JavaScript SDK - Auth#

All project auth methods are scoped to the client's projectId. Sessions are stored automatically (and persisted when persistSession: true).

Sign up#

const { data } = await db.auth.signup({
  email: 'user@example.com',
  password: 'strong-pass1',
  full_name: 'Asha Mwinyi',
  phone: '+255712345678', // all fields required
});
// data.user, data.tokens.access_token
TypeScript

Login#

// End-user login - always targets THIS project's auth
const { data } = await db.auth.login({ email: 'user@example.com', password: 'strong-pass1' });
// db.auth.signin(...) is an alias
TypeScript

The returned JWT is attached automatically to subsequent requests, so RLS evaluates them as the logged-in user.

Sessions#

db.auth.signOut();                    // clear the session (memory + storage)

// Advanced
db.client.getSession();               // { user, tokens } | null
db.client.setSession(session);        // set manually
db.client.subscribeSession((s) => {});// listen for changes
TypeScript

React hook#

import { useAuth } from '@rafikidb/sdk/react';

function App({ db }) {
  const { user, tokens, isAuthenticated, login, signup, otpVerify, signOut } = useAuth(db);
  if (!isAuthenticated) return <LoginScreen onDone={login} />;
  return <Dashboard user={user} onLogout={signOut} />;
}
TypeScript

useAuth re-renders on every session change (login, signup, OTP, signOut, page restore). It replaces manual auth stores entirely.

Password reset#

await db.auth.resetPassword('user@example.com'); // emails a 6-digit code
await db.auth.confirmResetPassword({
  email: 'user@example.com',
  code: '123456',
  new_password: 'brand-new-pass1',
});
TypeScript

Phone / OTP#

await db.auth.otpRequest('+255712345678');
const { data } = await db.auth.otpVerify({
  phone: '+255712345678',
  code: '123456',
  full_name: 'Asha Mwinyi',
});
TypeScript

Next: Realtime.