--- id: auth title: Auth description: Use Supabase to Authenticate and Authorize your users. sidebar_label: Overview --- import Link from '@docusaurus/Link' import Tabs from '@theme/Tabs' import TabItem from '@theme/TabItem' import providers from '@site/src/data/authProviders' import ButtonCard from '@site/src/components/ButtonCard' import useBaseUrl from '@docusaurus/useBaseUrl'
## Overview There are two parts to every Auth system: - **Authentication:** should this person be allowed in? If yes, who are they? - **Authorization:** once they are in, what are they allowed to do? Supabase Auth is designed to work either as a standalone product, or deeply integrated with the other Supabase products. Postgres is at the heart of everything we do, and the Auth system follows this principle. We leverage Postgres' built-in Auth functionality wherever possible. ## Authentication You can authenticate your users in several ways: - Email & password. - Magic links (one-click logins). - Social providers. - Phone logins. ### Providers We provide a suite of Providers and login methods.
{providers.map((x) => (
{x.logo && {x.name}}

{x.name}

{x.official ? ( Official ) : ( Unofficial )}

Platform: {x.platform.toString()}
Self-Hosted: {x.selfHosted.toString()}
))}
### Simple interface You can enable third-party providers with the click of a button by navigating to Authentication > Settings > External OAuth Providers and inputting your `Client ID` and `Secret` for each. ![OAuth Logins.](/img/supabase-oauth-logins.png) ## Authorization When you need granular authorization rules, nothing beats PostgreSQL's Row Level Security (RLS). Policies are PostgreSQL's rule engine. They are incredibly powerful and flexible, allowing you to write complex SQL rules which fit your unique business needs. Get started with our [Row Level Security Guides](/docs/guides/auth/row-level-security). ### Row Level Security Authentication only gets you so far. When you need granular authorization rules, nothing beats PostgreSQL's [Row Level Security (RLS)](https://www.postgresql.org/docs/current/ddl-rowsecurity.html). Supabase makes it simple to turn RLS on and off. ### Policies [Policies](https://www.postgresql.org/docs/current/sql-createpolicy.html) are PostgreSQL's rule engine. They are incredibly powerful and flexible, allowing you to write complex SQL rules which fit your unique business needs. With policies, your database becomes the rules engine. Instead of repetitively filtering your queries, like this ... ```js const loggedInUserId = 'd0714948' let { data, error } = await supabase .from('users') .select('user_id, name') .eq('user_id', loggedInUserId) // console.log(data) // => { id: 'd0714948', name: 'Jane' } ``` ... you can simply define a rule on your database table, `auth.uid() = user_id`, and your request will return the rows which pass the rule, even when you remove the filter from your middleware: ```js let { data, error } = await supabase.from('users').select('user_id, name') // console.log(data) // Still => { id: 'd0714948', name: 'Jane' } ``` ### How It Works 1. A user signs up. Supabase creates a new user in the `auth.users` table. 2. Supabase returns a new JWT, which contains the user's `UUID`. 3. Every request to your database also sends the JWT. 4. Postgres inspects the JWT to determine the user making the request. 5. The user's UID can be used in policies to restrict access to rows. Supabase provides a special function in Postgres, `auth.uid()`, which extracts the user's UID from the JWT. This is especially useful when creating policies. ## User Management Supabase makes it simple to manage your users. When users sign up, Supabase assigns them a unique ID. You can reference this ID anywhere in your database. For example, you might create a `profiles` table referencing `id` in the `auth.users` table using a `user_id` field. Supabase provides the routes to [sign up](/docs/reference/javascript/auth-signup), [log in](/docs/reference/javascript/auth-signin), [log out](/docs/reference/javascript/auth-signout), and manage users in your apps and websites. ## Next Steps - Sign in: [app.supabase.com](https://app.supabase.com)