Skip to content
Appwrite Auth

Authentication that ships with your product_

Give users a secure sign-in experience without building auth infrastructure. Appwrite Auth supports the methods your users expect, team collaboration signals, and the controls your team needs.

Acme

Welcome back

Sign in to your account

Email

paige@acme.io
Send magic link

Verification code

482 913

Check your inbox

OAuth providers
40+
Sign-in methods
7
Memberships & roles
Multi-Tenancy
Two-factor auth
MFA
Team collaboration
Presences

OAuth 2 and social login

Enable 30+ social providers from the Console Social providers tab. Users sign up in one click with GitHub, Google, Apple, and the identity providers your audience already uses.

Social providers

Enable OAuth 2 sign-in for external accounts.

Google
GitHub
Apple
30+ providers

Passwordless login

Turn on Magic URL, Email OTP, and Phone SMS from Auth settings. Ship secure sign-in without storing or resetting passwords.

Sign in

Choose a method

Magic URL

Email link sign-in

Email OTP

6-digit code

Phone SMS

Text verification

6-digit code

482913
await account.createMagicURLToken(
'paige@acme.io')

Multi-tenancy with teams and roles

Model each customer or workspace as a team with memberships, invites, and roles. Scope databases, storage, and other resources to the right tenant from the Console Users and Teams tabs, without building custom RBAC.

Acme Engineering

3 members · Owner access

W

Walter O'Brien

walter@acme.io

Owner
P

Paige Dineen

paige@acme.io

Developer
H

Happy Quinn

happy@acme.io

Member

documents.reports

team:acme/readuser:walter/updaterole:developer/read

SSR authentication

Verify sessions from Next.js, Nuxt, SvelteKit, and other server-rendered apps. Issue session cookies from your backend with dedicated guides and tutorials.

Next.jsNuxtSvelteKit
middleware.ts
SSR
import { createSessionClient } from '@appwrite.io/ssr'

const client = createSessionClient(request)
const user = await client.account.get()

Session verified

Set-Cookie: a_session_…

Security policies you control

Fine-tune Auth from the Console Policies and Settings tabs. Set session length and limits, password strength and history, email signup rules, membership privacy, and which auth methods are enabled for your project.

Session length

30 days

Sessions limit

10 active sessions

Session alerts

Enabled

Invalidate sessions

Enabled

Password policies

Strong presetMin 12 charsHistory: 54/7 compliant

Email policies

Block disposable emails
Block aliased emails
Block free providers
Email/PasswordMagic URLPhoneJWTAnonymous

Multi-factor authentication

Add TOTP authenticator apps and recovery codes for sensitive accounts. Require MFA when users update credentials or access protected actions.

Authenticator app

Acme

paige@acme.io

482 190

GitHub

paige

913 024

Enter verification code

482190

MFA enabled

Presence for team collaboration

Show who is online, on the same page, or typing in team chat. Presences sync status and metadata over Realtime so you can add collaboration cues to shared docs, dashboards, and support tools without building sockets.

Shared doc

Q4 launch plan

Finalize hero copy
Review pricing section
HQ
PD
TC
3 online

Happy Quinn is typing in team chat

Tools built for developers and agents_

API-first by design. Use the Console, Realtime, SDKs, CLI, Terraform, MCP, and agent skills on the same project.

FAQ_

Yes. Appwrite Auth is API-first, so you keep full control of the UI in your app and call the Account SDK for sign-up, login, sessions, and MFA. Quick starts cover React, Next.js, Vue, SvelteKit, Flutter, and other platforms. For server-rendered apps, verify sessions on your backend and issue HTTP-only cookies using the SSR guides.

Start building with Auth_

Create a project and add authentication in minutes with our quick start guides.