Python SDK - Auth#

All project auth methods are scoped to the client's project_id. Sessions are stored on the client automatically and sent as Authorization: Bearer <jwt> with every request, so row-level security evaluates them as the authenticated user.

Sign up#

session = db.auth.signup(
    email="user@example.com",
    password="strong-pass1",
    full_name="Asha Mwinyi",
    phone="+255712345678",           # required
    metadata={"plan": "free"},       # optional
)
# session.data.user, session.data.tokens.access_token
Python

Login#

session = db.auth.login("user@example.com", "strong-pass1")
# db.auth.signin(...) is an alias
Python

The returned JWT is attached automatically to subsequent requests.

Sessions#

db.auth.sign_out()          # clear the stored session

# Read the current session / token
db.client.session           # dict | None
db.client.access_token      # "eyJ..." | None

# Restore explicitly
db.client.set_session(stored)
Python

To keep users signed in across runs, save db.client.session yourself and pass it back to create_client:

from rafikidb import create_client

db = create_client(
    project_id="5c73dab0-...",
    api_key="raf_live_...",
    session=stored_session,
)
Python

Password reset#

db.auth.reset_password("user@example.com")  # emails a 6-digit code
db.auth.confirm_reset_password("user@example.com", "123456", "brand-new-pass1")
Python

Phone / OTP#

db.auth.otp_request("+255712345678")
session = db.auth.otp_verify("+255712345678", "123456", "Asha Mwinyi")
Python

Tokens#

db.auth.refresh(refresh_token)   # rotate for a fresh access token
db.auth.logout(refresh_token)    # revoke a refresh token
Python

Dashboard login (POST /auth/login) is a separate platform endpoint - it is not for your project's users.

Next: Realtime.