Options
All
  • Public
  • Public/Protected
  • All
Menu

Hierarchy

  • GoTrueClient

Index

Constructors

  • Create a new client for use in the browser.

    Parameters

    Returns GoTrueClient

Properties

__loadSession: any

NEVER USE DIRECTLY!

Always use {@link #_useSession}.

_acquireLock: any

Acquires a global lock based on the storage key.

_autoRefreshTokenTick: any

Runs the auto refresh token tick.

_callRefreshToken: any
_challenge: any

{@see GoTrueMFAApi#challenge}

_challengeAndVerify: any

{@see GoTrueMFAApi#challengeAndVerify}

_debug: any
_decodeJWT: any

Decodes a JWT (without performing any validation).

_emitInitialSession: any
_enroll: any

{@see GoTrueMFAApi#enroll}

_exchangeCodeForSession: any
_getAuthenticatorAssuranceLevel: any

{@see GoTrueMFAApi#getAuthenticatorAssuranceLevel}

_getSessionFromURL: any

Gets the session data from a URL string

_getUrlForProvider: any

Generates the relevant login URL for a third-party provider.

param options.redirectTo

A URL or mobile address to send the user to after they are confirmed.

param options.scopes

A space-separated list of scopes granted to the OAuth application.

param options.queryParams

An object of key-value pairs containing query parameters granted to the OAuth application.

_getUser: any
_handleProviderSignIn: any
_handleVisibilityChange: any

Registers callbacks on the browser / platform, which in-turn run algorithms when the browser window/tab are in foreground. On non-browser platforms it assumes always foreground.

_initialize: any

IMPORTANT:

  1. Never throw in this method, as it is called from the constructor
  2. Never return a session from this method as it would be cached over the whole lifetime of the client
_isImplicitGrantFlow: any

Checks if the current URL contains parameters given by an implicit oauth grant flow (https://www.rfc-editor.org/rfc/rfc6749.html#section-4.2)

_isPKCEFlow: any

Checks if the current URL and backing storage contain parameters given by a PKCE flow

_isValidSession: any
_listFactors: any

{@see GoTrueMFAApi#listFactors}

_notifyAllSubscribers: any
_onVisibilityChanged: any

Callback registered with window.addEventListener('visibilitychange').

_reauthenticate: any
_recoverAndRefresh: any

Recovers the session from LocalStorage and refreshes the token Note: this method is async to accommodate for AsyncStorage e.g. in React native.

_refreshAccessToken: any

Generates a new JWT.

param refreshToken

A valid refresh token that was returned on login.

_removeSession: any
_removeVisibilityChangedCallback: any

Removes any registered visibilitychange callback.

{@see #startAutoRefresh} {@see #stopAutoRefresh}

_saveSession: any

set currentSession and currentUser process to _startAutoRefreshToken if possible

_startAutoRefresh: any

This is the private implementation of {@link #startAutoRefresh}. Use this within the library.

_stopAutoRefresh: any

This is the private implementation of {@link #stopAutoRefresh}. Use this within the library.

_unenroll: any
_useSession: any

Use instead of {@link #getSession} inside the library. It is semantically usually what you want, as getting a session involves some processing afterwards that requires only one client operating on the session at once across multiple tabs or processes.

_verify: any

{@see GoTrueMFAApi#verify}

Namespace for the GoTrue admin methods. These methods should only be used in a trusted server-side environment.

autoRefreshTicker: null | Timer
autoRefreshToken: boolean
broadcastChannel: null | BroadcastChannel

Used to broadcast state change events to other tabs listening.

detectSessionInUrl: boolean
fetch: ((input: RequestInfo | URL, init?: RequestInit) => Promise<Response>)

Type declaration

    • (input: RequestInfo | URL, init?: RequestInit): Promise<Response>
    • Parameters

      • input: RequestInfo | URL
      • Optional init: RequestInit

      Returns Promise<Response>

flowType: AuthFlowType
hasCustomAuthorizationHeader: boolean
headers: {}

Type declaration

  • [key: string]: string
initializePromise: null | Promise<InitializeResult>

Keeps track of the async client initialization. When null or not yet resolved the auth state is unknown Once resolved the the auth state is known and it's save to call any further client methods. Keep extra care to never reject or throw uncaught errors

instanceID: any
lock: LockFunc
lockAcquired: boolean
logDebugMessages: boolean
logger: ((message: string, ...args: any[]) => void)

Type declaration

    • (message: string, ...args: any[]): void
    • Parameters

      • message: string
      • Rest ...args: any[]

      Returns void

memoryStorage: null | {}

Namespace for the MFA methods.

pendingInLock: Promise<any>[]
persistSession: boolean
refreshingDeferred: null | Deferred<CallRefreshTokenResult>
stateChangeEmitters: Map<string, Subscription>
storageKey: string

The storage key used to identify the values saved in localStorage

suppressGetSessionWarning: boolean
url: string
visibilityChangedCallback: null | (() => Promise<any>)
nextInstanceID: any

Methods

  • _refreshSession(currentSession?: { refresh_token: string }): Promise<AuthResponse>
  • Parameters

    • Optional currentSession: { refresh_token: string }
      • refresh_token: string

    Returns Promise<AuthResponse>

  • _setSession(currentSession: { access_token: string; refresh_token: string }): Promise<AuthResponse>
  • Parameters

    • currentSession: { access_token: string; refresh_token: string }
      • access_token: string
      • refresh_token: string

    Returns Promise<AuthResponse>

  • Parameters

    • Optional __namedParameters: SignOut

    Returns Promise<{ error: null | AuthError }>

  • Parameters

    • attributes: UserAttributes
    • Optional options: { emailRedirectTo?: string }
      • Optional emailRedirectTo?: string

    Returns Promise<UserResponse>

  • Log in an existing user by exchanging an Auth Code issued during the PKCE flow.

    Parameters

    • authCode: string

    Returns Promise<AuthTokenResponse>

  • getSession(): Promise<{ data: { session: AuthSession }; error: null } | { data: { session: null }; error: AuthError } | { data: { session: null }; error: null }>
  • Returns the session, refreshing it if necessary.

    The session returned can be null if the session is not detected which can happen in the event a user is not signed-in or has logged out.

    IMPORTANT: This method loads values directly from the storage attached to the client. If that storage is based on request cookies for example, the values in it may not be authentic and therefore it's strongly advised against using this method and its results in such circumstances. A warning will be emitted if this is detected. Use {@link #getUser()} instead.

    Returns Promise<{ data: { session: AuthSession }; error: null } | { data: { session: null }; error: AuthError } | { data: { session: null }; error: null }>

  • Gets the current user details if there is an existing session. This method performs a network request to the Supabase Auth server, so the returned value is authentic and can be used to base authorization rules on.

    Parameters

    • Optional jwt: string

      Takes in an optional access token JWT. If no JWT is provided, the JWT from the current session is used.

    Returns Promise<UserResponse>

  • getUserIdentities(): Promise<{ data: { identities: UserIdentity[] }; error: null } | { data: null; error: AuthError }>
  • Gets all the identities linked to a user.

    Returns Promise<{ data: { identities: UserIdentity[] }; error: null } | { data: null; error: AuthError }>

  • Initializes the client session either from the url or from storage. This method is automatically called when instantiating the client, but should also be called manually when checking for an error from an auth redirect (oauth, magiclink, password recovery, etc).

    Returns Promise<InitializeResult>

  • Links an oauth identity to an existing user. This method supports the PKCE flow.

    Parameters

    Returns Promise<OAuthResponse>

  • Sends a reauthentication OTP to the user's email or phone number. Requires the user to be signed-in.

    Returns Promise<AuthResponse>

  • refreshSession(currentSession?: { refresh_token: string }): Promise<AuthResponse>
  • Returns a new session, regardless of expiry status. Takes in an optional current session. If not passed in, then refreshSession() will attempt to retrieve it from getSession(). If the current session's refresh token is invalid, an error will be thrown.

    Parameters

    • Optional currentSession: { refresh_token: string }

      The current session. If passed in, it must contain a refresh token.

      • refresh_token: string

    Returns Promise<AuthResponse>

  • Resends an existing signup confirmation email, email change email, SMS OTP or phone change OTP.

    Parameters

    Returns Promise<AuthOtpResponse>

  • resetPasswordForEmail(email: string, options?: { captchaToken?: string; redirectTo?: string }): Promise<{ data: {}; error: null } | { data: null; error: AuthError }>
  • Sends a password reset request to an email address. This method supports the PKCE flow.

    Parameters

    • email: string

      The email address of the user.

    • Optional options: { captchaToken?: string; redirectTo?: string }
      • Optional captchaToken?: string

        Verification token received when the user completes the captcha on the site.

      • Optional redirectTo?: string

        The URL to send the user to after they click the password reset link.

    Returns Promise<{ data: {}; error: null } | { data: null; error: AuthError }>

  • setSession(currentSession: { access_token: string; refresh_token: string }): Promise<AuthResponse>
  • Sets the session data from the current session. If the current session is expired, setSession will take care of refreshing it to obtain a new session. If the refresh token or access token in the current session is invalid, an error will be thrown.

    Parameters

    • currentSession: { access_token: string; refresh_token: string }

      The current session that minimally contains an access token and refresh token.

      • access_token: string
      • refresh_token: string

    Returns Promise<AuthResponse>

  • Creates a new anonymous user.

    Parameters

    Returns Promise<AuthResponse>

    A session where the is_anonymous claim in the access token JWT set to true

  • Allows signing in with an OIDC ID token. The authentication provider used should be enabled and configured.

    Parameters

    Returns Promise<AuthTokenResponse>

  • Log in an existing user via a third-party provider. This method supports the PKCE flow.

    Parameters

    Returns Promise<OAuthResponse>

  • Log in a user using magiclink or a one-time password (OTP).

    If the {{ .ConfirmationURL }} variable is specified in the email template, a magiclink will be sent. If the {{ .Token }} variable is specified in the email template, an OTP will be sent. If you're using phone sign-ins, only an OTP will be sent. You won't be able to send a magiclink for phone sign-ins.

    Be aware that you may get back an error message that will not distinguish between the cases where the account does not exist or, that the account can only be accessed via social login.

    Do note that you will need to configure a Whatsapp sender on Twilio if you are using phone sign in with the 'whatsapp' channel. The whatsapp channel is not supported on other providers at this time. This method supports PKCE when an email is passed.

    Parameters

    Returns Promise<AuthOtpResponse>

  • Log in an existing user with an email and password or phone and password.

    Be aware that you may get back an error message that will not distinguish between the cases where the account does not exist or that the email/phone and password combination is wrong or that the account can only be accessed via social login.

    Parameters

    Returns Promise<AuthTokenResponsePassword>

  • Attempts a single-sign on using an enterprise Identity Provider. A successful SSO attempt will redirect the current page to the identity provider authorization page. The redirect URL is implementation and SSO protocol specific.

    You can use it by providing a SSO domain. Typically you can extract this domain by asking users for their email address. If this domain is registered on the Auth instance the redirect will use that organization's currently active SSO Identity Provider for the login.

    If you have built an organization-specific login page, you can use the organization's SSO Identity Provider UUID directly instead.

    Parameters

    Returns Promise<SSOResponse>

  • Inside a browser context, signOut() will remove the logged in user from the browser session and log them out - removing all items from localstorage and then trigger a "SIGNED_OUT" event.

    For server-side management, you can revoke all refresh tokens for a user by passing a user's JWT through to auth.api.signOut(JWT: string). There is no way to revoke a user's access token jwt until it expires. It is recommended to set a shorter expiry on the jwt for this reason.

    If using others scope, no SIGNED_OUT event is fired!

    Parameters

    Returns Promise<{ error: null | AuthError }>

  • Creates a new user.

    Be aware that if a user account exists in the system you may get back an error message that attempts to hide this information from the user. This method has support for PKCE via email signups. The PKCE flow cannot be used when autoconfirm is enabled.

    Parameters

    Returns Promise<AuthResponse>

    A logged-in session if the server has "autoconfirm" ON

  • startAutoRefresh(): Promise<void>
  • Starts an auto-refresh process in the background. The session is checked every few seconds. Close to the time of expiration a process is started to refresh the session. If refreshing fails it will be retried for as long as necessary.

    If you set the {@link GoTrueClientOptions#autoRefreshToken} you don't need to call this function, it will be called for you.

    On browsers the refresh process works only when the tab/window is in the foreground to conserve resources as well as prevent race conditions and flooding auth with requests. If you call this method any managed visibility change callback will be removed and you must manage visibility changes on your own.

    On non-browser platforms the refresh process works continuously in the background, which may not be desirable. You should hook into your platform's foreground indication mechanism and call these methods appropriately to conserve resources.

    {@see #stopAutoRefresh}

    Returns Promise<void>

  • stopAutoRefresh(): Promise<void>
  • Stops an active auto refresh process running in the background (if any).

    If you call this method any managed visibility change callback will be removed and you must manage visibility changes on your own.

    See {@link #startAutoRefresh} for more details.

    Returns Promise<void>

  • unlinkIdentity(identity: UserIdentity): Promise<{ data: {}; error: null } | { data: null; error: AuthError }>
  • Unlinks an identity from a user by deleting it. The user will no longer be able to sign in with that identity once it's unlinked.

    Parameters

    Returns Promise<{ data: {}; error: null } | { data: null; error: AuthError }>

  • Updates user data for a logged in user.

    Parameters

    • attributes: UserAttributes
    • Optional options: { emailRedirectTo?: string }
      • Optional emailRedirectTo?: string

    Returns Promise<UserResponse>

  • Log in a user given a User supplied OTP or TokenHash received through mobile or email.

    Parameters

    Returns Promise<AuthResponse>

Generated using TypeDoc