Email sign-in
Password, magic link and one-time code sign-in, email confirmation, password reset and the Supabase Auth email templates.
Three email-based methods ship. Turn on any combination in apps/web/.env (or your host's environment settings):
NEXT_PUBLIC_AUTH_PASSWORD=true # email and password (on by default) NEXT_PUBLIC_AUTH_MAGIC_LINK=false # a sign-in link by email NEXT_PUBLIC_AUTH_OTP=false # a one-time code by email
Email and password
- Passwords need at least 8 characters. Set
NEXT_PUBLIC_PASSWORD_REQUIRE_UPPERCASE,NEXT_PUBLIC_PASSWORD_REQUIRE_NUMBERSorNEXT_PUBLIC_PASSWORD_REQUIRE_SPECIAL_CHARStotruefor stricter rules (packages/features/auth/src/schemas/password.schema.ts). - The local stack requires email confirmation before the first sign-in (
enable_confirmations = trueinapps/web/supabase/config.toml). Set the same in your hosted Supabase project. - Forgotten passwords:
/auth/password-resetsends a reset email; the link opens/update-password. - Signed-in users change their password and email in account settings. An email change has to be confirmed on both the old and the new address locally (
double_confirm_changes = true).
Magic link and one-time code
Both send an email through Supabase Auth. The magic link signs the user in when clicked and returns through /auth/callback. The one-time code is typed into the sign-in page instead, which also works when the email is opened on another device.
When either is on, invited team members can join with their email alone. When both are off, a new member who joins through an invitation is asked to set up a password or another sign-in method afterwards (/identities).
Auth email templates
Supabase Auth sends its own emails (confirmation, password reset, email change, magic link, invitation). The kit's HTML for them is in apps/web/supabase/templates/:
| File | |
|---|---|
confirm-email.html | Confirm your email |
reset-password.html | Reset your password |
change-email-address.html | Confirm an email change |
magic-link.html | Sign-in email with both the link and the code |
invite-user.html | Supabase's own user invitation |
otp.html | A code-only sign-in email (not mapped in config.toml) |
config.toml points the local stack at the first five. A hosted Supabase project does not read config.toml on its own: set the templates and subjects in the project's Auth email settings. Set up your own SMTP server there too: Supabase's built-in sender only delivers to members of your Supabase organisation.
Locally, every Auth email lands in Mailpit at http://localhost:54324.
Team invitations, one-time codes for sensitive actions and the contact form are sent by the app itself, not by Supabase Auth. See Email.