Authentication sessions
TaruviBase's hosted pages handle sign-in, sign-up, logout, password reset, and invitation acceptance for your site, and create the user's browser session.
After sign-in, the hosted page returns the user to your app with the session
token in the address fragment. The JavaScript SDK stores it when the client is
created, or when you call Auth.handleRedirect() if you set
detectSessionInUrl: false. See
How browser sign-in works.
The Sign-up enabled security setting (security.signup-enabled) controls
whether the hosted sign-up page is available. Two-factor authentication isn't
available yet; the Enable 2FA setting currently has no effect.
An OpenID Connect provider can auto-redirect a hosted sign-in request. See OpenID Connect SSO to set it up.
For the operational paths and retry outcomes, use hosted sign-in.