Email sign-in

Password, magic link and one-time code sign-in, email confirmation, password reset and the Supabase Auth email templates.

Three email-based methods ship. Turn on any combination in apps/web/.env (or your host's environment settings):

NEXT_PUBLIC_AUTH_PASSWORD=true     # email and password (on by default)
NEXT_PUBLIC_AUTH_MAGIC_LINK=false  # a sign-in link by email
NEXT_PUBLIC_AUTH_OTP=false         # a one-time code by email

Email and password

  • Passwords need at least 8 characters. Set NEXT_PUBLIC_PASSWORD_REQUIRE_UPPERCASE, NEXT_PUBLIC_PASSWORD_REQUIRE_NUMBERS or NEXT_PUBLIC_PASSWORD_REQUIRE_SPECIAL_CHARS to true for stricter rules (packages/features/auth/src/schemas/password.schema.ts).
  • The local stack requires email confirmation before the first sign-in (enable_confirmations = true in apps/web/supabase/config.toml). Set the same in your hosted Supabase project.
  • Forgotten passwords: /auth/password-reset sends a reset email; the link opens /update-password.
  • Signed-in users change their password and email in account settings. An email change has to be confirmed on both the old and the new address locally (double_confirm_changes = true).

Both send an email through Supabase Auth. The magic link signs the user in when clicked and returns through /auth/callback. The one-time code is typed into the sign-in page instead, which also works when the email is opened on another device.

When either is on, invited team members can join with their email alone. When both are off, a new member who joins through an invitation is asked to set up a password or another sign-in method afterwards (/identities).

Auth email templates

Supabase Auth sends its own emails (confirmation, password reset, email change, magic link, invitation). The kit's HTML for them is in apps/web/supabase/templates/:

FileEmail
confirm-email.htmlConfirm your email
reset-password.htmlReset your password
change-email-address.htmlConfirm an email change
magic-link.htmlSign-in email with both the link and the code
invite-user.htmlSupabase's own user invitation
otp.htmlA code-only sign-in email (not mapped in config.toml)

config.toml points the local stack at the first five. A hosted Supabase project does not read config.toml on its own: set the templates and subjects in the project's Auth email settings. Set up your own SMTP server there too: Supabase's built-in sender only delivers to members of your Supabase organisation.

Locally, every Auth email lands in Mailpit at http://localhost:54324.

Team invitations, one-time codes for sensitive actions and the contact form are sent by the app itself, not by Supabase Auth. See Email.