's authentication flow.\nOn browsers you can set the URL to `window.location.href` to take the user to the authentication flow.", + "type": "string" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Sign in with email domain", + "code": "// You can extract the user's email domain and use it to trigger the\n // authentication flow with the correct identity provider.\n\n const { data, error } = await supabase.auth.signInWithSSO({\n domain: 'company.com'\n })\n\n if (data?.url) {\n // redirect the user to the identity provider's authentication flow\n window.location.href = data.url\n }" + }, + { + "title": "Sign in with provider UUID", + "code": "// Useful when you need to map a user's sign in request according\n // to different rules that can't use email domains.\n\n const { data, error } = await supabase.auth.signInWithSSO({\n providerId: '21648a9d-8d5a-4555-a9d1-d6375dc14e92'\n })\n\n if (data?.url) {\n // redirect the user to the identity provider's authentication flow\n window.location.href = data.url\n }" + } + ] + }, + { + "name": "signInWithWeb3", + "description": "Signs in a user by verifying a message signed by the user's private key. Supports Ethereum (via Sign-In-With-Ethereum) & Solana (Sign-In-With-Solana) standards, both of which derive from the EIP-4361 standard With slight variation on Solana's side.", + "remarks": [ + "- Uses a Web3 (Ethereum, Solana) wallet to sign a user in. - Read up on the [potential for abuse](/docs/guides/auth/auth-web3#potential-for-abuse) before using it." + ], + "parameters": [ + { + "name": "credentials", + "type": { + "kind": "union", + "types": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "chain", + "optional": false, + "type": { + "kind": "literal", + "value": "solana" + } + }, + { + "name": "options", "optional": true, - "description": "key option is used to track presence payload across clients", "type": { "kind": "object", "properties": [ { - "name": "enabled", + "name": "captchaToken", "optional": true, - "type": "boolean" + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" }, { - "name": "key", + "name": "signInWithSolana", "optional": true, + "type": { + "kind": "reference", + "name": "Partial", + "typeArguments": [ + { + "kind": "reference", + "name": "Omit", + "typeArguments": [ + { + "kind": "reference", + "name": "SolanaSignInInput" + }, + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "version" + }, + { + "kind": "literal", + "value": "chain" + }, + { + "kind": "literal", + "value": "domain" + }, + { + "kind": "literal", + "value": "uri" + }, + { + "kind": "literal", + "value": "statement" + } + ] + } + ] + } + ] + } + }, + { + "name": "url", + "optional": true, + "description": "URL to use with the wallet interface. Some wallets do not allow signing a message for URLs different from the current page.", "type": "string" } ] } }, { - "name": "private", + "name": "statement", "optional": true, - "description": "defines if the channel is private or not and if RLS policies will be used to check data", - "type": "boolean" + "description": "Optional statement to include in the Sign in with Solana message. Must not include new line characters. Most wallets like Phantom **require specifying a statement!**", + "type": "string" + }, + { + "name": "wallet", + "optional": true, + "description": "Wallet interface to use. If not specified will default to `window.solana`.", + "type": { + "kind": "object", + "properties": [ + { + "name": "publicKey", + "optional": true, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "toBase58", + "optional": false, + "type": { + "kind": "object", + "properties": [] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "signIn", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "signMessage", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + } + ], + "name": "SolanaWallet" + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "chain", + "optional": false, + "type": { + "kind": "literal", + "value": "solana" + } + }, + { + "name": "message", + "optional": false, + "description": "Sign in with Solana compatible message. Must include `Issued At`, `URI` and `Version`.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + } + ] + } + }, + { + "name": "signature", + "optional": false, + "description": "Ed25519 signature of the message.", + "type": { + "kind": "reference", + "name": "Uint8Array" + } } ] } - } - ], - "name": "RealtimeChannelOptions" - } - }, - { - "name": "presence", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimePresence", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "description": "The realtime channel to bind to.", - "type": { - "kind": "reference", - "name": "RealtimeChannel" - } - }, - { - "name": "state", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "private", - "optional": false, - "type": "boolean" - }, - { - "name": "socket", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimeClient", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "accessToken", - "optional": false, - "type": { - "kind": "union", - "types": [ + ] + }, + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ { - "kind": "literal", - "value": null + "name": "chain", + "optional": false, + "type": { + "kind": "literal", + "value": "ethereum" + } }, { - "kind": "object", - "properties": [] + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "signInWithEthereum", + "optional": true, + "type": { + "kind": "reference", + "name": "Partial", + "typeArguments": [ + { + "kind": "reference", + "name": "Omit", + "typeArguments": [ + { + "kind": "reference", + "name": "EthereumSignInInput" + }, + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "version" + }, + { + "kind": "literal", + "value": "domain" + }, + { + "kind": "literal", + "value": "uri" + }, + { + "kind": "literal", + "value": "statement" + } + ] + } + ] + } + ] + } + }, + { + "name": "url", + "optional": true, + "description": "URL to use with the wallet interface. Some wallets do not allow signing a message for URLs different from the current page.", + "type": "string" + } + ] + } + }, + { + "name": "statement", + "optional": true, + "description": "Optional statement to include in the Sign in with Ethereum message. Must not include new line characters. Most wallets like Phantom **require specifying a statement!**", + "type": "string" + }, + { + "name": "wallet", + "optional": true, + "description": "Wallet interface to use. If not specified will default to `window.ethereum`.", + "type": { + "kind": "reference", + "name": "EIP1193Provider" + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "chain", + "optional": false, + "type": { + "kind": "literal", + "value": "ethereum" + } + }, + { + "name": "message", + "optional": false, + "description": "Sign in with Ethereum compatible message. Must include `Issued At`, `URI` and `Version`.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + } + ] + } + }, + { + "name": "signature", + "optional": false, + "description": "Ethereum curve (secp256k1) signature of the message.", + "type": { + "kind": "reference", + "name": "Hex" + } } ] } - }, - { - "name": "accessTokenValue", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "apiKey", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "channels", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "reference", - "name": "RealtimeChannel" + ] + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "object", + "name": "Session", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null } } - }, - { - "name": "fetch", - "optional": false, - "type": { - "kind": "object", - "properties": [] + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } } - }, - { - "name": "headers", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "httpEndpoint", - "optional": false, - "type": "string" - }, - { - "name": "logLevel", - "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } - }, - { - "name": "params", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "ref", - "optional": false, - "type": "number" - }, - { - "name": "serializer", - "optional": false, - "type": { - "kind": "reference", - "name": "Serializer" - } - }, - { - "name": "worker", - "optional": true, - "type": "boolean" - }, - { - "name": "workerRef", - "optional": true, - "type": { - "kind": "reference", - "name": "Worker" - } - }, - { - "name": "workerUrl", - "optional": true, - "type": "string" - }, - { - "name": "decode", - "optional": false, - "type": null - }, - { - "name": "encode", - "optional": false, - "type": null - }, - { - "name": "endPoint", - "optional": false, - "type": null - }, - { - "name": "heartbeatCallback", - "optional": false, - "type": null - }, - { - "name": "heartbeatIntervalMs", - "optional": false, - "type": null - }, - { - "name": "heartbeatTimer", - "optional": false, - "type": null - }, - { - "name": "pendingHeartbeatRef", - "optional": false, - "type": null - }, - { - "name": "reconnectAfterMs", - "optional": false, - "type": null - }, - { - "name": "reconnectTimer", - "optional": false, - "type": null - }, - { - "name": "sendBuffer", - "optional": false, - "type": null - }, - { - "name": "stateChangeCallbacks", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "transport", - "optional": false, - "type": null - }, - { - "name": "vsn", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": null - }, - { - "name": "connect", - "optional": false, - "type": null - }, - { - "name": "connectionState", - "optional": false, - "type": null - }, - { - "name": "disconnect", - "optional": false, - "type": null - }, - { - "name": "endpointURL", - "optional": false, - "type": null - }, - { - "name": "getChannels", - "optional": false, - "type": null - }, - { - "name": "isConnected", - "optional": false, - "type": null - }, - { - "name": "isConnecting", - "optional": false, - "type": null - }, - { - "name": "isDisconnecting", - "optional": false, - "type": null - }, - { - "name": "log", - "optional": false, - "type": null - }, - { - "name": "onHeartbeat", - "optional": false, - "type": null - }, - { - "name": "push", - "optional": false, - "type": null - }, - { - "name": "removeAllChannels", - "optional": false, - "type": null - }, - { - "name": "removeChannel", - "optional": false, - "type": null - }, - { - "name": "sendHeartbeat", - "optional": false, - "type": null - }, - { - "name": "setAuth", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "subTopic", - "optional": false, - "type": "string" - }, - { - "name": "topic", - "optional": false, - "description": "Topic name can be any string.", - "type": "string" - }, - { - "name": "joinedOnce", - "optional": false, - "type": null - }, - { - "name": "joinPush", - "optional": false, - "type": null - }, - { - "name": "rejoinTimer", - "optional": false, - "type": null - }, - { - "name": "state", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "copyBindings", - "optional": false, - "type": null - }, - { - "name": "httpSend", - "optional": false, - "type": null - }, - { - "name": "on", - "optional": false, - "description": "Listen to realtime events on this channel.", - "type": null - }, - { - "name": "presenceState", - "optional": false, - "type": null - }, - { - "name": "send", - "optional": false, - "type": null - }, - { - "name": "subscribe", - "optional": false, - "type": null - }, - { - "name": "teardown", - "optional": false, - "type": null - }, - { - "name": "track", - "optional": false, - "type": null - }, - { - "name": "unsubscribe", - "optional": false, - "type": null - }, - { - "name": "untrack", - "optional": false, - "type": null - }, - { - "name": "updateJoinPayload", - "optional": false, - "type": null + ] + } + ] } ] }, "examples": [ { - "title": "Example for a public channel", - "code": "import RealtimeClient from '@supabase/realtime-js'\n\nconst client = new RealtimeClient('https://xyzcompany.supabase.co/realtime/v1', {\n params: { apikey: 'public-anon-key' },\n})\nconst channel = new RealtimeChannel('realtime:public:messages', { config: {} }, client)" + "title": "Sign in with Solana or Ethereum (Window API)", + "code": "// uses window.ethereum for the wallet\n const { data, error } = await supabase.auth.signInWithWeb3({\n chain: 'ethereum',\n statement: 'I accept the Terms of Service at https://example.com/tos'\n })\n\n // uses window.solana for the wallet\n const { data, error } = await supabase.auth.signInWithWeb3({\n chain: 'solana',\n statement: 'I accept the Terms of Service at https://example.com/tos'\n })" + }, + { + "title": "Sign in with Ethereum (Message and Signature)", + "code": "const { data, error } = await supabase.auth.signInWithWeb3({\n chain: 'ethereum',\n message: '',\n signature: '',\n })" + }, + { + "title": "Sign in with Solana (Brave)", + "code": "const { data, error } = await supabase.auth.signInWithWeb3({\n chain: 'solana',\n statement: 'I accept the Terms of Service at https://example.com/tos',\n wallet: window.braveSolana\n })" + }, + { + "title": "Sign in with Solana (Wallet Adapter)", + "code": "function SignInButton() {\n const wallet = useWallet()\n\n return (\n <>\n {wallet.connected ? (\n {\n supabase.auth.signInWithWeb3({\n chain: 'solana',\n statement: 'I accept the Terms of Service at https://example.com/tos',\n wallet,\n })\n }}\n >\n Sign in with Solana\n \n ) : (\n \n )}\n \n )\n}\n\nfunction App() {\n const endpoint = clusterApiUrl('devnet')\n const wallets = useMemo(() => [], [])\n\n return (\n \n \n \n \n \n \n \n )\n}" } ] }, + { + "name": "signOut", + "description": "Inside a browser context, `signOut()` will remove the logged in user from the browser session and log them out - removing all items from localstorage and then trigger a `\"SIGNED_OUT\"` event.\nFor server-side management, you can revoke all refresh tokens for a user by passing a user's JWT through to `auth.api.signOut(JWT: string)`. There is no way to revoke a user's access token jwt until it expires. It is recommended to set a shorter expiry on the jwt for this reason.\nIf using `others` scope, no `SIGNED_OUT` event is fired!", + "remarks": [ + "- In order to use the `signOut()` method, the user needs to be signed in first. - By default, `signOut()` uses the global scope, which signs out all other sessions that the user is logged into as well. Customize this behavior by passing a scope parameter. - Since Supabase Auth uses JWTs for authentication, the access token JWT will be valid until it's expired. When the user signs out, Supabase revokes the refresh token and deletes the JWT from the client-side. This does not revoke the JWT and it will still be valid until it expires." + ], + "parameters": [ + { + "name": "options", + "type": { + "kind": "object", + "properties": [ + { + "name": "scope", + "optional": true, + "description": "Determines which sessions should be logged out. Global means all sessions by this account. Local means only this session. Others means all other sessions except the current one. When using others, there is no sign-out event fired on the current session!", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "global" + }, + { + "kind": "literal", + "value": "local" + }, + { + "kind": "literal", + "value": "others" + } + ] + } + } + ], + "name": "SignOut" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "object", + "properties": [ + { + "name": "error", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + ] + } + } + ] + } + ] + }, + "examples": [ + { + "title": "Sign out (all sessions)", + "code": "const { error } = await supabase.auth.signOut()" + }, + { + "title": "Sign out (current session)", + "code": "const { error } = await supabase.auth.signOut({ scope: 'local' })" + }, + { + "title": "Sign out (other sessions)", + "code": "const { error } = await supabase.auth.signOut({ scope: 'others' })" + } + ] + }, + { + "name": "signUp", + "description": "Creates a new user.\nBe aware that if a user account exists in the system you may get back an error message that attempts to hide this information from the user. This method has support for PKCE via email signups. The PKCE flow cannot be used when autoconfirm is enabled.", + "remarks": [ + "- By default, the user needs to verify their email address before logging in. To turn this off, disable **Confirm email** in [your project](/dashboard/project/_/auth/providers). - **Confirm email** determines if users need to confirm their email address after signing up. - If **Confirm email** is enabled, a `user` is returned but `session` is null. - If **Confirm email** is disabled, both a `user` and a `session` are returned. - When the user confirms their email address, they are redirected to the [`SITE_URL`](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) by default. You can modify your `SITE_URL` or add additional redirect URLs in [your project](/dashboard/project/_/auth/url-configuration). - If signUp() is called for an existing confirmed user: - When both **Confirm email** and **Confirm phone** (even when phone provider is disabled) are enabled in [your project](/dashboard/project/_/auth/providers), an obfuscated/fake user object is returned. - When either **Confirm email** or **Confirm phone** (even when phone provider is disabled) is disabled, the error message, `User already registered` is returned. - To fetch the currently logged-in user, refer to [`getUser()`](/docs/reference/javascript/auth-getuser)." + ], + "parameters": [ + { + "name": "credentials", + "type": { + "kind": "conditional" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "Session", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Sign up with an email and password", + "code": "const { data, error } = await supabase.auth.signUp({\n email: 'example@email.com',\n password: 'example-password',\n})", + "response": "// Some fields may be null if \"confirm email\" is enabled.\n{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n }\n }\n },\n \"error\": null\n}", + "notes": "Sign up with a phone number and password (whatsapp)\nThe user will be sent a WhatsApp message which contains a OTP. By default, a given user can only request a OTP once every 60 seconds. Note that a user will need to have a valid WhatsApp account that is linked to Twilio in order to use this feature." + }, + { + "title": "Sign up with a phone number and password (SMS)", + "code": "const { data, error } = await supabase.auth.signUp({\n phone: '123456789',\n password: 'example-password',\n options: {\n channel: 'sms'\n }\n})", + "notes": "Sign up with a redirect URL\n- See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project." + }, + { + "title": "Sign up with a phone number and password (whatsapp)", + "code": "const { data, error } = await supabase.auth.signUp({\n phone: '123456789',\n password: 'example-password',\n options: {\n channel: 'whatsapp'\n }\n})", + "notes": "The user will be sent a WhatsApp message which contains a OTP. By default, a given user can only request a OTP once every 60 seconds. Note that a user will need to have a valid WhatsApp account that is linked to Twilio in order to use this feature." + }, + { + "title": "Sign up with additional user metadata", + "code": "const { data, error } = await supabase.auth.signUp(\n {\n email: 'example@email.com',\n password: 'example-password',\n options: {\n data: {\n first_name: 'John',\n age: 27,\n }\n }\n }\n)" + }, + { + "title": "Sign up with a redirect URL", + "code": "const { data, error } = await supabase.auth.signUp(\n {\n email: 'example@email.com',\n password: 'example-password',\n options: {\n emailRedirectTo: 'https://example.com/welcome'\n }\n }\n)", + "notes": "- See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project." + } + ] + }, + { + "name": "startAutoRefresh", + "description": "Starts an auto-refresh process in the background. The session is checked every few seconds. Close to the time of expiration a process is started to refresh the session. If refreshing fails it will be retried for as long as necessary.\nIf you set the GoTrueClientOptions#autoRefreshToken you don't need to call this function, it will be called for you.\nOn browsers the refresh process works only when the tab/window is in the foreground to conserve resources as well as prevent race conditions and flooding auth with requests. If you call this method any managed visibility change callback will be removed and you must manage visibility changes on your own.\nOn non-browser platforms the refresh process works *continuously* in the background, which may not be desirable. You should hook into your platform's foreground indication mechanism and call these methods appropriately to conserve resources.\n#stopAutoRefresh", + "remarks": [ + "- Only useful in non-browser environments such as React Native or Electron. - The Supabase Auth library automatically starts and stops proactively refreshing the session when a tab is focused or not. - On non-browser platforms, such as mobile or desktop apps built with web technologies, the library is not able to effectively determine whether the application is _focused_ or not. - To give this hint to the application, you should be calling this method when the app is in focus and calling `supabase.auth.stopAutoRefresh()` when it's out of focus." + ], + "parameters": [], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + "void" + ] + }, + "examples": [ + { + "title": "Start and stop auto refresh in React Native", + "code": "import { AppState } from 'react-native'\n\n// make sure you register this only once!\nAppState.addEventListener('change', (state) => {\n if (state === 'active') {\n supabase.auth.startAutoRefresh()\n } else {\n supabase.auth.stopAutoRefresh()\n }\n})" + } + ] + }, + { + "name": "stopAutoRefresh", + "description": "Stops an active auto refresh process running in the background (if any).\nIf you call this method any managed visibility change callback will be removed and you must manage visibility changes on your own.\nSee #startAutoRefresh for more details.", + "remarks": [ + "- Only useful in non-browser environments such as React Native or Electron. - The Supabase Auth library automatically starts and stops proactively refreshing the session when a tab is focused or not. - On non-browser platforms, such as mobile or desktop apps built with web technologies, the library is not able to effectively determine whether the application is _focused_ or not. - When your application goes in the background or out of focus, call this method to stop the proactive refreshing of the session." + ], + "parameters": [], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + "void" + ] + }, + "examples": [ + { + "title": "Start and stop auto refresh in React Native", + "code": "import { AppState } from 'react-native'\n\n// make sure you register this only once!\nAppState.addEventListener('change', (state) => {\n if (state === 'active') {\n supabase.auth.startAutoRefresh()\n } else {\n supabase.auth.stopAutoRefresh()\n }\n})" + } + ] + }, + { + "name": "unlinkIdentity", + "description": "Unlinks an identity from a user by deleting it. The user will no longer be able to sign in with that identity once it's unlinked.", + "remarks": [ + "- The **Enable Manual Linking** option must be enabled from your [project's authentication settings](/dashboard/project/_/auth/providers). - The user needs to be signed in to call `unlinkIdentity()`. - The user must have at least 2 identities in order to unlink an identity. - The identity to be unlinked must belong to the user." + ], + "parameters": [ + { + "name": "identity", + "type": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Unlink an identity", + "code": "// retrieve all identities linked to a user\nconst identities = await supabase.auth.getUserIdentities()\n\n// find the google identity\nconst googleIdentity = identities.find(\n identity => identity.provider === 'google'\n)\n\n// unlink the google identity\nconst { error } = await supabase.auth.unlinkIdentity(googleIdentity)" + } + ] + }, + { + "name": "updateUser", + "description": "Updates user data for a logged in user.", + "remarks": [ + "- In order to use the `updateUser()` method, the user needs to be signed in first. - By default, email updates sends a confirmation link to both the user's current and new email. To only send a confirmation link to the user's new email, disable **Secure email change** in your project's [email auth provider settings](/dashboard/project/_/auth/providers)." + ], + "parameters": [ + { + "name": "attributes", + "type": { + "kind": "object", + "name": "UserAttributes", + "properties": [ + { + "name": "current_password", + "optional": true, + "description": "The user's current password\nThis is only ever present when the user is resetting their password and GOTRUE_SECURITY_UPDATE_PASSWORD_REQUIRE_CURRENT_PASSWORD is true.", + "type": "string" + }, + { + "name": "data", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", + "type": "object" + }, + { + "name": "email", + "optional": true, + "description": "The user's email.", + "type": "string" + }, + { + "name": "nonce", + "optional": true, + "description": "The nonce sent for reauthentication if the user's password is to be updated.\nCall reauthenticate() to obtain the nonce first.", + "type": "string" + }, + { + "name": "password", + "optional": true, + "description": "The user's password.", + "type": "string" + }, + { + "name": "phone", + "optional": true, + "description": "The user's phone.", + "type": "string" + } + ] + } + }, + { + "name": "options", + "type": { + "kind": "object", + "properties": [ + { + "name": "emailRedirectTo", + "optional": true, + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Update the email for an authenticated user", + "code": "const { data, error } = await supabase.auth.updateUser({\n email: 'new@email.com'\n})", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"new_email\": \"new@email.com\",\n \"email_change_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}", + "notes": "Sends a \"Confirm Email Change\" email to the new address. If **Secure Email Change** is enabled (default), confirmation is also required from the **old email** before the change is applied. To skip dual confirmation and apply the change after only the new email is verified, disable **Secure Email Change** in the [Email Auth Provider settings](/dashboard/project/_/auth/providers?provider=Email)." + }, + { + "title": "Update the phone number for an authenticated user", + "code": "const { data, error } = await supabase.auth.updateUser({\n phone: '123456789'\n})", + "notes": "Sends a one-time password (OTP) to the new phone number." + }, + { + "title": "Update the password for an authenticated user", + "code": "const { data, error } = await supabase.auth.updateUser({\n password: 'new password'\n})", + "notes": "Update the user's metadata\nUpdates the user's custom metadata.\n\n**Note**: The `data` field maps to the `auth.users.raw_user_meta_data` column in your Supabase database. When calling `getUser()`, the data will be available as `user.user_metadata`." + }, + { + "title": "Update the user's metadata", + "code": "const { data, error } = await supabase.auth.updateUser({\n data: { hello: 'world' }\n})", + "notes": "Updates the user's custom metadata.\n\n**Note**: The `data` field maps to the `auth.users.raw_user_meta_data` column in your Supabase database. When calling `getUser()`, the data will be available as `user.user_metadata`." + }, + { + "title": "Update the user's password with a nonce", + "code": "const { data, error } = await supabase.auth.updateUser({\n password: 'new password',\n nonce: '123456'\n})", + "notes": "If **Secure password change** is enabled in your [project's email provider settings](/dashboard/project/_/auth/providers), updating the user's password would require a nonce if the user **hasn't recently signed in**. The nonce is sent to the user's email or phone number. A user is deemed recently signed in if the session was created in the last 24 hours." + } + ] + }, + { + "name": "verifyOtp", + "description": "Log in a user given a User supplied OTP or TokenHash received through mobile or email.", + "remarks": [ + "- The `verifyOtp` method takes in different verification types. - If a phone number is used, the type can either be: 1. `sms` – Used when verifying a one-time password (OTP) sent via SMS during sign-up or sign-in. 2. `phone_change` – Used when verifying an OTP sent to a new phone number during a phone number update process. - If an email address is used, the type can be one of the following (note: `signup` and `magiclink` types are deprecated): 1. `email` – Used when verifying an OTP sent to the user's email during sign-up or sign-in. 2. `recovery` – Used when verifying an OTP sent for account recovery, typically after a password reset request. 3. `invite` – Used when verifying an OTP sent as part of an invitation to join a project or organization. 4. `email_change` – Used when verifying an OTP sent to a new email address during an email update process. - The verification type used should be determined based on the corresponding auth method called before `verifyOtp` to sign up / sign-in a user. - The `TokenHash` is contained in the [email templates](/docs/guides/auth/auth-email-templates) and can be used to sign in. You may wish to use the hash for the PKCE flow for Server Side Auth. Read [the Password-based Auth guide](/docs/guides/auth/passwords) for more details." + ], + "parameters": [ + { + "name": "params", + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "VerifyMobileOtpParams", + "properties": [ + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "redirectTo", + "optional": true, + "description": "A URL to send the user to after they are confirmed.", + "type": "string" + } + ] + } + }, + { + "name": "phone", + "optional": false, + "description": "The user's phone number.", + "type": "string" + }, + { + "name": "token", + "optional": false, + "description": "The otp sent to the user's phone number.", + "type": "string" + }, + { + "name": "type", + "optional": false, + "description": "The user's verification type.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "sms" + }, + { + "kind": "literal", + "value": "phone_change" + } + ] + } + } + ] + }, + { + "kind": "object", + "name": "VerifyEmailOtpParams", + "properties": [ + { + "name": "email", + "optional": false, + "description": "The user's email address.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "redirectTo", + "optional": true, + "description": "A URL to send the user to after they are confirmed.", + "type": "string" + } + ] + } + }, + { + "name": "token", + "optional": false, + "description": "The otp sent to the user's email address.", + "type": "string" + }, + { + "name": "type", + "optional": false, + "description": "The user's verification type.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "signup" + }, + { + "kind": "literal", + "value": "invite" + }, + { + "kind": "literal", + "value": "magiclink" + }, + { + "kind": "literal", + "value": "recovery" + }, + { + "kind": "literal", + "value": "email_change" + }, + { + "kind": "literal", + "value": "email" + } + ] + } + } + ] + }, + { + "kind": "object", + "name": "VerifyTokenHashParams", + "properties": [ + { + "name": "token_hash", + "optional": false, + "description": "The token hash used in an email link", + "type": "string" + }, + { + "name": "type", + "optional": false, + "description": "The user's verification type.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "signup" + }, + { + "kind": "literal", + "value": "invite" + }, + { + "kind": "literal", + "value": "magiclink" + }, + { + "kind": "literal", + "value": "recovery" + }, + { + "kind": "literal", + "value": "email_change" + }, + { + "kind": "literal", + "value": "email" + } + ] + } + } + ] + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "Session", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Verify Signup One-Time Password (OTP)", + "code": "const { data, error } = await supabase.auth.verifyOtp({ email, token, type: 'email'})", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"recovery_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"recovery_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n }\n },\n \"error\": null\n}" + }, + { + "title": "Verify SMS One-Time Password (OTP)", + "code": "const { data, error } = await supabase.auth.verifyOtp({ phone, token, type: 'sms'})" + }, + { + "title": "Verify Email Auth (Token Hash)", + "code": "const { data, error } = await supabase.auth.verifyOtp({ token_hash: tokenHash, type: 'email'})" + } + ] + }, + { + "name": "approveAuthorization", + "description": "Approves an OAuth authorization request. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nAfter approval, the user's consent is stored and an authorization code is generated. The response contains a complete redirect URL with the authorization code and state.", + "parameters": [ + { + "name": "authorizationId", + "description": "The authorization ID to approve", + "type": "string" + }, + { + "name": "options", + "optional": true, + "description": "Optional parameters", + "type": { + "kind": "object", + "properties": [ + { + "name": "skipBrowserRedirect", + "optional": true, + "description": "If false (default), automatically redirects the browser to the OAuth client. If true, returns the redirect_url without automatic redirect (useful for custom handling).", + "type": "boolean" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "redirect_url", + "optional": false, + "description": "Complete redirect URL with authorization code and state parameters (e.g., \"https://app.com/callback?code=xxx&state=yyy\")", + "type": "string" + } + ], + "name": "OAuthRedirect" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "denyAuthorization", + "description": "Denies an OAuth authorization request. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nAfter denial, the response contains a redirect URL with an OAuth error (access_denied) to inform the OAuth client that the user rejected the request.", + "parameters": [ + { + "name": "authorizationId", + "description": "The authorization ID to deny", + "type": "string" + }, + { + "name": "options", + "optional": true, + "description": "Optional parameters", + "type": { + "kind": "object", + "properties": [ + { + "name": "skipBrowserRedirect", + "optional": true, + "description": "If false (default), automatically redirects the browser to the OAuth client. If true, returns the redirect_url without automatic redirect (useful for custom handling).", + "type": "boolean" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "redirect_url", + "optional": false, + "description": "Complete redirect URL with authorization code and state parameters (e.g., \"https://app.com/callback?code=xxx&state=yyy\")", + "type": "string" + } + ], + "name": "OAuthRedirect" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "getAuthorizationDetails", + "description": "Retrieves details about an OAuth authorization request. Used to display consent information to the user. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis method returns one of two response types: - `OAuthAuthorizationDetails`: User needs to consent - show consent page with client info - `OAuthRedirect`: User already consented - redirect immediately to the OAuth client\nUse type narrowing to distinguish between the responses: ```typescript if ('authorization_id' in data) { // Show consent page } else { // Redirect to data.redirect_url } ```", + "parameters": [ + { + "name": "authorizationId", + "description": "The authorization ID from the authorization request", + "type": "string" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "authorization_id", + "optional": false, + "description": "The authorization ID used to approve or deny the request", + "type": "string" + }, + { + "name": "client", + "optional": false, + "description": "OAuth client requesting authorization", + "type": { + "kind": "object", + "properties": [ + { + "name": "id", + "optional": false, + "description": "Unique identifier for the OAuth client (UUID)", + "type": "string" + }, + { + "name": "logo_uri", + "optional": false, + "description": "URI of the OAuth client's logo", + "type": "string" + }, + { + "name": "name", + "optional": false, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "uri", + "optional": false, + "description": "URI of the OAuth client's website", + "type": "string" + } + ], + "name": "OAuthAuthorizationClient" + } + }, + { + "name": "redirect_uri", + "optional": false, + "description": "The OAuth client's registered redirect URI (base URI without query parameters)", + "type": "string" + }, + { + "name": "scope", + "optional": false, + "description": "Space-separated list of requested scopes (e.g., \"openid profile email\")", + "type": "string" + }, + { + "name": "user", + "optional": false, + "description": "User object associated with the authorization", + "type": { + "kind": "object", + "properties": [ + { + "name": "email", + "optional": false, + "description": "User email", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "User ID (UUID)", + "type": "string" + } + ] + } + } + ], + "name": "OAuthAuthorizationDetails" + }, + { + "kind": "object", + "properties": [ + { + "name": "redirect_url", + "optional": false, + "description": "Complete redirect URL with authorization code and state parameters (e.g., \"https://app.com/callback?code=xxx&state=yyy\")", + "type": "string" + } + ], + "name": "OAuthRedirect" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "listGrants", + "description": "Lists all OAuth grants that the authenticated user has authorized. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.", + "parameters": [], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "properties": [ + { + "name": "client", + "optional": false, + "description": "OAuth client information", + "type": { + "kind": "object", + "properties": [ + { + "name": "id", + "optional": false, + "description": "Unique identifier for the OAuth client (UUID)", + "type": "string" + }, + { + "name": "logo_uri", + "optional": false, + "description": "URI of the OAuth client's logo", + "type": "string" + }, + { + "name": "name", + "optional": false, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "uri", + "optional": false, + "description": "URI of the OAuth client's website", + "type": "string" + } + ], + "name": "OAuthAuthorizationClient" + } + }, + { + "name": "granted_at", + "optional": false, + "description": "Timestamp when the grant was created (ISO 8601 date-time)", + "type": "string" + }, + { + "name": "scopes", + "optional": false, + "description": "Array of scopes granted to this client", + "type": { + "kind": "array", + "elementType": "string" + } + } + ], + "name": "OAuthGrant" + } + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "revokeGrant", + "description": "Revokes a user's OAuth grant for a specific client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nRevocation marks consent as revoked, deletes active sessions for that OAuth client, and invalidates associated refresh tokens.", + "parameters": [ + { + "name": "options", + "description": "Revocation options", + "type": { + "kind": "object", + "properties": [ + { + "name": "clientId", + "optional": false, + "description": "The OAuth client identifier (UUID) to revoke access for", + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "deleteFactor", + "description": "Deletes a factor on a user. This will log the user out of all active sessions if the deleted factor was verified.", + "parameters": [ + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "id", + "optional": false, + "description": "ID of the MFA factor to delete.", + "type": "string" + }, + { + "name": "userId", + "optional": false, + "description": "ID of the user whose factor is being deleted.", + "type": "string" + } + ], + "name": "AuthMFAAdminDeleteFactorParams" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "id", + "optional": false, + "description": "ID of the factor that was successfully deleted.", + "type": "string" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Delete a factor for a user", + "code": "const { data, error } = await supabase.auth.admin.mfa.deleteFactor({\n id: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n userId: 'a89baba7-b1b7-440f-b4bb-91026967f66b',\n})", + "response": "{\n data: {\n id: '34e770dd-9ff9-416c-87fa-43b31d7ef225'\n },\n error: null\n}" + } + ] + }, + { + "name": "listFactors", + "description": "Lists all factors associated to a user.", + "parameters": [ + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "userId", + "optional": false, + "description": "ID of the user.", + "type": "string" + } + ], + "name": "AuthMFAAdminListFactorsParams" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "factors", + "optional": false, + "description": "All factors attached to the user.", + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "typeParam", + "name": "Type" + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "typeParam", + "name": "Status" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "List all factors for a user", + "code": "const { data, error } = await supabase.auth.admin.mfa.listFactors()", + "response": "{\n data: {\n factors: Factor[\n {\n id: '',\n friendly_name: 'Auth App Factor',\n factor_type: 'totp',\n status: 'verified',\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z'\n }\n ]\n },\n error: null\n}" + } + ] + }, + { + "name": "createClient", + "description": "Creates a new OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "parameters": [ + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "client_name", + "optional": false, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "client_uri", + "optional": true, + "description": "URI of the OAuth client", + "type": "string" + }, + { + "name": "grant_types", + "optional": true, + "description": "Array of allowed grant types (optional, defaults to authorization_code and refresh_token)", + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "authorization_code" + }, + { + "kind": "literal", + "value": "refresh_token" + } + ] + } + } + }, + { + "name": "redirect_uris", + "optional": false, + "description": "Array of allowed redirect URIs", + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "response_types", + "optional": true, + "description": "Array of allowed response types (optional, defaults to code)", + "type": { + "kind": "array", + "elementType": { + "kind": "literal", + "value": "code" + } + } + }, + { + "name": "scope", + "optional": true, + "description": "Scope of the OAuth client", + "type": "string" + }, + { + "name": "token_endpoint_auth_method", + "optional": true, + "description": "Token endpoint authentication method (defaults to server default if not specified)", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "none" + }, + { + "kind": "literal", + "value": "client_secret_basic" + }, + { + "kind": "literal", + "value": "client_secret_post" + } + ] + } + } + ], + "name": "CreateOAuthClientParams" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "client_id", + "optional": false, + "description": "Unique identifier for the OAuth client", + "type": "string" + }, + { + "name": "client_name", + "optional": false, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "client_secret", + "optional": true, + "description": "Client secret (only returned on registration and regeneration)", + "type": "string" + }, + { + "name": "client_type", + "optional": false, + "description": "Type of OAuth client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "public" + }, + { + "kind": "literal", + "value": "confidential" + } + ] + } + }, + { + "name": "client_uri", + "optional": true, + "description": "URI of the OAuth client", + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "description": "Timestamp when the client was created", + "type": "string" + }, + { + "name": "grant_types", + "optional": false, + "description": "Array of allowed grant types", + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "authorization_code" + }, + { + "kind": "literal", + "value": "refresh_token" + } + ] + } + } + }, + { + "name": "logo_uri", + "optional": true, + "description": "URI of the OAuth client's logo", + "type": "string" + }, + { + "name": "redirect_uris", + "optional": false, + "description": "Array of allowed redirect URIs", + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "registration_type", + "optional": false, + "description": "Registration type of the client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "dynamic" + }, + { + "kind": "literal", + "value": "manual" + } + ] + } + }, + { + "name": "response_types", + "optional": false, + "description": "Array of allowed response types", + "type": { + "kind": "array", + "elementType": { + "kind": "literal", + "value": "code" + } + } + }, + { + "name": "scope", + "optional": true, + "description": "Scope of the OAuth client", + "type": "string" + }, + { + "name": "token_endpoint_auth_method", + "optional": false, + "description": "Token endpoint authentication method", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "none" + }, + { + "kind": "literal", + "value": "client_secret_basic" + }, + { + "kind": "literal", + "value": "client_secret_post" + } + ] + } + }, + { + "name": "updated_at", + "optional": false, + "description": "Timestamp when the client was last updated", + "type": "string" + } + ], + "name": "OAuthClient" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "deleteClient", + "description": "Deletes an OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "parameters": [ + { + "name": "clientId", + "type": "string" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + ] + } + } + ] + } + ] + } + }, + { + "name": "getClient", + "description": "Gets details of a specific OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "parameters": [ + { + "name": "clientId", + "type": "string" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "client_id", + "optional": false, + "description": "Unique identifier for the OAuth client", + "type": "string" + }, + { + "name": "client_name", + "optional": false, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "client_secret", + "optional": true, + "description": "Client secret (only returned on registration and regeneration)", + "type": "string" + }, + { + "name": "client_type", + "optional": false, + "description": "Type of OAuth client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "public" + }, + { + "kind": "literal", + "value": "confidential" + } + ] + } + }, + { + "name": "client_uri", + "optional": true, + "description": "URI of the OAuth client", + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "description": "Timestamp when the client was created", + "type": "string" + }, + { + "name": "grant_types", + "optional": false, + "description": "Array of allowed grant types", + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "authorization_code" + }, + { + "kind": "literal", + "value": "refresh_token" + } + ] + } + } + }, + { + "name": "logo_uri", + "optional": true, + "description": "URI of the OAuth client's logo", + "type": "string" + }, + { + "name": "redirect_uris", + "optional": false, + "description": "Array of allowed redirect URIs", + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "registration_type", + "optional": false, + "description": "Registration type of the client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "dynamic" + }, + { + "kind": "literal", + "value": "manual" + } + ] + } + }, + { + "name": "response_types", + "optional": false, + "description": "Array of allowed response types", + "type": { + "kind": "array", + "elementType": { + "kind": "literal", + "value": "code" + } + } + }, + { + "name": "scope", + "optional": true, + "description": "Scope of the OAuth client", + "type": "string" + }, + { + "name": "token_endpoint_auth_method", + "optional": false, + "description": "Token endpoint authentication method", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "none" + }, + { + "kind": "literal", + "value": "client_secret_basic" + }, + { + "kind": "literal", + "value": "client_secret_post" + } + ] + } + }, + { + "name": "updated_at", + "optional": false, + "description": "Timestamp when the client was last updated", + "type": "string" + } + ], + "name": "OAuthClient" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "listClients", + "description": "Lists all OAuth clients with optional pagination. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "parameters": [ + { + "name": "params", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "page", + "optional": true, + "description": "The page number", + "type": "number" + }, + { + "name": "perPage", + "optional": true, + "description": "Number of items returned per page", + "type": "number" + } + ], + "name": "PageParams" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "intersection", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "clients", + "optional": false, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "properties": [ + { + "name": "client_id", + "optional": false, + "description": "Unique identifier for the OAuth client", + "type": "string" + }, + { + "name": "client_name", + "optional": false, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "client_secret", + "optional": true, + "description": "Client secret (only returned on registration and regeneration)", + "type": "string" + }, + { + "name": "client_type", + "optional": false, + "description": "Type of OAuth client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "public" + }, + { + "kind": "literal", + "value": "confidential" + } + ] + } + }, + { + "name": "client_uri", + "optional": true, + "description": "URI of the OAuth client", + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "description": "Timestamp when the client was created", + "type": "string" + }, + { + "name": "grant_types", + "optional": false, + "description": "Array of allowed grant types", + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "authorization_code" + }, + { + "kind": "literal", + "value": "refresh_token" + } + ] + } + } + }, + { + "name": "logo_uri", + "optional": true, + "description": "URI of the OAuth client's logo", + "type": "string" + }, + { + "name": "redirect_uris", + "optional": false, + "description": "Array of allowed redirect URIs", + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "registration_type", + "optional": false, + "description": "Registration type of the client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "dynamic" + }, + { + "kind": "literal", + "value": "manual" + } + ] + } + }, + { + "name": "response_types", + "optional": false, + "description": "Array of allowed response types", + "type": { + "kind": "array", + "elementType": { + "kind": "literal", + "value": "code" + } + } + }, + { + "name": "scope", + "optional": true, + "description": "Scope of the OAuth client", + "type": "string" + }, + { + "name": "token_endpoint_auth_method", + "optional": false, + "description": "Token endpoint authentication method", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "none" + }, + { + "kind": "literal", + "value": "client_secret_basic" + }, + { + "kind": "literal", + "value": "client_secret_post" + } + ] + } + }, + { + "name": "updated_at", + "optional": false, + "description": "Timestamp when the client was last updated", + "type": "string" + } + ], + "name": "OAuthClient" + } + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "lastPage", + "optional": false, + "type": "number" + }, + { + "name": "nextPage", + "optional": false, + "type": { + "kind": "union", + "types": [ + "number", + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "total", + "optional": false, + "type": "number" + } + ], + "name": "Pagination" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "clients", + "optional": false, + "type": { + "kind": "tuple", + "elements": [] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + } + }, + { + "name": "regenerateClientSecret", + "description": "Regenerates the secret for an OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "parameters": [ + { + "name": "clientId", + "type": "string" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "client_id", + "optional": false, + "description": "Unique identifier for the OAuth client", + "type": "string" + }, + { + "name": "client_name", + "optional": false, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "client_secret", + "optional": true, + "description": "Client secret (only returned on registration and regeneration)", + "type": "string" + }, + { + "name": "client_type", + "optional": false, + "description": "Type of OAuth client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "public" + }, + { + "kind": "literal", + "value": "confidential" + } + ] + } + }, + { + "name": "client_uri", + "optional": true, + "description": "URI of the OAuth client", + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "description": "Timestamp when the client was created", + "type": "string" + }, + { + "name": "grant_types", + "optional": false, + "description": "Array of allowed grant types", + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "authorization_code" + }, + { + "kind": "literal", + "value": "refresh_token" + } + ] + } + } + }, + { + "name": "logo_uri", + "optional": true, + "description": "URI of the OAuth client's logo", + "type": "string" + }, + { + "name": "redirect_uris", + "optional": false, + "description": "Array of allowed redirect URIs", + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "registration_type", + "optional": false, + "description": "Registration type of the client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "dynamic" + }, + { + "kind": "literal", + "value": "manual" + } + ] + } + }, + { + "name": "response_types", + "optional": false, + "description": "Array of allowed response types", + "type": { + "kind": "array", + "elementType": { + "kind": "literal", + "value": "code" + } + } + }, + { + "name": "scope", + "optional": true, + "description": "Scope of the OAuth client", + "type": "string" + }, + { + "name": "token_endpoint_auth_method", + "optional": false, + "description": "Token endpoint authentication method", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "none" + }, + { + "kind": "literal", + "value": "client_secret_basic" + }, + { + "kind": "literal", + "value": "client_secret_post" + } + ] + } + }, + { + "name": "updated_at", + "optional": false, + "description": "Timestamp when the client was last updated", + "type": "string" + } + ], + "name": "OAuthClient" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "updateClient", + "description": "Updates an existing OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "parameters": [ + { + "name": "clientId", + "type": "string" + }, + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "client_name", + "optional": true, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "client_uri", + "optional": true, + "description": "URI of the OAuth client", + "type": "string" + }, + { + "name": "grant_types", + "optional": true, + "description": "Array of allowed grant types", + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "authorization_code" + }, + { + "kind": "literal", + "value": "refresh_token" + } + ] + } + } + }, + { + "name": "logo_uri", + "optional": true, + "description": "URI of the OAuth client's logo", + "type": "string" + }, + { + "name": "redirect_uris", + "optional": true, + "description": "Array of allowed redirect URIs", + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "token_endpoint_auth_method", + "optional": true, + "description": "Token endpoint authentication method", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "none" + }, + { + "kind": "literal", + "value": "client_secret_basic" + }, + { + "kind": "literal", + "value": "client_secret_post" + } + ] + } + } + ], + "name": "UpdateOAuthClientParams" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "client_id", + "optional": false, + "description": "Unique identifier for the OAuth client", + "type": "string" + }, + { + "name": "client_name", + "optional": false, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "client_secret", + "optional": true, + "description": "Client secret (only returned on registration and regeneration)", + "type": "string" + }, + { + "name": "client_type", + "optional": false, + "description": "Type of OAuth client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "public" + }, + { + "kind": "literal", + "value": "confidential" + } + ] + } + }, + { + "name": "client_uri", + "optional": true, + "description": "URI of the OAuth client", + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "description": "Timestamp when the client was created", + "type": "string" + }, + { + "name": "grant_types", + "optional": false, + "description": "Array of allowed grant types", + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "authorization_code" + }, + { + "kind": "literal", + "value": "refresh_token" + } + ] + } + } + }, + { + "name": "logo_uri", + "optional": true, + "description": "URI of the OAuth client's logo", + "type": "string" + }, + { + "name": "redirect_uris", + "optional": false, + "description": "Array of allowed redirect URIs", + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "registration_type", + "optional": false, + "description": "Registration type of the client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "dynamic" + }, + { + "kind": "literal", + "value": "manual" + } + ] + } + }, + { + "name": "response_types", + "optional": false, + "description": "Array of allowed response types", + "type": { + "kind": "array", + "elementType": { + "kind": "literal", + "value": "code" + } + } + }, + { + "name": "scope", + "optional": true, + "description": "Scope of the OAuth client", + "type": "string" + }, + { + "name": "token_endpoint_auth_method", + "optional": false, + "description": "Token endpoint authentication method", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "none" + }, + { + "kind": "literal", + "value": "client_secret_basic" + }, + { + "kind": "literal", + "value": "client_secret_post" + } + ] + } + }, + { + "name": "updated_at", + "optional": false, + "description": "Timestamp when the client was last updated", + "type": "string" + } + ], + "name": "OAuthClient" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "challenge", + "description": "Prepares a challenge used to verify that a user has access to a MFA factor.", + "remarks": [ + "- An [enrolled factor](/docs/reference/javascript/auth-mfa-enroll) is required before creating a challenge. - To verify a challenge, see [`mfa.verify()`](/docs/reference/javascript/auth-mfa-verify). - A phone factor sends a code to the user upon challenge. The channel defaults to `sms` unless otherwise specified." + ], + "parameters": [ + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "factorId", + "optional": false, + "description": "ID of the factor to be challenged. Returned in enroll().", + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "expires_at", + "optional": false, + "description": "Timestamp in UNIX seconds when this challenge will no longer be usable.", + "type": "number" + }, + { + "name": "id", + "optional": false, + "description": "ID of the newly created challenge.", + "type": "string" + }, + { + "name": "type", + "optional": false, + "description": "Factor Type which generated the challenge", + "type": { + "kind": "literal", + "value": "totp" + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Create a challenge for a factor", + "code": "const { data, error } = await supabase.auth.mfa.challenge({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225'\n})", + "response": "{\n data: {\n id: '',\n type: 'totp',\n expires_at: 1700000000\n },\n error: null\n}" + }, + { + "title": "Create a challenge for a phone factor", + "code": "const { data, error } = await supabase.auth.mfa.challenge({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n})", + "response": "{\n data: {\n id: '',\n type: 'phone',\n expires_at: 1700000000\n },\n error: null\n}" + }, + { + "title": "Create a challenge for a phone factor (WhatsApp)", + "code": "const { data, error } = await supabase.auth.mfa.challenge({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n channel: 'whatsapp',\n})", + "response": "{\n data: {\n id: '',\n expires_at: 1700000000\n },\n error: null\n}" + } + ] + }, + { + "name": "challengeAndVerify", + "description": "Helper method which creates a challenge and immediately uses the given code to verify against it thereafter. The verification code is provided by the user by entering a code seen in their authenticator app.", + "remarks": [ + "- Intended for use with only TOTP factors. - An [enrolled factor](/docs/reference/javascript/auth-mfa-enroll) is required before invoking `challengeAndVerify()`. - Executes [`mfa.challenge()`](/docs/reference/javascript/auth-mfa-challenge) and [`mfa.verify()`](/docs/reference/javascript/auth-mfa-verify) in a single step." + ], + "parameters": [ + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "code", + "optional": false, + "description": "Verification code provided by the user.", + "type": "string" + }, + { + "name": "factorId", + "optional": false, + "description": "ID of the factor being verified. Returned in enroll().", + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "New access token (JWT) after successful verification.", + "type": "string" + }, + { + "name": "expires_in", + "optional": false, + "description": "Number of seconds in which the access token will expire.", + "type": "number" + }, + { + "name": "refresh_token", + "optional": false, + "description": "Refresh token you can use to obtain new access tokens when expired.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "description": "Type of token, always `bearer`.", + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "Updated user profile.", + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ], + "name": "AuthMFAVerifyResponseData" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Create and verify a challenge for a factor", + "code": "const { data, error } = await supabase.auth.mfa.challengeAndVerify({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n code: '123456'\n})", + "response": "{\n data: {\n access_token: '',\n token_type: 'Bearer',\n expires_in: 3600,\n refresh_token: '',\n user: {\n id: '11111111-1111-1111-1111-111111111111',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {\n provider: 'email',\n providers: [\n \"email\",\n ]\n },\n user_metadata: {},\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false,\n factors: [\n \"id\": '',\n \"friendly_name\": 'Important Auth App',\n \"factor_type\": 'totp',\n \"status\": 'verified',\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n ]\n }\n }\n error: null\n}" + } + ] + }, + { + "name": "enroll", + "description": "Starts the enrollment process for a new Multi-Factor Authentication (MFA) factor. This method creates a new `unverified` factor. To verify a factor, present the QR code or secret to the user and ask them to add it to their authenticator app. The user has to enter the code from their authenticator app to verify it.\nUpon verifying a factor, all other sessions are logged out and the current session's authenticator level is promoted to `aal2`.", + "remarks": [ + "- Use `totp` or `phone` as the `factorType` and use the returned `id` to create a challenge. - To create a challenge, see [`mfa.challenge()`](/docs/reference/javascript/auth-mfa-challenge). - To verify a challenge, see [`mfa.verify()`](/docs/reference/javascript/auth-mfa-verify). - To create and verify a TOTP challenge in a single step, see [`mfa.challengeAndVerify()`](/docs/reference/javascript/auth-mfa-challengeandverify). - To generate a QR code for the `totp` secret in Next.js, you can do the following: ```html {data.totp.uri} ``` - The `challenge` and `verify` steps are separated when using Phone factors as the user will need time to receive and input the code obtained from the SMS in challenge." + ], + "parameters": [ + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "factorType", + "optional": false, + "description": "The type of factor being enrolled.", + "type": { + "kind": "literal", + "value": "totp" + } + }, + { + "name": "friendlyName", + "optional": true, + "description": "Human readable name assigned to the factor.", + "type": "string" + }, + { + "name": "issuer", + "optional": true, + "description": "Domain which the user is enrolled with.", + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Enroll a time-based, one-time password (TOTP) factor", + "code": "const { data, error } = await supabase.auth.mfa.enroll({\n factorType: 'totp',\n friendlyName: 'your_friendly_name'\n})\n\n// Use the id to create a challenge.\n// The challenge can be verified by entering the code generated from the authenticator app.\n// The code will be generated upon scanning the qr_code or entering the secret into the authenticator app.\nconst { id, type, totp: { qr_code, secret, uri }, friendly_name } = data\nconst challenge = await supabase.auth.mfa.challenge({ factorId: id });", + "response": "{\n data: {\n id: '',\n type: 'totp'\n totp: {\n qr_code: '',\n secret: '',\n uri: '',\n }\n friendly_name?: 'Important app'\n },\n error: null\n}" + }, + { + "title": "Enroll a Phone Factor", + "code": "const { data, error } = await supabase.auth.mfa.enroll({\n factorType: 'phone',\n friendlyName: 'your_friendly_name',\n phone: '+12345678',\n})\n\n// Use the id to create a challenge and send an SMS with a code to the user.\nconst { id, type, friendly_name, phone } = data\n\nconst challenge = await supabase.auth.mfa.challenge({ factorId: id });", + "response": "{\n data: {\n id: '',\n type: 'phone',\n friendly_name?: 'Important app',\n phone: '+5787123456'\n },\n error: null\n}" + } + ] + }, + { + "name": "getAuthenticatorAssuranceLevel", + "description": "Returns the Authenticator Assurance Level (AAL) for the active session.\n- `aal1` (or `null`) means that the user's identity has been verified only with a conventional login (email+password, OTP, magic link, social login, etc.). - `aal2` means that the user's identity has been verified both with a conventional login and at least one MFA factor.\nWhen called without a JWT parameter, this method is fairly quick (microseconds) and rarely uses the network. When a JWT is provided (useful in server-side environments like Edge Functions where no session is stored), this method will make a network request to validate the user and fetch their MFA factors.", + "remarks": [ + "- Authenticator Assurance Level (AAL) is the measure of the strength of an authentication mechanism. - In Supabase, having an AAL of `aal1` refers to having the 1st factor of authentication such as an email and password or OAuth sign-in while `aal2` refers to the 2nd factor of authentication such as a time-based, one-time-password (TOTP) or Phone factor. - If the user has a verified factor, the `nextLevel` field will return `aal2`, else, it will return `aal1`. - An optional `jwt` parameter can be passed to check the AAL level of a specific JWT instead of the current session." + ], + "parameters": [ + { + "name": "jwt", + "optional": true, + "description": "Takes in an optional access token JWT. If no JWT is provided, the JWT from the current session is used.", + "type": "string" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "currentAuthenticationMethods", + "optional": false, + "description": "A list of all authentication methods attached to this session. Use the information here to detect the last time a user verified a factor, for example if implementing a step-up scenario.\nSupports both RFC-8176 compliant format (string[]) and detailed format (AMREntry[]). - String format: ['password', 'otp'] - RFC-8176 compliant - Object format: [{ method: 'password', timestamp: 1234567890 }] - includes timestamps", + "type": { + "kind": "union", + "types": [ + { + "kind": "array", + "elementType": { + "kind": "object", + "name": "AMREntry", + "properties": [ + { + "name": "method", + "optional": false, + "description": "Authentication method name.", + "type": { + "kind": "union", + "types": [ + { + "kind": "indexedAccess", + "objectType": { + "kind": "query" + }, + "indexType": null + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "timestamp", + "optional": false, + "description": "Timestamp when the method was successfully used. Represents number of seconds since 1st January 1970 (UNIX epoch) in UTC.", + "type": "number" + } + ] + } + }, + { + "kind": "array", + "elementType": "string" + } + ] + } + }, + { + "name": "currentLevel", + "optional": false, + "description": "Current AAL level of the session.", + "type": { + "kind": "union", + "types": [ + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "aal1" + }, + { + "kind": "literal", + "value": "aal2" + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "nextLevel", + "optional": false, + "description": "Next possible AAL level for the session. If the next level is higher than the current one, the user should go through MFA.", + "type": { + "kind": "union", + "types": [ + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "aal1" + }, + { + "kind": "literal", + "value": "aal2" + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Get the AAL details of a session", + "code": "const { data, error } = await supabase.auth.mfa.getAuthenticatorAssuranceLevel()\nconst { currentLevel, nextLevel, currentAuthenticationMethods } = data", + "response": "{\n data: {\n currentLevel: 'aal1',\n nextLevel: 'aal2',\n currentAuthenticationMethods: [\n {\n method: 'password',\n timestamp: 1700000000\n }\n ]\n }\n error: null\n}" + }, + { + "title": "Get the AAL details for a specific JWT", + "code": "const { data, error } = await supabase.auth.mfa.getAuthenticatorAssuranceLevel(jwt)" + } + ] + }, + { + "name": "listFactors", + "description": "Returns the list of MFA factors enabled for this user.", + "parameters": [], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "intersection", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "all", + "optional": false, + "description": "All available factors (verified and unverified).", + "type": { + "kind": "array", + "elementType": { + "kind": "conditional" + } + } + } + ] + }, + { + "kind": "mapped" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "unenroll", + "description": "Unenroll removes a MFA factor. A user has to have an `aal2` authenticator level in order to unenroll a `verified` factor.", + "parameters": [ + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "factorId", + "optional": false, + "description": "ID of the factor being unenrolled.", + "type": "string" + } + ], + "name": "MFAUnenrollParams" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "id", + "optional": false, + "description": "ID of the factor that was successfully unenrolled.", + "type": "string" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Unenroll a factor", + "code": "const { data, error } = await supabase.auth.mfa.unenroll({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n})", + "response": "{\n data: {\n id: ''\n },\n error: null\n}" + } + ] + }, + { + "name": "verify", + "description": "Verifies a code against a challenge. The verification code is provided by the user by entering a code seen in their authenticator app.", + "remarks": [ + "- To verify a challenge, please [create a challenge](/docs/reference/javascript/auth-mfa-challenge) first." + ], + "parameters": [ + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "challengeId", + "optional": false, + "description": "ID of the challenge being verified. Returned in challenge().", + "type": "string" + }, + { + "name": "code", + "optional": false, + "description": "Verification code provided by the user.", + "type": "string" + }, + { + "name": "factorId", + "optional": false, + "description": "ID of the factor being verified. Returned in enroll().", + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "New access token (JWT) after successful verification.", + "type": "string" + }, + { + "name": "expires_in", + "optional": false, + "description": "Number of seconds in which the access token will expire.", + "type": "number" + }, + { + "name": "refresh_token", + "optional": false, + "description": "Refresh token you can use to obtain new access tokens when expired.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "description": "Type of token, always `bearer`.", + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "Updated user profile.", + "type": { + "kind": "object", + "name": "User", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + }, + { + "kind": "literal", + "value": "webauthn" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ], + "name": "AuthMFAVerifyResponseData" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Verify a challenge for a factor", + "code": "const { data, error } = await supabase.auth.mfa.verify({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n challengeId: '4034ae6f-a8ce-4fb5-8ee5-69a5863a7c15',\n code: '123456'\n})", + "response": "{\n data: {\n access_token: '',\n token_type: 'Bearer',\n expires_in: 3600,\n refresh_token: '',\n user: {\n id: '11111111-1111-1111-1111-111111111111',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {\n provider: 'email',\n providers: [\n \"email\",\n ]\n },\n user_metadata: {},\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false,\n factors: [\n \"id\": '',\n \"friendly_name\": 'Important Auth App',\n \"factor_type\": 'totp',\n \"status\": 'verified',\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n ]\n }\n }\n error: null\n}" + } + ] + }, + { + "name": "createUser", + "description": "Creates a new user. This function should only be called on a server. Never expose your `service_role` key in the browser.", + "remarks": [ + "- To confirm the user's email address or phone number, set `email_confirm` or `phone_confirm` to true. Both arguments default to false. - `createUser()` will not send a confirmation email to the user. You can use [`inviteUserByEmail()`](/docs/reference/javascript/auth-admin-inviteuserbyemail) if you want to send them an email invite instead. - If you are sure that the created user's email or phone number is legitimate and verified, you can set the `email_confirm` or `phone_confirm` param to `true`." + ], + "parameters": [ + { + "name": "attributes", + "type": { + "kind": "object", + "name": "AdminUserAttributes", + "properties": [ + { + "name": "app_metadata", + "optional": true, + "description": "A custom data object to store the user's application specific metadata. This maps to the `auth.users.app_metadata` column.\nOnly a service role can modify.\nThe `app_metadata` should be a JSON object that includes app-specific info, such as identity providers, roles, and other access control information.", + "type": "object" + }, + { + "name": "ban_duration", + "optional": true, + "description": "Determines how long a user is banned for.\nThe format for the ban duration follows a strict sequence of decimal numbers with a unit suffix. Valid time units are \"ns\", \"us\" (or \"µs\"), \"ms\", \"s\", \"m\", \"h\".\nFor example, some possible durations include: '300ms', '2h45m'.\nSetting the ban duration to 'none' lifts the ban on the user.", + "type": "string" + }, + { + "name": "current_password", + "optional": true, + "description": "The user's current password\nThis is only ever present when the user is resetting their password and GOTRUE_SECURITY_UPDATE_PASSWORD_REQUIRE_CURRENT_PASSWORD is true.", + "type": "string" + }, + { + "name": "email", + "optional": true, + "description": "The user's email.", + "type": "string" + }, + { + "name": "email_confirm", + "optional": true, + "description": "Sets the user's email as confirmed when true, or unconfirmed when false.\nOnly a service role can modify.", + "type": "boolean" + }, + { + "name": "id", + "optional": true, + "description": "The `id` for the user.\nAllows you to overwrite the default `id` set for the user.", + "type": "string" + }, + { + "name": "nonce", + "optional": true, + "description": "The nonce sent for reauthentication if the user's password is to be updated.\nCall reauthenticate() to obtain the nonce first.", + "type": "string" + }, + { + "name": "password", + "optional": true, + "description": "The user's password.", + "type": "string" + }, + { + "name": "password_hash", + "optional": true, + "description": "The `password_hash` for the user's password.\nAllows you to specify a password hash for the user. This is useful for migrating a user's password hash from another service.\nSupports bcrypt, scrypt (firebase), and argon2 password hashes.", + "type": "string" + }, + { + "name": "phone", + "optional": true, + "description": "The user's phone.", + "type": "string" + }, + { + "name": "phone_confirm", + "optional": true, + "description": "Sets the user's phone as confirmed when true, or unconfirmed when false.\nOnly a service role can modify.", + "type": "boolean" + }, + { + "name": "role", + "optional": true, + "description": "The `role` claim set in the user's access token JWT.\nWhen a user signs up, this role is set to `authenticated` by default. You should only modify the `role` if you need to provision several levels of admin access that have different permissions on individual columns in your database.\nSetting this role to `service_role` is not recommended as it grants the user admin privileges.", + "type": "string" + }, + { + "name": "user_metadata", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `user_metadata` should be a JSON object that includes user-specific info, such as their first and last name.\nNote: When using the GoTrueAdminApi and wanting to modify a user's metadata, this attribute is used instead of UserAttributes data.", + "type": "object" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "With custom user metadata", + "code": "const { data, error } = await supabase.auth.admin.createUser({\n email: 'user@email.com',\n password: 'password',\n user_metadata: { name: 'Yoda' }\n})", + "response": "{\n data: {\n user: {\n id: '1',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {},\n user_metadata: {},\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"1\",\n \"user_id\": \"1\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"phone_verified\": false,\n \"sub\": \"1\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false,\n }\n }\n error: null\n}" + }, + { + "title": "Auto-confirm the user's email", + "code": "const { data, error } = await supabase.auth.admin.createUser({\n email: 'user@email.com',\n email_confirm: true\n})" + }, + { + "title": "Auto-confirm the user's phone number", + "code": "const { data, error } = await supabase.auth.admin.createUser({\n phone: '1234567890',\n phone_confirm: true\n})" + } + ] + }, + { + "name": "deleteUser", + "description": "Delete a user. Requires a `service_role` key.", + "remarks": [ + "- The `deleteUser()` method requires the user's ID, which maps to the `auth.users.id` column." + ], + "parameters": [ + { + "name": "id", + "description": "The user id you want to remove.", + "type": "string" + }, + { + "name": "shouldSoftDelete", + "optional": true, + "description": "If true, then the user will be soft-deleted from the auth schema. Soft deletion allows user identification from the hashed user ID but is not reversible. Defaults to false for backward compatibility.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "type": "boolean" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Removes a user", + "code": "const { data, error } = await supabase.auth.admin.deleteUser(\n '715ed5db-f090-4b8c-a067-640ecee36aa0'\n)", + "response": "{\n \"data\": {\n \"user\": {}\n },\n \"error\": null\n}" + } + ] + }, + { + "name": "generateLink", + "description": "Generates email links and OTPs to be sent via a custom email provider.", + "remarks": [ + "- The following types can be passed into `generateLink()`: `signup`, `magiclink`, `invite`, `recovery`, `email_change_current`, `email_change_new`, `phone_change`. - `generateLink()` only generates the email link for `email_change_email` if the **Secure email change** is enabled in your project's [email auth provider settings](/dashboard/project/_/auth/providers). - `generateLink()` handles the creation of the user for `signup`, `invite` and `magiclink`." + ], + "parameters": [ + { + "name": "params", + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "email", + "optional": false, + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "reference", + "name": "Pick", + "typeArguments": [ + { + "kind": "object", + "name": "GenerateLinkOptions", + "properties": [ + { + "name": "data", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", + "type": "object" + }, + { + "name": "redirectTo", + "optional": true, + "description": "The URL which will be appended to the email link generated.", + "type": "string" + } + ] + }, + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "data" + }, + { + "kind": "literal", + "value": "redirectTo" + } + ] + } + ] + } + }, + { + "name": "password", + "optional": false, + "type": "string" + }, + { + "name": "type", + "optional": false, + "type": { + "kind": "literal", + "value": "signup" + } + } + ], + "name": "GenerateSignupLinkParams" + }, + { + "kind": "object", + "properties": [ + { + "name": "email", + "optional": false, + "description": "The user's email", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "reference", + "name": "Pick", + "typeArguments": [ + { + "kind": "object", + "name": "GenerateLinkOptions", + "properties": [ + { + "name": "data", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", + "type": "object" + }, + { + "name": "redirectTo", + "optional": true, + "description": "The URL which will be appended to the email link generated.", + "type": "string" + } + ] + }, + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "data" + }, + { + "kind": "literal", + "value": "redirectTo" + } + ] + } + ] + } + }, + { + "name": "type", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "invite" + }, + { + "kind": "literal", + "value": "magiclink" + } + ] + } + } + ], + "name": "GenerateInviteOrMagiclinkParams" + }, + { + "kind": "object", + "properties": [ + { + "name": "email", + "optional": false, + "description": "The user's email", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "reference", + "name": "Pick", + "typeArguments": [ + { + "kind": "object", + "name": "GenerateLinkOptions", + "properties": [ + { + "name": "data", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", + "type": "object" + }, + { + "name": "redirectTo", + "optional": true, + "description": "The URL which will be appended to the email link generated.", + "type": "string" + } + ] + }, + { + "kind": "literal", + "value": "redirectTo" + } + ] + } + }, + { + "name": "type", + "optional": false, + "type": { + "kind": "literal", + "value": "recovery" + } + } + ], + "name": "GenerateRecoveryLinkParams" + }, + { + "kind": "object", + "properties": [ + { + "name": "email", + "optional": false, + "description": "The user's email", + "type": "string" + }, + { + "name": "newEmail", + "optional": false, + "description": "The user's new email. Only required if type is 'email_change_current' or 'email_change_new'.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "reference", + "name": "Pick", + "typeArguments": [ + { + "kind": "object", + "name": "GenerateLinkOptions", + "properties": [ + { + "name": "data", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", + "type": "object" + }, + { + "name": "redirectTo", + "optional": true, + "description": "The URL which will be appended to the email link generated.", + "type": "string" + } + ] + }, + { + "kind": "literal", + "value": "redirectTo" + } + ] + } + }, + { + "name": "type", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "email_change_current" + }, + { + "kind": "literal", + "value": "email_change_new" + } + ] + } + } + ], + "name": "GenerateEmailChangeLinkParams" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "properties", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "action_link", + "optional": false, + "description": "The email link to send to the user. The action_link follows the following format: auth/v1/verify?type={verification_type}&token={hashed_token}&redirect_to={redirect_to}", + "type": "string" + }, + { + "name": "email_otp", + "optional": false, + "description": "The raw email OTP. You should send this in the email if you want your users to verify using an OTP instead of the action link.", + "type": "string" + }, + { + "name": "hashed_token", + "optional": false, + "description": "The hashed token appended to the action link.", + "type": "string" + }, + { + "name": "redirect_to", + "optional": false, + "description": "The URL appended to the action link.", + "type": "string" + }, + { + "name": "verification_type", + "optional": false, + "description": "The verification type that the email link is associated to.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "signup" + }, + { + "kind": "literal", + "value": "invite" + }, + { + "kind": "literal", + "value": "magiclink" + }, + { + "kind": "literal", + "value": "recovery" + }, + { + "kind": "literal", + "value": "email_change_current" + }, + { + "kind": "literal", + "value": "email_change_new" + } + ] + } + } + ], + "name": "GenerateLinkProperties" + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Generate a signup link", + "code": "const { data, error } = await supabase.auth.admin.generateLink({\n type: 'signup',\n email: 'email@example.com',\n password: 'secret'\n})", + "response": "{\n \"data\": {\n \"properties\": {\n \"action_link\": \"\",\n \"email_otp\": \"999999\",\n \"hashed_token\": \"\",\n \"verification_type\": \"signup\"\n },\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"email@example.com\",\n \"phone\": \"\",\n \"confirmation_sent_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"email@example.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" + }, + { + "title": "Generate an invite link", + "code": "const { data, error } = await supabase.auth.admin.generateLink({\n type: 'invite',\n email: 'email@example.com'\n})" + }, + { + "title": "Generate a magic link", + "code": "const { data, error } = await supabase.auth.admin.generateLink({\n type: 'magiclink',\n email: 'email@example.com'\n})" + }, + { + "title": "Generate a recovery link", + "code": "const { data, error } = await supabase.auth.admin.generateLink({\n type: 'recovery',\n email: 'email@example.com'\n})" + }, + { + "title": "Generate links to change current email address", + "code": "// generate an email change link to be sent to the current email address\nconst { data, error } = await supabase.auth.admin.generateLink({\n type: 'email_change_current',\n email: 'current.email@example.com',\n newEmail: 'new.email@example.com'\n})\n\n// generate an email change link to be sent to the new email address\nconst { data, error } = await supabase.auth.admin.generateLink({\n type: 'email_change_new',\n email: 'current.email@example.com',\n newEmail: 'new.email@example.com'\n})" + } + ] + }, + { + "name": "getUserById", + "description": "Get user by id.", + "remarks": [ + "- Fetches the user object from the database based on the user's id. - The `getUserById()` method requires the user's id which maps to the `auth.users.id` column." + ], + "parameters": [ + { + "name": "uid", + "description": "The user's unique identifier\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "type": "string" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Fetch the user object using the access_token jwt", + "code": "const { data, error } = await supabase.auth.admin.getUserById(1)", + "response": "{\n data: {\n user: {\n id: '1',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {},\n user_metadata: {},\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"1\",\n \"user_id\": \"1\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"phone_verified\": false,\n \"sub\": \"1\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false,\n }\n }\n error: null\n}" + } + ] + }, + { + "name": "inviteUserByEmail", + "description": "Sends an invite link to an email address.", + "remarks": [ + "- Sends an invite link to the user's email address. - The `inviteUserByEmail()` method is typically used by administrators to invite users to join the application. - Note that PKCE is not supported when using `inviteUserByEmail`. This is because the browser initiating the invite is often different from the browser accepting the invite which makes it difficult to provide the security guarantees required of the PKCE flow." + ], + "parameters": [ + { + "name": "email", + "description": "The email address of the user.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "description": "Additional options to be included when inviting.", + "type": { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": true, + "description": "A custom data object to store additional metadata about the user. This maps to the `auth.users.user_metadata` column.", + "type": "object" + }, + { + "name": "redirectTo", + "optional": true, + "description": "The URL which will be appended to the email link sent to the user's email address. Once clicked the user will end up on this URL.", + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Invite a user", + "code": "const { data, error } = await supabase.auth.admin.inviteUserByEmail('email@example.com')", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"invited_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmation_sent_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" + } + ] + }, + { + "name": "listUsers", + "description": "Get a list of users.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "remarks": [ + "- Defaults to return 50 users per page." + ], + "parameters": [ + { + "name": "params", + "optional": true, + "description": "An object which supports `page` and `perPage` as numbers, to alter the paginated results.", + "type": { + "kind": "object", + "properties": [ + { + "name": "page", + "optional": true, + "description": "The page number", + "type": "number" + }, + { + "name": "perPage", + "optional": true, + "description": "Number of items returned per page", + "type": "number" + } + ], + "name": "PageParams" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "intersection", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "users", + "optional": false, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "lastPage", + "optional": false, + "type": "number" + }, + { + "name": "nextPage", + "optional": false, + "type": { + "kind": "union", + "types": [ + "number", + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "total", + "optional": false, + "type": "number" + } + ], + "name": "Pagination" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "users", + "optional": false, + "type": { + "kind": "tuple", + "elements": [] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Get a page of users", + "code": "const { data: { users }, error } = await supabase.auth.admin.listUsers()" + }, + { + "title": "Paginated list of users", + "code": "const { data: { users }, error } = await supabase.auth.admin.listUsers({\n page: 1,\n perPage: 1000\n})" + } + ] + }, + { + "name": "signOut", + "description": "Removes a logged-in session.", + "parameters": [ + { + "name": "jwt", + "description": "A valid, logged-in JWT.", + "type": "string" + }, + { + "name": "scope", + "optional": true, + "description": "The logout sope.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "global" + }, + { + "kind": "literal", + "value": "local" + }, + { + "kind": "literal", + "value": "others" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + ] + } + } + ] + } + ] + } + }, + { + "name": "updateUserById", + "description": "Updates the user data. Changes are applied directly without confirmation flows.", + "remarks": [ + "**Important:** This is a server-side operation and does **not** trigger client-side `onAuthStateChange` listeners. The admin API has no connection to client state.\nTo sync changes to the client after calling this method: 1. On the client, call `supabase.auth.refreshSession()` to fetch the updated user data 2. This will trigger the `TOKEN_REFRESHED` event and notify all listeners" + ], + "parameters": [ + { + "name": "uid", + "description": "The user's unique identifier", + "type": "string" + }, + { + "name": "attributes", + "description": "The data you want to update.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "type": { + "kind": "object", + "name": "AdminUserAttributes", + "properties": [ + { + "name": "app_metadata", + "optional": true, + "description": "A custom data object to store the user's application specific metadata. This maps to the `auth.users.app_metadata` column.\nOnly a service role can modify.\nThe `app_metadata` should be a JSON object that includes app-specific info, such as identity providers, roles, and other access control information.", + "type": "object" + }, + { + "name": "ban_duration", + "optional": true, + "description": "Determines how long a user is banned for.\nThe format for the ban duration follows a strict sequence of decimal numbers with a unit suffix. Valid time units are \"ns\", \"us\" (or \"µs\"), \"ms\", \"s\", \"m\", \"h\".\nFor example, some possible durations include: '300ms', '2h45m'.\nSetting the ban duration to 'none' lifts the ban on the user.", + "type": "string" + }, + { + "name": "current_password", + "optional": true, + "description": "The user's current password\nThis is only ever present when the user is resetting their password and GOTRUE_SECURITY_UPDATE_PASSWORD_REQUIRE_CURRENT_PASSWORD is true.", + "type": "string" + }, + { + "name": "email", + "optional": true, + "description": "The user's email.", + "type": "string" + }, + { + "name": "email_confirm", + "optional": true, + "description": "Sets the user's email as confirmed when true, or unconfirmed when false.\nOnly a service role can modify.", + "type": "boolean" + }, + { + "name": "id", + "optional": true, + "description": "The `id` for the user.\nAllows you to overwrite the default `id` set for the user.", + "type": "string" + }, + { + "name": "nonce", + "optional": true, + "description": "The nonce sent for reauthentication if the user's password is to be updated.\nCall reauthenticate() to obtain the nonce first.", + "type": "string" + }, + { + "name": "password", + "optional": true, + "description": "The user's password.", + "type": "string" + }, + { + "name": "password_hash", + "optional": true, + "description": "The `password_hash` for the user's password.\nAllows you to specify a password hash for the user. This is useful for migrating a user's password hash from another service.\nSupports bcrypt, scrypt (firebase), and argon2 password hashes.", + "type": "string" + }, + { + "name": "phone", + "optional": true, + "description": "The user's phone.", + "type": "string" + }, + { + "name": "phone_confirm", + "optional": true, + "description": "Sets the user's phone as confirmed when true, or unconfirmed when false.\nOnly a service role can modify.", + "type": "boolean" + }, + { + "name": "role", + "optional": true, + "description": "The `role` claim set in the user's access token JWT.\nWhen a user signs up, this role is set to `authenticated` by default. You should only modify the `role` if you need to provision several levels of admin access that have different permissions on individual columns in your database.\nSetting this role to `service_role` is not recommended as it grants the user admin privileges.", + "type": "string" + }, + { + "name": "user_metadata", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `user_metadata` should be a JSON object that includes user-specific info, such as their first and last name.\nNote: When using the GoTrueAdminApi and wanting to modify a user's metadata, this attribute is used instead of UserAttributes data.", + "type": "object" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Example 1", + "code": "// Server-side (Edge Function)\nconst { data, error } = await supabase.auth.admin.updateUserById(\n userId,\n { user_metadata: { preferences: { theme: 'dark' } } }\n)\n\n// Client-side (to sync the changes)\nconst { data, error } = await supabase.auth.refreshSession()\n// onAuthStateChange listeners will now be notified with updated user", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"new@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"recovery_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" + }, + { + "title": "Updates a user's email", + "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '11111111-1111-1111-1111-111111111111',\n { email: 'new@email.com' }\n)", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"new@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"recovery_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" + }, + { + "title": "Updates a user's password", + "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { password: 'new_password' }\n)" + }, + { + "title": "Updates a user's metadata", + "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { user_metadata: { hello: 'world' } }\n)" + }, + { + "title": "Updates a user's app_metadata", + "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { app_metadata: { plan: 'trial' } }\n)" + }, + { + "title": "Confirms a user's email address", + "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { email_confirm: true }\n)" + }, + { + "title": "Confirms a user's phone number", + "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { phone_confirm: true }\n)" + }, + { + "title": "Ban a user for 100 years", + "code": "const { data: user, error } = await supabase.auth.admin.updateUserById(\n '6aa5d0d4-2a9f-4483-b6c8-0cf4c6c98ac4',\n { ban_duration: '876000h' }\n)" + } + ] + }, + { + "name": "exchangeCodeForSession", + "description": "Log in an existing user by exchanging an Auth Code issued during the PKCE flow.", + "remarks": [ + "- Used when `flowType` is set to `pkce` in client options." + ], + "parameters": [ + { + "name": "authCode", + "type": "string" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "object", + "name": "AuthSession", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Exchange Auth Code", + "code": "supabase.auth.exchangeCodeForSession('34e770dd-9ff9-416c-87fa-43b31d7ef225')", + "response": "{\n \"data\": {\n session: {\n access_token: '',\n token_type: 'bearer',\n expires_in: 3600,\n expires_at: 1700000000,\n refresh_token: '',\n user: {\n id: '11111111-1111-1111-1111-111111111111',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com'\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {\n \"provider\": \"email\",\n \"providers\": [\n \"email\",\n \"\"\n ]\n },\n user_metadata: {\n email: 'email@email.com',\n email_verified: true,\n full_name: 'User Name',\n iss: '',\n name: 'User Name',\n phone_verified: false,\n provider_id: '',\n sub: ''\n },\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n {\n \"identity_id\": \"33333333-3333-3333-3333-333333333333\",\n \"id\": \"\",\n \"user_id\": \"\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"full_name\": \"User Name\",\n \"iss\": \"\",\n \"name\": \"User Name\",\n \"phone_verified\": false,\n \"provider_id\": \"\",\n \"sub\": \"\"\n },\n \"provider\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false\n },\n provider_token: '',\n provider_refresh_token: ''\n },\n user: {\n id: '11111111-1111-1111-1111-111111111111',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {\n provider: 'email',\n providers: [\n \"email\",\n \"\"\n ]\n },\n user_metadata: {\n email: 'email@email.com',\n email_verified: true,\n full_name: 'User Name',\n iss: '',\n name: 'User Name',\n phone_verified: false,\n provider_id: '',\n sub: ''\n },\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n {\n \"identity_id\": \"33333333-3333-3333-3333-333333333333\",\n \"id\": \"\",\n \"user_id\": \"\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"full_name\": \"User Name\",\n \"iss\": \"\",\n \"name\": \"User Name\",\n \"phone_verified\": false,\n \"provider_id\": \"\",\n \"sub\": \"\"\n },\n \"provider\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false\n },\n redirectType: null\n },\n \"error\": null\n}" + } + ] + }, + { + "name": "getClaims", + "description": "Extracts the JWT claims present in the access token by first verifying the JWT against the server's JSON Web Key Set endpoint `/.well-known/jwks.json` which is often cached, resulting in significantly faster responses. Prefer this method over #getUser which always sends a request to the Auth server for each JWT.\nIf the project is not using an asymmetric JWT signing key (like ECC or RSA) it always sends a request to the Auth server (similar to #getUser) to verify the JWT.", + "remarks": [ + "- Parses the user's [access token](/docs/guides/auth/sessions#access-token-jwt-claims) as a [JSON Web Token (JWT)](/docs/guides/auth/jwts) and returns its components if valid and not expired. - If your project is using asymmetric JWT signing keys, then the verification is done locally usually without a network request using the [WebCrypto API](https://developer.mozilla.org/en-US/docs/Web/API/Web_Crypto_API). - A network request is sent to your project's JWT signing key discovery endpoint `https://project-id.supabase.co/auth/v1/.well-known/jwks.json`, which is cached locally. If your environment is ephemeral, such as a Lambda function that is destroyed after every request, a network request will be sent for each new invocation. Supabase provides a network-edge cache providing fast responses for these situations. - If the user's access token is about to expire when calling this function, the user's session will first be refreshed before validating the JWT. - If your project is using a symmetric secret to sign the JWT, it always sends a request similar to `getUser()` to validate the JWT at the server before returning the decoded token. This is also used if the WebCrypto API is not available in the environment. Make sure you polyfill it in such situations. - The returned claims can be customized per project using the [Custom Access Token Hook](/docs/guides/auth/auth-hooks/custom-access-token-hook)." + ], + "parameters": [ + { + "name": "jwt", + "optional": true, + "description": "An optional specific JWT you wish to verify, not the one you can obtain from #getSession.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "description": "Various additional options that allow you to customize the behavior of this method.", + "type": { + "kind": "object", + "properties": [ + { + "name": "allowExpired", + "optional": true, + "description": "If set to `true` the `exp` claim will not be validated against the current time.", + "type": "boolean" + }, + { + "name": "jwks", + "optional": true, + "description": "If set, this JSON Web Key Set is going to have precedence over the cached value available on the server.", + "type": { + "kind": "object", + "properties": [ + { + "name": "keys", + "optional": false, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "JWK", + "properties": [ + { + "name": "alg", + "optional": true, + "type": "string" + }, + { + "name": "key_ops", + "optional": false, + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "kid", + "optional": true, + "type": "string" + }, + { + "name": "kty", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "RSA" + }, + { + "kind": "literal", + "value": "EC" + }, + { + "kind": "literal", + "value": "oct" + } + ] + } + } + ] + } + } + } + ] + } + }, + { + "name": "keys", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "JWK", + "properties": [ + { + "name": "alg", + "optional": true, + "type": "string" + }, + { + "name": "key_ops", + "optional": false, + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "kid", + "optional": true, + "type": "string" + }, + { + "name": "kty", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "RSA" + }, + { + "kind": "literal", + "value": "EC" + }, + { + "kind": "literal", + "value": "oct" + } + ] + } + } + ] + } + } + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "claims", + "optional": false, + "type": { + "kind": "object", + "name": "JwtPayload", + "properties": [ + { + "name": "aal", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "aal1" + }, + { + "kind": "literal", + "value": "aal2" + } + ] + } + }, + { + "name": "amr", + "optional": true, + "description": "Authentication Method References. Supports both RFC-8176 compliant format (string[]) and detailed format (AMREntry[]). - String format: ['password', 'otp'] - RFC-8176 compliant - Object format: [{ method: 'password', timestamp: 1234567890 }] - includes timestamps", + "type": { + "kind": "union", + "types": [ + { + "kind": "array", + "elementType": "string" + }, + { + "kind": "array", + "elementType": { + "kind": "object", + "name": "AMREntry", + "properties": [ + { + "name": "method", + "optional": false, + "description": "Authentication method name.", + "type": { + "kind": "union", + "types": [ + { + "kind": "indexedAccess", + "objectType": { + "kind": "query" + }, + "indexType": null + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "timestamp", + "optional": false, + "description": "Timestamp when the method was successfully used. Represents number of seconds since 1st January 1970 (UNIX epoch) in UTC.", + "type": "number" + } + ] + } + } + ] + } + }, + { + "name": "app_metadata", + "optional": true, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": { + "kind": "union", + "types": [ + "string", + { + "kind": "array", + "elementType": "string" + } + ] + } + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "exp", + "optional": false, + "type": "number" + }, + { + "name": "iat", + "optional": false, + "type": "number" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "iss", + "optional": false, + "type": "string" + }, + { + "name": "jti", + "optional": true, + "type": "string" + }, + { + "name": "nbf", + "optional": true, + "type": "number" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "ref", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": false, + "type": "string" + }, + { + "name": "session_id", + "optional": false, + "type": "string" + }, + { + "name": "sub", + "optional": false, + "type": "string" + }, + { + "name": "user_metadata", + "optional": true, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + }, + { + "name": "header", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "alg", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "RS256" + }, + { + "kind": "literal", + "value": "ES256" + }, + { + "kind": "literal", + "value": "HS256" + } + ] + } + }, + { + "name": "kid", + "optional": false, + "type": "string" + }, + { + "name": "typ", + "optional": false, + "type": "string" + } + ], + "name": "JwtHeader" + } + }, + { + "name": "signature", + "optional": false, + "type": { + "kind": "reference", + "name": "Uint8Array" + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Get JWT claims, header and signature", + "code": "const { data, error } = await supabase.auth.getClaims()", + "response": "{\n \"data\": {\n \"claims\": {\n \"aal\": \"aal1\",\n \"amr\": [{\n \"method\": \"email\",\n \"timestamp\": 1715766000\n }],\n \"app_metadata\": {},\n \"aud\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"exp\": 1715769600,\n \"iat\": 1715766000,\n \"is_anonymous\": false,\n \"iss\": \"https://project-id.supabase.co/auth/v1\",\n \"phone\": \"+13334445555\",\n \"role\": \"authenticated\",\n \"session_id\": \"11111111-1111-1111-1111-111111111111\",\n \"sub\": \"11111111-1111-1111-1111-111111111111\",\n \"user_metadata\": {}\n },\n \"header\": {\n \"alg\": \"RS256\",\n \"typ\": \"JWT\",\n \"kid\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"signature\": [/** Uint8Array */],\n },\n \"error\": null\n}" + } + ] + }, + { + "name": "getSession", + "description": "Returns the session, refreshing it if necessary.\nThe session returned can be null if the session is not detected which can happen in the event a user is not signed-in or has logged out.\n**IMPORTANT:** This method loads values directly from the storage attached to the client. If that storage is based on request cookies for example, the values in it may not be authentic and therefore it's strongly advised against using this method and its results in such circumstances. A warning will be emitted if this is detected. Use #getUser() instead.", + "remarks": [ + "- Since the introduction of [asymmetric JWT signing keys](/docs/guides/auth/signing-keys), this method is considered low-level and we encourage you to use `getClaims()` or `getUser()` instead. - Retrieves the current [user session](/docs/guides/auth/sessions) from the storage medium (local storage, cookies). - The session contains an access token (signed JWT), a refresh token and the user object. - If the session's access token is expired or is about to expire, this method will use the refresh token to refresh the session. - When using in a browser, or you've called `startAutoRefresh()` in your environment (React Native, etc.) this function always returns a valid access token without refreshing the session itself, as this is done in the background. This function returns very fast. - **IMPORTANT SECURITY NOTICE:** If using an insecure storage medium, such as cookies or request headers, the user object returned by this function **must not be trusted**. Always verify the JWT using `getClaims()` or your own JWT verification library to securely establish the user's identity and access. You can also use `getUser()` to fetch the user object directly from the Auth server for this purpose. - When using in a browser, this function is synchronized across all tabs using the [LockManager](https://developer.mozilla.org/en-US/docs/Web/API/LockManager) API. In other environments make sure you've defined a proper `lock` property, if necessary, to make sure there are no race conditions while the session is being refreshed." + ], + "parameters": [], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "object", + "name": "AuthSession", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Get the session data", + "code": "const { data, error } = await supabase.auth.getSession()", + "response": "{\n \"data\": {\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n }\n },\n \"error\": null\n}" + } + ] + }, + { + "name": "getUser", + "description": "Gets the current user details if there is an existing session. This method performs a network request to the Supabase Auth server, so the returned value is authentic and can be used to base authorization rules on.", + "remarks": [ + "- This method fetches the user object from the database instead of local session. - This method is useful for checking if the user is authorized because it validates the user's access token JWT on the server. - Should always be used when checking for user authorization on the server. On the client, you can instead use `getSession().session.user` for faster results. `getSession` is insecure on the server." + ], + "parameters": [ + { + "name": "jwt", + "optional": true, + "description": "Takes in an optional access token JWT. If no JWT is provided, the JWT from the current session is used.", + "type": "string" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Get the logged in user with the current existing session", + "code": "const { data: { user } } = await supabase.auth.getUser()", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}" + }, + { + "title": "Get the logged in user with a custom access token jwt", + "code": "const { data: { user } } = await supabase.auth.getUser(jwt)" + } + ] + }, + { + "name": "getUserIdentities", + "description": "Gets all the identities linked to a user.", + "remarks": [ + "- The user needs to be signed in to call `getUserIdentities()`." + ], + "parameters": [], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "identities", + "optional": false, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Returns a list of identities linked to the user", + "code": "const { data, error } = await supabase.auth.getUserIdentities()", + "response": "{\n \"data\": {\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"2024-01-01T00:00:00Z\",\n \"user_id\": \"2024-01-01T00:00:00Z\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ]\n },\n \"error\": null\n}" + } + ] + }, + { + "name": "initialize", + "description": "Initializes the client session either from the url or from storage. This method is automatically called when instantiating the client, but should also be called manually when checking for an error from an auth redirect (oauth, magiclink, password recovery, etc).", + "parameters": [], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "object", + "properties": [ + { + "name": "error", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + } + ], + "name": "InitializeResult" + } + ] + } + }, + { + "name": "reauthenticate", + "description": "Sends a reauthentication OTP to the user's email or phone number. Requires the user to be signed-in.", + "remarks": [ + "- This method is used together with `updateUser()` when a user's password needs to be updated. - If you require your user to reauthenticate before updating their password, you need to enable the **Secure password change** option in your [project's email provider settings](/dashboard/project/_/auth/providers). - A user is only require to reauthenticate before updating their password if **Secure password change** is enabled and the user **hasn't recently signed in**. A user is deemed recently signed in if the session was created in the last 24 hours. - This method will send a nonce to the user's email. If the user doesn't have a confirmed email address, the method will send the nonce to the user's confirmed phone number instead. - After receiving the OTP, include it as the `nonce` in your `updateUser()` call to finalize the password change." + ], + "parameters": [], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "AuthSession", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Send reauthentication nonce", + "code": "const { error } = await supabase.auth.reauthenticate()", + "notes": "Sends a reauthentication nonce to the user's email or phone number." + } + ] + }, + { + "name": "refreshSession", + "description": "Returns a new session, regardless of expiry status. Takes in an optional current session. If not passed in, then refreshSession() will attempt to retrieve it from getSession(). If the current session's refresh token is invalid, an error will be thrown.", + "remarks": [ + "- This method will refresh and return a new session whether the current one is expired or not." + ], + "parameters": [ + { + "name": "currentSession", + "optional": true, + "description": "The current session. If passed in, it must contain a refresh token.", + "type": { + "kind": "object", + "properties": [ + { + "name": "refresh_token", + "optional": false, + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "AuthSession", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Refresh session using the current session", + "code": "const { data, error } = await supabase.auth.refreshSession()\nconst { session, user } = data", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n }\n },\n \"error\": null\n}" + }, + { + "title": "Refresh session using a refresh token", + "code": "const { data, error } = await supabase.auth.refreshSession({ refresh_token })\nconst { session, user } = data" + } + ] + }, + { + "name": "resend", + "description": "Resends an existing signup confirmation email, email change email, SMS OTP or phone change OTP.", + "remarks": [ + "- Resends a signup confirmation, email change or phone change email to the user. - Passwordless sign-ins can be resent by calling the `signInWithOtp()` method again. - Password recovery emails can be resent by calling the `resetPasswordForEmail()` method again. - This method will only resend an email or phone OTP to the user if there was an initial signup, email change or phone change request being made(note: For existing users signing in with OTP, you should use `signInWithOtp()` again to resend the OTP). - You can specify a redirect url when you resend an email link using the `emailRedirectTo` option." + ], + "parameters": [ + { + "name": "credentials", + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "email", + "optional": false, + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "emailRedirectTo", + "optional": true, + "description": "A URL to send the user to after they have signed-in.", + "type": "string" + } + ] + } + }, + { + "name": "type", + "optional": false, + "type": { + "kind": "reference", + "name": "Extract", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "signup" + }, + { + "kind": "literal", + "value": "invite" + }, + { + "kind": "literal", + "value": "magiclink" + }, + { + "kind": "literal", + "value": "recovery" + }, + { + "kind": "literal", + "value": "email_change" + }, + { + "kind": "literal", + "value": "email" + } + ] + }, + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "signup" + }, + { + "kind": "literal", + "value": "email_change" + } + ] + } + ] + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + } + ] + } + }, + { + "name": "phone", + "optional": false, + "type": "string" + }, + { + "name": "type", + "optional": false, + "type": { + "kind": "reference", + "name": "Extract", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "sms" + }, + { + "kind": "literal", + "value": "phone_change" + } + ] + }, + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "sms" + }, + { + "kind": "literal", + "value": "phone_change" + } + ] + } + ] + } + } + ] + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "messageId", + "optional": true, + "type": { + "kind": "union", + "types": [ + "string", + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "session", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Resend an email signup confirmation", + "code": "const { error } = await supabase.auth.resend({\n type: 'signup',\n email: 'email@example.com',\n options: {\n emailRedirectTo: 'https://example.com/welcome'\n }\n})", + "notes": "Resends the email signup confirmation to the user" + }, + { + "title": "Resend a phone signup confirmation", + "code": "const { error } = await supabase.auth.resend({\n type: 'sms',\n phone: '1234567890'\n})", + "notes": "Resends the phone signup confirmation email to the user" + }, + { + "title": "Resend email change email", + "code": "const { error } = await supabase.auth.resend({\n type: 'email_change',\n email: 'email@example.com'\n})", + "notes": "Resends the email change email to the user" + }, + { + "title": "Resend phone change OTP", + "code": "const { error } = await supabase.auth.resend({\n type: 'phone_change',\n phone: '1234567890'\n})", + "notes": "Resends the phone change OTP to the user" + } + ] + }, + { + "name": "resetPasswordForEmail", + "description": "Sends a password reset request to an email address. This method supports the PKCE flow.", + "remarks": [ + "- The password reset flow consist of 2 broad steps: (i) Allow the user to login via the password reset link; (ii) Update the user's password. - The `resetPasswordForEmail()` only sends a password reset link to the user's email. To update the user's password, see [`updateUser()`](/docs/reference/javascript/auth-updateuser). - A `PASSWORD_RECOVERY` event will be emitted when the password recovery link is clicked. You can use [`onAuthStateChange()`](/docs/reference/javascript/auth-onauthstatechange) to listen and invoke a callback function on these events. - When the user clicks the reset link in the email they are redirected back to your application. You can configure the URL that the user is redirected to with the `redirectTo` parameter. See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project. - After the user has been redirected successfully, prompt them for a new password and call `updateUser()`: ```js const { data, error } = await supabase.auth.updateUser({ password: new_password }) ```" + ], + "parameters": [ + { + "name": "email", + "description": "The email address of the user.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "redirectTo", + "optional": true, + "description": "The URL to send the user to after they click the password reset link.", + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Reset password", + "code": "const { data, error } = await supabase.auth.resetPasswordForEmail(email, {\n redirectTo: 'https://example.com/update-password',\n})", + "response": "{\n data: {}\n error: null\n}" + }, + { + "title": "Reset password (React)", + "code": "/**\n * Step 1: Send the user an email to get a password reset token.\n * This email contains a link which sends the user back to your application.\n */\nconst { data, error } = await supabase.auth\n .resetPasswordForEmail('user@email.com')\n\n/**\n * Step 2: Once the user is redirected back to your application,\n * ask the user to reset their password.\n */\n useEffect(() => {\n supabase.auth.onAuthStateChange(async (event, session) => {\n if (event == \"PASSWORD_RECOVERY\") {\n const newPassword = prompt(\"What would you like your new password to be?\");\n const { data, error } = await supabase.auth\n .updateUser({ password: newPassword })\n\n if (data) alert(\"Password updated successfully!\")\n if (error) alert(\"There was an error updating your password.\")\n }\n })\n }, [])" + } + ] + }, + { + "name": "setSession", + "description": "Sets the session data from the current session. If the current session is expired, setSession will take care of refreshing it to obtain a new session. If the refresh token or access token in the current session is invalid, an error will be thrown.", + "remarks": [ + "- This method sets the session using an `access_token` and `refresh_token`. - If successful, a `SIGNED_IN` event is emitted." + ], + "parameters": [ + { + "name": "currentSession", + "description": "The current session that minimally contains an access token and refresh token.", + "type": { + "kind": "object", + "properties": [ + { + "name": "access_token", + "optional": false, + "type": "string" + }, + { + "name": "refresh_token", + "optional": false, + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "AuthSession", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Set the session", + "code": "const { data, error } = await supabase.auth.setSession({\n access_token,\n refresh_token\n })", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n },\n \"session\": {\n \"access_token\": \"\",\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"11111111-1111-1111-1111-111111111111\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"2024-01-01T00:00:00Z\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n },\n \"token_type\": \"bearer\",\n \"expires_in\": 3500,\n \"expires_at\": 1700000000\n }\n },\n \"error\": null\n}", + "notes": "Sets the session data from an access_token and refresh_token, then returns an auth response or error." + } + ] + }, + { + "name": "signInAnonymously", + "description": "Creates a new anonymous user.", + "remarks": [ + "- Returns an anonymous user - It is recommended to set up captcha for anonymous sign-ins to prevent abuse. You can pass in the captcha token in the `options` param." + ], + "parameters": [ + { + "name": "credentials", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "data", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", + "type": "object" + } + ] + } + } + ], + "name": "SignInAnonymouslyCredentials" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "AuthSession", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Create an anonymous user", + "code": "const { data, error } = await supabase.auth.signInAnonymously({\n options: {\n captchaToken\n }\n});", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {},\n \"user_metadata\": {},\n \"identities\": [],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": true\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {},\n \"user_metadata\": {},\n \"identities\": [],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": true\n }\n }\n },\n \"error\": null\n}" + }, + { + "title": "Create an anonymous user with custom user metadata", + "code": "const { data, error } = await supabase.auth.signInAnonymously({\n options: {\n data\n }\n})" + } + ] + }, + { + "name": "signInWithIdToken", + "description": "Allows signing in with an OIDC ID token. The authentication provider used should be enabled and configured.", + "remarks": [ + "- Use an ID token to sign in. - Especially useful when implementing sign in using native platform dialogs in mobile or desktop apps using Sign in with Apple or Sign in with Google on iOS and Android. - You can also use Google's [One Tap](https://developers.google.com/identity/gsi/web/guides/display-google-one-tap) and [Automatic sign-in](https://developers.google.com/identity/gsi/web/guides/automatic-sign-in-sign-out) via this API." + ], + "parameters": [ + { + "name": "credentials", + "type": { + "kind": "object", + "properties": [ + { + "name": "access_token", + "optional": true, + "description": "If the ID token contains an `at_hash` claim, then the hash of this value is compared to the value in the ID token.", + "type": "string" + }, + { + "name": "nonce", + "optional": true, + "description": "If the ID token contains a `nonce` claim, then the hash of this value is compared to the value in the ID token.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + } + ] + } + }, + { + "name": "provider", + "optional": false, + "description": "Provider name or OIDC `iss` value identifying which provider should be used to verify the provided token. Supported names: `google`, `apple`, `azure`, `facebook`, `kakao`. Use the `custom:` prefix for custom OIDC providers (e.g. `custom:my-oidc-provider`).", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "google" + }, + { + "kind": "literal", + "value": "apple" + }, + { + "kind": "literal", + "value": "azure" + }, + { + "kind": "literal", + "value": "facebook" + }, + { + "kind": "literal", + "value": "kakao" + }, + { + "kind": "templateLiteral" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "token", + "optional": false, + "description": "OIDC ID token issued by the specified provider. The `iss` claim in the ID token must match the supplied provider. Some ID tokens contain an `at_hash` which require that you provide an `access_token` value to be accepted properly. If the token contains a `nonce` claim you must supply the nonce used to obtain the ID token.", + "type": "string" + } + ], + "name": "SignInWithIdTokenCredentials" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "object", + "name": "AuthSession", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Sign In using ID Token", + "code": "const { data, error } = await supabase.auth.signInWithIdToken({\n provider: 'google',\n token: 'your-id-token'\n})", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n ...\n },\n \"user_metadata\": {\n ...\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"provider\": \"google\",\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n ...\n },\n \"user_metadata\": {\n ...\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"provider\": \"google\",\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n }\n }\n },\n \"error\": null\n}" + } + ] + }, + { + "name": "signInWithOAuth", + "description": "Log in an existing user via a third-party provider. This method supports the PKCE flow.", + "remarks": [ + "- This method is used for signing in using [Social Login (OAuth) providers](/docs/guides/auth#configure-third-party-providers). - It works by redirecting your application to the provider's authorization screen, before bringing back the user to your app." + ], + "parameters": [ + { + "name": "credentials", + "type": { + "kind": "object", + "properties": [ + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "queryParams", + "optional": true, + "description": "An object of query params", + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "redirectTo", + "optional": true, + "description": "A URL to send the user to after they are confirmed.", + "type": "string" + }, + { + "name": "scopes", + "optional": true, + "description": "A space-separated list of scopes granted to the OAuth application.", + "type": "string" + }, + { + "name": "skipBrowserRedirect", + "optional": true, + "description": "If set to true does not immediately redirect the current browser context to visit the OAuth authorization page for the provider.", + "type": "boolean" + } + ] + } + }, + { + "name": "provider", + "optional": false, + "description": "One of the providers supported by GoTrue.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "apple" + }, + { + "kind": "literal", + "value": "azure" + }, + { + "kind": "literal", + "value": "bitbucket" + }, + { + "kind": "literal", + "value": "discord" + }, + { + "kind": "literal", + "value": "facebook" + }, + { + "kind": "literal", + "value": "figma" + }, + { + "kind": "literal", + "value": "github" + }, + { + "kind": "literal", + "value": "gitlab" + }, + { + "kind": "literal", + "value": "google" + }, + { + "kind": "literal", + "value": "kakao" + }, + { + "kind": "literal", + "value": "keycloak" + }, + { + "kind": "literal", + "value": "linkedin" + }, + { + "kind": "literal", + "value": "linkedin_oidc" + }, + { + "kind": "literal", + "value": "notion" + }, + { + "kind": "literal", + "value": "slack" + }, + { + "kind": "literal", + "value": "slack_oidc" + }, + { + "kind": "literal", + "value": "spotify" + }, + { + "kind": "literal", + "value": "twitch" + }, + { + "kind": "literal", + "value": "twitter" + }, + { + "kind": "literal", + "value": "x" + }, + { + "kind": "literal", + "value": "workos" + }, + { + "kind": "literal", + "value": "zoom" + }, + { + "kind": "literal", + "value": "fly" + }, + { + "kind": "templateLiteral" + } + ] + } + } + ], + "name": "SignInWithOAuthCredentials" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "provider", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "apple" + }, + { + "kind": "literal", + "value": "azure" + }, + { + "kind": "literal", + "value": "bitbucket" + }, + { + "kind": "literal", + "value": "discord" + }, + { + "kind": "literal", + "value": "facebook" + }, + { + "kind": "literal", + "value": "figma" + }, + { + "kind": "literal", + "value": "github" + }, + { + "kind": "literal", + "value": "gitlab" + }, + { + "kind": "literal", + "value": "google" + }, + { + "kind": "literal", + "value": "kakao" + }, + { + "kind": "literal", + "value": "keycloak" + }, + { + "kind": "literal", + "value": "linkedin" + }, + { + "kind": "literal", + "value": "linkedin_oidc" + }, + { + "kind": "literal", + "value": "notion" + }, + { + "kind": "literal", + "value": "slack" + }, + { + "kind": "literal", + "value": "slack_oidc" + }, + { + "kind": "literal", + "value": "spotify" + }, + { + "kind": "literal", + "value": "twitch" + }, + { + "kind": "literal", + "value": "twitter" + }, + { + "kind": "literal", + "value": "x" + }, + { + "kind": "literal", + "value": "workos" + }, + { + "kind": "literal", + "value": "zoom" + }, + { + "kind": "literal", + "value": "fly" + }, + { + "kind": "templateLiteral" + } + ] + } + }, + { + "name": "url", + "optional": false, + "type": "string" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "provider", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "apple" + }, + { + "kind": "literal", + "value": "azure" + }, + { + "kind": "literal", + "value": "bitbucket" + }, + { + "kind": "literal", + "value": "discord" + }, + { + "kind": "literal", + "value": "facebook" + }, + { + "kind": "literal", + "value": "figma" + }, + { + "kind": "literal", + "value": "github" + }, + { + "kind": "literal", + "value": "gitlab" + }, + { + "kind": "literal", + "value": "google" + }, + { + "kind": "literal", + "value": "kakao" + }, + { + "kind": "literal", + "value": "keycloak" + }, + { + "kind": "literal", + "value": "linkedin" + }, + { + "kind": "literal", + "value": "linkedin_oidc" + }, + { + "kind": "literal", + "value": "notion" + }, + { + "kind": "literal", + "value": "slack" + }, + { + "kind": "literal", + "value": "slack_oidc" + }, + { + "kind": "literal", + "value": "spotify" + }, + { + "kind": "literal", + "value": "twitch" + }, + { + "kind": "literal", + "value": "twitter" + }, + { + "kind": "literal", + "value": "x" + }, + { + "kind": "literal", + "value": "workos" + }, + { + "kind": "literal", + "value": "zoom" + }, + { + "kind": "literal", + "value": "fly" + }, + { + "kind": "templateLiteral" + } + ] + } + }, + { + "name": "url", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Sign in using a third-party provider", + "code": "const { data, error } = await supabase.auth.signInWithOAuth({\n provider: 'github'\n})", + "response": "{\n data: {\n provider: 'github',\n url: \n },\n error: null\n}", + "notes": "with redirect\n- When the OAuth provider successfully authenticates the user, they are redirected to the URL specified in the `redirectTo` parameter. This parameter defaults to the [`SITE_URL`](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls). It does not redirect the user immediately after invoking this method.\n- See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project." + }, + { + "title": "Sign in using a third-party provider with redirect", + "code": "const { data, error } = await supabase.auth.signInWithOAuth({\n provider: 'github',\n options: {\n redirectTo: 'https://example.com/welcome'\n }\n})", + "notes": "- When the OAuth provider successfully authenticates the user, they are redirected to the URL specified in the `redirectTo` parameter. This parameter defaults to the [`SITE_URL`](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls). It does not redirect the user immediately after invoking this method.\n- See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project." + }, + { + "title": "Sign in with scopes and access provider tokens", + "code": "// Register this immediately after calling createClient!\n// Because signInWithOAuth causes a redirect, you need to fetch the\n// provider tokens from the callback.\nsupabase.auth.onAuthStateChange((event, session) => {\n if (session && session.provider_token) {\n window.localStorage.setItem('oauth_provider_token', session.provider_token)\n }\n\n if (session && session.provider_refresh_token) {\n window.localStorage.setItem('oauth_provider_refresh_token', session.provider_refresh_token)\n }\n\n if (event === 'SIGNED_OUT') {\n window.localStorage.removeItem('oauth_provider_token')\n window.localStorage.removeItem('oauth_provider_refresh_token')\n }\n})\n\n// Call this on your Sign in with GitHub button to initiate OAuth\n// with GitHub with the requested elevated scopes.\nawait supabase.auth.signInWithOAuth({\n provider: 'github',\n options: {\n scopes: 'repo gist notifications'\n }\n})", + "notes": "If you need additional access from an OAuth provider, in order to access provider specific APIs in the name of the user, you can do this by passing in the scopes the user should authorize for your application. Note that the `scopes` option takes in **a space-separated list** of scopes.\n\nBecause OAuth sign-in often includes redirects, you should register an `onAuthStateChange` callback immediately after you create the Supabase client. This callback will listen for the presence of `provider_token` and `provider_refresh_token` properties on the `session` object and store them in local storage. The client library will emit these values **only once** immediately after the user signs in. You can then access them by looking them up in local storage, or send them to your backend servers for further processing.\n\nFinally, make sure you remove them from local storage on the `SIGNED_OUT` event. If the OAuth provider supports token revocation, make sure you call those APIs either from the frontend or schedule them to be called on the backend." + } + ] + }, + { + "name": "signInWithOtp", + "description": "Log in a user using magiclink or a one-time password (OTP).\nIf the `{{ .ConfirmationURL }}` variable is specified in the email template, a magiclink will be sent. If the `{{ .Token }}` variable is specified in the email template, an OTP will be sent. If you're using phone sign-ins, only an OTP will be sent. You won't be able to send a magiclink for phone sign-ins.\nBe aware that you may get back an error message that will not distinguish between the cases where the account does not exist or, that the account can only be accessed via social login.\nDo note that you will need to configure a Whatsapp sender on Twilio if you are using phone sign in with the 'whatsapp' channel. The whatsapp channel is not supported on other providers at this time. This method supports PKCE when an email is passed.", + "remarks": [ + "- Requires either an email or phone number. - This method is used for passwordless sign-ins where a OTP is sent to the user's email or phone number. - If the user doesn't exist, `signInWithOtp()` will signup the user instead. To restrict this behavior, you can set `shouldCreateUser` in `SignInWithPasswordlessCredentials.options` to `false`. - If you're using an email, you can configure whether you want the user to receive a magiclink or a OTP. - If you're using phone, you can configure whether you want the user to receive a OTP. - The magic link's destination URL is determined by the [`SITE_URL`](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls). - See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project. - Magic links and OTPs share the same implementation. To send users a one-time code instead of a magic link, [modify the magic link email template](/dashboard/project/_/auth/templates) to include `{{ .Token }}` instead of `{{ .ConfirmationURL }}`. - See our [Twilio Phone Auth Guide](/docs/guides/auth/phone-login?showSMSProvider=Twilio) for details about configuring WhatsApp sign in." + ], + "parameters": [ + { + "name": "credentials", + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "email", + "optional": false, + "description": "The user's email address.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "data", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", + "type": "object" + }, + { + "name": "emailRedirectTo", + "optional": true, + "description": "The redirect url embedded in the email link", + "type": "string" + }, + { + "name": "shouldCreateUser", + "optional": true, + "description": "If set to false, this method will not create a new user. Defaults to true.", + "type": "boolean" + } + ] + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "channel", + "optional": true, + "description": "Messaging channel to use (e.g. whatsapp or sms)", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "sms" + }, + { + "kind": "literal", + "value": "whatsapp" + } + ] + } + }, + { + "name": "data", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", + "type": "object" + }, + { + "name": "shouldCreateUser", + "optional": true, + "description": "If set to false, this method will not create a new user. Defaults to true.", + "type": "boolean" + } + ] + } + }, + { + "name": "phone", + "optional": false, + "description": "The user's phone number.", + "type": "string" + } + ] + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "messageId", + "optional": true, + "type": { + "kind": "union", + "types": [ + "string", + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "session", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Sign in with email", + "code": "const { data, error } = await supabase.auth.signInWithOtp({\n email: 'example@email.com',\n options: {\n emailRedirectTo: 'https://example.com/welcome'\n }\n})", + "response": "{\n \"data\": {\n \"user\": null,\n \"session\": null\n },\n \"error\": null\n}", + "notes": "The user will be sent an email which contains either a magiclink or a OTP or both. By default, a given user can only request a OTP once every 60 seconds." + }, + { + "title": "Sign in with SMS OTP", + "code": "const { data, error } = await supabase.auth.signInWithOtp({\n phone: '+13334445555',\n})", + "notes": "The user will be sent a SMS which contains a OTP. By default, a given user can only request a OTP once every 60 seconds." + }, + { + "title": "Sign in with WhatsApp OTP", + "code": "const { data, error } = await supabase.auth.signInWithOtp({\n phone: '+13334445555',\n options: {\n channel:'whatsapp',\n }\n})", + "notes": "The user will be sent a WhatsApp message which contains a OTP. By default, a given user can only request a OTP once every 60 seconds. Note that a user will need to have a valid WhatsApp account that is linked to Twilio in order to use this feature." + } + ] + }, + { + "name": "signInWithPassword", + "description": "Log in an existing user with an email and password or phone and password.\nBe aware that you may get back an error message that will not distinguish between the cases where the account does not exist or that the email/phone and password combination is wrong or that the account can only be accessed via social login.", + "remarks": [ + "- Requires either an email and password or a phone number and password." + ], + "parameters": [ + { + "name": "credentials", + "type": { + "kind": "intersection", + "types": [ + { + "kind": "reference", + "name": "PasswordCredentialsBase" + }, + { + "kind": "object", + "properties": [ + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "type": "string" + } + ] + } + } + ] + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "object", + "name": "AuthSession", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + }, + { + "name": "weakPassword", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "message", + "optional": false, + "type": "string" + }, + { + "name": "reasons", + "optional": false, + "type": { + "kind": "array", + "elementType": { + "kind": "indexedAccess", + "objectType": { + "kind": "query" + }, + "indexType": null + } + } + } + ], + "name": "WeakPassword" + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Sign in with email and password", + "code": "const { data, error } = await supabase.auth.signInWithPassword({\n email: 'example@email.com',\n password: 'example-password',\n})", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n }\n }\n },\n \"error\": null\n}" + }, + { + "title": "Sign in with phone and password", + "code": "const { data, error } = await supabase.auth.signInWithPassword({\n phone: '+13334445555',\n password: 'some-password',\n})" + } + ] + }, + { + "name": "signInWithSSO", + "description": "Attempts a single-sign on using an enterprise Identity Provider. A successful SSO attempt will redirect the current page to the identity provider authorization page. The redirect URL is implementation and SSO protocol specific.\nYou can use it by providing a SSO domain. Typically you can extract this domain by asking users for their email address. If this domain is registered on the Auth instance the redirect will use that organization's currently active SSO Identity Provider for the login.\nIf you have built an organization-specific login page, you can use the organization's SSO Identity Provider UUID directly instead.", + "remarks": [ + "- Before you can call this method you need to [establish a connection](/docs/guides/auth/sso/auth-sso-saml#managing-saml-20-connections) to an identity provider. Use the [CLI commands](/docs/reference/cli/supabase-sso) to do this. - If you've associated an email domain to the identity provider, you can use the `domain` property to start a sign-in flow. - In case you need to use a different way to start the authentication flow with an identity provider, you can use the `providerId` property. For example: - Mapping specific user email addresses with an identity provider. - Using different hints to identity the identity provider to be used by the user, like a company-specific page, IP address or other tracking information." + ], + "parameters": [ + { + "name": "params", + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "redirectTo", + "optional": true, + "description": "A URL to send the user to after they have signed-in.", + "type": "string" + }, + { + "name": "skipBrowserRedirect", + "optional": true, + "description": "If set to true, the redirect will not happen on the client side. This parameter is used when you wish to handle the redirect yourself. Defaults to false.", + "type": "boolean" + } + ] + } + }, + { + "name": "providerId", + "optional": false, + "description": "UUID of the SSO provider to invoke single-sign on to.", + "type": "string" + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "domain", + "optional": false, + "description": "Domain name of the organization for which to invoke single-sign on.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "redirectTo", + "optional": true, + "description": "A URL to send the user to after they have signed-in.", + "type": "string" + }, + { + "name": "skipBrowserRedirect", + "optional": true, + "description": "If set to true, the redirect will not happen on the client side. This parameter is used when you wish to handle the redirect yourself. Defaults to false.", + "type": "boolean" + } + ] + } + } + ] + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "url", + "optional": false, + "description": "URL to open in a browser which will complete the sign-in flow by taking the user to the identity provider's authentication flow.\nOn browsers you can set the URL to `window.location.href` to take the user to the authentication flow.", + "type": "string" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Sign in with email domain", + "code": "// You can extract the user's email domain and use it to trigger the\n // authentication flow with the correct identity provider.\n\n const { data, error } = await supabase.auth.signInWithSSO({\n domain: 'company.com'\n })\n\n if (data?.url) {\n // redirect the user to the identity provider's authentication flow\n window.location.href = data.url\n }" + }, + { + "title": "Sign in with provider UUID", + "code": "// Useful when you need to map a user's sign in request according\n // to different rules that can't use email domains.\n\n const { data, error } = await supabase.auth.signInWithSSO({\n providerId: '21648a9d-8d5a-4555-a9d1-d6375dc14e92'\n })\n\n if (data?.url) {\n // redirect the user to the identity provider's authentication flow\n window.location.href = data.url\n }" + } + ] + }, + { + "name": "signInWithWeb3", + "description": "Signs in a user by verifying a message signed by the user's private key. Supports Ethereum (via Sign-In-With-Ethereum) & Solana (Sign-In-With-Solana) standards, both of which derive from the EIP-4361 standard With slight variation on Solana's side.", + "remarks": [ + "- Uses a Web3 (Ethereum, Solana) wallet to sign a user in. - Read up on the [potential for abuse](/docs/guides/auth/auth-web3#potential-for-abuse) before using it." + ], + "parameters": [ + { + "name": "credentials", + "type": { + "kind": "union", + "types": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "chain", + "optional": false, + "type": { + "kind": "literal", + "value": "solana" + } + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "signInWithSolana", + "optional": true, + "type": { + "kind": "reference", + "name": "Partial", + "typeArguments": [ + { + "kind": "reference", + "name": "Omit", + "typeArguments": [ + { + "kind": "reference", + "name": "SolanaSignInInput" + }, + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "version" + }, + { + "kind": "literal", + "value": "chain" + }, + { + "kind": "literal", + "value": "domain" + }, + { + "kind": "literal", + "value": "uri" + }, + { + "kind": "literal", + "value": "statement" + } + ] + } + ] + } + ] + } + }, + { + "name": "url", + "optional": true, + "description": "URL to use with the wallet interface. Some wallets do not allow signing a message for URLs different from the current page.", + "type": "string" + } + ] + } + }, + { + "name": "statement", + "optional": true, + "description": "Optional statement to include in the Sign in with Solana message. Must not include new line characters. Most wallets like Phantom **require specifying a statement!**", + "type": "string" + }, + { + "name": "wallet", + "optional": true, + "description": "Wallet interface to use. If not specified will default to `window.solana`.", + "type": { + "kind": "object", + "properties": [ + { + "name": "publicKey", + "optional": true, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "toBase58", + "optional": false, + "type": { + "kind": "object", + "properties": [] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "signIn", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "signMessage", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + } + ], + "name": "SolanaWallet" + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "chain", + "optional": false, + "type": { + "kind": "literal", + "value": "solana" + } + }, + { + "name": "message", + "optional": false, + "description": "Sign in with Solana compatible message. Must include `Issued At`, `URI` and `Version`.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + } + ] + } + }, + { + "name": "signature", + "optional": false, + "description": "Ed25519 signature of the message.", + "type": { + "kind": "reference", + "name": "Uint8Array" + } + } + ] + } + ] + }, + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "chain", + "optional": false, + "type": { + "kind": "literal", + "value": "ethereum" + } + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "signInWithEthereum", + "optional": true, + "type": { + "kind": "reference", + "name": "Partial", + "typeArguments": [ + { + "kind": "reference", + "name": "Omit", + "typeArguments": [ + { + "kind": "reference", + "name": "EthereumSignInInput" + }, + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "version" + }, + { + "kind": "literal", + "value": "domain" + }, + { + "kind": "literal", + "value": "uri" + }, + { + "kind": "literal", + "value": "statement" + } + ] + } + ] + } + ] + } + }, + { + "name": "url", + "optional": true, + "description": "URL to use with the wallet interface. Some wallets do not allow signing a message for URLs different from the current page.", + "type": "string" + } + ] + } + }, + { + "name": "statement", + "optional": true, + "description": "Optional statement to include in the Sign in with Ethereum message. Must not include new line characters. Most wallets like Phantom **require specifying a statement!**", + "type": "string" + }, + { + "name": "wallet", + "optional": true, + "description": "Wallet interface to use. If not specified will default to `window.ethereum`.", + "type": { + "kind": "reference", + "name": "EIP1193Provider" + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "chain", + "optional": false, + "type": { + "kind": "literal", + "value": "ethereum" + } + }, + { + "name": "message", + "optional": false, + "description": "Sign in with Ethereum compatible message. Must include `Issued At`, `URI` and `Version`.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + } + ] + } + }, + { + "name": "signature", + "optional": false, + "description": "Ethereum curve (secp256k1) signature of the message.", + "type": { + "kind": "reference", + "name": "Hex" + } + } + ] + } + ] + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "object", + "name": "AuthSession", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Sign in with Solana or Ethereum (Window API)", + "code": "// uses window.ethereum for the wallet\n const { data, error } = await supabase.auth.signInWithWeb3({\n chain: 'ethereum',\n statement: 'I accept the Terms of Service at https://example.com/tos'\n })\n\n // uses window.solana for the wallet\n const { data, error } = await supabase.auth.signInWithWeb3({\n chain: 'solana',\n statement: 'I accept the Terms of Service at https://example.com/tos'\n })" + }, + { + "title": "Sign in with Ethereum (Message and Signature)", + "code": "const { data, error } = await supabase.auth.signInWithWeb3({\n chain: 'ethereum',\n message: '',\n signature: '',\n })" + }, + { + "title": "Sign in with Solana (Brave)", + "code": "const { data, error } = await supabase.auth.signInWithWeb3({\n chain: 'solana',\n statement: 'I accept the Terms of Service at https://example.com/tos',\n wallet: window.braveSolana\n })" + }, + { + "title": "Sign in with Solana (Wallet Adapter)", + "code": "function SignInButton() {\n const wallet = useWallet()\n\n return (\n <>\n {wallet.connected ? (\n {\n supabase.auth.signInWithWeb3({\n chain: 'solana',\n statement: 'I accept the Terms of Service at https://example.com/tos',\n wallet,\n })\n }}\n >\n Sign in with Solana\n \n ) : (\n \n )}\n \n )\n}\n\nfunction App() {\n const endpoint = clusterApiUrl('devnet')\n const wallets = useMemo(() => [], [])\n\n return (\n \n \n \n \n \n \n \n )\n}" + } + ] + }, + { + "name": "signOut", + "description": "Inside a browser context, `signOut()` will remove the logged in user from the browser session and log them out - removing all items from localstorage and then trigger a `\"SIGNED_OUT\"` event.\nFor server-side management, you can revoke all refresh tokens for a user by passing a user's JWT through to `auth.api.signOut(JWT: string)`. There is no way to revoke a user's access token jwt until it expires. It is recommended to set a shorter expiry on the jwt for this reason.\nIf using `others` scope, no `SIGNED_OUT` event is fired!", + "remarks": [ + "- In order to use the `signOut()` method, the user needs to be signed in first. - By default, `signOut()` uses the global scope, which signs out all other sessions that the user is logged into as well. Customize this behavior by passing a scope parameter. - Since Supabase Auth uses JWTs for authentication, the access token JWT will be valid until it's expired. When the user signs out, Supabase revokes the refresh token and deletes the JWT from the client-side. This does not revoke the JWT and it will still be valid until it expires." + ], + "parameters": [ + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "scope", + "optional": true, + "description": "Determines which sessions should be logged out. Global means all sessions by this account. Local means only this session. Others means all other sessions except the current one. When using others, there is no sign-out event fired on the current session!", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "global" + }, + { + "kind": "literal", + "value": "local" + }, + { + "kind": "literal", + "value": "others" + } + ] + } + } + ], + "name": "SignOut" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "object", + "properties": [ + { + "name": "error", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + ] + } + } + ] + } + ] + }, + "examples": [ + { + "title": "Sign out (all sessions)", + "code": "const { error } = await supabase.auth.signOut()" + }, + { + "title": "Sign out (current session)", + "code": "const { error } = await supabase.auth.signOut({ scope: 'local' })" + }, + { + "title": "Sign out (other sessions)", + "code": "const { error } = await supabase.auth.signOut({ scope: 'others' })" + } + ] + }, + { + "name": "signUp", + "description": "Creates a new user.\nBe aware that if a user account exists in the system you may get back an error message that attempts to hide this information from the user. This method has support for PKCE via email signups. The PKCE flow cannot be used when autoconfirm is enabled.", + "remarks": [ + "- By default, the user needs to verify their email address before logging in. To turn this off, disable **Confirm email** in [your project](/dashboard/project/_/auth/providers). - **Confirm email** determines if users need to confirm their email address after signing up. - If **Confirm email** is enabled, a `user` is returned but `session` is null. - If **Confirm email** is disabled, both a `user` and a `session` are returned. - When the user confirms their email address, they are redirected to the [`SITE_URL`](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) by default. You can modify your `SITE_URL` or add additional redirect URLs in [your project](/dashboard/project/_/auth/url-configuration). - If signUp() is called for an existing confirmed user: - When both **Confirm email** and **Confirm phone** (even when phone provider is disabled) are enabled in [your project](/dashboard/project/_/auth/providers), an obfuscated/fake user object is returned. - When either **Confirm email** or **Confirm phone** (even when phone provider is disabled) is disabled, the error message, `User already registered` is returned. - To fetch the currently logged-in user, refer to [`getUser()`](/docs/reference/javascript/auth-getuser)." + ], + "parameters": [ + { + "name": "credentials", + "type": { + "kind": "conditional" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "AuthSession", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Sign up with an email and password", + "code": "const { data, error } = await supabase.auth.signUp({\n email: 'example@email.com',\n password: 'example-password',\n})", + "response": "// Some fields may be null if \"confirm email\" is enabled.\n{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {},\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n }\n }\n },\n \"error\": null\n}", + "notes": "Sign up with a phone number and password (whatsapp)\nThe user will be sent a WhatsApp message which contains a OTP. By default, a given user can only request a OTP once every 60 seconds. Note that a user will need to have a valid WhatsApp account that is linked to Twilio in order to use this feature." + }, + { + "title": "Sign up with a phone number and password (SMS)", + "code": "const { data, error } = await supabase.auth.signUp({\n phone: '123456789',\n password: 'example-password',\n options: {\n channel: 'sms'\n }\n})", + "notes": "Sign up with a redirect URL\n- See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project." + }, + { + "title": "Sign up with a phone number and password (whatsapp)", + "code": "const { data, error } = await supabase.auth.signUp({\n phone: '123456789',\n password: 'example-password',\n options: {\n channel: 'whatsapp'\n }\n})", + "notes": "The user will be sent a WhatsApp message which contains a OTP. By default, a given user can only request a OTP once every 60 seconds. Note that a user will need to have a valid WhatsApp account that is linked to Twilio in order to use this feature." + }, + { + "title": "Sign up with additional user metadata", + "code": "const { data, error } = await supabase.auth.signUp(\n {\n email: 'example@email.com',\n password: 'example-password',\n options: {\n data: {\n first_name: 'John',\n age: 27,\n }\n }\n }\n)" + }, + { + "title": "Sign up with a redirect URL", + "code": "const { data, error } = await supabase.auth.signUp(\n {\n email: 'example@email.com',\n password: 'example-password',\n options: {\n emailRedirectTo: 'https://example.com/welcome'\n }\n }\n)", + "notes": "- See [redirect URLs and wildcards](/docs/guides/auth/redirect-urls#use-wildcards-in-redirect-urls) to add additional redirect URLs to your project." + } + ] + }, + { + "name": "startAutoRefresh", + "description": "Starts an auto-refresh process in the background. The session is checked every few seconds. Close to the time of expiration a process is started to refresh the session. If refreshing fails it will be retried for as long as necessary.\nIf you set the GoTrueClientOptions#autoRefreshToken you don't need to call this function, it will be called for you.\nOn browsers the refresh process works only when the tab/window is in the foreground to conserve resources as well as prevent race conditions and flooding auth with requests. If you call this method any managed visibility change callback will be removed and you must manage visibility changes on your own.\nOn non-browser platforms the refresh process works *continuously* in the background, which may not be desirable. You should hook into your platform's foreground indication mechanism and call these methods appropriately to conserve resources.\n#stopAutoRefresh", + "remarks": [ + "- Only useful in non-browser environments such as React Native or Electron. - The Supabase Auth library automatically starts and stops proactively refreshing the session when a tab is focused or not. - On non-browser platforms, such as mobile or desktop apps built with web technologies, the library is not able to effectively determine whether the application is _focused_ or not. - To give this hint to the application, you should be calling this method when the app is in focus and calling `supabase.auth.stopAutoRefresh()` when it's out of focus." + ], + "parameters": [], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + "void" + ] + }, + "examples": [ + { + "title": "Start and stop auto refresh in React Native", + "code": "import { AppState } from 'react-native'\n\n// make sure you register this only once!\nAppState.addEventListener('change', (state) => {\n if (state === 'active') {\n supabase.auth.startAutoRefresh()\n } else {\n supabase.auth.stopAutoRefresh()\n }\n})" + } + ] + }, + { + "name": "stopAutoRefresh", + "description": "Stops an active auto refresh process running in the background (if any).\nIf you call this method any managed visibility change callback will be removed and you must manage visibility changes on your own.\nSee #startAutoRefresh for more details.", + "remarks": [ + "- Only useful in non-browser environments such as React Native or Electron. - The Supabase Auth library automatically starts and stops proactively refreshing the session when a tab is focused or not. - On non-browser platforms, such as mobile or desktop apps built with web technologies, the library is not able to effectively determine whether the application is _focused_ or not. - When your application goes in the background or out of focus, call this method to stop the proactive refreshing of the session." + ], + "parameters": [], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + "void" + ] + }, + "examples": [ + { + "title": "Start and stop auto refresh in React Native", + "code": "import { AppState } from 'react-native'\n\n// make sure you register this only once!\nAppState.addEventListener('change', (state) => {\n if (state === 'active') {\n supabase.auth.startAutoRefresh()\n } else {\n supabase.auth.stopAutoRefresh()\n }\n})" + } + ] + }, + { + "name": "unlinkIdentity", + "description": "Unlinks an identity from a user by deleting it. The user will no longer be able to sign in with that identity once it's unlinked.", + "remarks": [ + "- The **Enable Manual Linking** option must be enabled from your [project's authentication settings](/dashboard/project/_/auth/providers). - The user needs to be signed in to call `unlinkIdentity()`. - The user must have at least 2 identities in order to unlink an identity. - The identity to be unlinked must belong to the user." + ], + "parameters": [ + { + "name": "identity", + "type": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Unlink an identity", + "code": "// retrieve all identities linked to a user\nconst identities = await supabase.auth.getUserIdentities()\n\n// find the google identity\nconst googleIdentity = identities.find(\n identity => identity.provider === 'google'\n)\n\n// unlink the google identity\nconst { error } = await supabase.auth.unlinkIdentity(googleIdentity)" + } + ] + }, + { + "name": "updateUser", + "description": "Updates user data for a logged in user.", + "remarks": [ + "- In order to use the `updateUser()` method, the user needs to be signed in first. - By default, email updates sends a confirmation link to both the user's current and new email. To only send a confirmation link to the user's new email, disable **Secure email change** in your project's [email auth provider settings](/dashboard/project/_/auth/providers)." + ], + "parameters": [ + { + "name": "attributes", + "type": { + "kind": "object", + "name": "UserAttributes", + "properties": [ + { + "name": "current_password", + "optional": true, + "description": "The user's current password\nThis is only ever present when the user is resetting their password and GOTRUE_SECURITY_UPDATE_PASSWORD_REQUIRE_CURRENT_PASSWORD is true.", + "type": "string" + }, + { + "name": "data", + "optional": true, + "description": "A custom data object to store the user's metadata. This maps to the `auth.users.raw_user_meta_data` column.\nThe `data` should be a JSON object that includes user-specific info, such as their first and last name.", + "type": "object" + }, + { + "name": "email", + "optional": true, + "description": "The user's email.", + "type": "string" + }, + { + "name": "nonce", + "optional": true, + "description": "The nonce sent for reauthentication if the user's password is to be updated.\nCall reauthenticate() to obtain the nonce first.", + "type": "string" + }, + { + "name": "password", + "optional": true, + "description": "The user's password.", + "type": "string" + }, + { + "name": "phone", + "optional": true, + "description": "The user's phone.", + "type": "string" + } + ] + } + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "emailRedirectTo", + "optional": true, + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "user", + "optional": false, + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Update the email for an authenticated user", + "code": "const { data, error } = await supabase.auth.updateUser({\n email: 'new@email.com'\n})", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"new_email\": \"new@email.com\",\n \"email_change_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n },\n \"error\": null\n}", + "notes": "Sends a \"Confirm Email Change\" email to the new address. If **Secure Email Change** is enabled (default), confirmation is also required from the **old email** before the change is applied. To skip dual confirmation and apply the change after only the new email is verified, disable **Secure Email Change** in the [Email Auth Provider settings](/dashboard/project/_/auth/providers?provider=Email)." + }, + { + "title": "Update the phone number for an authenticated user", + "code": "const { data, error } = await supabase.auth.updateUser({\n phone: '123456789'\n})", + "notes": "Sends a one-time password (OTP) to the new phone number." + }, + { + "title": "Update the password for an authenticated user", + "code": "const { data, error } = await supabase.auth.updateUser({\n password: 'new password'\n})", + "notes": "Update the user's metadata\nUpdates the user's custom metadata.\n\n**Note**: The `data` field maps to the `auth.users.raw_user_meta_data` column in your Supabase database. When calling `getUser()`, the data will be available as `user.user_metadata`." + }, + { + "title": "Update the user's metadata", + "code": "const { data, error } = await supabase.auth.updateUser({\n data: { hello: 'world' }\n})", + "notes": "Updates the user's custom metadata.\n\n**Note**: The `data` field maps to the `auth.users.raw_user_meta_data` column in your Supabase database. When calling `getUser()`, the data will be available as `user.user_metadata`." + }, + { + "title": "Update the user's password with a nonce", + "code": "const { data, error } = await supabase.auth.updateUser({\n password: 'new password',\n nonce: '123456'\n})", + "notes": "If **Secure password change** is enabled in your [project's email provider settings](/dashboard/project/_/auth/providers), updating the user's password would require a nonce if the user **hasn't recently signed in**. The nonce is sent to the user's email or phone number. A user is deemed recently signed in if the session was created in the last 24 hours." + } + ] + }, + { + "name": "verifyOtp", + "description": "Log in a user given a User supplied OTP or TokenHash received through mobile or email.", + "remarks": [ + "- The `verifyOtp` method takes in different verification types. - If a phone number is used, the type can either be: 1. `sms` – Used when verifying a one-time password (OTP) sent via SMS during sign-up or sign-in. 2. `phone_change` – Used when verifying an OTP sent to a new phone number during a phone number update process. - If an email address is used, the type can be one of the following (note: `signup` and `magiclink` types are deprecated): 1. `email` – Used when verifying an OTP sent to the user's email during sign-up or sign-in. 2. `recovery` – Used when verifying an OTP sent for account recovery, typically after a password reset request. 3. `invite` – Used when verifying an OTP sent as part of an invitation to join a project or organization. 4. `email_change` – Used when verifying an OTP sent to a new email address during an email update process. - The verification type used should be determined based on the corresponding auth method called before `verifyOtp` to sign up / sign-in a user. - The `TokenHash` is contained in the [email templates](/docs/guides/auth/auth-email-templates) and can be used to sign in. You may wish to use the hash for the PKCE flow for Server Side Auth. Read [the Password-based Auth guide](/docs/guides/auth/passwords) for more details." + ], + "parameters": [ + { + "name": "params", + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "VerifyMobileOtpParams", + "properties": [ + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "redirectTo", + "optional": true, + "description": "A URL to send the user to after they are confirmed.", + "type": "string" + } + ] + } + }, + { + "name": "phone", + "optional": false, + "description": "The user's phone number.", + "type": "string" + }, + { + "name": "token", + "optional": false, + "description": "The otp sent to the user's phone number.", + "type": "string" + }, + { + "name": "type", + "optional": false, + "description": "The user's verification type.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "sms" + }, + { + "kind": "literal", + "value": "phone_change" + } + ] + } + } + ] + }, + { + "kind": "object", + "name": "VerifyEmailOtpParams", + "properties": [ + { + "name": "email", + "optional": false, + "description": "The user's email address.", + "type": "string" + }, + { + "name": "options", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "captchaToken", + "optional": true, + "description": "Verification token received when the user completes the captcha on the site.", + "type": "string" + }, + { + "name": "redirectTo", + "optional": true, + "description": "A URL to send the user to after they are confirmed.", + "type": "string" + } + ] + } + }, + { + "name": "token", + "optional": false, + "description": "The otp sent to the user's email address.", + "type": "string" + }, + { + "name": "type", + "optional": false, + "description": "The user's verification type.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "signup" + }, + { + "kind": "literal", + "value": "invite" + }, + { + "kind": "literal", + "value": "magiclink" + }, + { + "kind": "literal", + "value": "recovery" + }, + { + "kind": "literal", + "value": "email_change" + }, + { + "kind": "literal", + "value": "email" + } + ] + } + } + ] + }, + { + "kind": "object", + "name": "VerifyTokenHashParams", + "properties": [ + { + "name": "token_hash", + "optional": false, + "description": "The token hash used in an email link", + "type": "string" + }, + { + "name": "type", + "optional": false, + "description": "The user's verification type.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "signup" + }, + { + "kind": "literal", + "value": "invite" + }, + { + "kind": "literal", + "value": "magiclink" + }, + { + "kind": "literal", + "value": "recovery" + }, + { + "kind": "literal", + "value": "email_change" + }, + { + "kind": "literal", + "value": "email" + } + ] + } + } + ] + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "session", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "AuthSession", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "The access token jwt. It is recommended to set the JWT_EXPIRY to a shorter expiry value.", + "type": "string" + }, + { + "name": "expires_at", + "optional": true, + "description": "A timestamp of when the token will expire. Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "expires_in", + "optional": false, + "description": "The number of seconds until the token expires (since it was issued). Returned when a login is confirmed.", + "type": "number" + }, + { + "name": "provider_refresh_token", + "optional": true, + "description": "The oauth provider refresh token. If present, this can be used to refresh the provider_token via the oauth provider's API. Not all oauth providers return a provider refresh token. If the provider_refresh_token is missing, please refer to the oauth provider's documentation for information on how to obtain the provider refresh token.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "provider_token", + "optional": true, + "description": "The oauth provider token. If present, this can be used to make external API requests to the oauth provider used.", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + "string" + ] + } + }, + { + "name": "refresh_token", + "optional": false, + "description": "A one-time used refresh token that never expires.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "When using a separate user storage, accessing properties of this object will throw an error.", + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "user", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Verify Signup One-Time Password (OTP)", + "code": "const { data, error } = await supabase.auth.verifyOtp({ email, token, type: 'email'})", + "response": "{\n \"data\": {\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"recovery_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n },\n \"session\": {\n \"access_token\": \"\",\n \"token_type\": \"bearer\",\n \"expires_in\": 3600,\n \"expires_at\": 1700000000,\n \"refresh_token\": \"\",\n \"user\": {\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"aud\": \"authenticated\",\n \"role\": \"authenticated\",\n \"email\": \"example@email.com\",\n \"email_confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"phone\": \"\",\n \"confirmed_at\": \"2024-01-01T00:00:00Z\",\n \"recovery_sent_at\": \"2024-01-01T00:00:00Z\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"app_metadata\": {\n \"provider\": \"email\",\n \"providers\": [\n \"email\"\n ]\n },\n \"user_metadata\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"identities\": [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": false,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"example@email.com\"\n }\n ],\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"is_anonymous\": false\n }\n }\n },\n \"error\": null\n}" + }, + { + "title": "Verify SMS One-Time Password (OTP)", + "code": "const { data, error } = await supabase.auth.verifyOtp({ phone, token, type: 'sms'})" + }, + { + "title": "Verify Email Auth (Token Hash)", + "code": "const { data, error } = await supabase.auth.verifyOtp({ token_hash: tokenHash, type: 'email'})" + } + ] + }, + { + "name": "approveAuthorization", + "description": "Approves an OAuth authorization request. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nAfter approval, the user's consent is stored and an authorization code is generated. The response contains a complete redirect URL with the authorization code and state.", + "parameters": [ + { + "name": "authorizationId", + "description": "The authorization ID to approve", + "type": "string" + }, + { + "name": "options", + "optional": true, + "description": "Optional parameters", + "type": { + "kind": "object", + "properties": [ + { + "name": "skipBrowserRedirect", + "optional": true, + "description": "If false (default), automatically redirects the browser to the OAuth client. If true, returns the redirect_url without automatic redirect (useful for custom handling).", + "type": "boolean" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "redirect_url", + "optional": false, + "description": "Complete redirect URL with authorization code and state parameters (e.g., \"https://app.com/callback?code=xxx&state=yyy\")", + "type": "string" + } + ], + "name": "OAuthRedirect" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "denyAuthorization", + "description": "Denies an OAuth authorization request. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nAfter denial, the response contains a redirect URL with an OAuth error (access_denied) to inform the OAuth client that the user rejected the request.", + "parameters": [ + { + "name": "authorizationId", + "description": "The authorization ID to deny", + "type": "string" + }, + { + "name": "options", + "optional": true, + "description": "Optional parameters", + "type": { + "kind": "object", + "properties": [ + { + "name": "skipBrowserRedirect", + "optional": true, + "description": "If false (default), automatically redirects the browser to the OAuth client. If true, returns the redirect_url without automatic redirect (useful for custom handling).", + "type": "boolean" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "redirect_url", + "optional": false, + "description": "Complete redirect URL with authorization code and state parameters (e.g., \"https://app.com/callback?code=xxx&state=yyy\")", + "type": "string" + } + ], + "name": "OAuthRedirect" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "getAuthorizationDetails", + "description": "Retrieves details about an OAuth authorization request. Used to display consent information to the user. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis method returns one of two response types: - `OAuthAuthorizationDetails`: User needs to consent - show consent page with client info - `OAuthRedirect`: User already consented - redirect immediately to the OAuth client\nUse type narrowing to distinguish between the responses: ```typescript if ('authorization_id' in data) { // Show consent page } else { // Redirect to data.redirect_url } ```", + "parameters": [ + { + "name": "authorizationId", + "description": "The authorization ID from the authorization request", + "type": "string" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "authorization_id", + "optional": false, + "description": "The authorization ID used to approve or deny the request", + "type": "string" + }, + { + "name": "client", + "optional": false, + "description": "OAuth client requesting authorization", + "type": { + "kind": "object", + "properties": [ + { + "name": "id", + "optional": false, + "description": "Unique identifier for the OAuth client (UUID)", + "type": "string" + }, + { + "name": "logo_uri", + "optional": false, + "description": "URI of the OAuth client's logo", + "type": "string" + }, + { + "name": "name", + "optional": false, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "uri", + "optional": false, + "description": "URI of the OAuth client's website", + "type": "string" + } + ], + "name": "OAuthAuthorizationClient" + } + }, + { + "name": "redirect_uri", + "optional": false, + "description": "The OAuth client's registered redirect URI (base URI without query parameters)", + "type": "string" + }, + { + "name": "scope", + "optional": false, + "description": "Space-separated list of requested scopes (e.g., \"openid profile email\")", + "type": "string" + }, + { + "name": "user", + "optional": false, + "description": "User object associated with the authorization", + "type": { + "kind": "object", + "properties": [ + { + "name": "email", + "optional": false, + "description": "User email", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "User ID (UUID)", + "type": "string" + } + ] + } + } + ], + "name": "OAuthAuthorizationDetails" + }, + { + "kind": "object", + "properties": [ + { + "name": "redirect_url", + "optional": false, + "description": "Complete redirect URL with authorization code and state parameters (e.g., \"https://app.com/callback?code=xxx&state=yyy\")", + "type": "string" + } + ], + "name": "OAuthRedirect" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "listGrants", + "description": "Lists all OAuth grants that the authenticated user has authorized. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.", + "parameters": [], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "properties": [ + { + "name": "client", + "optional": false, + "description": "OAuth client information", + "type": { + "kind": "object", + "properties": [ + { + "name": "id", + "optional": false, + "description": "Unique identifier for the OAuth client (UUID)", + "type": "string" + }, + { + "name": "logo_uri", + "optional": false, + "description": "URI of the OAuth client's logo", + "type": "string" + }, + { + "name": "name", + "optional": false, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "uri", + "optional": false, + "description": "URI of the OAuth client's website", + "type": "string" + } + ], + "name": "OAuthAuthorizationClient" + } + }, + { + "name": "granted_at", + "optional": false, + "description": "Timestamp when the grant was created (ISO 8601 date-time)", + "type": "string" + }, + { + "name": "scopes", + "optional": false, + "description": "Array of scopes granted to this client", + "type": { + "kind": "array", + "elementType": "string" + } + } + ], + "name": "OAuthGrant" + } + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "revokeGrant", + "description": "Revokes a user's OAuth grant for a specific client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nRevocation marks consent as revoked, deletes active sessions for that OAuth client, and invalidates associated refresh tokens.", + "parameters": [ + { + "name": "options", + "description": "Revocation options", + "type": { + "kind": "object", + "properties": [ + { + "name": "clientId", + "optional": false, + "description": "The OAuth client identifier (UUID) to revoke access for", + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "deleteFactor", + "description": "Deletes a factor on a user. This will log the user out of all active sessions if the deleted factor was verified.", + "parameters": [ + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "id", + "optional": false, + "description": "ID of the MFA factor to delete.", + "type": "string" + }, + { + "name": "userId", + "optional": false, + "description": "ID of the user whose factor is being deleted.", + "type": "string" + } + ], + "name": "AuthMFAAdminDeleteFactorParams" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "id", + "optional": false, + "description": "ID of the factor that was successfully deleted.", + "type": "string" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Delete a factor for a user", + "code": "const { data, error } = await supabase.auth.admin.mfa.deleteFactor({\n id: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n userId: 'a89baba7-b1b7-440f-b4bb-91026967f66b',\n})", + "response": "{\n data: {\n id: '34e770dd-9ff9-416c-87fa-43b31d7ef225'\n },\n error: null\n}" + } + ] + }, + { + "name": "listFactors", + "description": "Lists all factors associated to a user.", + "parameters": [ + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "userId", + "optional": false, + "description": "ID of the user.", + "type": "string" + } + ], + "name": "AuthMFAAdminListFactorsParams" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "factors", + "optional": false, + "description": "All factors attached to the user.", + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "typeParam", + "name": "Type" + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "typeParam", + "name": "Status" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "List all factors for a user", + "code": "const { data, error } = await supabase.auth.admin.mfa.listFactors()", + "response": "{\n data: {\n factors: Factor[\n {\n id: '',\n friendly_name: 'Auth App Factor',\n factor_type: 'totp',\n status: 'verified',\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z'\n }\n ]\n },\n error: null\n}" + } + ] + }, + { + "name": "createClient", + "description": "Creates a new OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "parameters": [ + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "client_name", + "optional": false, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "client_uri", + "optional": true, + "description": "URI of the OAuth client", + "type": "string" + }, + { + "name": "grant_types", + "optional": true, + "description": "Array of allowed grant types (optional, defaults to authorization_code and refresh_token)", + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "authorization_code" + }, + { + "kind": "literal", + "value": "refresh_token" + } + ] + } + } + }, + { + "name": "redirect_uris", + "optional": false, + "description": "Array of allowed redirect URIs", + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "response_types", + "optional": true, + "description": "Array of allowed response types (optional, defaults to code)", + "type": { + "kind": "array", + "elementType": { + "kind": "literal", + "value": "code" + } + } + }, + { + "name": "scope", + "optional": true, + "description": "Scope of the OAuth client", + "type": "string" + }, + { + "name": "token_endpoint_auth_method", + "optional": true, + "description": "Token endpoint authentication method (defaults to server default if not specified)", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "none" + }, + { + "kind": "literal", + "value": "client_secret_basic" + }, + { + "kind": "literal", + "value": "client_secret_post" + } + ] + } + } + ], + "name": "CreateOAuthClientParams" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "client_id", + "optional": false, + "description": "Unique identifier for the OAuth client", + "type": "string" + }, + { + "name": "client_name", + "optional": false, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "client_secret", + "optional": true, + "description": "Client secret (only returned on registration and regeneration)", + "type": "string" + }, + { + "name": "client_type", + "optional": false, + "description": "Type of OAuth client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "public" + }, + { + "kind": "literal", + "value": "confidential" + } + ] + } + }, + { + "name": "client_uri", + "optional": true, + "description": "URI of the OAuth client", + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "description": "Timestamp when the client was created", + "type": "string" + }, + { + "name": "grant_types", + "optional": false, + "description": "Array of allowed grant types", + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "authorization_code" + }, + { + "kind": "literal", + "value": "refresh_token" + } + ] + } + } + }, + { + "name": "logo_uri", + "optional": true, + "description": "URI of the OAuth client's logo", + "type": "string" + }, + { + "name": "redirect_uris", + "optional": false, + "description": "Array of allowed redirect URIs", + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "registration_type", + "optional": false, + "description": "Registration type of the client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "dynamic" + }, + { + "kind": "literal", + "value": "manual" + } + ] + } + }, + { + "name": "response_types", + "optional": false, + "description": "Array of allowed response types", + "type": { + "kind": "array", + "elementType": { + "kind": "literal", + "value": "code" + } + } + }, + { + "name": "scope", + "optional": true, + "description": "Scope of the OAuth client", + "type": "string" + }, + { + "name": "token_endpoint_auth_method", + "optional": false, + "description": "Token endpoint authentication method", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "none" + }, + { + "kind": "literal", + "value": "client_secret_basic" + }, + { + "kind": "literal", + "value": "client_secret_post" + } + ] + } + }, + { + "name": "updated_at", + "optional": false, + "description": "Timestamp when the client was last updated", + "type": "string" + } + ], + "name": "OAuthClient" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "deleteClient", + "description": "Deletes an OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "parameters": [ + { + "name": "clientId", + "type": "string" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": null + }, + { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + ] + } + } + ] + } + ] + } + }, + { + "name": "getClient", + "description": "Gets details of a specific OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "parameters": [ + { + "name": "clientId", + "type": "string" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "client_id", + "optional": false, + "description": "Unique identifier for the OAuth client", + "type": "string" + }, + { + "name": "client_name", + "optional": false, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "client_secret", + "optional": true, + "description": "Client secret (only returned on registration and regeneration)", + "type": "string" + }, + { + "name": "client_type", + "optional": false, + "description": "Type of OAuth client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "public" + }, + { + "kind": "literal", + "value": "confidential" + } + ] + } + }, + { + "name": "client_uri", + "optional": true, + "description": "URI of the OAuth client", + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "description": "Timestamp when the client was created", + "type": "string" + }, + { + "name": "grant_types", + "optional": false, + "description": "Array of allowed grant types", + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "authorization_code" + }, + { + "kind": "literal", + "value": "refresh_token" + } + ] + } + } + }, + { + "name": "logo_uri", + "optional": true, + "description": "URI of the OAuth client's logo", + "type": "string" + }, + { + "name": "redirect_uris", + "optional": false, + "description": "Array of allowed redirect URIs", + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "registration_type", + "optional": false, + "description": "Registration type of the client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "dynamic" + }, + { + "kind": "literal", + "value": "manual" + } + ] + } + }, + { + "name": "response_types", + "optional": false, + "description": "Array of allowed response types", + "type": { + "kind": "array", + "elementType": { + "kind": "literal", + "value": "code" + } + } + }, + { + "name": "scope", + "optional": true, + "description": "Scope of the OAuth client", + "type": "string" + }, + { + "name": "token_endpoint_auth_method", + "optional": false, + "description": "Token endpoint authentication method", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "none" + }, + { + "kind": "literal", + "value": "client_secret_basic" + }, + { + "kind": "literal", + "value": "client_secret_post" + } + ] + } + }, + { + "name": "updated_at", + "optional": false, + "description": "Timestamp when the client was last updated", + "type": "string" + } + ], + "name": "OAuthClient" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "listClients", + "description": "Lists all OAuth clients with optional pagination. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "parameters": [ + { + "name": "params", + "optional": true, + "type": { + "kind": "object", + "properties": [ + { + "name": "page", + "optional": true, + "description": "The page number", + "type": "number" + }, + { + "name": "perPage", + "optional": true, + "description": "Number of items returned per page", + "type": "number" + } + ], + "name": "PageParams" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "intersection", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "clients", + "optional": false, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "properties": [ + { + "name": "client_id", + "optional": false, + "description": "Unique identifier for the OAuth client", + "type": "string" + }, + { + "name": "client_name", + "optional": false, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "client_secret", + "optional": true, + "description": "Client secret (only returned on registration and regeneration)", + "type": "string" + }, + { + "name": "client_type", + "optional": false, + "description": "Type of OAuth client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "public" + }, + { + "kind": "literal", + "value": "confidential" + } + ] + } + }, + { + "name": "client_uri", + "optional": true, + "description": "URI of the OAuth client", + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "description": "Timestamp when the client was created", + "type": "string" + }, + { + "name": "grant_types", + "optional": false, + "description": "Array of allowed grant types", + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "authorization_code" + }, + { + "kind": "literal", + "value": "refresh_token" + } + ] + } + } + }, + { + "name": "logo_uri", + "optional": true, + "description": "URI of the OAuth client's logo", + "type": "string" + }, + { + "name": "redirect_uris", + "optional": false, + "description": "Array of allowed redirect URIs", + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "registration_type", + "optional": false, + "description": "Registration type of the client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "dynamic" + }, + { + "kind": "literal", + "value": "manual" + } + ] + } + }, + { + "name": "response_types", + "optional": false, + "description": "Array of allowed response types", + "type": { + "kind": "array", + "elementType": { + "kind": "literal", + "value": "code" + } + } + }, + { + "name": "scope", + "optional": true, + "description": "Scope of the OAuth client", + "type": "string" + }, + { + "name": "token_endpoint_auth_method", + "optional": false, + "description": "Token endpoint authentication method", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "none" + }, + { + "kind": "literal", + "value": "client_secret_basic" + }, + { + "kind": "literal", + "value": "client_secret_post" + } + ] + } + }, + { + "name": "updated_at", + "optional": false, + "description": "Timestamp when the client was last updated", + "type": "string" + } + ], + "name": "OAuthClient" + } + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "lastPage", + "optional": false, + "type": "number" + }, + { + "name": "nextPage", + "optional": false, + "type": { + "kind": "union", + "types": [ + "number", + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "total", + "optional": false, + "type": "number" + } + ], + "name": "Pagination" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "clients", + "optional": false, + "type": { + "kind": "tuple", + "elements": [] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + } + ] + } + ] + } + }, + { + "name": "regenerateClientSecret", + "description": "Regenerates the secret for an OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "parameters": [ + { + "name": "clientId", + "type": "string" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "client_id", + "optional": false, + "description": "Unique identifier for the OAuth client", + "type": "string" + }, + { + "name": "client_name", + "optional": false, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "client_secret", + "optional": true, + "description": "Client secret (only returned on registration and regeneration)", + "type": "string" + }, + { + "name": "client_type", + "optional": false, + "description": "Type of OAuth client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "public" + }, + { + "kind": "literal", + "value": "confidential" + } + ] + } + }, + { + "name": "client_uri", + "optional": true, + "description": "URI of the OAuth client", + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "description": "Timestamp when the client was created", + "type": "string" + }, + { + "name": "grant_types", + "optional": false, + "description": "Array of allowed grant types", + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "authorization_code" + }, + { + "kind": "literal", + "value": "refresh_token" + } + ] + } + } + }, + { + "name": "logo_uri", + "optional": true, + "description": "URI of the OAuth client's logo", + "type": "string" + }, + { + "name": "redirect_uris", + "optional": false, + "description": "Array of allowed redirect URIs", + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "registration_type", + "optional": false, + "description": "Registration type of the client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "dynamic" + }, + { + "kind": "literal", + "value": "manual" + } + ] + } + }, + { + "name": "response_types", + "optional": false, + "description": "Array of allowed response types", + "type": { + "kind": "array", + "elementType": { + "kind": "literal", + "value": "code" + } + } + }, + { + "name": "scope", + "optional": true, + "description": "Scope of the OAuth client", + "type": "string" + }, + { + "name": "token_endpoint_auth_method", + "optional": false, + "description": "Token endpoint authentication method", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "none" + }, + { + "kind": "literal", + "value": "client_secret_basic" + }, + { + "kind": "literal", + "value": "client_secret_post" + } + ] + } + }, + { + "name": "updated_at", + "optional": false, + "description": "Timestamp when the client was last updated", + "type": "string" + } + ], + "name": "OAuthClient" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "updateClient", + "description": "Updates an existing OAuth client. Only relevant when the OAuth 2.1 server is enabled in Supabase Auth.\nThis function should only be called on a server. Never expose your `service_role` key in the browser.", + "parameters": [ + { + "name": "clientId", + "type": "string" + }, + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "client_name", + "optional": true, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "client_uri", + "optional": true, + "description": "URI of the OAuth client", + "type": "string" + }, + { + "name": "grant_types", + "optional": true, + "description": "Array of allowed grant types", + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "authorization_code" + }, + { + "kind": "literal", + "value": "refresh_token" + } + ] + } + } + }, + { + "name": "logo_uri", + "optional": true, + "description": "URI of the OAuth client's logo", + "type": "string" + }, + { + "name": "redirect_uris", + "optional": true, + "description": "Array of allowed redirect URIs", + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "token_endpoint_auth_method", + "optional": true, + "description": "Token endpoint authentication method", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "none" + }, + { + "kind": "literal", + "value": "client_secret_basic" + }, + { + "kind": "literal", + "value": "client_secret_post" + } + ] + } + } + ], + "name": "UpdateOAuthClientParams" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "client_id", + "optional": false, + "description": "Unique identifier for the OAuth client", + "type": "string" + }, + { + "name": "client_name", + "optional": false, + "description": "Human-readable name of the OAuth client", + "type": "string" + }, + { + "name": "client_secret", + "optional": true, + "description": "Client secret (only returned on registration and regeneration)", + "type": "string" + }, + { + "name": "client_type", + "optional": false, + "description": "Type of OAuth client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "public" + }, + { + "kind": "literal", + "value": "confidential" + } + ] + } + }, + { + "name": "client_uri", + "optional": true, + "description": "URI of the OAuth client", + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "description": "Timestamp when the client was created", + "type": "string" + }, + { + "name": "grant_types", + "optional": false, + "description": "Array of allowed grant types", + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "authorization_code" + }, + { + "kind": "literal", + "value": "refresh_token" + } + ] + } + } + }, + { + "name": "logo_uri", + "optional": true, + "description": "URI of the OAuth client's logo", + "type": "string" + }, + { + "name": "redirect_uris", + "optional": false, + "description": "Array of allowed redirect URIs", + "type": { + "kind": "array", + "elementType": "string" + } + }, + { + "name": "registration_type", + "optional": false, + "description": "Registration type of the client", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "dynamic" + }, + { + "kind": "literal", + "value": "manual" + } + ] + } + }, + { + "name": "response_types", + "optional": false, + "description": "Array of allowed response types", + "type": { + "kind": "array", + "elementType": { + "kind": "literal", + "value": "code" + } + } + }, + { + "name": "scope", + "optional": true, + "description": "Scope of the OAuth client", + "type": "string" + }, + { + "name": "token_endpoint_auth_method", + "optional": false, + "description": "Token endpoint authentication method", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "none" + }, + { + "kind": "literal", + "value": "client_secret_basic" + }, + { + "kind": "literal", + "value": "client_secret_post" + } + ] + } + }, + { + "name": "updated_at", + "optional": false, + "description": "Timestamp when the client was last updated", + "type": "string" + } + ], + "name": "OAuthClient" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "challenge", + "description": "Prepares a challenge used to verify that a user has access to a MFA factor.", + "remarks": [ + "- An [enrolled factor](/docs/reference/javascript/auth-mfa-enroll) is required before creating a challenge. - To verify a challenge, see [`mfa.verify()`](/docs/reference/javascript/auth-mfa-verify). - A phone factor sends a code to the user upon challenge. The channel defaults to `sms` unless otherwise specified." + ], + "parameters": [ + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "factorId", + "optional": false, + "description": "ID of the factor to be challenged. Returned in enroll().", + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "object", + "name": "AuthError", + "properties": [ + { + "name": "constructor", + "optional": false, + "type": null + }, + { + "name": "__isAuthError", + "optional": false, + "type": "boolean" + }, + { + "name": "code", + "optional": false, + "description": "Error code associated with the error. Most errors coming from HTTP responses will have a code, though some errors that occur before a response is received will not have one present. In that case #status will also be undefined.", + "type": { + "kind": "union", + "types": [ + "undefined", + { + "kind": "reference", + "name": "ErrorCode" + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "status", + "optional": false, + "description": "HTTP status code that caused the error.", + "type": { + "kind": "union", + "types": [ + "undefined", + "number" + ] + } + } + ] + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "expires_at", + "optional": false, + "description": "Timestamp in UNIX seconds when this challenge will no longer be usable.", + "type": "number" + }, + { + "name": "id", + "optional": false, + "description": "ID of the newly created challenge.", + "type": "string" + }, + { + "name": "type", + "optional": false, + "description": "Factor Type which generated the challenge", + "type": { + "kind": "literal", + "value": "totp" + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Create a challenge for a factor", + "code": "const { data, error } = await supabase.auth.mfa.challenge({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225'\n})", + "response": "{\n data: {\n id: '',\n type: 'totp',\n expires_at: 1700000000\n },\n error: null\n}" + }, + { + "title": "Create a challenge for a phone factor", + "code": "const { data, error } = await supabase.auth.mfa.challenge({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n})", + "response": "{\n data: {\n id: '',\n type: 'phone',\n expires_at: 1700000000\n },\n error: null\n}" + }, + { + "title": "Create a challenge for a phone factor (WhatsApp)", + "code": "const { data, error } = await supabase.auth.mfa.challenge({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n channel: 'whatsapp',\n})", + "response": "{\n data: {\n id: '',\n expires_at: 1700000000\n },\n error: null\n}" + } + ] + }, + { + "name": "challengeAndVerify", + "description": "Helper method which creates a challenge and immediately uses the given code to verify against it thereafter. The verification code is provided by the user by entering a code seen in their authenticator app.", + "remarks": [ + "- Intended for use with only TOTP factors. - An [enrolled factor](/docs/reference/javascript/auth-mfa-enroll) is required before invoking `challengeAndVerify()`. - Executes [`mfa.challenge()`](/docs/reference/javascript/auth-mfa-challenge) and [`mfa.verify()`](/docs/reference/javascript/auth-mfa-verify) in a single step." + ], + "parameters": [ + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "code", + "optional": false, + "description": "Verification code provided by the user.", + "type": "string" + }, + { + "name": "factorId", + "optional": false, + "description": "ID of the factor being verified. Returned in enroll().", + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "New access token (JWT) after successful verification.", + "type": "string" + }, + { + "name": "expires_in", + "optional": false, + "description": "Number of seconds in which the access token will expire.", + "type": "number" + }, + { + "name": "refresh_token", + "optional": false, + "description": "Refresh token you can use to obtain new access tokens when expired.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "description": "Type of token, always `bearer`.", + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "Updated user profile.", + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ], + "name": "AuthMFAVerifyResponseData" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Create and verify a challenge for a factor", + "code": "const { data, error } = await supabase.auth.mfa.challengeAndVerify({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n code: '123456'\n})", + "response": "{\n data: {\n access_token: '',\n token_type: 'Bearer',\n expires_in: 3600,\n refresh_token: '',\n user: {\n id: '11111111-1111-1111-1111-111111111111',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {\n provider: 'email',\n providers: [\n \"email\",\n ]\n },\n user_metadata: {},\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false,\n factors: [\n \"id\": '',\n \"friendly_name\": 'Important Auth App',\n \"factor_type\": 'totp',\n \"status\": 'verified',\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n ]\n }\n }\n error: null\n}" + } + ] + }, + { + "name": "enroll", + "description": "Starts the enrollment process for a new Multi-Factor Authentication (MFA) factor. This method creates a new `unverified` factor. To verify a factor, present the QR code or secret to the user and ask them to add it to their authenticator app. The user has to enter the code from their authenticator app to verify it.\nUpon verifying a factor, all other sessions are logged out and the current session's authenticator level is promoted to `aal2`.", + "remarks": [ + "- Use `totp` or `phone` as the `factorType` and use the returned `id` to create a challenge. - To create a challenge, see [`mfa.challenge()`](/docs/reference/javascript/auth-mfa-challenge). - To verify a challenge, see [`mfa.verify()`](/docs/reference/javascript/auth-mfa-verify). - To create and verify a TOTP challenge in a single step, see [`mfa.challengeAndVerify()`](/docs/reference/javascript/auth-mfa-challengeandverify). - To generate a QR code for the `totp` secret in Next.js, you can do the following: ```html {data.totp.uri} ``` - The `challenge` and `verify` steps are separated when using Phone factors as the user will need time to receive and input the code obtained from the SMS in challenge." + ], + "parameters": [ + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "factorType", + "optional": false, + "description": "The type of factor being enrolled.", + "type": { + "kind": "literal", + "value": "totp" + } + }, + { + "name": "friendlyName", + "optional": true, + "description": "Human readable name assigned to the factor.", + "type": "string" + }, + { + "name": "issuer", + "optional": true, + "description": "Domain which the user is enrolled with.", + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "conditional" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Enroll a time-based, one-time password (TOTP) factor", + "code": "const { data, error } = await supabase.auth.mfa.enroll({\n factorType: 'totp',\n friendlyName: 'your_friendly_name'\n})\n\n// Use the id to create a challenge.\n// The challenge can be verified by entering the code generated from the authenticator app.\n// The code will be generated upon scanning the qr_code or entering the secret into the authenticator app.\nconst { id, type, totp: { qr_code, secret, uri }, friendly_name } = data\nconst challenge = await supabase.auth.mfa.challenge({ factorId: id });", + "response": "{\n data: {\n id: '',\n type: 'totp'\n totp: {\n qr_code: '',\n secret: '',\n uri: '',\n }\n friendly_name?: 'Important app'\n },\n error: null\n}" + }, + { + "title": "Enroll a Phone Factor", + "code": "const { data, error } = await supabase.auth.mfa.enroll({\n factorType: 'phone',\n friendlyName: 'your_friendly_name',\n phone: '+12345678',\n})\n\n// Use the id to create a challenge and send an SMS with a code to the user.\nconst { id, type, friendly_name, phone } = data\n\nconst challenge = await supabase.auth.mfa.challenge({ factorId: id });", + "response": "{\n data: {\n id: '',\n type: 'phone',\n friendly_name?: 'Important app',\n phone: '+5787123456'\n },\n error: null\n}" + } + ] + }, + { + "name": "getAuthenticatorAssuranceLevel", + "description": "Returns the Authenticator Assurance Level (AAL) for the active session.\n- `aal1` (or `null`) means that the user's identity has been verified only with a conventional login (email+password, OTP, magic link, social login, etc.). - `aal2` means that the user's identity has been verified both with a conventional login and at least one MFA factor.\nWhen called without a JWT parameter, this method is fairly quick (microseconds) and rarely uses the network. When a JWT is provided (useful in server-side environments like Edge Functions where no session is stored), this method will make a network request to validate the user and fetch their MFA factors.", + "remarks": [ + "- Authenticator Assurance Level (AAL) is the measure of the strength of an authentication mechanism. - In Supabase, having an AAL of `aal1` refers to having the 1st factor of authentication such as an email and password or OAuth sign-in while `aal2` refers to the 2nd factor of authentication such as a time-based, one-time-password (TOTP) or Phone factor. - If the user has a verified factor, the `nextLevel` field will return `aal2`, else, it will return `aal1`. - An optional `jwt` parameter can be passed to check the AAL level of a specific JWT instead of the current session." + ], + "parameters": [ + { + "name": "jwt", + "optional": true, + "description": "Takes in an optional access token JWT. If no JWT is provided, the JWT from the current session is used.", + "type": "string" + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "currentAuthenticationMethods", + "optional": false, + "description": "A list of all authentication methods attached to this session. Use the information here to detect the last time a user verified a factor, for example if implementing a step-up scenario.\nSupports both RFC-8176 compliant format (string[]) and detailed format (AMREntry[]). - String format: ['password', 'otp'] - RFC-8176 compliant - Object format: [{ method: 'password', timestamp: 1234567890 }] - includes timestamps", + "type": { + "kind": "union", + "types": [ + { + "kind": "array", + "elementType": { + "kind": "object", + "name": "AMREntry", + "properties": [ + { + "name": "method", + "optional": false, + "description": "Authentication method name.", + "type": { + "kind": "union", + "types": [ + { + "kind": "indexedAccess", + "objectType": { + "kind": "query" + }, + "indexType": null + }, + { + "kind": "intersection", + "types": [ + "string", + { + "kind": "object", + "properties": [] + } + ] + } + ] + } + }, + { + "name": "timestamp", + "optional": false, + "description": "Timestamp when the method was successfully used. Represents number of seconds since 1st January 1970 (UNIX epoch) in UTC.", + "type": "number" + } + ] + } + }, + { + "kind": "array", + "elementType": "string" + } + ] + } + }, + { + "name": "currentLevel", + "optional": false, + "description": "Current AAL level of the session.", + "type": { + "kind": "union", + "types": [ + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "aal1" + }, + { + "kind": "literal", + "value": "aal2" + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + }, + { + "name": "nextLevel", + "optional": false, + "description": "Next possible AAL level for the session. If the next level is higher than the current one, the user should go through MFA.", + "type": { + "kind": "union", + "types": [ + { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "aal1" + }, + { + "kind": "literal", + "value": "aal2" + } + ] + }, + { + "kind": "literal", + "value": null + } + ] + } + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Get the AAL details of a session", + "code": "const { data, error } = await supabase.auth.mfa.getAuthenticatorAssuranceLevel()\nconst { currentLevel, nextLevel, currentAuthenticationMethods } = data", + "response": "{\n data: {\n currentLevel: 'aal1',\n nextLevel: 'aal2',\n currentAuthenticationMethods: [\n {\n method: 'password',\n timestamp: 1700000000\n }\n ]\n }\n error: null\n}" + }, + { + "title": "Get the AAL details for a specific JWT", + "code": "const { data, error } = await supabase.auth.mfa.getAuthenticatorAssuranceLevel(jwt)" + } + ] + }, + { + "name": "listFactors", + "description": "Returns the list of MFA factors enabled for this user.", + "parameters": [], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "intersection", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "all", + "optional": false, + "description": "All available factors (verified and unverified).", + "type": { + "kind": "array", + "elementType": { + "kind": "conditional" + } + } + } + ] + }, + { + "kind": "mapped" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + } + }, + { + "name": "unenroll", + "description": "Unenroll removes a MFA factor. A user has to have an `aal2` authenticator level in order to unenroll a `verified` factor.", + "parameters": [ + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "factorId", + "optional": false, + "description": "ID of the factor being unenrolled.", + "type": "string" + } + ], + "name": "MFAUnenrollParams" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "id", + "optional": false, + "description": "ID of the factor that was successfully unenrolled.", + "type": "string" + } + ] + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Unenroll a factor", + "code": "const { data, error } = await supabase.auth.mfa.unenroll({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n})", + "response": "{\n data: {\n id: ''\n },\n error: null\n}" + } + ] + }, + { + "name": "verify", + "description": "Verifies a code against a challenge. The verification code is provided by the user by entering a code seen in their authenticator app.", + "remarks": [ + "- To verify a challenge, please [create a challenge](/docs/reference/javascript/auth-mfa-challenge) first." + ], + "parameters": [ + { + "name": "params", + "type": { + "kind": "object", + "properties": [ + { + "name": "challengeId", + "optional": false, + "description": "ID of the challenge being verified. Returned in challenge().", + "type": "string" + }, + { + "name": "code", + "optional": false, + "description": "Verification code provided by the user.", + "type": "string" + }, + { + "name": "factorId", + "optional": false, + "description": "ID of the factor being verified. Returned in enroll().", + "type": "string" + } + ] + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "object", + "properties": [ + { + "name": "access_token", + "optional": false, + "description": "New access token (JWT) after successful verification.", + "type": "string" + }, + { + "name": "expires_in", + "optional": false, + "description": "Number of seconds in which the access token will expire.", + "type": "number" + }, + { + "name": "refresh_token", + "optional": false, + "description": "Refresh token you can use to obtain new access tokens when expired.", + "type": "string" + }, + { + "name": "token_type", + "optional": false, + "description": "Type of token, always `bearer`.", + "type": { + "kind": "literal", + "value": "bearer" + } + }, + { + "name": "user", + "optional": false, + "description": "Updated user profile.", + "type": { + "kind": "object", + "name": "AuthUser", + "properties": [ + { + "name": "action_link", + "optional": true, + "type": "string" + }, + { + "name": "app_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserAppMetadata", + "properties": [ + { + "name": "provider", + "optional": true, + "description": "The first provider that the user used to sign up with.", + "type": "string" + }, + { + "name": "providers", + "optional": true, + "description": "A list of all providers that the user has linked to their account.", + "type": { + "kind": "array", + "elementType": "string" + } + } + ] + } + }, + { + "name": "aud", + "optional": false, + "type": "string" + }, + { + "name": "banned_until", + "optional": true, + "type": "string" + }, + { + "name": "confirmation_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "deleted_at", + "optional": true, + "type": "string" + }, + { + "name": "email", + "optional": true, + "type": "string" + }, + { + "name": "email_change_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "email_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "factors", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "union", + "types": [ + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "verified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + }, + { + "kind": "object", + "properties": [ + { + "name": "created_at", + "optional": false, + "type": "string" + }, + { + "name": "factor_type", + "optional": false, + "description": "Type of factor. `totp` and `phone` supported with this version", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "webauthn" + }, + { + "kind": "literal", + "value": "totp" + }, + { + "kind": "literal", + "value": "phone" + } + ] + } + }, + { + "name": "friendly_name", + "optional": true, + "description": "Friendly name of the factor, useful to disambiguate between multiple factors.", + "type": "string" + }, + { + "name": "id", + "optional": false, + "description": "ID of the factor.", + "type": "string" + }, + { + "name": "last_challenged_at", + "optional": true, + "type": "string" + }, + { + "name": "status", + "optional": false, + "description": "The verification status of the factor, default is `unverified` after `.enroll()`, then `verified` after the user verifies it with `.verify()`", + "type": { + "kind": "literal", + "value": "unverified" + } + }, + { + "name": "updated_at", + "optional": false, + "type": "string" + } + ], + "name": "Factor" + } + ] + } + } + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identities", + "optional": true, + "type": { + "kind": "array", + "elementType": { + "kind": "object", + "name": "UserIdentity", + "properties": [ + { + "name": "created_at", + "optional": true, + "type": "string" + }, + { + "name": "id", + "optional": false, + "type": "string" + }, + { + "name": "identity_data", + "optional": true, + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "identity_id", + "optional": false, + "type": "string" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "provider", + "optional": false, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_id", + "optional": false, + "type": "string" + } + ] + } + } + }, + { + "name": "invited_at", + "optional": true, + "type": "string" + }, + { + "name": "is_anonymous", + "optional": true, + "type": "boolean" + }, + { + "name": "is_sso_user", + "optional": true, + "type": "boolean" + }, + { + "name": "last_sign_in_at", + "optional": true, + "type": "string" + }, + { + "name": "new_email", + "optional": true, + "type": "string" + }, + { + "name": "new_phone", + "optional": true, + "type": "string" + }, + { + "name": "phone", + "optional": true, + "type": "string" + }, + { + "name": "phone_confirmed_at", + "optional": true, + "type": "string" + }, + { + "name": "recovery_sent_at", + "optional": true, + "type": "string" + }, + { + "name": "role", + "optional": true, + "type": "string" + }, + { + "name": "updated_at", + "optional": true, + "type": "string" + }, + { + "name": "user_metadata", + "optional": false, + "type": { + "kind": "object", + "name": "UserMetadata", + "properties": [] + } + } + ] + } + } + ], + "name": "AuthMFAVerifyResponseData" + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + } + ] + }, + { + "kind": "object", + "properties": [ + { + "name": "data", + "optional": false, + "type": { + "kind": "literal", + "value": null + } + }, + { + "name": "error", + "optional": false, + "type": { + "kind": "conditional" + } + } + ] + } + ] + } + ] + }, + "examples": [ + { + "title": "Verify a challenge for a factor", + "code": "const { data, error } = await supabase.auth.mfa.verify({\n factorId: '34e770dd-9ff9-416c-87fa-43b31d7ef225',\n challengeId: '4034ae6f-a8ce-4fb5-8ee5-69a5863a7c15',\n code: '123456'\n})", + "response": "{\n data: {\n access_token: '',\n token_type: 'Bearer',\n expires_in: 3600,\n refresh_token: '',\n user: {\n id: '11111111-1111-1111-1111-111111111111',\n aud: 'authenticated',\n role: 'authenticated',\n email: 'example@email.com',\n email_confirmed_at: '2024-01-01T00:00:00Z',\n phone: '',\n confirmation_sent_at: '2024-01-01T00:00:00Z',\n confirmed_at: '2024-01-01T00:00:00Z',\n last_sign_in_at: '2024-01-01T00:00:00Z',\n app_metadata: {\n provider: 'email',\n providers: [\n \"email\",\n ]\n },\n user_metadata: {},\n identities: [\n {\n \"identity_id\": \"22222222-2222-2222-2222-222222222222\",\n \"id\": \"11111111-1111-1111-1111-111111111111\",\n \"user_id\": \"11111111-1111-1111-1111-111111111111\",\n \"identity_data\": {\n \"email\": \"example@email.com\",\n \"email_verified\": true,\n \"phone_verified\": false,\n \"sub\": \"11111111-1111-1111-1111-111111111111\"\n },\n \"provider\": \"email\",\n \"last_sign_in_at\": \"2024-01-01T00:00:00Z\",\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\",\n \"email\": \"email@example.com\"\n },\n ],\n created_at: '2024-01-01T00:00:00Z',\n updated_at: '2024-01-01T00:00:00Z',\n is_anonymous: false,\n factors: [\n \"id\": '',\n \"friendly_name\": 'Important Auth App',\n \"factor_type\": 'totp',\n \"status\": 'verified',\n \"created_at\": \"2024-01-01T00:00:00Z\",\n \"updated_at\": \"2024-01-01T00:00:00Z\"\n ]\n }\n }\n error: null\n}" + } + ] + } + ] + }, + { + "category": "Functions", + "definitions": [ + { + "name": "invoke", + "description": "Invokes a function", + "remarks": [ + "- Requires an Authorization header. - Invoke params generally match the [Fetch API](https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API) spec. - When you pass in a body to your function, we automatically attach the Content-Type header for `Blob`, `ArrayBuffer`, `File`, `FormData` and `String`. If it doesn't match any of these types we assume the payload is `json`, serialize it and attach the `Content-Type` header as `application/json`. You can override this behavior by passing in a `Content-Type` header of your own. - Responses are automatically parsed as `json`, `blob` and `form-data` depending on the `Content-Type` header sent by your function. Responses are parsed as `text` by default." + ], + "parameters": [ + { + "name": "functionName", + "description": "The name of the Function to invoke.", + "type": "string" + }, + { + "name": "options", + "description": "Options for invoking the Function.", + "type": { + "kind": "object", + "properties": [ + { + "name": "body", + "optional": true, + "description": "The body of the request.", + "type": { + "kind": "union", + "types": [ + { + "kind": "reference", + "name": "File" + }, + { + "kind": "reference", + "name": "Blob" + }, + { + "kind": "reference", + "name": "ArrayBuffer" + }, + { + "kind": "reference", + "name": "FormData" + }, + { + "kind": "reference", + "name": "ReadableStream", + "typeArguments": [ + { + "kind": "reference", + "name": "Uint8Array" + } + ] + }, + { + "kind": "reference", + "name": "Record", + "typeArguments": [ + "string", + "any" + ] + }, + "string" + ] + } + }, + { + "name": "headers", + "optional": true, + "description": "Object representing the headers to send with the request.", + "type": { + "kind": "object", + "properties": [] + } + }, + { + "name": "method", + "optional": true, + "description": "The HTTP verb of the request", + "type": { + "kind": "union", + "types": [ + { + "kind": "literal", + "value": "POST" + }, + { + "kind": "literal", + "value": "GET" + }, + { + "kind": "literal", + "value": "PUT" + }, + { + "kind": "literal", + "value": "PATCH" + }, + { + "kind": "literal", + "value": "DELETE" + } + ] + } + }, + { + "name": "region", + "optional": true, + "description": "The Region to invoke the function in.", + "type": { + "kind": "reference", + "name": "FunctionRegion" + } + }, + { + "name": "signal", + "optional": true, + "description": "The AbortSignal to use for the request.", + "type": { + "kind": "reference", + "name": "AbortSignal" + } + }, + { + "name": "timeout", + "optional": true, + "description": "The timeout for the request in milliseconds. If the function takes longer than this, the request will be aborted.", + "type": "number" + } + ], + "name": "FunctionInvokeOptions" + } + } + ], + "returnType": { + "kind": "reference", + "name": "Promise", + "typeArguments": [ + { + "kind": "union", + "types": [ + { + "kind": "reference", + "name": "FunctionsResponseSuccess", + "typeArguments": [ + { + "kind": "typeParam", + "name": "T" + } + ] + }, + { + "kind": "reference", + "name": "FunctionsResponseFailure" + } + ] + } + ] + }, + "examples": [ + { + "title": "Example 1", + "code": "const { data, error } = await functions.invoke('hello-world', {\n body: { name: 'Ada' },\n})", + "notes": "Error handling\nA `FunctionsHttpError` error is returned if your function throws an error, `FunctionsRelayError` if the Supabase Relay has an error processing your function and `FunctionsFetchError` if there is a network error in calling your function." + }, + { + "title": "Basic invocation", + "code": "const { data, error } = await supabase.functions.invoke('hello', {\n body: { foo: 'bar' }\n})", + "notes": "Passing custom headers\nYou can pass custom headers to your function. Note: supabase-js automatically passes the `Authorization` header with the signed in user's JWT." + }, + { + "title": "Error handling", + "code": "import { FunctionsHttpError, FunctionsRelayError, FunctionsFetchError } from \"@supabase/supabase-js\";\n\nconst { data, error } = await supabase.functions.invoke('hello', {\n headers: {\n \"my-custom-header\": 'my-custom-header-value'\n },\n body: { foo: 'bar' }\n})\n\nif (error instanceof FunctionsHttpError) {\n const errorMessage = await error.context.json()\n console.log('Function returned an error', errorMessage)\n} else if (error instanceof FunctionsRelayError) {\n console.log('Relay error:', error.message)\n} else if (error instanceof FunctionsFetchError) {\n console.log('Fetch error:', error.message)\n}", + "notes": "A `FunctionsHttpError` error is returned if your function throws an error, `FunctionsRelayError` if the Supabase Relay has an error processing your function and `FunctionsFetchError` if there is a network error in calling your function." + }, + { + "title": "Passing custom headers", + "code": "const { data, error } = await supabase.functions.invoke('hello', {\n headers: {\n \"my-custom-header\": 'my-custom-header-value'\n },\n body: { foo: 'bar' }\n})", + "notes": "You can pass custom headers to your function. Note: supabase-js automatically passes the `Authorization` header with the signed in user's JWT." + }, + { + "title": "Calling with DELETE HTTP verb", + "code": "const { data, error } = await supabase.functions.invoke('hello', {\n headers: {\n \"my-custom-header\": 'my-custom-header-value'\n },\n body: { foo: 'bar' },\n method: 'DELETE'\n})", + "notes": "You can also set the HTTP verb to `DELETE` when calling your Edge Function." + }, + { + "title": "Invoking a Function in the UsEast1 region", + "code": "import { createClient, FunctionRegion } from '@supabase/supabase-js'\n\nconst { data, error } = await supabase.functions.invoke('hello', {\n body: { foo: 'bar' },\n region: FunctionRegion.UsEast1\n})", + "notes": "Here are the available regions:\n- `FunctionRegion.Any`\n- `FunctionRegion.ApNortheast1`\n- `FunctionRegion.ApNortheast2`\n- `FunctionRegion.ApSouth1`\n- `FunctionRegion.ApSoutheast1`\n- `FunctionRegion.ApSoutheast2`\n- `FunctionRegion.CaCentral1`\n- `FunctionRegion.EuCentral1`\n- `FunctionRegion.EuWest1`\n- `FunctionRegion.EuWest2`\n- `FunctionRegion.EuWest3`\n- `FunctionRegion.SaEast1`\n- `FunctionRegion.UsEast1`\n- `FunctionRegion.UsWest1`\n- `FunctionRegion.UsWest2`" + }, + { + "title": "Calling with GET HTTP verb", + "code": "const { data, error } = await supabase.functions.invoke('hello', {\n headers: {\n \"my-custom-header\": 'my-custom-header-value'\n },\n method: 'GET'\n})", + "notes": "You can also set the HTTP verb to `GET` when calling your Edge Function." + }, + { + "title": "Example 7", + "code": "const { data, error } = await functions.invoke('hello-world', {\n body: { name: 'Ada' },\n})" + } + ] + }, + { + "name": "setAuth", + "description": "Updates the authorization header", + "parameters": [ + { + "name": "token", + "description": "the new jwt token sent in the authorisation header", + "type": "string" + } + ], + "returnType": "void", + "examples": [ + { + "title": "Setting the authorization header", + "code": "functions.setAuth(session.access_token)" + } + ] + } + ] + }, + { + "category": "Realtime", + "definitions": [ { "name": "httpSend", "description": "Sends a broadcast message explicitly via REST API.\nThis method always uses the REST API endpoint regardless of WebSocket connection state. Useful when you want to guarantee REST delivery or when gradually migrating from implicit REST fallback.", @@ -57064,691 +54803,15 @@ "type": { "kind": "reference", "name": "Record", - "typeArguments": ["string", "any"] + "typeArguments": [ + "string", + "any" + ] } } ], "returnType": "void" }, - { - "name": "constructor", - "description": "Initializes the Socket.", - "parameters": [ - { - "name": "endPoint", - "description": "The string WebSocket endpoint, ie, \"ws://example.com/socket\", \"wss://example.com\", \"/socket\" (inherited host & protocol)", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "accessToken", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "decode", - "optional": true, - "type": { - "kind": "reference", - "name": "Decode", - "typeArguments": ["void"] - } - }, - { - "name": "encode", - "optional": true, - "type": { - "kind": "reference", - "name": "Encode", - "typeArguments": ["void"] - } - }, - { - "name": "fetch", - "optional": true, - "type": { - "kind": "reference", - "name": "Fetch" - } - }, - { - "name": "headers", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "heartbeatCallback", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "heartbeatIntervalMs", - "optional": true, - "type": "number" - }, - { - "name": "log_level", - "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } - }, - { - "name": "logger", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "logLevel", - "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } - }, - { - "name": "params", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "reconnectAfterMs", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "timeout", - "optional": true, - "type": "number" - }, - { - "name": "transport", - "optional": true, - "type": { - "kind": "object", - "name": "WebSocketLikeConstructor", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "vsn", - "optional": true, - "type": "string" - }, - { - "name": "worker", - "optional": true, - "type": "boolean" - }, - { - "name": "workerUrl", - "optional": true, - "type": "string" - } - ], - "name": "RealtimeClientOptions" - } - } - ], - "returnType": { - "kind": "object", - "name": "RealtimeClient", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "accessToken", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - { - "kind": "object", - "properties": [] - } - ] - } - }, - { - "name": "accessTokenValue", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "apiKey", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "channels", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "RealtimeChannel", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "bindings", - "optional": false, - "type": { - "kind": "reference", - "name": "Record", - "typeArguments": [ - "string", - { - "kind": "array", - "elementType": { - "kind": "reference", - "name": "Binding" - } - } - ] - } - }, - { - "name": "broadcastEndpointURL", - "optional": false, - "type": "string" - }, - { - "name": "params", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "config", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "broadcast", - "optional": true, - "description": "self option enables client to receive message it broadcast ack option instructs server to acknowledge that broadcast message was received replay option instructs server to replay broadcast messages", - "type": { - "kind": "object", - "properties": [ - { - "name": "ack", - "optional": true, - "type": "boolean" - }, - { - "name": "replay", - "optional": true, - "type": { - "kind": "reference", - "name": "ReplayOption" - } - }, - { - "name": "self", - "optional": true, - "type": "boolean" - } - ] - } - }, - { - "name": "presence", - "optional": true, - "description": "key option is used to track presence payload across clients", - "type": { - "kind": "object", - "properties": [ - { - "name": "enabled", - "optional": true, - "type": "boolean" - }, - { - "name": "key", - "optional": true, - "type": "string" - } - ] - } - }, - { - "name": "private", - "optional": true, - "description": "defines if the channel is private or not and if RLS policies will be used to check data", - "type": "boolean" - } - ] - } - } - ], - "name": "RealtimeChannelOptions" - } - }, - { - "name": "presence", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimePresence", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "description": "The realtime channel to bind to.", - "type": { - "kind": "reference", - "name": "RealtimeChannel" - } - }, - { - "name": "state", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "private", - "optional": false, - "type": "boolean" - }, - { - "name": "socket", - "optional": false, - "type": { - "kind": "reference", - "name": "RealtimeClient" - } - }, - { - "name": "subTopic", - "optional": false, - "type": "string" - }, - { - "name": "topic", - "optional": false, - "description": "Topic name can be any string.", - "type": "string" - }, - { - "name": "joinedOnce", - "optional": false, - "type": null - }, - { - "name": "joinPush", - "optional": false, - "type": null - }, - { - "name": "rejoinTimer", - "optional": false, - "type": null - }, - { - "name": "state", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "copyBindings", - "optional": false, - "type": null - }, - { - "name": "httpSend", - "optional": false, - "type": null - }, - { - "name": "on", - "optional": false, - "description": "Listen to realtime events on this channel.", - "type": null - }, - { - "name": "presenceState", - "optional": false, - "type": null - }, - { - "name": "send", - "optional": false, - "type": null - }, - { - "name": "subscribe", - "optional": false, - "type": null - }, - { - "name": "teardown", - "optional": false, - "type": null - }, - { - "name": "track", - "optional": false, - "type": null - }, - { - "name": "unsubscribe", - "optional": false, - "type": null - }, - { - "name": "untrack", - "optional": false, - "type": null - }, - { - "name": "updateJoinPayload", - "optional": false, - "type": null - } - ] - } - } - }, - { - "name": "fetch", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "httpEndpoint", - "optional": false, - "type": "string" - }, - { - "name": "logLevel", - "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } - }, - { - "name": "params", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "ref", - "optional": false, - "type": "number" - }, - { - "name": "serializer", - "optional": false, - "type": { - "kind": "reference", - "name": "Serializer" - } - }, - { - "name": "worker", - "optional": true, - "type": "boolean" - }, - { - "name": "workerRef", - "optional": true, - "type": { - "kind": "reference", - "name": "Worker" - } - }, - { - "name": "workerUrl", - "optional": true, - "type": "string" - }, - { - "name": "decode", - "optional": false, - "type": null - }, - { - "name": "encode", - "optional": false, - "type": null - }, - { - "name": "endPoint", - "optional": false, - "type": null - }, - { - "name": "heartbeatCallback", - "optional": false, - "type": null - }, - { - "name": "heartbeatIntervalMs", - "optional": false, - "type": null - }, - { - "name": "heartbeatTimer", - "optional": false, - "type": null - }, - { - "name": "pendingHeartbeatRef", - "optional": false, - "type": null - }, - { - "name": "reconnectAfterMs", - "optional": false, - "type": null - }, - { - "name": "reconnectTimer", - "optional": false, - "type": null - }, - { - "name": "sendBuffer", - "optional": false, - "type": null - }, - { - "name": "stateChangeCallbacks", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "transport", - "optional": false, - "type": null - }, - { - "name": "vsn", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": null - }, - { - "name": "connect", - "optional": false, - "type": null - }, - { - "name": "connectionState", - "optional": false, - "type": null - }, - { - "name": "disconnect", - "optional": false, - "type": null - }, - { - "name": "endpointURL", - "optional": false, - "type": null - }, - { - "name": "getChannels", - "optional": false, - "type": null - }, - { - "name": "isConnected", - "optional": false, - "type": null - }, - { - "name": "isConnecting", - "optional": false, - "type": null - }, - { - "name": "isDisconnecting", - "optional": false, - "type": null - }, - { - "name": "log", - "optional": false, - "type": null - }, - { - "name": "onHeartbeat", - "optional": false, - "type": null - }, - { - "name": "push", - "optional": false, - "type": null - }, - { - "name": "removeAllChannels", - "optional": false, - "type": null - }, - { - "name": "removeChannel", - "optional": false, - "type": null - }, - { - "name": "sendHeartbeat", - "optional": false, - "type": null - }, - { - "name": "setAuth", - "optional": false, - "type": null - } - ] - }, - "examples": [ - { - "title": "Example for a public channel", - "code": "import RealtimeClient from '@supabase/realtime-js'\n\nconst client = new RealtimeClient('https://xyzcompany.supabase.co/realtime/v1', {\n params: { apikey: 'public-anon-key' },\n})\nclient.connect()" - } - ] - }, { "name": "channel", "description": "Creates (or reuses) a RealtimeChannel for the provided topic.\nTopics are automatically prefixed with `realtime:` to match the Realtime service. If a channel with the same topic already exists it will be returned instead of creating a duplicate connection.", @@ -59627,7 +56690,9 @@ "returnType": { "kind": "reference", "name": "Promise", - "typeArguments": ["void"] + "typeArguments": [ + "void" + ] } }, { @@ -59652,7 +56717,9 @@ "returnType": { "kind": "reference", "name": "Promise", - "typeArguments": ["void"] + "typeArguments": [ + "void" + ] }, "examples": [ { @@ -59661,1075 +56728,6 @@ } ] }, - { - "name": "constructor", - "description": "Creates a Presence helper that keeps the local presence state in sync with the server.", - "parameters": [ - { - "name": "channel", - "description": "The realtime channel to bind to.", - "type": { - "kind": "object", - "name": "RealtimeChannel", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "bindings", - "optional": false, - "type": { - "kind": "reference", - "name": "Record", - "typeArguments": [ - "string", - { - "kind": "array", - "elementType": { - "kind": "reference", - "name": "Binding" - } - } - ] - } - }, - { - "name": "broadcastEndpointURL", - "optional": false, - "type": "string" - }, - { - "name": "params", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "config", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "broadcast", - "optional": true, - "description": "self option enables client to receive message it broadcast ack option instructs server to acknowledge that broadcast message was received replay option instructs server to replay broadcast messages", - "type": { - "kind": "object", - "properties": [ - { - "name": "ack", - "optional": true, - "type": "boolean" - }, - { - "name": "replay", - "optional": true, - "type": { - "kind": "reference", - "name": "ReplayOption" - } - }, - { - "name": "self", - "optional": true, - "type": "boolean" - } - ] - } - }, - { - "name": "presence", - "optional": true, - "description": "key option is used to track presence payload across clients", - "type": { - "kind": "object", - "properties": [ - { - "name": "enabled", - "optional": true, - "type": "boolean" - }, - { - "name": "key", - "optional": true, - "type": "string" - } - ] - } - }, - { - "name": "private", - "optional": true, - "description": "defines if the channel is private or not and if RLS policies will be used to check data", - "type": "boolean" - } - ] - } - } - ], - "name": "RealtimeChannelOptions" - } - }, - { - "name": "presence", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimePresence", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "description": "The realtime channel to bind to.", - "type": { - "kind": "reference", - "name": "RealtimeChannel" - } - }, - { - "name": "state", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "private", - "optional": false, - "type": "boolean" - }, - { - "name": "socket", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimeClient", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "accessToken", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - { - "kind": "object", - "properties": [] - } - ] - } - }, - { - "name": "accessTokenValue", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "apiKey", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "channels", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "reference", - "name": "RealtimeChannel" - } - } - }, - { - "name": "fetch", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "httpEndpoint", - "optional": false, - "type": "string" - }, - { - "name": "logLevel", - "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } - }, - { - "name": "params", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "ref", - "optional": false, - "type": "number" - }, - { - "name": "serializer", - "optional": false, - "type": { - "kind": "reference", - "name": "Serializer" - } - }, - { - "name": "worker", - "optional": true, - "type": "boolean" - }, - { - "name": "workerRef", - "optional": true, - "type": { - "kind": "reference", - "name": "Worker" - } - }, - { - "name": "workerUrl", - "optional": true, - "type": "string" - }, - { - "name": "decode", - "optional": false, - "type": null - }, - { - "name": "encode", - "optional": false, - "type": null - }, - { - "name": "endPoint", - "optional": false, - "type": null - }, - { - "name": "heartbeatCallback", - "optional": false, - "type": null - }, - { - "name": "heartbeatIntervalMs", - "optional": false, - "type": null - }, - { - "name": "heartbeatTimer", - "optional": false, - "type": null - }, - { - "name": "pendingHeartbeatRef", - "optional": false, - "type": null - }, - { - "name": "reconnectAfterMs", - "optional": false, - "type": null - }, - { - "name": "reconnectTimer", - "optional": false, - "type": null - }, - { - "name": "sendBuffer", - "optional": false, - "type": null - }, - { - "name": "stateChangeCallbacks", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "transport", - "optional": false, - "type": null - }, - { - "name": "vsn", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": null - }, - { - "name": "connect", - "optional": false, - "type": null - }, - { - "name": "connectionState", - "optional": false, - "type": null - }, - { - "name": "disconnect", - "optional": false, - "type": null - }, - { - "name": "endpointURL", - "optional": false, - "type": null - }, - { - "name": "getChannels", - "optional": false, - "type": null - }, - { - "name": "isConnected", - "optional": false, - "type": null - }, - { - "name": "isConnecting", - "optional": false, - "type": null - }, - { - "name": "isDisconnecting", - "optional": false, - "type": null - }, - { - "name": "log", - "optional": false, - "type": null - }, - { - "name": "onHeartbeat", - "optional": false, - "type": null - }, - { - "name": "push", - "optional": false, - "type": null - }, - { - "name": "removeAllChannels", - "optional": false, - "type": null - }, - { - "name": "removeChannel", - "optional": false, - "type": null - }, - { - "name": "sendHeartbeat", - "optional": false, - "type": null - }, - { - "name": "setAuth", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "subTopic", - "optional": false, - "type": "string" - }, - { - "name": "topic", - "optional": false, - "description": "Topic name can be any string.", - "type": "string" - }, - { - "name": "joinedOnce", - "optional": false, - "type": null - }, - { - "name": "joinPush", - "optional": false, - "type": null - }, - { - "name": "rejoinTimer", - "optional": false, - "type": null - }, - { - "name": "state", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "copyBindings", - "optional": false, - "type": null - }, - { - "name": "httpSend", - "optional": false, - "type": null - }, - { - "name": "on", - "optional": false, - "description": "Listen to realtime events on this channel.", - "type": null - }, - { - "name": "presenceState", - "optional": false, - "type": null - }, - { - "name": "send", - "optional": false, - "type": null - }, - { - "name": "subscribe", - "optional": false, - "type": null - }, - { - "name": "teardown", - "optional": false, - "type": null - }, - { - "name": "track", - "optional": false, - "type": null - }, - { - "name": "unsubscribe", - "optional": false, - "type": null - }, - { - "name": "untrack", - "optional": false, - "type": null - }, - { - "name": "updateJoinPayload", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "opts", - "optional": true, - "description": "Optional custom event names, e.g. `{ events: { state: 'state', diff: 'diff' } }`.", - "type": { - "kind": "reference", - "name": "RealtimePresenceOptions" - } - } - ], - "returnType": { - "kind": "object", - "name": "RealtimePresence", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "description": "The realtime channel to bind to.", - "type": { - "kind": "object", - "name": "RealtimeChannel", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "bindings", - "optional": false, - "type": { - "kind": "reference", - "name": "Record", - "typeArguments": [ - "string", - { - "kind": "array", - "elementType": { - "kind": "reference", - "name": "Binding" - } - } - ] - } - }, - { - "name": "broadcastEndpointURL", - "optional": false, - "type": "string" - }, - { - "name": "params", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "config", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "broadcast", - "optional": true, - "description": "self option enables client to receive message it broadcast ack option instructs server to acknowledge that broadcast message was received replay option instructs server to replay broadcast messages", - "type": { - "kind": "object", - "properties": [ - { - "name": "ack", - "optional": true, - "type": "boolean" - }, - { - "name": "replay", - "optional": true, - "type": { - "kind": "reference", - "name": "ReplayOption" - } - }, - { - "name": "self", - "optional": true, - "type": "boolean" - } - ] - } - }, - { - "name": "presence", - "optional": true, - "description": "key option is used to track presence payload across clients", - "type": { - "kind": "object", - "properties": [ - { - "name": "enabled", - "optional": true, - "type": "boolean" - }, - { - "name": "key", - "optional": true, - "type": "string" - } - ] - } - }, - { - "name": "private", - "optional": true, - "description": "defines if the channel is private or not and if RLS policies will be used to check data", - "type": "boolean" - } - ] - } - } - ], - "name": "RealtimeChannelOptions" - } - }, - { - "name": "presence", - "optional": false, - "type": { - "kind": "reference", - "name": "RealtimePresence" - } - }, - { - "name": "private", - "optional": false, - "type": "boolean" - }, - { - "name": "socket", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimeClient", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "accessToken", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - { - "kind": "object", - "properties": [] - } - ] - } - }, - { - "name": "accessTokenValue", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "apiKey", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "channels", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "reference", - "name": "RealtimeChannel" - } - } - }, - { - "name": "fetch", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "httpEndpoint", - "optional": false, - "type": "string" - }, - { - "name": "logLevel", - "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } - }, - { - "name": "params", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "ref", - "optional": false, - "type": "number" - }, - { - "name": "serializer", - "optional": false, - "type": { - "kind": "reference", - "name": "Serializer" - } - }, - { - "name": "worker", - "optional": true, - "type": "boolean" - }, - { - "name": "workerRef", - "optional": true, - "type": { - "kind": "reference", - "name": "Worker" - } - }, - { - "name": "workerUrl", - "optional": true, - "type": "string" - }, - { - "name": "decode", - "optional": false, - "type": null - }, - { - "name": "encode", - "optional": false, - "type": null - }, - { - "name": "endPoint", - "optional": false, - "type": null - }, - { - "name": "heartbeatCallback", - "optional": false, - "type": null - }, - { - "name": "heartbeatIntervalMs", - "optional": false, - "type": null - }, - { - "name": "heartbeatTimer", - "optional": false, - "type": null - }, - { - "name": "pendingHeartbeatRef", - "optional": false, - "type": null - }, - { - "name": "reconnectAfterMs", - "optional": false, - "type": null - }, - { - "name": "reconnectTimer", - "optional": false, - "type": null - }, - { - "name": "sendBuffer", - "optional": false, - "type": null - }, - { - "name": "stateChangeCallbacks", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "transport", - "optional": false, - "type": null - }, - { - "name": "vsn", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": null - }, - { - "name": "connect", - "optional": false, - "type": null - }, - { - "name": "connectionState", - "optional": false, - "type": null - }, - { - "name": "disconnect", - "optional": false, - "type": null - }, - { - "name": "endpointURL", - "optional": false, - "type": null - }, - { - "name": "getChannels", - "optional": false, - "type": null - }, - { - "name": "isConnected", - "optional": false, - "type": null - }, - { - "name": "isConnecting", - "optional": false, - "type": null - }, - { - "name": "isDisconnecting", - "optional": false, - "type": null - }, - { - "name": "log", - "optional": false, - "type": null - }, - { - "name": "onHeartbeat", - "optional": false, - "type": null - }, - { - "name": "push", - "optional": false, - "type": null - }, - { - "name": "removeAllChannels", - "optional": false, - "type": null - }, - { - "name": "removeChannel", - "optional": false, - "type": null - }, - { - "name": "sendHeartbeat", - "optional": false, - "type": null - }, - { - "name": "setAuth", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "subTopic", - "optional": false, - "type": "string" - }, - { - "name": "topic", - "optional": false, - "description": "Topic name can be any string.", - "type": "string" - }, - { - "name": "joinedOnce", - "optional": false, - "type": null - }, - { - "name": "joinPush", - "optional": false, - "type": null - }, - { - "name": "rejoinTimer", - "optional": false, - "type": null - }, - { - "name": "state", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "copyBindings", - "optional": false, - "type": null - }, - { - "name": "httpSend", - "optional": false, - "type": null - }, - { - "name": "on", - "optional": false, - "description": "Listen to realtime events on this channel.", - "type": null - }, - { - "name": "presenceState", - "optional": false, - "type": null - }, - { - "name": "send", - "optional": false, - "type": null - }, - { - "name": "subscribe", - "optional": false, - "type": null - }, - { - "name": "teardown", - "optional": false, - "type": null - }, - { - "name": "track", - "optional": false, - "type": null - }, - { - "name": "unsubscribe", - "optional": false, - "type": null - }, - { - "name": "untrack", - "optional": false, - "type": null - }, - { - "name": "updateJoinPayload", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "state", - "optional": false, - "type": null - } - ] - }, - "examples": [ - { - "title": "Example for a presence channel", - "code": "const presence = new RealtimePresence(channel)\n\nchannel.on('presence', ({ event, key }) => {\n console.log(`Presence ${event} on ${key}`)\n})" - } - ] - }, { "name": "getWebSocketConstructor", "description": "Returns the best available WebSocket constructor for the current runtime.", @@ -60757,1144 +56755,6 @@ } ] }, - { - "name": "constructor", - "description": "Creates a channel that can broadcast messages, sync presence, and listen to Postgres changes.\nThe topic determines which realtime stream you are subscribing to. Config options let you enable acknowledgement for broadcasts, presence tracking, or private channels.", - "parameters": [ - { - "name": "topic", - "description": "Topic name can be any string.", - "type": "string" - }, - { - "name": "params", - "type": { - "kind": "union", - "types": [ - "undefined", - { - "kind": "object", - "properties": [ - { - "name": "config", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "broadcast", - "optional": true, - "description": "self option enables client to receive message it broadcast ack option instructs server to acknowledge that broadcast message was received replay option instructs server to replay broadcast messages", - "type": { - "kind": "object", - "properties": [ - { - "name": "ack", - "optional": true, - "type": "boolean" - }, - { - "name": "replay", - "optional": true, - "type": { - "kind": "reference", - "name": "ReplayOption" - } - }, - { - "name": "self", - "optional": true, - "type": "boolean" - } - ] - } - }, - { - "name": "presence", - "optional": true, - "description": "key option is used to track presence payload across clients", - "type": { - "kind": "object", - "properties": [ - { - "name": "enabled", - "optional": true, - "type": "boolean" - }, - { - "name": "key", - "optional": true, - "type": "string" - } - ] - } - }, - { - "name": "private", - "optional": true, - "description": "defines if the channel is private or not and if RLS policies will be used to check data", - "type": "boolean" - } - ] - } - } - ], - "name": "RealtimeChannelOptions" - } - ] - } - }, - { - "name": "socket", - "type": { - "kind": "object", - "name": "RealtimeClient", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "accessToken", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - { - "kind": "object", - "properties": [] - } - ] - } - }, - { - "name": "accessTokenValue", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "apiKey", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "channels", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "RealtimeChannel", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "bindings", - "optional": false, - "type": { - "kind": "reference", - "name": "Record", - "typeArguments": [ - "string", - { - "kind": "array", - "elementType": { - "kind": "reference", - "name": "Binding" - } - } - ] - } - }, - { - "name": "broadcastEndpointURL", - "optional": false, - "type": "string" - }, - { - "name": "params", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "config", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "broadcast", - "optional": true, - "description": "self option enables client to receive message it broadcast ack option instructs server to acknowledge that broadcast message was received replay option instructs server to replay broadcast messages", - "type": { - "kind": "object", - "properties": [ - { - "name": "ack", - "optional": true, - "type": "boolean" - }, - { - "name": "replay", - "optional": true, - "type": { - "kind": "reference", - "name": "ReplayOption" - } - }, - { - "name": "self", - "optional": true, - "type": "boolean" - } - ] - } - }, - { - "name": "presence", - "optional": true, - "description": "key option is used to track presence payload across clients", - "type": { - "kind": "object", - "properties": [ - { - "name": "enabled", - "optional": true, - "type": "boolean" - }, - { - "name": "key", - "optional": true, - "type": "string" - } - ] - } - }, - { - "name": "private", - "optional": true, - "description": "defines if the channel is private or not and if RLS policies will be used to check data", - "type": "boolean" - } - ] - } - } - ], - "name": "RealtimeChannelOptions" - } - }, - { - "name": "presence", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimePresence", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": { - "kind": "reference", - "name": "RealtimeChannel" - } - }, - { - "name": "state", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "private", - "optional": false, - "type": "boolean" - }, - { - "name": "socket", - "optional": false, - "type": { - "kind": "reference", - "name": "RealtimeClient" - } - }, - { - "name": "subTopic", - "optional": false, - "type": "string" - }, - { - "name": "topic", - "optional": false, - "description": "Topic name can be any string.", - "type": "string" - }, - { - "name": "joinedOnce", - "optional": false, - "type": null - }, - { - "name": "joinPush", - "optional": false, - "type": null - }, - { - "name": "rejoinTimer", - "optional": false, - "type": null - }, - { - "name": "state", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "copyBindings", - "optional": false, - "type": null - }, - { - "name": "httpSend", - "optional": false, - "type": null - }, - { - "name": "on", - "optional": false, - "type": null - }, - { - "name": "presenceState", - "optional": false, - "type": null - }, - { - "name": "send", - "optional": false, - "type": null - }, - { - "name": "subscribe", - "optional": false, - "type": null - }, - { - "name": "teardown", - "optional": false, - "type": null - }, - { - "name": "track", - "optional": false, - "type": null - }, - { - "name": "unsubscribe", - "optional": false, - "type": null - }, - { - "name": "untrack", - "optional": false, - "type": null - }, - { - "name": "updateJoinPayload", - "optional": false, - "type": null - } - ] - } - } - }, - { - "name": "fetch", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "httpEndpoint", - "optional": false, - "type": "string" - }, - { - "name": "logLevel", - "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } - }, - { - "name": "params", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "ref", - "optional": false, - "type": "number" - }, - { - "name": "serializer", - "optional": false, - "type": { - "kind": "reference", - "name": "Serializer" - } - }, - { - "name": "worker", - "optional": true, - "type": "boolean" - }, - { - "name": "workerRef", - "optional": true, - "type": { - "kind": "reference", - "name": "Worker" - } - }, - { - "name": "workerUrl", - "optional": true, - "type": "string" - }, - { - "name": "decode", - "optional": false, - "type": null - }, - { - "name": "encode", - "optional": false, - "type": null - }, - { - "name": "endPoint", - "optional": false, - "type": null - }, - { - "name": "heartbeatCallback", - "optional": false, - "type": null - }, - { - "name": "heartbeatIntervalMs", - "optional": false, - "type": null - }, - { - "name": "heartbeatTimer", - "optional": false, - "type": null - }, - { - "name": "pendingHeartbeatRef", - "optional": false, - "type": null - }, - { - "name": "reconnectAfterMs", - "optional": false, - "type": null - }, - { - "name": "reconnectTimer", - "optional": false, - "type": null - }, - { - "name": "sendBuffer", - "optional": false, - "type": null - }, - { - "name": "stateChangeCallbacks", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "transport", - "optional": false, - "type": null - }, - { - "name": "vsn", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": null - }, - { - "name": "connect", - "optional": false, - "type": null - }, - { - "name": "connectionState", - "optional": false, - "type": null - }, - { - "name": "disconnect", - "optional": false, - "type": null - }, - { - "name": "endpointURL", - "optional": false, - "type": null - }, - { - "name": "getChannels", - "optional": false, - "type": null - }, - { - "name": "isConnected", - "optional": false, - "type": null - }, - { - "name": "isConnecting", - "optional": false, - "type": null - }, - { - "name": "isDisconnecting", - "optional": false, - "type": null - }, - { - "name": "log", - "optional": false, - "type": null - }, - { - "name": "onHeartbeat", - "optional": false, - "type": null - }, - { - "name": "push", - "optional": false, - "type": null - }, - { - "name": "removeAllChannels", - "optional": false, - "type": null - }, - { - "name": "removeChannel", - "optional": false, - "type": null - }, - { - "name": "sendHeartbeat", - "optional": false, - "type": null - }, - { - "name": "setAuth", - "optional": false, - "type": null - } - ] - } - } - ], - "returnType": { - "kind": "object", - "name": "RealtimeChannel", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "bindings", - "optional": false, - "type": { - "kind": "reference", - "name": "Record", - "typeArguments": [ - "string", - { - "kind": "array", - "elementType": { - "kind": "reference", - "name": "Binding" - } - } - ] - } - }, - { - "name": "broadcastEndpointURL", - "optional": false, - "type": "string" - }, - { - "name": "params", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "config", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "broadcast", - "optional": true, - "description": "self option enables client to receive message it broadcast ack option instructs server to acknowledge that broadcast message was received replay option instructs server to replay broadcast messages", - "type": { - "kind": "object", - "properties": [ - { - "name": "ack", - "optional": true, - "type": "boolean" - }, - { - "name": "replay", - "optional": true, - "type": { - "kind": "reference", - "name": "ReplayOption" - } - }, - { - "name": "self", - "optional": true, - "type": "boolean" - } - ] - } - }, - { - "name": "presence", - "optional": true, - "description": "key option is used to track presence payload across clients", - "type": { - "kind": "object", - "properties": [ - { - "name": "enabled", - "optional": true, - "type": "boolean" - }, - { - "name": "key", - "optional": true, - "type": "string" - } - ] - } - }, - { - "name": "private", - "optional": true, - "description": "defines if the channel is private or not and if RLS policies will be used to check data", - "type": "boolean" - } - ] - } - } - ], - "name": "RealtimeChannelOptions" - } - }, - { - "name": "presence", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimePresence", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": { - "kind": "reference", - "name": "RealtimeChannel" - } - }, - { - "name": "state", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "private", - "optional": false, - "type": "boolean" - }, - { - "name": "socket", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimeClient", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "accessToken", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - { - "kind": "object", - "properties": [] - } - ] - } - }, - { - "name": "accessTokenValue", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "apiKey", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "channels", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "reference", - "name": "RealtimeChannel" - } - } - }, - { - "name": "fetch", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "httpEndpoint", - "optional": false, - "type": "string" - }, - { - "name": "logLevel", - "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } - }, - { - "name": "params", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "ref", - "optional": false, - "type": "number" - }, - { - "name": "serializer", - "optional": false, - "type": { - "kind": "reference", - "name": "Serializer" - } - }, - { - "name": "worker", - "optional": true, - "type": "boolean" - }, - { - "name": "workerRef", - "optional": true, - "type": { - "kind": "reference", - "name": "Worker" - } - }, - { - "name": "workerUrl", - "optional": true, - "type": "string" - }, - { - "name": "decode", - "optional": false, - "type": null - }, - { - "name": "encode", - "optional": false, - "type": null - }, - { - "name": "endPoint", - "optional": false, - "type": null - }, - { - "name": "heartbeatCallback", - "optional": false, - "type": null - }, - { - "name": "heartbeatIntervalMs", - "optional": false, - "type": null - }, - { - "name": "heartbeatTimer", - "optional": false, - "type": null - }, - { - "name": "pendingHeartbeatRef", - "optional": false, - "type": null - }, - { - "name": "reconnectAfterMs", - "optional": false, - "type": null - }, - { - "name": "reconnectTimer", - "optional": false, - "type": null - }, - { - "name": "sendBuffer", - "optional": false, - "type": null - }, - { - "name": "stateChangeCallbacks", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "transport", - "optional": false, - "type": null - }, - { - "name": "vsn", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": null - }, - { - "name": "connect", - "optional": false, - "type": null - }, - { - "name": "connectionState", - "optional": false, - "type": null - }, - { - "name": "disconnect", - "optional": false, - "type": null - }, - { - "name": "endpointURL", - "optional": false, - "type": null - }, - { - "name": "getChannels", - "optional": false, - "type": null - }, - { - "name": "isConnected", - "optional": false, - "type": null - }, - { - "name": "isConnecting", - "optional": false, - "type": null - }, - { - "name": "isDisconnecting", - "optional": false, - "type": null - }, - { - "name": "log", - "optional": false, - "type": null - }, - { - "name": "onHeartbeat", - "optional": false, - "type": null - }, - { - "name": "push", - "optional": false, - "type": null - }, - { - "name": "removeAllChannels", - "optional": false, - "type": null - }, - { - "name": "removeChannel", - "optional": false, - "type": null - }, - { - "name": "sendHeartbeat", - "optional": false, - "type": null - }, - { - "name": "setAuth", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "subTopic", - "optional": false, - "type": "string" - }, - { - "name": "topic", - "optional": false, - "description": "Topic name can be any string.", - "type": "string" - }, - { - "name": "joinedOnce", - "optional": false, - "type": null - }, - { - "name": "joinPush", - "optional": false, - "type": null - }, - { - "name": "rejoinTimer", - "optional": false, - "type": null - }, - { - "name": "state", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "copyBindings", - "optional": false, - "type": null - }, - { - "name": "httpSend", - "optional": false, - "type": null - }, - { - "name": "on", - "optional": false, - "type": null - }, - { - "name": "presenceState", - "optional": false, - "type": null - }, - { - "name": "send", - "optional": false, - "type": null - }, - { - "name": "subscribe", - "optional": false, - "type": null - }, - { - "name": "teardown", - "optional": false, - "type": null - }, - { - "name": "track", - "optional": false, - "type": null - }, - { - "name": "unsubscribe", - "optional": false, - "type": null - }, - { - "name": "untrack", - "optional": false, - "type": null - }, - { - "name": "updateJoinPayload", - "optional": false, - "type": null - } - ] - }, - "examples": [ - { - "title": "Example for a public channel", - "code": "import RealtimeClient from '@supabase/realtime-js'\n\nconst client = new RealtimeClient('https://xyzcompany.supabase.co/realtime/v1', {\n params: { apikey: 'public-anon-key' },\n})\nconst channel = new RealtimeChannel('realtime:public:messages', { config: {} }, client)" - } - ] - }, { "name": "httpSend", "description": "Sends a broadcast message explicitly via REST API.\nThis method always uses the REST API endpoint regardless of WebSocket connection state. Useful when you want to guarantee REST delivery or when gradually migrating from implicit REST fallback.", @@ -62747,689 +57607,15 @@ "type": { "kind": "reference", "name": "Record", - "typeArguments": ["string", "any"] + "typeArguments": [ + "string", + "any" + ] } } ], "returnType": "void" }, - { - "name": "constructor", - "description": "Initializes the Socket.", - "parameters": [ - { - "name": "endPoint", - "description": "The string WebSocket endpoint, ie, \"ws://example.com/socket\", \"wss://example.com\", \"/socket\" (inherited host & protocol)", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "accessToken", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "decode", - "optional": true, - "type": { - "kind": "reference", - "name": "Decode", - "typeArguments": ["void"] - } - }, - { - "name": "encode", - "optional": true, - "type": { - "kind": "reference", - "name": "Encode", - "typeArguments": ["void"] - } - }, - { - "name": "fetch", - "optional": true, - "type": { - "kind": "reference", - "name": "Fetch" - } - }, - { - "name": "headers", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "heartbeatCallback", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "heartbeatIntervalMs", - "optional": true, - "type": "number" - }, - { - "name": "log_level", - "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } - }, - { - "name": "logger", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "logLevel", - "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } - }, - { - "name": "params", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "reconnectAfterMs", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "timeout", - "optional": true, - "type": "number" - }, - { - "name": "transport", - "optional": true, - "type": { - "kind": "object", - "name": "WebSocketLikeConstructor", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "vsn", - "optional": true, - "type": "string" - }, - { - "name": "worker", - "optional": true, - "type": "boolean" - }, - { - "name": "workerUrl", - "optional": true, - "type": "string" - } - ], - "name": "RealtimeClientOptions" - } - } - ], - "returnType": { - "kind": "object", - "name": "RealtimeClient", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "accessToken", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - { - "kind": "object", - "properties": [] - } - ] - } - }, - { - "name": "accessTokenValue", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "apiKey", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "channels", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "RealtimeChannel", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "bindings", - "optional": false, - "type": { - "kind": "reference", - "name": "Record", - "typeArguments": [ - "string", - { - "kind": "array", - "elementType": { - "kind": "reference", - "name": "Binding" - } - } - ] - } - }, - { - "name": "broadcastEndpointURL", - "optional": false, - "type": "string" - }, - { - "name": "params", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "config", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "broadcast", - "optional": true, - "description": "self option enables client to receive message it broadcast ack option instructs server to acknowledge that broadcast message was received replay option instructs server to replay broadcast messages", - "type": { - "kind": "object", - "properties": [ - { - "name": "ack", - "optional": true, - "type": "boolean" - }, - { - "name": "replay", - "optional": true, - "type": { - "kind": "reference", - "name": "ReplayOption" - } - }, - { - "name": "self", - "optional": true, - "type": "boolean" - } - ] - } - }, - { - "name": "presence", - "optional": true, - "description": "key option is used to track presence payload across clients", - "type": { - "kind": "object", - "properties": [ - { - "name": "enabled", - "optional": true, - "type": "boolean" - }, - { - "name": "key", - "optional": true, - "type": "string" - } - ] - } - }, - { - "name": "private", - "optional": true, - "description": "defines if the channel is private or not and if RLS policies will be used to check data", - "type": "boolean" - } - ] - } - } - ], - "name": "RealtimeChannelOptions" - } - }, - { - "name": "presence", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimePresence", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": { - "kind": "reference", - "name": "RealtimeChannel" - } - }, - { - "name": "state", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "private", - "optional": false, - "type": "boolean" - }, - { - "name": "socket", - "optional": false, - "type": { - "kind": "reference", - "name": "RealtimeClient" - } - }, - { - "name": "subTopic", - "optional": false, - "type": "string" - }, - { - "name": "topic", - "optional": false, - "description": "Topic name can be any string.", - "type": "string" - }, - { - "name": "joinedOnce", - "optional": false, - "type": null - }, - { - "name": "joinPush", - "optional": false, - "type": null - }, - { - "name": "rejoinTimer", - "optional": false, - "type": null - }, - { - "name": "state", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "copyBindings", - "optional": false, - "type": null - }, - { - "name": "httpSend", - "optional": false, - "type": null - }, - { - "name": "on", - "optional": false, - "type": null - }, - { - "name": "presenceState", - "optional": false, - "type": null - }, - { - "name": "send", - "optional": false, - "type": null - }, - { - "name": "subscribe", - "optional": false, - "type": null - }, - { - "name": "teardown", - "optional": false, - "type": null - }, - { - "name": "track", - "optional": false, - "type": null - }, - { - "name": "unsubscribe", - "optional": false, - "type": null - }, - { - "name": "untrack", - "optional": false, - "type": null - }, - { - "name": "updateJoinPayload", - "optional": false, - "type": null - } - ] - } - } - }, - { - "name": "fetch", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "httpEndpoint", - "optional": false, - "type": "string" - }, - { - "name": "logLevel", - "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } - }, - { - "name": "params", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "ref", - "optional": false, - "type": "number" - }, - { - "name": "serializer", - "optional": false, - "type": { - "kind": "reference", - "name": "Serializer" - } - }, - { - "name": "worker", - "optional": true, - "type": "boolean" - }, - { - "name": "workerRef", - "optional": true, - "type": { - "kind": "reference", - "name": "Worker" - } - }, - { - "name": "workerUrl", - "optional": true, - "type": "string" - }, - { - "name": "decode", - "optional": false, - "type": null - }, - { - "name": "encode", - "optional": false, - "type": null - }, - { - "name": "endPoint", - "optional": false, - "type": null - }, - { - "name": "heartbeatCallback", - "optional": false, - "type": null - }, - { - "name": "heartbeatIntervalMs", - "optional": false, - "type": null - }, - { - "name": "heartbeatTimer", - "optional": false, - "type": null - }, - { - "name": "pendingHeartbeatRef", - "optional": false, - "type": null - }, - { - "name": "reconnectAfterMs", - "optional": false, - "type": null - }, - { - "name": "reconnectTimer", - "optional": false, - "type": null - }, - { - "name": "sendBuffer", - "optional": false, - "type": null - }, - { - "name": "stateChangeCallbacks", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "transport", - "optional": false, - "type": null - }, - { - "name": "vsn", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": null - }, - { - "name": "connect", - "optional": false, - "type": null - }, - { - "name": "connectionState", - "optional": false, - "type": null - }, - { - "name": "disconnect", - "optional": false, - "type": null - }, - { - "name": "endpointURL", - "optional": false, - "type": null - }, - { - "name": "getChannels", - "optional": false, - "type": null - }, - { - "name": "isConnected", - "optional": false, - "type": null - }, - { - "name": "isConnecting", - "optional": false, - "type": null - }, - { - "name": "isDisconnecting", - "optional": false, - "type": null - }, - { - "name": "log", - "optional": false, - "type": null - }, - { - "name": "onHeartbeat", - "optional": false, - "type": null - }, - { - "name": "push", - "optional": false, - "type": null - }, - { - "name": "removeAllChannels", - "optional": false, - "type": null - }, - { - "name": "removeChannel", - "optional": false, - "type": null - }, - { - "name": "sendHeartbeat", - "optional": false, - "type": null - }, - { - "name": "setAuth", - "optional": false, - "type": null - } - ] - }, - "examples": [ - { - "title": "Example for a public channel", - "code": "import RealtimeClient from '@supabase/realtime-js'\n\nconst client = new RealtimeClient('https://xyzcompany.supabase.co/realtime/v1', {\n params: { apikey: 'public-anon-key' },\n})\nclient.connect()" - } - ] - }, { "name": "channel", "description": "Creates (or reuses) a RealtimeChannel for the provided topic.\nTopics are automatically prefixed with `realtime:` to match the Realtime service. If a channel with the same topic already exists it will be returned instead of creating a duplicate connection.", @@ -65303,7 +59489,9 @@ "returnType": { "kind": "reference", "name": "Promise", - "typeArguments": ["void"] + "typeArguments": [ + "void" + ] } }, { @@ -65329,7 +59517,9 @@ "returnType": { "kind": "reference", "name": "Promise", - "typeArguments": ["void"] + "typeArguments": [ + "void" + ] }, "examples": [ { @@ -65338,1071 +59528,6 @@ } ] }, - { - "name": "constructor", - "description": "Creates a Presence helper that keeps the local presence state in sync with the server.", - "parameters": [ - { - "name": "channel", - "description": "The realtime channel to bind to.", - "type": { - "kind": "object", - "name": "RealtimeChannel", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "bindings", - "optional": false, - "type": { - "kind": "reference", - "name": "Record", - "typeArguments": [ - "string", - { - "kind": "array", - "elementType": { - "kind": "reference", - "name": "Binding" - } - } - ] - } - }, - { - "name": "broadcastEndpointURL", - "optional": false, - "type": "string" - }, - { - "name": "params", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "config", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "broadcast", - "optional": true, - "description": "self option enables client to receive message it broadcast ack option instructs server to acknowledge that broadcast message was received replay option instructs server to replay broadcast messages", - "type": { - "kind": "object", - "properties": [ - { - "name": "ack", - "optional": true, - "type": "boolean" - }, - { - "name": "replay", - "optional": true, - "type": { - "kind": "reference", - "name": "ReplayOption" - } - }, - { - "name": "self", - "optional": true, - "type": "boolean" - } - ] - } - }, - { - "name": "presence", - "optional": true, - "description": "key option is used to track presence payload across clients", - "type": { - "kind": "object", - "properties": [ - { - "name": "enabled", - "optional": true, - "type": "boolean" - }, - { - "name": "key", - "optional": true, - "type": "string" - } - ] - } - }, - { - "name": "private", - "optional": true, - "description": "defines if the channel is private or not and if RLS policies will be used to check data", - "type": "boolean" - } - ] - } - } - ], - "name": "RealtimeChannelOptions" - } - }, - { - "name": "presence", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimePresence", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": { - "kind": "reference", - "name": "RealtimeChannel" - } - }, - { - "name": "state", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "private", - "optional": false, - "type": "boolean" - }, - { - "name": "socket", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimeClient", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "accessToken", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - { - "kind": "object", - "properties": [] - } - ] - } - }, - { - "name": "accessTokenValue", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "apiKey", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "channels", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "reference", - "name": "RealtimeChannel" - } - } - }, - { - "name": "fetch", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "httpEndpoint", - "optional": false, - "type": "string" - }, - { - "name": "logLevel", - "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } - }, - { - "name": "params", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "ref", - "optional": false, - "type": "number" - }, - { - "name": "serializer", - "optional": false, - "type": { - "kind": "reference", - "name": "Serializer" - } - }, - { - "name": "worker", - "optional": true, - "type": "boolean" - }, - { - "name": "workerRef", - "optional": true, - "type": { - "kind": "reference", - "name": "Worker" - } - }, - { - "name": "workerUrl", - "optional": true, - "type": "string" - }, - { - "name": "decode", - "optional": false, - "type": null - }, - { - "name": "encode", - "optional": false, - "type": null - }, - { - "name": "endPoint", - "optional": false, - "type": null - }, - { - "name": "heartbeatCallback", - "optional": false, - "type": null - }, - { - "name": "heartbeatIntervalMs", - "optional": false, - "type": null - }, - { - "name": "heartbeatTimer", - "optional": false, - "type": null - }, - { - "name": "pendingHeartbeatRef", - "optional": false, - "type": null - }, - { - "name": "reconnectAfterMs", - "optional": false, - "type": null - }, - { - "name": "reconnectTimer", - "optional": false, - "type": null - }, - { - "name": "sendBuffer", - "optional": false, - "type": null - }, - { - "name": "stateChangeCallbacks", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "transport", - "optional": false, - "type": null - }, - { - "name": "vsn", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": null - }, - { - "name": "connect", - "optional": false, - "type": null - }, - { - "name": "connectionState", - "optional": false, - "type": null - }, - { - "name": "disconnect", - "optional": false, - "type": null - }, - { - "name": "endpointURL", - "optional": false, - "type": null - }, - { - "name": "getChannels", - "optional": false, - "type": null - }, - { - "name": "isConnected", - "optional": false, - "type": null - }, - { - "name": "isConnecting", - "optional": false, - "type": null - }, - { - "name": "isDisconnecting", - "optional": false, - "type": null - }, - { - "name": "log", - "optional": false, - "type": null - }, - { - "name": "onHeartbeat", - "optional": false, - "type": null - }, - { - "name": "push", - "optional": false, - "type": null - }, - { - "name": "removeAllChannels", - "optional": false, - "type": null - }, - { - "name": "removeChannel", - "optional": false, - "type": null - }, - { - "name": "sendHeartbeat", - "optional": false, - "type": null - }, - { - "name": "setAuth", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "subTopic", - "optional": false, - "type": "string" - }, - { - "name": "topic", - "optional": false, - "description": "Topic name can be any string.", - "type": "string" - }, - { - "name": "joinedOnce", - "optional": false, - "type": null - }, - { - "name": "joinPush", - "optional": false, - "type": null - }, - { - "name": "rejoinTimer", - "optional": false, - "type": null - }, - { - "name": "state", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "copyBindings", - "optional": false, - "type": null - }, - { - "name": "httpSend", - "optional": false, - "type": null - }, - { - "name": "on", - "optional": false, - "type": null - }, - { - "name": "presenceState", - "optional": false, - "type": null - }, - { - "name": "send", - "optional": false, - "type": null - }, - { - "name": "subscribe", - "optional": false, - "type": null - }, - { - "name": "teardown", - "optional": false, - "type": null - }, - { - "name": "track", - "optional": false, - "type": null - }, - { - "name": "unsubscribe", - "optional": false, - "type": null - }, - { - "name": "untrack", - "optional": false, - "type": null - }, - { - "name": "updateJoinPayload", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "opts", - "optional": true, - "description": "Optional custom event names, e.g. `{ events: { state: 'state', diff: 'diff' } }`.", - "type": { - "kind": "reference", - "name": "RealtimePresenceOptions" - } - } - ], - "returnType": { - "kind": "object", - "name": "RealtimePresence", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimeChannel", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "bindings", - "optional": false, - "type": { - "kind": "reference", - "name": "Record", - "typeArguments": [ - "string", - { - "kind": "array", - "elementType": { - "kind": "reference", - "name": "Binding" - } - } - ] - } - }, - { - "name": "broadcastEndpointURL", - "optional": false, - "type": "string" - }, - { - "name": "params", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "config", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "broadcast", - "optional": true, - "description": "self option enables client to receive message it broadcast ack option instructs server to acknowledge that broadcast message was received replay option instructs server to replay broadcast messages", - "type": { - "kind": "object", - "properties": [ - { - "name": "ack", - "optional": true, - "type": "boolean" - }, - { - "name": "replay", - "optional": true, - "type": { - "kind": "reference", - "name": "ReplayOption" - } - }, - { - "name": "self", - "optional": true, - "type": "boolean" - } - ] - } - }, - { - "name": "presence", - "optional": true, - "description": "key option is used to track presence payload across clients", - "type": { - "kind": "object", - "properties": [ - { - "name": "enabled", - "optional": true, - "type": "boolean" - }, - { - "name": "key", - "optional": true, - "type": "string" - } - ] - } - }, - { - "name": "private", - "optional": true, - "description": "defines if the channel is private or not and if RLS policies will be used to check data", - "type": "boolean" - } - ] - } - } - ], - "name": "RealtimeChannelOptions" - } - }, - { - "name": "presence", - "optional": false, - "type": { - "kind": "reference", - "name": "RealtimePresence" - } - }, - { - "name": "private", - "optional": false, - "type": "boolean" - }, - { - "name": "socket", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimeClient", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "accessToken", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - { - "kind": "object", - "properties": [] - } - ] - } - }, - { - "name": "accessTokenValue", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "apiKey", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "channels", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "reference", - "name": "RealtimeChannel" - } - } - }, - { - "name": "fetch", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "httpEndpoint", - "optional": false, - "type": "string" - }, - { - "name": "logLevel", - "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } - }, - { - "name": "params", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "ref", - "optional": false, - "type": "number" - }, - { - "name": "serializer", - "optional": false, - "type": { - "kind": "reference", - "name": "Serializer" - } - }, - { - "name": "worker", - "optional": true, - "type": "boolean" - }, - { - "name": "workerRef", - "optional": true, - "type": { - "kind": "reference", - "name": "Worker" - } - }, - { - "name": "workerUrl", - "optional": true, - "type": "string" - }, - { - "name": "decode", - "optional": false, - "type": null - }, - { - "name": "encode", - "optional": false, - "type": null - }, - { - "name": "endPoint", - "optional": false, - "type": null - }, - { - "name": "heartbeatCallback", - "optional": false, - "type": null - }, - { - "name": "heartbeatIntervalMs", - "optional": false, - "type": null - }, - { - "name": "heartbeatTimer", - "optional": false, - "type": null - }, - { - "name": "pendingHeartbeatRef", - "optional": false, - "type": null - }, - { - "name": "reconnectAfterMs", - "optional": false, - "type": null - }, - { - "name": "reconnectTimer", - "optional": false, - "type": null - }, - { - "name": "sendBuffer", - "optional": false, - "type": null - }, - { - "name": "stateChangeCallbacks", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "transport", - "optional": false, - "type": null - }, - { - "name": "vsn", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": null - }, - { - "name": "connect", - "optional": false, - "type": null - }, - { - "name": "connectionState", - "optional": false, - "type": null - }, - { - "name": "disconnect", - "optional": false, - "type": null - }, - { - "name": "endpointURL", - "optional": false, - "type": null - }, - { - "name": "getChannels", - "optional": false, - "type": null - }, - { - "name": "isConnected", - "optional": false, - "type": null - }, - { - "name": "isConnecting", - "optional": false, - "type": null - }, - { - "name": "isDisconnecting", - "optional": false, - "type": null - }, - { - "name": "log", - "optional": false, - "type": null - }, - { - "name": "onHeartbeat", - "optional": false, - "type": null - }, - { - "name": "push", - "optional": false, - "type": null - }, - { - "name": "removeAllChannels", - "optional": false, - "type": null - }, - { - "name": "removeChannel", - "optional": false, - "type": null - }, - { - "name": "sendHeartbeat", - "optional": false, - "type": null - }, - { - "name": "setAuth", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "subTopic", - "optional": false, - "type": "string" - }, - { - "name": "topic", - "optional": false, - "description": "Topic name can be any string.", - "type": "string" - }, - { - "name": "joinedOnce", - "optional": false, - "type": null - }, - { - "name": "joinPush", - "optional": false, - "type": null - }, - { - "name": "rejoinTimer", - "optional": false, - "type": null - }, - { - "name": "state", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "copyBindings", - "optional": false, - "type": null - }, - { - "name": "httpSend", - "optional": false, - "type": null - }, - { - "name": "on", - "optional": false, - "type": null - }, - { - "name": "presenceState", - "optional": false, - "type": null - }, - { - "name": "send", - "optional": false, - "type": null - }, - { - "name": "subscribe", - "optional": false, - "type": null - }, - { - "name": "teardown", - "optional": false, - "type": null - }, - { - "name": "track", - "optional": false, - "type": null - }, - { - "name": "unsubscribe", - "optional": false, - "type": null - }, - { - "name": "untrack", - "optional": false, - "type": null - }, - { - "name": "updateJoinPayload", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "state", - "optional": false, - "type": null - } - ] - }, - "examples": [ - { - "title": "Example for a presence channel", - "code": "const presence = new RealtimePresence(channel)\n\nchannel.on('presence', ({ event, key }) => {\n console.log(`Presence ${event} on ${key}`)\n})" - } - ] - }, { "name": "getWebSocketConstructor", "description": "Returns the best available WebSocket constructor for the current runtime.", @@ -66435,118 +59560,6 @@ { "category": "File Buckets", "definitions": [ - { - "name": "constructor", - "description": "Creates a client for Storage buckets, files, analytics, and vectors.", - "parameters": [ - { - "name": "url", - "type": "string" - }, - { - "name": "headers", - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "fetch", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "opts", - "optional": true, - "type": { - "kind": "object", - "name": "StorageClientOptions", - "properties": [ - { - "name": "useNewHostname", - "optional": true, - "type": "boolean" - } - ] - } - } - ], - "returnType": { - "kind": "object", - "name": "StorageClient", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "analytics", - "optional": false, - "type": null - }, - { - "name": "vectors", - "optional": false, - "type": null - }, - { - "name": "createBucket", - "optional": false, - "type": null - }, - { - "name": "deleteBucket", - "optional": false, - "type": null - }, - { - "name": "emptyBucket", - "optional": false, - "type": null - }, - { - "name": "from", - "optional": false, - "type": null - }, - { - "name": "getBucket", - "optional": false, - "type": null - }, - { - "name": "listBuckets", - "optional": false, - "type": null - }, - { - "name": "setHeader", - "optional": false, - "type": null - }, - { - "name": "throwOnError", - "optional": false, - "type": null - }, - { - "name": "updateBucket", - "optional": false, - "type": null - } - ] - }, - "examples": [ - { - "title": "Creating a Storage client", - "code": "import { StorageClient } from '@supabase/storage-js'\n\nconst storage = new StorageClient('https://xyzcompany.supabase.co/storage/v1', {\n apikey: 'public-anon-key',\n})\nconst avatars = storage.from('avatars')" - } - ] - }, { "name": "createBucket", "description": "Creates a new Storage bucket", @@ -66754,7 +59767,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -66762,7 +59778,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -66856,7 +59875,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -66864,7 +59886,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -66958,7 +59983,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -66966,7 +59994,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -67234,7 +60265,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -67242,7 +60276,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -67458,7 +60495,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -67466,7 +60506,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -67612,7 +60655,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -67620,7 +60666,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -67846,7 +60895,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -67854,7 +60906,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -67948,7 +61003,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -67956,7 +61014,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -68050,7 +61111,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -68058,7 +61122,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -68208,7 +61275,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -68216,7 +61286,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -68432,7 +61505,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -68440,7 +61516,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -68586,7 +61665,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -68594,7 +61676,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -68709,7 +61794,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -68717,7 +61805,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -68836,7 +61927,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -68844,7 +61938,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -68892,7 +61989,10 @@ "description": "triggers the file as a download if set to true. Set this parameter as the name of the file if you want to trigger the download with a different filename.", "type": { "kind": "union", - "types": ["string", "boolean"] + "types": [ + "string", + "boolean" + ] } }, { @@ -69021,7 +62121,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -69029,7 +62132,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -69088,7 +62194,10 @@ "description": "triggers the file as a download if set to true. Set this parameter as the name of the file if you want to trigger the download with a different filename.", "type": { "kind": "union", - "types": ["string", "boolean"] + "types": [ + "string", + "boolean" + ] } } ] @@ -69188,7 +62297,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -69196,7 +62308,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -69405,7 +62520,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -69413,7 +62531,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -69456,7 +62577,10 @@ "description": "Triggers the file as a download if set to true. Set this parameter as the name of the file if you want to trigger the download with a different filename.", "type": { "kind": "union", - "types": ["string", "boolean"] + "types": [ + "string", + "boolean" + ] } }, { @@ -69622,7 +62746,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -69630,7 +62757,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -70035,7 +63165,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -70043,7 +63176,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -70412,7 +63548,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -70420,7 +63559,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -70535,7 +63677,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -70543,7 +63688,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -70846,7 +63994,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -70854,7 +64005,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -70988,7 +64142,10 @@ "type": { "kind": "reference", "name": "Record", - "typeArguments": ["string", "string"] + "typeArguments": [ + "string", + "string" + ] } }, { @@ -70998,7 +64155,10 @@ "type": { "kind": "reference", "name": "Record", - "typeArguments": ["string", "any"] + "typeArguments": [ + "string", + "any" + ] } }, { @@ -71083,7 +64243,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -71091,7 +64254,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -71167,7 +64333,10 @@ "type": { "kind": "reference", "name": "Record", - "typeArguments": ["string", "string"] + "typeArguments": [ + "string", + "string" + ] } }, { @@ -71177,7 +64346,10 @@ "type": { "kind": "reference", "name": "Record", - "typeArguments": ["string", "any"] + "typeArguments": [ + "string", + "any" + ] } }, { @@ -71262,7 +64434,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -71270,7 +64445,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -71351,7 +64529,10 @@ "type": { "kind": "reference", "name": "Record", - "typeArguments": ["string", "string"] + "typeArguments": [ + "string", + "string" + ] } }, { @@ -71361,7 +64542,10 @@ "type": { "kind": "reference", "name": "Record", - "typeArguments": ["string", "any"] + "typeArguments": [ + "string", + "any" + ] } }, { @@ -71409,7 +64593,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -71417,7 +64604,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -71473,81 +64663,6 @@ { "category": "Analytics Buckets", "definitions": [ - { - "name": "constructor", - "description": "Creates a new StorageAnalyticsClient instance\n**Public alpha:** This API is part of a public alpha release and may not be available to your account type.", - "parameters": [ - { - "name": "url", - "description": "The base URL for the storage API", - "type": "string" - }, - { - "name": "headers", - "description": "HTTP headers to include in requests", - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "fetch", - "optional": true, - "description": "Optional custom fetch implementation", - "type": { - "kind": "object", - "properties": [] - } - } - ], - "returnType": { - "kind": "object", - "name": "default", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "createBucket", - "optional": false, - "type": null - }, - { - "name": "deleteBucket", - "optional": false, - "type": null - }, - { - "name": "from", - "optional": false, - "type": null - }, - { - "name": "listBuckets", - "optional": false, - "type": null - }, - { - "name": "setHeader", - "optional": false, - "type": null - }, - { - "name": "throwOnError", - "optional": false, - "type": null - } - ] - }, - "examples": [ - { - "title": "Creating a StorageAnalyticsClient instance", - "code": "const client = new StorageAnalyticsClient(url, headers)" - } - ] - }, { "name": "createBucket", "description": "Creates a new analytics bucket using Iceberg tables Analytics buckets are optimized for analytical queries and data processing\n**Public alpha:** This API is part of a public alpha release and may not be available to your account type.", @@ -71652,7 +64767,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -71660,7 +64778,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -71682,7 +64803,9 @@ { "name": "deleteBucket", "description": "Deletes an existing analytics bucket A bucket can't be deleted with existing objects inside it You must first empty the bucket before deletion\n**Public alpha:** This API is part of a public alpha release and may not be available to your account type.", - "remarks": ["- Deletes an analytics bucket"], + "remarks": [ + "- Deletes an analytics bucket" + ], "parameters": [ { "name": "bucketName", @@ -71752,7 +64875,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -71760,7 +64886,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -71984,7 +65113,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -71992,7 +65124,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -72016,96 +65151,6 @@ { "category": "Vector Buckets", "definitions": [ - { - "name": "constructor", - "description": "Creates a StorageVectorsClient that can manage buckets, indexes, and vectors.\n**Public alpha:** This API is part of a public alpha release and may not be available to your account type.", - "parameters": [ - { - "name": "url", - "description": "Base URL of the Storage Vectors REST API.", - "type": "string" - }, - { - "name": "options", - "type": { - "kind": "object", - "name": "StorageVectorsClientOptions", - "properties": [ - { - "name": "fetch", - "optional": true, - "description": "Custom fetch implementation (optional) Useful for testing or custom request handling", - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": true, - "description": "Custom headers to include in all requests", - "type": { - "kind": "object", - "properties": [] - } - } - ] - } - } - ], - "returnType": { - "kind": "object", - "name": "StorageVectorsClient", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "createBucket", - "optional": false, - "type": null - }, - { - "name": "deleteBucket", - "optional": false, - "type": null - }, - { - "name": "from", - "optional": false, - "type": null - }, - { - "name": "getBucket", - "optional": false, - "type": null - }, - { - "name": "listBuckets", - "optional": false, - "type": null - }, - { - "name": "setHeader", - "optional": false, - "type": null - }, - { - "name": "throwOnError", - "optional": false, - "type": null - } - ] - }, - "examples": [ - { - "title": "Creating a StorageVectorsClient instance", - "code": "const client = new StorageVectorsClient(url, options)" - } - ] - }, { "name": "createBucket", "description": "Creates a new vector bucket Vector buckets are containers for vector indexes and their data\n**Public alpha:** This API is part of a public alpha release and may not be available to your account type.", @@ -72178,7 +65223,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -72186,7 +65234,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -72277,7 +65328,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -72285,7 +65339,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -72439,7 +65496,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -72447,7 +65507,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -72561,7 +65624,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -72569,7 +65635,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -72588,87 +65657,6 @@ } ] }, - { - "name": "constructor", - "description": "Creates a helper that automatically scopes all index operations to the provided bucket.\n**Public alpha:** This API is part of a public alpha release and may not be available to your account type.", - "parameters": [ - { - "name": "url", - "type": "string" - }, - { - "name": "headers", - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "vectorBucketName", - "type": "string" - }, - { - "name": "fetch", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - } - ], - "returnType": { - "kind": "object", - "name": "VectorBucketScope", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "createIndex", - "optional": false, - "type": null - }, - { - "name": "deleteIndex", - "optional": false, - "type": null - }, - { - "name": "getIndex", - "optional": false, - "type": null - }, - { - "name": "index", - "optional": false, - "type": null - }, - { - "name": "listIndexes", - "optional": false, - "type": null - }, - { - "name": "setHeader", - "optional": false, - "type": null - }, - { - "name": "throwOnError", - "optional": false, - "type": null - } - ] - }, - "examples": [ - { - "title": "Creating a vector bucket scope", - "code": "const bucket = supabase.storage.vectors.from('embeddings-prod')" - } - ] - }, { "name": "createIndex", "description": "Creates a new vector index in this bucket Convenience method that automatically includes the bucket name\n**Public alpha:** This API is part of a public alpha release and may not be available to your account type.", @@ -72819,7 +65807,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -72827,7 +65818,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -72918,7 +65912,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -72926,7 +65923,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -73017,7 +66017,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -73025,7 +66028,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -73218,7 +66224,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -73226,7 +66235,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -73245,91 +66257,6 @@ } ] }, - { - "name": "constructor", - "description": "Creates a helper that automatically scopes all vector operations to the provided bucket/index names.\n**Public alpha:** This API is part of a public alpha release and may not be available to your account type.", - "parameters": [ - { - "name": "url", - "type": "string" - }, - { - "name": "headers", - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "vectorBucketName", - "type": "string" - }, - { - "name": "indexName", - "type": "string" - }, - { - "name": "fetch", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - } - ], - "returnType": { - "kind": "object", - "name": "VectorIndexScope", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "deleteVectors", - "optional": false, - "type": null - }, - { - "name": "getVectors", - "optional": false, - "type": null - }, - { - "name": "listVectors", - "optional": false, - "type": null - }, - { - "name": "putVectors", - "optional": false, - "type": null - }, - { - "name": "queryVectors", - "optional": false, - "type": null - }, - { - "name": "setHeader", - "optional": false, - "type": null - }, - { - "name": "throwOnError", - "optional": false, - "type": null - } - ] - }, - "examples": [ - { - "title": "Creating a vector index scope", - "code": "const index = supabase.storage.vectors.from('embeddings-prod').index('documents-openai')" - } - ] - }, { "name": "deleteVectors", "description": "Deletes vectors by keys from this index Convenience method that automatically includes bucket and index names\n**Public alpha:** This API is part of a public alpha release and may not be available to your account type.", @@ -73447,7 +66374,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -73455,7 +66385,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -73603,7 +66536,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -73611,7 +66547,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -73774,7 +66713,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -73782,7 +66724,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -73871,7 +66816,10 @@ "type": { "kind": "reference", "name": "Record", - "typeArguments": ["string", "any"] + "typeArguments": [ + "string", + "any" + ] } } ] @@ -73959,7 +66907,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -73967,7 +66918,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -74008,7 +66962,10 @@ "type": { "kind": "reference", "name": "Record", - "typeArguments": ["string", "any"] + "typeArguments": [ + "string", + "any" + ] } }, { @@ -74142,7 +67099,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "number"] + "types": [ + "undefined", + "number" + ] } }, { @@ -74150,7 +67110,10 @@ "optional": false, "type": { "kind": "union", - "types": ["undefined", "string"] + "types": [ + "undefined", + "string" + ] } } ] @@ -74174,1104 +67137,6 @@ { "category": "Initializing", "definitions": [ - { - "name": "constructor", - "description": "Create a new client for use in the browser.", - "parameters": [ - { - "name": "supabaseUrl", - "description": "The unique Supabase URL which is supplied when you create a new project in your project dashboard.", - "type": "string" - }, - { - "name": "supabaseKey", - "description": "The unique Supabase Key which is supplied when you create a new project in your project dashboard.", - "type": "string" - }, - { - "name": "options", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "accessToken", - "optional": true, - "description": "Optional function for using a third-party authentication system with Supabase. The function should return an access token or ID token (JWT) by obtaining it from the third-party auth SDK. Note that this function may be called concurrently and many times. Use memoization and locking techniques if this is not supported by the SDKs.\nWhen set, the `auth` namespace of the Supabase client cannot be used. Create another client if you wish to use Supabase Auth and third-party authentications concurrently in the same application.", - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "auth", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "autoRefreshToken", - "optional": true, - "description": "Automatically refreshes the token for logged-in users. Defaults to true.", - "type": "boolean" - }, - { - "name": "debug", - "optional": true, - "description": "If debug messages for authentication client are emitted. Can be used to inspect the behavior of the library.", - "type": { - "kind": "indexedAccess", - "objectType": { - "kind": "reference", - "name": "SupabaseAuthClientOptions" - }, - "indexType": null - } - }, - { - "name": "detectSessionInUrl", - "optional": true, - "description": "Detect a session from the URL. Used for OAuth login callbacks. Defaults to true.\nCan be set to a function to provide custom logic for determining if a URL contains a Supabase auth callback. The function receives the current URL and parsed parameters, and should return true if the URL should be processed as a Supabase auth callback.\nThis is useful when your app uses other OAuth providers (e.g., Facebook Login) that also return access_token in the URL fragment, which would otherwise be incorrectly intercepted by Supabase Auth.", - "type": { - "kind": "union", - "types": [ - "boolean", - { - "kind": "object", - "properties": [] - } - ] - } - }, - { - "name": "flowType", - "optional": true, - "description": "OAuth flow to use - defaults to implicit flow. PKCE is recommended for mobile and server-side applications.", - "type": { - "kind": "indexedAccess", - "objectType": { - "kind": "reference", - "name": "SupabaseAuthClientOptions" - }, - "indexType": null - } - }, - { - "name": "lock", - "optional": true, - "description": "Provide your own locking mechanism based on the environment. By default no locking is done at this time.", - "type": { - "kind": "indexedAccess", - "objectType": { - "kind": "reference", - "name": "SupabaseAuthClientOptions" - }, - "indexType": null - } - }, - { - "name": "persistSession", - "optional": true, - "description": "Whether to persist a logged-in session to storage. Defaults to true.", - "type": "boolean" - }, - { - "name": "storage", - "optional": true, - "description": "A storage provider. Used to store the logged-in session.", - "type": { - "kind": "indexedAccess", - "objectType": { - "kind": "reference", - "name": "SupabaseAuthClientOptions" - }, - "indexType": null - } - }, - { - "name": "storageKey", - "optional": true, - "description": "Optional key name used for storing tokens in local storage.", - "type": "string" - }, - { - "name": "throwOnError", - "optional": true, - "description": "If there is an error with the query, throwOnError will reject the promise by throwing the error instead of returning it as part of a successful response.", - "type": { - "kind": "indexedAccess", - "objectType": { - "kind": "reference", - "name": "SupabaseAuthClientOptions" - }, - "indexType": null - } - }, - { - "name": "userStorage", - "optional": true, - "description": "A storage provider to store the user profile separately from the session. Useful when you need to store the session information in cookies, without bloating the data with the redundant user object.", - "type": { - "kind": "indexedAccess", - "objectType": { - "kind": "reference", - "name": "SupabaseAuthClientOptions" - }, - "indexType": null - } - } - ] - } - }, - { - "name": "db", - "optional": true, - "description": "The Postgres schema which your tables belong to. Must be on the list of exposed schemas in Supabase. Defaults to `public`.", - "type": { - "kind": "object", - "properties": [ - { - "name": "schema", - "optional": true, - "type": { - "kind": "typeParam", - "name": "SchemaName" - } - }, - { - "name": "timeout", - "optional": true, - "description": "Optional timeout in milliseconds for PostgREST requests. When set, requests will automatically abort after this duration to prevent indefinite hangs.", - "type": "number" - }, - { - "name": "urlLengthLimit", - "optional": true, - "description": "Maximum URL length in characters before warnings/errors are triggered. Defaults to 8000 characters. Used to provide helpful hints when URLs exceed server limits.", - "type": "number" - } - ] - } - }, - { - "name": "global", - "optional": true, - "type": { - "kind": "object", - "properties": [ - { - "name": "fetch", - "optional": true, - "description": "A custom `fetch` implementation.", - "type": { - "kind": "reference", - "name": "Fetch" - } - }, - { - "name": "headers", - "optional": true, - "description": "Optional headers for initializing the client.", - "type": { - "kind": "reference", - "name": "Record", - "typeArguments": ["string", "string"] - } - } - ] - } - }, - { - "name": "realtime", - "optional": true, - "description": "Options passed to the realtime-js instance", - "type": { - "kind": "object", - "properties": [ - { - "name": "accessToken", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "decode", - "optional": true, - "type": { - "kind": "reference", - "name": "Decode", - "typeArguments": ["void"] - } - }, - { - "name": "encode", - "optional": true, - "type": { - "kind": "reference", - "name": "Encode", - "typeArguments": ["void"] - } - }, - { - "name": "fetch", - "optional": true, - "type": { - "kind": "reference", - "name": "Fetch" - } - }, - { - "name": "headers", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "heartbeatCallback", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "heartbeatIntervalMs", - "optional": true, - "type": "number" - }, - { - "name": "log_level", - "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } - }, - { - "name": "logger", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "logLevel", - "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } - }, - { - "name": "params", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "reconnectAfterMs", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "timeout", - "optional": true, - "type": "number" - }, - { - "name": "transport", - "optional": true, - "type": { - "kind": "object", - "name": "WebSocketLikeConstructor", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "vsn", - "optional": true, - "type": "string" - }, - { - "name": "worker", - "optional": true, - "type": "boolean" - }, - { - "name": "workerUrl", - "optional": true, - "type": "string" - } - ], - "name": "RealtimeClientOptions" - } - }, - { - "name": "storage", - "optional": true, - "type": { - "kind": "reference", - "name": "StorageClientOptions" - } - } - ], - "name": "SupabaseClientOptions" - } - } - ], - "returnType": { - "kind": "object", - "name": "SupabaseClient", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "accessToken", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "auth", - "optional": false, - "description": "Supabase Auth allows you to create and manage user sessions for access to data that is secured by access policies.", - "type": { - "kind": "reference", - "name": "SupabaseAuthClient" - } - }, - { - "name": "authUrl", - "optional": false, - "type": { - "kind": "reference", - "name": "URL" - } - }, - { - "name": "changedAccessToken", - "optional": true, - "type": "string" - }, - { - "name": "fetch", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "functionsUrl", - "optional": false, - "type": { - "kind": "reference", - "name": "URL" - } - }, - { - "name": "headers", - "optional": false, - "type": { - "kind": "reference", - "name": "Record", - "typeArguments": ["string", "string"] - } - }, - { - "name": "realtime", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimeClient", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "accessToken", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - { - "kind": "object", - "properties": [] - } - ] - } - }, - { - "name": "accessTokenValue", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "apiKey", - "optional": false, - "type": { - "kind": "union", - "types": [ - { - "kind": "literal", - "value": null - }, - "string" - ] - } - }, - { - "name": "channels", - "optional": false, - "type": { - "kind": "array", - "elementType": { - "kind": "object", - "name": "RealtimeChannel", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "bindings", - "optional": false, - "type": { - "kind": "reference", - "name": "Record", - "typeArguments": [ - "string", - { - "kind": "array", - "elementType": { - "kind": "reference", - "name": "Binding" - } - } - ] - } - }, - { - "name": "broadcastEndpointURL", - "optional": false, - "type": "string" - }, - { - "name": "params", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "config", - "optional": false, - "type": { - "kind": "object", - "properties": [ - { - "name": "broadcast", - "optional": true, - "description": "self option enables client to receive message it broadcast ack option instructs server to acknowledge that broadcast message was received replay option instructs server to replay broadcast messages", - "type": { - "kind": "object", - "properties": [ - { - "name": "ack", - "optional": true, - "type": "boolean" - }, - { - "name": "replay", - "optional": true, - "type": { - "kind": "reference", - "name": "ReplayOption" - } - }, - { - "name": "self", - "optional": true, - "type": "boolean" - } - ] - } - }, - { - "name": "presence", - "optional": true, - "description": "key option is used to track presence payload across clients", - "type": { - "kind": "object", - "properties": [ - { - "name": "enabled", - "optional": true, - "type": "boolean" - }, - { - "name": "key", - "optional": true, - "type": "string" - } - ] - } - }, - { - "name": "private", - "optional": true, - "description": "defines if the channel is private or not and if RLS policies will be used to check data", - "type": "boolean" - } - ] - } - } - ], - "name": "RealtimeChannelOptions" - } - }, - { - "name": "presence", - "optional": false, - "type": { - "kind": "object", - "name": "RealtimePresence", - "properties": [ - { - "name": "constructor", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": { - "kind": "reference", - "name": "RealtimeChannel" - } - }, - { - "name": "state", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "private", - "optional": false, - "type": "boolean" - }, - { - "name": "socket", - "optional": false, - "type": { - "kind": "reference", - "name": "RealtimeClient" - } - }, - { - "name": "subTopic", - "optional": false, - "type": "string" - }, - { - "name": "topic", - "optional": false, - "description": "Topic name can be any string.", - "type": "string" - }, - { - "name": "joinedOnce", - "optional": false, - "type": null - }, - { - "name": "joinPush", - "optional": false, - "type": null - }, - { - "name": "rejoinTimer", - "optional": false, - "type": null - }, - { - "name": "state", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "copyBindings", - "optional": false, - "type": null - }, - { - "name": "httpSend", - "optional": false, - "type": null - }, - { - "name": "on", - "optional": false, - "type": null - }, - { - "name": "presenceState", - "optional": false, - "type": null - }, - { - "name": "send", - "optional": false, - "type": null - }, - { - "name": "subscribe", - "optional": false, - "type": null - }, - { - "name": "teardown", - "optional": false, - "type": null - }, - { - "name": "track", - "optional": false, - "type": null - }, - { - "name": "unsubscribe", - "optional": false, - "type": null - }, - { - "name": "untrack", - "optional": false, - "type": null - }, - { - "name": "updateJoinPayload", - "optional": false, - "type": null - } - ] - } - } - }, - { - "name": "fetch", - "optional": false, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "headers", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "httpEndpoint", - "optional": false, - "type": "string" - }, - { - "name": "logLevel", - "optional": true, - "type": { - "kind": "reference", - "name": "LogLevel" - } - }, - { - "name": "params", - "optional": true, - "type": { - "kind": "object", - "properties": [] - } - }, - { - "name": "ref", - "optional": false, - "type": "number" - }, - { - "name": "serializer", - "optional": false, - "type": { - "kind": "reference", - "name": "Serializer" - } - }, - { - "name": "worker", - "optional": true, - "type": "boolean" - }, - { - "name": "workerRef", - "optional": true, - "type": { - "kind": "reference", - "name": "Worker" - } - }, - { - "name": "workerUrl", - "optional": true, - "type": "string" - }, - { - "name": "decode", - "optional": false, - "type": null - }, - { - "name": "encode", - "optional": false, - "type": null - }, - { - "name": "endPoint", - "optional": false, - "type": null - }, - { - "name": "heartbeatCallback", - "optional": false, - "type": null - }, - { - "name": "heartbeatIntervalMs", - "optional": false, - "type": null - }, - { - "name": "heartbeatTimer", - "optional": false, - "type": null - }, - { - "name": "pendingHeartbeatRef", - "optional": false, - "type": null - }, - { - "name": "reconnectAfterMs", - "optional": false, - "type": null - }, - { - "name": "reconnectTimer", - "optional": false, - "type": null - }, - { - "name": "sendBuffer", - "optional": false, - "type": null - }, - { - "name": "stateChangeCallbacks", - "optional": false, - "type": null - }, - { - "name": "timeout", - "optional": false, - "type": null - }, - { - "name": "transport", - "optional": false, - "type": null - }, - { - "name": "vsn", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": null - }, - { - "name": "connect", - "optional": false, - "type": null - }, - { - "name": "connectionState", - "optional": false, - "type": null - }, - { - "name": "disconnect", - "optional": false, - "type": null - }, - { - "name": "endpointURL", - "optional": false, - "type": null - }, - { - "name": "getChannels", - "optional": false, - "type": null - }, - { - "name": "isConnected", - "optional": false, - "type": null - }, - { - "name": "isConnecting", - "optional": false, - "type": null - }, - { - "name": "isDisconnecting", - "optional": false, - "type": null - }, - { - "name": "log", - "optional": false, - "type": null - }, - { - "name": "onHeartbeat", - "optional": false, - "type": null - }, - { - "name": "push", - "optional": false, - "type": null - }, - { - "name": "removeAllChannels", - "optional": false, - "type": null - }, - { - "name": "removeChannel", - "optional": false, - "type": null - }, - { - "name": "sendHeartbeat", - "optional": false, - "type": null - }, - { - "name": "setAuth", - "optional": false, - "type": null - } - ] - } - }, - { - "name": "realtimeUrl", - "optional": false, - "type": { - "kind": "reference", - "name": "URL" - } - }, - { - "name": "rest", - "optional": false, - "type": { - "kind": "reference", - "name": "PostgrestClient", - "typeArguments": [ - { - "kind": "typeParam", - "name": "Database" - }, - { - "kind": "typeParam", - "name": "ClientOptions" - }, - { - "kind": "typeParam", - "name": "SchemaName" - } - ] - } - }, - { - "name": "storage", - "optional": false, - "description": "Supabase Storage allows you to manage user-generated content, such as photos or videos.", - "type": { - "kind": "reference", - "name": "StorageClient" - } - }, - { - "name": "storageKey", - "optional": false, - "type": "string" - }, - { - "name": "storageUrl", - "optional": false, - "type": { - "kind": "reference", - "name": "URL" - } - }, - { - "name": "supabaseKey", - "optional": false, - "description": "The unique Supabase Key which is supplied when you create a new project in your project dashboard.", - "type": "string" - }, - { - "name": "supabaseUrl", - "optional": false, - "description": "The unique Supabase URL which is supplied when you create a new project in your project dashboard.", - "type": "string" - }, - { - "name": "functions", - "optional": false, - "type": null - }, - { - "name": "channel", - "optional": false, - "type": null - }, - { - "name": "from", - "optional": false, - "description": "Perform a query on a table or a view.", - "type": null - }, - { - "name": "getChannels", - "optional": false, - "type": null - }, - { - "name": "removeAllChannels", - "optional": false, - "type": null - }, - { - "name": "removeChannel", - "optional": false, - "type": null - }, - { - "name": "rpc", - "optional": false, - "type": null - }, - { - "name": "schema", - "optional": false, - "type": null - } - ] - }, - "examples": [ - { - "title": "Creating a client", - "code": "import { createClient } from '@supabase/supabase-js'\n\n// Create a single supabase client for interacting with your database\nconst supabase = createClient('https://xyzcompany.supabase.co', 'publishable-or-anon-key')", - "notes": "With custom schemas\nBy default the API server points to the `public` schema. You can enable other database schemas within the Dashboard.\nGo to [Settings > API > Exposed schemas](/dashboard/project/_/settings/api) and add the schema which you want to expose to the API.\n\nNote: each client connection can only access a single schema, so the code above can access the `other_schema` schema but cannot access the `public` schema." - }, - { - "title": "With a custom domain", - "code": "import { createClient } from '@supabase/supabase-js'\n\n// Use a custom domain as the supabase URL\nconst supabase = createClient('https://my-custom-domain.com', 'publishable-or-anon-key')", - "notes": "Custom fetch implementation\n`supabase-js` uses the [`cross-fetch`](https://www.npmjs.com/package/cross-fetch) library to make HTTP requests,\nbut an alternative `fetch` implementation can be provided as an option.\nThis is most useful in environments where `cross-fetch` is not compatible (for instance Cloudflare Workers)." - }, - { - "title": "With additional parameters", - "code": "import { createClient } from '@supabase/supabase-js'\n\nconst options = {\n db: {\n schema: 'public',\n },\n auth: {\n autoRefreshToken: true,\n persistSession: true,\n detectSessionInUrl: true\n },\n global: {\n headers: { 'x-my-custom-header': 'my-app-name' },\n },\n}\nconst supabase = createClient(\"https://xyzcompany.supabase.co\", \"publishable-or-anon-key\", options)", - "notes": "React Native options with AsyncStorage\nFor React Native we recommend using `AsyncStorage` as the storage implementation for Supabase Auth." - }, - { - "title": "With custom schemas", - "code": "import { createClient } from '@supabase/supabase-js'\n\nconst supabase = createClient('https://xyzcompany.supabase.co', 'publishable-or-anon-key', {\n // Provide a custom schema. Defaults to \"public\".\n db: { schema: 'other_schema' }\n})", - "notes": "By default the API server points to the `public` schema. You can enable other database schemas within the Dashboard.\nGo to [Settings > API > Exposed schemas](/dashboard/project/_/settings/api) and add the schema which you want to expose to the API.\n\nNote: each client connection can only access a single schema, so the code above can access the `other_schema` schema but cannot access the `public` schema." - }, - { - "title": "Custom fetch implementation", - "code": "import { createClient } from '@supabase/supabase-js'\n\nconst supabase = createClient('https://xyzcompany.supabase.co', 'publishable-or-anon-key', {\n global: { fetch: fetch.bind(globalThis) }\n})", - "notes": "`supabase-js` uses the [`cross-fetch`](https://www.npmjs.com/package/cross-fetch) library to make HTTP requests,\nbut an alternative `fetch` implementation can be provided as an option.\nThis is most useful in environments where `cross-fetch` is not compatible (for instance Cloudflare Workers)." - }, - { - "title": "React Native options with AsyncStorage", - "code": "import 'react-native-url-polyfill/auto'\nimport { createClient } from '@supabase/supabase-js'\nimport AsyncStorage from \"@react-native-async-storage/async-storage\";\n\nconst supabase = createClient(\"https://xyzcompany.supabase.co\", \"publishable-or-anon-key\", {\n auth: {\n storage: AsyncStorage,\n autoRefreshToken: true,\n persistSession: true,\n detectSessionInUrl: false,\n },\n});", - "notes": "For React Native we recommend using `AsyncStorage` as the storage implementation for Supabase Auth." - }, - { - "title": "React Native options with Expo SecureStore", - "code": "import 'react-native-url-polyfill/auto'\nimport { createClient } from '@supabase/supabase-js'\nimport AsyncStorage from '@react-native-async-storage/async-storage';\nimport * as SecureStore from 'expo-secure-store';\nimport * as aesjs from 'aes-js';\nimport 'react-native-get-random-values';\n\n// As Expo's SecureStore does not support values larger than 2048\n// bytes, an AES-256 key is generated and stored in SecureStore, while\n// it is used to encrypt/decrypt values stored in AsyncStorage.\nclass LargeSecureStore {\n private async _encrypt(key: string, value: string) {\n const encryptionKey = crypto.getRandomValues(new Uint8Array(256 / 8));\n\n const cipher = new aesjs.ModeOfOperation.ctr(encryptionKey, new aesjs.Counter(1));\n const encryptedBytes = cipher.encrypt(aesjs.utils.utf8.toBytes(value));\n\n await SecureStore.setItemAsync(key, aesjs.utils.hex.fromBytes(encryptionKey));\n\n return aesjs.utils.hex.fromBytes(encryptedBytes);\n }\n\n private async _decrypt(key: string, value: string) {\n const encryptionKeyHex = await SecureStore.getItemAsync(key);\n if (!encryptionKeyHex) {\n return encryptionKeyHex;\n }\n\n const cipher = new aesjs.ModeOfOperation.ctr(aesjs.utils.hex.toBytes(encryptionKeyHex), new aesjs.Counter(1));\n const decryptedBytes = cipher.decrypt(aesjs.utils.hex.toBytes(value));\n\n return aesjs.utils.utf8.fromBytes(decryptedBytes);\n }\n\n async getItem(key: string) {\n const encrypted = await AsyncStorage.getItem(key);\n if (!encrypted) { return encrypted; }\n\n return await this._decrypt(key, encrypted);\n }\n\n async removeItem(key: string) {\n await AsyncStorage.removeItem(key);\n await SecureStore.deleteItemAsync(key);\n }\n\n async setItem(key: string, value: string) {\n const encrypted = await this._encrypt(key, value);\n\n await AsyncStorage.setItem(key, encrypted);\n }\n}\n\nconst supabase = createClient(\"https://xyzcompany.supabase.co\", \"publishable-or-anon-key\", {\n auth: {\n storage: new LargeSecureStore(),\n autoRefreshToken: true,\n persistSession: true,\n detectSessionInUrl: false,\n },\n});", - "notes": "If you wish to encrypt the user's session information, you can use `aes-js` and store the encryption key in Expo SecureStore.\nThe `aes-js` library, a reputable JavaScript-only implementation of the AES encryption algorithm in CTR mode.\nA new 256-bit encryption key is generated using the `react-native-get-random-values` library.\nThis key is stored inside Expo's SecureStore, while the value is encrypted and placed inside AsyncStorage.\n\nPlease make sure that:\n- You keep the `expo-secure-store`, `aes-js` and `react-native-get-random-values` libraries up-to-date.\n- Choose the correct [`SecureStoreOptions`](https://docs.expo.dev/versions/latest/sdk/securestore/#securestoreoptions) for your app's needs.\n E.g. [`SecureStore.WHEN_UNLOCKED`](https://docs.expo.dev/versions/latest/sdk/securestore/#securestorewhen_unlocked) regulates when the data can be accessed.\n- Carefully consider optimizations or other modifications to the above example, as those can lead to introducing subtle security vulnerabilities." - }, - { - "title": "With a database query", - "code": "import { createClient } from '@supabase/supabase-js'\n\nconst supabase = createClient('https://xyzcompany.supabase.co', 'public-anon-key')\n\nconst { data } = await supabase.from('profiles').select('*')" - } - ] - }, { "name": "getChannels", "description": "Returns all Realtime channels.", @@ -76410,4 +68275,4 @@ } ] } -] +] \ No newline at end of file