Skip to main content

Authentication sessions

TaruviBase's hosted pages handle sign-in, sign-up, logout, password reset, and invitation acceptance for your site, and create the user's browser session.

After sign-in, the hosted page returns the user to your app with the session token in the address fragment. The JavaScript SDK stores it when the client is created, or when you call Auth.handleRedirect() if you set detectSessionInUrl: false. See How browser sign-in works.

The Sign-up enabled security setting (security.signup-enabled) controls whether the hosted sign-up page is available. Two-factor authentication isn't available yet; the Enable 2FA setting currently has no effect.

An OpenID Connect provider can auto-redirect a hosted sign-in request. See OpenID Connect SSO to set it up.

For the operational paths and retry outcomes, use hosted sign-in.