Introduction
Auth UI is a drop-in authentication interface for Appwrite. One script tag gives you every sign-in method, MFA, session management and account settings as web components that run on your own domain.
What it is
Auth UI is a set of framework-agnostic web components built with Lit on top of the official Appwrite Web SDK. You add it to any page, point it at your Appwrite project, and get a complete, accessible, themeable authentication experience:
- Sign in and sign up with email and password, including password recovery.
- Passwordless sign in with magic URLs, email one-time codes and SMS codes.
- OAuth2 with every provider Appwrite supports, with brand icons for the common ones.
- Guest sessions that can later be upgraded to a full account.
- Multi-factor authentication: challenges during sign in, authenticator app enrollment with a QR code, recovery codes, and step-up verification for protected actions.
- Account management: profile, email and phone verification, password changes, active sessions, connected OAuth identities, a security log when the server exposes it, and account deletion.
- Modal, inline and headless usage, plus
<authui-show when="signed-in">for conditional content.
<link rel="stylesheet" href="https://unpkg.com/@getauthui/core@0.1.45/dist/fouc.css" />
<!-- ESM CDN: defines custom elements only (no window.AuthUI). -->
<script type="module" src="https://unpkg.com/@getauthui/core@0.1.45"></script>
<authui-config endpoint="https://cloud.appwrite.io/v1" project="YOUR_PROJECT_ID"></authui-config>
<authui-show when="signed-out"><authui-button>Sign in</authui-button></authui-show>
<authui-show when="signed-in"><authui-user-button></authui-user-button></authui-show>Why it runs on your domain
Earlier versions of Auth UI were a hosted login page on a separate domain. Browsers now block or partition third-party cookies, so a session created on one site cannot be read from another. Auth UI v2 runs inside your page instead. Its requests to Appwrite are indistinguishable from your own app's requests, so the session lands exactly where your app needs it. Read more in How it works.
What it's not
Auth UI is not a hosted identity provider and not a multi-backend auth kit. It does not:
- Replace Appwrite (or work with Clerk, Auth0, Supabase Auth, and so on)
- Run an Auth UI backend or a custom login domain
- Store or broker sessions off your origin
- Replace a fully custom form when you only need one Appwrite call
If you need those things, see the Comparison page. For Appwrite apps that want drop-in Lit components on your own domain, start with Getting started.