
A JWT based API for managing users and issuing JWT tokens
Auth is a user management and authentication server written in Go that powers Supabase's features such as:
It is originally based on the excellent GoTrue codebase by Netlify, however both have diverged significantly in features and capabilities.
If you wish to contribute to the project, please refer to the contributing guide.
Create a .env file to store your own custom environment variables. See example.env
docker-compose -f docker-compose-dev.yml up postgresmake build . You should see an output like this:go build -ldflags "-X github.com/supabase/auth/cmd.Version=`git rev-parse HEAD`"
GOOS=linux GOARCH=arm64 go build -ldflags "-X github.com/supabase/auth/cmd.Version=`git rev-parse HEAD`" -o gotrue-arm64
./authCreate a .env.docker file to store your own custom env vars. See example.docker.env
make buildmake devdocker ps should show two Docker containers (auth-auth-1 and auth-postgres-1)Running an authentication server in production is not an easy feat. We recommend using Supabase Auth which gets regular security updates.
Otherwise, please make sure you set up a process to promptly update to the latest version. You can do that by following this repository, specifically the Releases and Security Advisories sections.
Auth uses the Semantic Versioning scheme. Here are some further clarifications on backward compatibility guarantees:
Go API compatibility
Auth is not meant to be used as a Go library. There are no guarantees on backward API compatibility when used this way regardless of which version number changes.
Patch
Changes to the patch version guarantees backward compatibility with:
Guaranteed examples:
Not guaranteed examples:
Minor
Changes to minor version guarantees backward compatibility with:
Exceptions to these guarantees will be made only when serious security issues are found that can't be remedied in any other way.
Guaranteed examples:
Not guaranteed examples:
We aim to provide a deprecation notice in execution logs for at least two major version releases or two weeks if multiple releases go out. Compatibility will be guaranteed while the notice is live.
Major
Changes to the major version do not guarantee any backward compatibility with previous versions.
Certain inherited features from the Netlify codebase are not supported by Supabase and they may be removed without prior notice in the future. This is a comprehensive list of those features:
instances table i.e. GOTRUE_MULTI_INSTANCE_MODE
configuration parameter.is_super_admin column.GOTRUE_JWT_ADMIN_GROUP_NAME and other
configuration fields.Note that this is not an exhaustive list and it may change.
These are some best practices to follow when self-hosting to ensure backward compatibility with Auth:
migrations directory.You may configure Auth using either a configuration file named .env,
environment variables, or a combination of both. Environment variables are prefixed with GOTRUE_, and will always have precedence over values provided via file.
GOTRUE_SITE_URL=https://example.netlify.com/
SITE_URL - string required
The base URL your site is located at. Currently used in combination with other settings to construct URLs used in emails. Any URI that shares a host with SITE_URL is a permitted value for redirect_to params (see /authorize etc.).
URI_ALLOW_LIST - string
A comma-separated list of URIs (e.g. "https://foo.example.com,https://*.foo.example.com,https://bar.example.com") which are permitted as valid redirect_to destinations. Defaults to []. Supports wildcard matching through globbing. e.g. https://*.foo.example.com will allow https://a.foo.example.com and https://b.foo.example.com to be accepted. Globbing is also supported on subdomains. e.g. https://foo.example.com/* will allow https://foo.example.com/page1 and https://foo.example.com/page2 to be accepted.
For more common glob patterns, check out the following link.
OPERATOR_TOKEN - string Multi-instance mode only
The shared secret with an operator (usually Netlify) for this microservice. Used to verify requests have been proxied through the operator and the payload values can be trusted.
DISABLE_SIGNUP - bool