Overview
Authentication module for managing user authentication and authorization. The module automatically stores tokens in local storage when available and manages authorization headers for API requests.Features
This module provides comprehensive authentication functionality including:- Email/password login and registration
- Token management
- User profile access and updates
- Password reset flows
- OTP verification
- User invitations
Authentication Modes
The auth module is only available in user authentication mode (base44.auth).
Methods
me()
me():Gets the current authenticated user’s information.Promise<User>
Returns
User
An authenticated user.
Properties
Properties
string
נדרש
Unique user identifier.
string
נדרש
When the user was created.
string
נדרש
When the user was last updated.
string
נדרש
User’s email address.
string | null
נדרש
User’s full name.
boolean | null
נדרש
Whether the user is disabled.
boolean
נדרש
Whether the user’s email has been verified.
string
נדרש
The app ID this user belongs to.
boolean
נדרש
Whether this is a service account.
string
נדרש
User’s role in the app. Roles are configured in the app settings and determine the user’s permissions and access levels.
any
Additional custom fields defined in the user schema. Any custom properties added to the user schema in the app will be available here with their configured types and values.
Example
updateMe()
updateMe(Updates the current authenticated user’s information. You can update any custom fields defined in your User entity schema. Updatingdata):Promise<User>
role requires editor access on the app.
These fields can’t be changed with this method:
id, email, full_name, created_date, updated_date, created_by,
and collaborator_role.Parameters
Record<string, any>
נדרש
Object containing the fields to update.
Returns
User
An authenticated user.
Properties
Properties
string
נדרש
Unique user identifier.
string
נדרש
When the user was created.
string
נדרש
When the user was last updated.
string
נדרש
User’s email address.
string | null
נדרש
User’s full name.
boolean | null
נדרש
Whether the user is disabled.
boolean
נדרש
Whether the user’s email has been verified.
string
נדרש
The app ID this user belongs to.
boolean
נדרש
Whether this is a service account.
string
נדרש
User’s role in the app. Roles are configured in the app settings and determine the user’s permissions and access levels.
any
Additional custom fields defined in the user schema. Any custom properties added to the user schema in the app will be available here with their configured types and values.
Example
redirectToLogin()
redirectToLogin(Redirects the user to the app’s login page. Redirects with a callback URL to return to after successful authentication. Requires a browser environment and can’t be used in the backend.nextUrl):void
Parameters
string
נדרש
URL to redirect to after successful login.
Returns
void
Throws
When not in a browser environment.Examples
loginWithProvider()
loginWithProvider(Redirects the user to a third-party authentication provider’s login page. Initiates an OAuth login flow with one of the built-in providers. Requires a browser environment and can’t be used in the backend. Supported providers:provider,fromUrl?):void
'google': Google OAuth. Enabled by default.'microsoft': Microsoft OAuth. Enable Microsoft in your app’s authentication settings before specifying this provider.'facebook': Facebook Login. Enable Facebook in your app’s authentication settings before using.'apple': Sign in with Apple. Enable Apple in your app’s authentication settings before using this provider.'sso': Enterprise SSO. Set up an SSO provider in your app’s authentication settings before using this provider.
Parameters
Properties
Properties
Returns
void
Examples
logout()
logout(Logs out the current user. Removes the authentication token from local storage and Axios headers, then optionally redirects to a URL or reloads the page. Requires a browser environment and can’t be used in the backend.redirectUrl?):void
Parameters
string
Optional URL to redirect to after logout. Reloads the page if not provided.
Returns
void
Examples
setToken()
setToken(Sets the authentication token. Updates the authorization header for API requests and optionally saves the token to local storage for persistence. Saving to local storage requires a browser environment and is automatically skipped in backend environments.token,saveToStorage?):void
Parameters
Properties
Properties
Returns
void
Examples
loginViaEmailPassword()
loginViaEmailPassword(Logs in a registered user using email and password. Authenticates a user with email and password credentials. The user must already have a registered account. For new users, use
password,
turnstileToken?
):Promise<LoginResponse>
register() first to create an account. On successful login, automatically sets the token for subsequent requests.
Parameters
Properties
Properties
string
נדרש
User’s email address.
string
נדרש
User’s password.
string
Optional Cloudflare Turnstile CAPTCHA token for bot protection.
Returns
LoginResponse
Response from login endpoints containing user information and access token.
Properties
Properties
string
נדרש
JWT access token for authentication.
User
נדרש
User information.
Properties
Properties
string
נדרש
Unique user identifier.
string
נדרש
When the user was created.
string
נדרש
When the user was last updated.
string
נדרש
User’s email address.
string | null
נדרש
User’s full name.
boolean | null
נדרש
Whether the user is disabled.
boolean
נדרש
Whether the user’s email has been verified.
string
נדרש
The app ID this user belongs to.
boolean
נדרש
Whether this is a service account.
string
נדרש
User’s role in the app. Roles are configured in the app settings and determine the user’s permissions and access levels.
Examples
isAuthenticated()
isAuthenticated():Checks if the current user is authenticated.Promise<boolean>
Returns
Promise<boolean>
Promise resolving to true if authenticated, false otherwise.
Example
inviteUser()
inviteUser(Invites a user to the app. Sends an invitation email to a potential user with a specific role. Roles are configured in the app settings and determine the user’s permissions and access levels.userEmail,role):Promise<any>
Parameters
Properties
Properties
Returns
Promise<any>
Promise that resolves when the invitation is sent successfully. Throws an error if the invitation fails.
Example
register()
register(Registers a new user account. Creates a new user account with email and password. Registration sends an OTP code to the user’s email. Pass that code toparams):Promise<any>
verifyOtp() to complete verification, then log the user
in with loginViaEmailPassword().
Parameters
RegisterParams
נדרש
Registration details including email, password, and optional fields.
Properties
Properties
Returns
Promise<any>
Promise resolving to the registration response.
Example
verifyOtp()
verifyOtp(Verifies an OTP (one-time password) code. Confirms that the user owns the email address by checking the code sent to their inbox duringparams):Promise<any>
register(). After a successful
call, log the user in with
loginViaEmailPassword(). If the code
has expired or the user didn’t receive it, send a fresh one with
resendOtp().
Parameters
VerifyOtpParams
נדרש
The email being verified and the OTP code the user entered.
Returns
Promise<any>
Promise resolving to the verification response, which includes an
access token for the now-verified user.
Throws
Error if the OTP code is invalid or expired.Examples
resendOtp()
resendOtp(Resends an OTP code to the user’s email address. Call this when the user didn’t receive the original code sent byPromise<any>
register(), or when the previous code has expired.
The new code replaces the previous one. Pass it to
verifyOtp() to complete verification.
Parameters
string
נדרש
Email address to send the new OTP to.
Returns
Promise<any>
Promise resolving once the new OTP has been sent, with a
confirmation message and the new code’s expiration window.
Throws
Error if the email is invalid or the request fails.Example
resetPasswordRequest()
resetPasswordRequest(Requests a password reset. Sends a password reset email to the specified email address.Promise<any>
Parameters
string
נדרש
Email address for the account to reset.
Returns
Promise<any>
Promise resolving when the password reset email is sent successfully.
Throws
Error if the email is invalid or the request fails.Example
resetPassword()
resetPassword(Resets password using a reset token. Completes the password reset flow by setting a new password using the token received by email.params):Promise<any>
Parameters
ResetPasswordParams
נדרש
Object containing the reset token and new password.
Returns
Promise<any>
Promise resolving when the password is reset successfully.
Throws
Error if the reset token is invalid, expired, or the request fails.Example
changePassword()
changePassword(Changes the user’s password. Updates the password for an authenticated user by verifying the current password and setting a new one.params):Promise<any>
Parameters
ChangePasswordParams
נדרש
Object containing user ID, current password, and new password.
Properties
Properties
Returns
Promise<any>
Promise resolving when the password is changed successfully.