Dart SDK - Auth#
All project auth methods are scoped to the client's projectId. Sessions are
stored on the client automatically and sent as Authorization: Bearer <jwt>
with every request, so row-level security evaluates them as the authenticated
user.
Sign up#
final created = await db.auth.signup(SignupOptions(
email: 'user@example.com',
password: 'strong-pass1',
fullName: 'Asha Mwinyi',
phone: '+255712345678', // required
metadata: {'plan': 'free'}, // optional
));
// created.data!.user, created.data!.tokens.accessToken
DARTLogin#
final session = await db.auth.login(SigninOptions(
email: 'user@example.com',
password: 'strong-pass1',
));
// db.auth.signin(...) is an alias
DARTThe returned JWT is attached automatically to subsequent requests.
Sessions#
db.auth.signOut(); // clear the stored session
db.session; // Session? (user + tokens)
db.setSession(session); // set manually
// React to changes
db.sessionStream.listen((session) {}); // emits null on sign-out
db.subscribeSession((session) {}); // returns an unsubscribe function
DARTPersistence#
With persistSession: true the SDK uses a FileSessionStore (pure Dart) that
writes ~/.rafikidb/{projectId}.json. In Flutter, pass a custom store backed
by shared_preferences:
class PrefsSessionStore implements SessionStore {
PrefsSessionStore(this.prefs);
final SharedPreferences prefs;
Session? read() {
final raw = prefs.getString('rafikidb_session');
return raw == null ? null : Session.fromJson(jsonDecode(raw));
}
void write(Session? session) {
if (session == null) {
prefs.remove('rafikidb_session');
} else {
prefs.setString('rafikidb_session', jsonEncode(session.toJson()));
}
}
}
final db = RafikiDB(
projectId: '5c73dab0-...',
apiKey: 'raf_live_...',
sessionStore: PrefsSessionStore(prefs),
);
DARTPassword reset#
await db.auth.resetPassword('user@example.com'); // emails a 6-digit code
await db.auth.confirmResetPassword(
email: 'user@example.com',
code: '123456',
newPassword: 'brand-new-pass1',
);
DARTPhone / OTP#
await db.auth.otpRequest('+255712345678');
final session = await db.auth.otpVerify(
phone: '+255712345678',
code: '123456',
fullName: 'Asha Mwinyi',
);
DARTEmail verification#
await db.auth.verifyEmail(token);
DARTTokens#
await db.auth.refresh(refreshToken); // rotate for a fresh access token
await db.auth.logout(refreshToken); // revoke a refresh token
DARTDashboard login (db.auth.platformLogin(email:, password:)) is a separate
platform endpoint for RafikiDB account holders - not for your project's users.
Most apps should use db.auth.login instead.
Next: Realtime.