PHP SDK - Auth#
All project auth methods are scoped to the client's projectId. The session
is stored on the client and sent as Authorization: Bearer <jwt> with every
request, so row-level security evaluates it as the authenticated user.
Sign up#
$db->auth->signup(
'user@example.com',
'strong-pass1',
'Asha Mwinyi',
'+255712345678', // required
['plan' => 'free'], // optional metadata
);
PHPLogin#
$session = $db->auth->login('user@example.com', 'strong-pass1');
// $db->auth->signin(...) is an alias
// $session->data contains the user + access/refresh tokens
PHPSessions#
$db->client->session(); // array | null
$db->auth->signOut(); // clear the in-memory session
// Restore a persisted session
$db->client->setSession($storedArray);
PHPThe SDK keeps the session in memory only. To keep users signed in across requests, store it yourself:
// After login
file_put_contents('/tmp/session.json', json_encode($db->client->session()));
// On the next request
$db->client->setSession(json_decode(file_get_contents('/tmp/session.json'), true));
PHPPassword reset#
$db->auth->resetPassword('user@example.com'); // emails a 6-digit code
$db->auth->confirmResetPassword('user@example.com', '123456', 'brand-new-pass1');
PHPPhone / OTP#
$db->auth->otpRequest('+255712345678');
$session = $db->auth->otpVerify('+255712345678', '123456', 'Asha Mwinyi');
PHPTokens#
$fresh = $db->auth->refresh($refreshToken); // rotate for a fresh access token
$db->auth->logout($refreshToken); // revoke a refresh token
PHPDashboard login (POST /auth/login) is a separate platform endpoint - it is
not for your project's users.
Next: Realtime.