Dart SDK - Auth#

All project auth methods are scoped to the client's projectId. Sessions are stored on the client automatically and sent as Authorization: Bearer <jwt> with every request, so row-level security evaluates them as the authenticated user.

Sign up#

final created = await db.auth.signup(SignupOptions(
  email: 'user@example.com',
  password: 'strong-pass1',
  fullName: 'Asha Mwinyi',
  phone: '+255712345678',           // required
  metadata: {'plan': 'free'},       // optional
));
// created.data!.user, created.data!.tokens.accessToken
DART

Login#

final session = await db.auth.login(SigninOptions(
  email: 'user@example.com',
  password: 'strong-pass1',
));
// db.auth.signin(...) is an alias
DART

The returned JWT is attached automatically to subsequent requests.

Sessions#

db.auth.signOut();       // clear the stored session
db.session;              // Session? (user + tokens)
db.setSession(session);  // set manually

// React to changes
db.sessionStream.listen((session) {}); // emits null on sign-out
db.subscribeSession((session) {});     // returns an unsubscribe function
DART

Persistence#

With persistSession: true the SDK uses a FileSessionStore (pure Dart) that writes ~/.rafikidb/{projectId}.json. In Flutter, pass a custom store backed by shared_preferences:

class PrefsSessionStore implements SessionStore {
  PrefsSessionStore(this.prefs);
  final SharedPreferences prefs;

  
  Session? read() {
    final raw = prefs.getString('rafikidb_session');
    return raw == null ? null : Session.fromJson(jsonDecode(raw));
  }

  
  void write(Session? session) {
    if (session == null) {
      prefs.remove('rafikidb_session');
    } else {
      prefs.setString('rafikidb_session', jsonEncode(session.toJson()));
    }
  }
}

final db = RafikiDB(
  projectId: '5c73dab0-...',
  apiKey: 'raf_live_...',
  sessionStore: PrefsSessionStore(prefs),
);
DART

Password reset#

await db.auth.resetPassword('user@example.com'); // emails a 6-digit code
await db.auth.confirmResetPassword(
  email: 'user@example.com',
  code: '123456',
  newPassword: 'brand-new-pass1',
);
DART

Phone / OTP#

await db.auth.otpRequest('+255712345678');
final session = await db.auth.otpVerify(
  phone: '+255712345678',
  code: '123456',
  fullName: 'Asha Mwinyi',
);
DART

Email verification#

await db.auth.verifyEmail(token);
DART

Tokens#

await db.auth.refresh(refreshToken); // rotate for a fresh access token
await db.auth.logout(refreshToken);  // revoke a refresh token
DART

Dashboard login (db.auth.platformLogin(email:, password:)) is a separate platform endpoint for RafikiDB account holders - not for your project's users. Most apps should use db.auth.login instead.

Next: Realtime.