PHP SDK - Auth#

All project auth methods are scoped to the client's projectId. The session is stored on the client and sent as Authorization: Bearer <jwt> with every request, so row-level security evaluates it as the authenticated user.

Sign up#

$db->auth->signup(
    'user@example.com',
    'strong-pass1',
    'Asha Mwinyi',
    '+255712345678',        // required
    ['plan' => 'free'],     // optional metadata
);
PHP

Login#

$session = $db->auth->login('user@example.com', 'strong-pass1');
// $db->auth->signin(...) is an alias
// $session->data contains the user + access/refresh tokens
PHP

Sessions#

$db->client->session();      // array | null
$db->auth->signOut();        // clear the in-memory session

// Restore a persisted session
$db->client->setSession($storedArray);
PHP

The SDK keeps the session in memory only. To keep users signed in across requests, store it yourself:

// After login
file_put_contents('/tmp/session.json', json_encode($db->client->session()));

// On the next request
$db->client->setSession(json_decode(file_get_contents('/tmp/session.json'), true));
PHP

Password reset#

$db->auth->resetPassword('user@example.com');  // emails a 6-digit code
$db->auth->confirmResetPassword('user@example.com', '123456', 'brand-new-pass1');
PHP

Phone / OTP#

$db->auth->otpRequest('+255712345678');

$session = $db->auth->otpVerify('+255712345678', '123456', 'Asha Mwinyi');
PHP

Tokens#

$fresh = $db->auth->refresh($refreshToken); // rotate for a fresh access token
$db->auth->logout($refreshToken);           // revoke a refresh token
PHP

Dashboard login (POST /auth/login) is a separate platform endpoint - it is not for your project's users.

Next: Realtime.