mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 01:45:10 +03:00
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update ## What is the current behavior? The Auth rate-limit table contains stale customization statuses and time windows, omits SMS and Web3 limits, and describes the anonymous sign-in burst incorrectly. ## What is the new behavior? - Aligns documented limits with the current Auth, Studio, and Management API behavior - Documents SMS, Web3, and sign-up/sign-in request limits - Corrects verification, token, MFA, email, and anonymous sign-in details - Updates shared rate-limit values and units used by the docs ## Additional context Validation: - Prettier check - Focused MDX lint - Shared-data TypeScript check - All 16 SharedData references resolve <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Updates** * Refined authentication rate limits with clearer per-minute and per-five-minute windows. * Added rate limits for SMS, password reset requests, and Web3 sign-ups and sign-ins. * Updated sign-in, sign-up, verification, token refresh, MFA, and anonymous sign-in limits, including customizable settings where supported. * Clarified email-sending limits and OTP behavior. * **Documentation** * Updated rate-limit reference tables and guidance on request bucket capacity and sustained traffic. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
14 lines
6.4 KiB
Plaintext
14 lines
6.4 KiB
Plaintext
| Operation | Path | Limited By | Customizable | Limit |
|
|
| ---------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------- | ------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
|
| Emails sent by Supabase Auth | All email-sending Auth endpoints | Project | Custom SMTP or Send Email hook | <SharedData data="config">auth.rate_limits.email.inbuilt_smtp_per_hour</SharedData> emails per hour with the built-in email provider. You can configure this limit when you use custom SMTP or the Send Email hook. |
|
|
| SMS messages sent by Supabase Auth | All SMS-sending Auth endpoints | Project | Yes | Defaults to <SharedData data="config">auth.rate_limits.sms.requests_per_hour</SharedData> SMS messages per hour. |
|
|
| Sign-ups and sign-ins | `/auth/v1/signup` `/auth/v1/recover` `/auth/v1/resend` `/auth/v1/magiclink` `/auth/v1/otp` `/auth/v1/user` | IP Address | Yes | Defaults to <SharedData data="config">auth.rate_limits.sign_in_sign_ups.requests_per_five_minutes</SharedData> requests per 5 minutes, with bursts up to <SharedData data="config">auth.rate_limits.sign_in_sign_ups.requests_burst</SharedData> requests. This limit excludes anonymous sign-ins. |
|
|
| Send OTPs or magic links | `/auth/v1/otp` | User | Yes | Defaults to a <SharedData data="config">auth.rate_limits.otp.period</SharedData> window before a new request is allowed for the same user. |
|
|
| Signup confirmation request | `/auth/v1/signup` | User | Yes | Defaults to a <SharedData data="config">auth.rate_limits.signup_confirmation.period</SharedData> window before a new request is allowed for the same user. |
|
|
| Password reset request | `/auth/v1/recover` | User | Yes | Defaults to a <SharedData data="config">auth.rate_limits.password_reset.period</SharedData> window before a new request is allowed for the same user. |
|
|
| Verification requests | `/auth/v1/verify` | IP Address | Yes | Defaults to <SharedData data="config">auth.rate_limits.verification.requests_per_five_minutes</SharedData> requests per 5 minutes, with bursts up to <SharedData data="config">auth.rate_limits.verification.requests_burst</SharedData> requests. |
|
|
| Token endpoint requests | `/auth/v1/token` | IP Address | Yes | Defaults to <SharedData data="config">auth.rate_limits.token_refresh.requests_per_five_minutes</SharedData> requests per 5 minutes, with bursts up to <SharedData data="config">auth.rate_limits.token_refresh.requests_burst</SharedData> requests. This covers password, refresh token, ID token, and PKCE grants. |
|
|
| Create or verify an MFA challenge | `/auth/v1/factors/:id/challenge` `/auth/v1/factors/:id/verify` | IP Address | No | <SharedData data="config">auth.rate_limits.mfa.requests_per_minute</SharedData> requests per minute, with bursts up to <SharedData data="config">auth.rate_limits.mfa.requests_burst</SharedData> requests. |
|
|
| Anonymous sign-ins | `/auth/v1/signup` | IP Address | Yes | Defaults to <SharedData data="config">auth.rate_limits.anonymous_signin.requests_per_hour</SharedData> requests per hour, with a burst capacity equal to the configured limit. This limit only applies if the endpoint is called without an email or phone number in the request body. |
|
|
| Web3 sign-ups and sign-ins | `/auth/v1/token` | IP Address | Yes | Defaults to <SharedData data="config">auth.rate_limits.web3.requests_per_five_minutes</SharedData> requests per 5 minutes, with bursts up to <SharedData data="config">auth.rate_limits.web3.requests_burst</SharedData> requests. |
|