Auth & Identity
Identity, solved.
34 auth capabilities through the ee.auth face. Users, sessions, permissions, federation — every identity pattern, zero configuration.
34
Auth capabilities
40+
OAuth providers
0
Passwords required
<15ms
Token verification
Capabilities
Single Sign-On (SSO)
SAML 2.0 and OIDC federation with any identity provider. One-click setup for Google, Microsoft, Okta.
Multi-Factor Auth (MFA)
TOTP, SMS, email, WebAuthn, and hardware key support. Configurable enforcement per role or action.
Role-Based Access (RBAC)
Hierarchical roles with granular permissions. Tenant-scoped, inherited, and custom role definitions.
Session Management
Secure session tokens with configurable TTL, device tracking, and concurrent session limits.
API Keys
Scoped API keys with rate limits, IP allowlists, and automatic rotation schedules.
OAuth Providers
Pre-built OAuth flows for 40+ providers: GitHub, Google, Apple, Discord, LinkedIn, and more.
JWT Management
Issue, verify, and rotate JWTs with custom claims, key rotation, and configurable algorithms.
SAML Federation
Full SAML 2.0 service provider and identity provider support for enterprise SSO.
Passwordless Auth
Magic links, one-time codes, and WebAuthn passkey flows. No passwords to leak.
Code Example
User to session in three calls.
import { ee } from "@vertebase/sdk";
// Create a user with passwordless auth
const { data: user } = await ee.auth.createUser({
email: "ada@example.com",
method: "magic-link",
roles: ["editor"],
metadata: { team: "engineering" },
});
// Verify a session token (e.g. in middleware)
const { data: session } = await ee.auth.verifySession({
token: request.headers.get("Authorization"),
requiredRoles: ["editor"],
});
console.log(session.user.email); // => "ada@example.com"
console.log(session.expiresAt); // => "2024-11-01T00:00:00Z"