7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Supabase Auth

Open source

Go-based user management and authentication server from Supabase that issues JWTs and supports email, passwordless, phone, and social sign-in.

supabase.com
Supabase Auth homepage screenshot
GitHub stars
2.6k
Last commit
yesterday
Repository age
6 years
Version
v2.197.0
Licence
MIT
Self-hosted
Yes

About Supabase Auth

Supabase Auth is an authentication and user management server written in Go. It powers Supabase's sign-in features by issuing JSON Web Tokens that downstream services, such as PostgREST with Row Level Security, can trust. It started from Netlify's GoTrue codebase, but both projects have diverged significantly. It is released under the MIT license.

Supported sign-in methods include email and password, magic links, phone numbers, and external providers such as Google, Apple, Facebook, and Discord. The server exposes an HTTP API for managing users and sessions, and its configuration is handled through environment variables in a .env file, with an example file provided.

The README walks through a quick start using a local Postgres database and has sections on running in production, configuration, and endpoints. The service can be used as part of the Supabase hosted platform or run on its own, which suits teams that want an open-source JWT-based identity service they can host themselves.

Key features

  • JWT issuing for application sessions
  • Email and password sign-in
  • Magic link and phone number login
  • OAuth providers such as Google and Apple
  • User management API
  • Row Level Security integration with PostgREST

Good fit for

  • →Adding user login to an app on Postgres
  • →Running a self-hosted JWT authentication service
Built with
Go
Tags
authentication
jwt
supabase
user-management
oauth
go
magic-link
self-hosted

Supabase Auth: questions and answers

What is Supabase Auth used for?
Supabase Auth is a Go-based user management and authentication server from Supabase that issues JWTs and supports email, passwordless, phone, and social sign-in. It is a good fit for adding user login to an app on Postgres and running a self-hosted JWT authentication service.
Is Supabase Auth open source?
Yes. Supabase Auth is open source under the MIT licence. Its source code is on GitHub at supabase/auth and is written mainly in Go.
Is Supabase Auth free?
Yes. Supabase Auth is open source, so the software itself is free to use. A managed cloud version is also available.
Can I self-host Supabase Auth?
Yes. Supabase Auth can be self-hosted on your own server or infrastructure.
What is Supabase Auth an alternative to?
Supabase Auth is an open-source alternative to Auth0, Amazon Cognito, Google Cloud Identity Platform and Clerk. Other open-source alternatives to Auth0 include Authorizer, SuperTokens and ZITADEL.
Is Supabase Auth actively maintained?
Yes. The most recent commit to Supabase Auth was on 2 October 2026, and the latest release is v2.197.0, published on 9 September 2026. The project has 2.6k stars on GitHub.

Open-source alternatives to Supabase Auth

See all

SaaS alternatives to Supabase Auth

See all