<authui />

AuthStore

Every operation the components use, available for headless integrations.

import { authStore } from "@getauthui/core";

All methods reject with the original AppwriteException and emit an error event before rethrowing. Use describeError(err, authStore.getStrings()) for a user-facing message.

State

MethodReturns
configure(config)void. Also runs handleRedirect() then refresh().
getState()AuthUIState
getConfig()AuthUIConfig | null
getClient()Client | null
getAccount()Account | null, the service every method above calls
getStrings()merged AuthUIStrings
refresh()Promise<void>. Re-fetches the user and derives status.
on(event, listener)unsubscribe function
getActiveTeamId()string | null. Local active team id for the project.
setActiveTeam(team)void. Remember { $id, name } or null; emits active-team. Does not call Appwrite.
listTeams()Promise<Models.Team[]>. Teams the signed-in user belongs to; empty when signed out or in preview. What show-teams on the user button uses.
createTeam(name)Promise<Models.Team>. Creates a team; the signed-in user becomes owner.
listTeamMemberships(teamId)Promise<Models.Membership[]>. Members of a team.
createTeamMembership(teamId, email, roles?)Invite by email. Redirect URL uses authui=team-invite.
deleteTeamMembership(teamId, membershipId)Leave or remove a member.
leaveTeam(teamId)Leave as the signed-in user.
acceptTeamInvite(teamId, membershipId, userId, secret)Accept invite via teams.updateMembershipStatus (also opens a session).
listConsentTokens(consentId) / deleteConsentToken(consentId, tokenId)Per-device token families under an OAuth2 consent.
previewSignIn()Promise<void>. Preview mode only: sign the sample user in without a form. Also on AuthUI.
notifyConfigIncomplete()void. Called by <authui-config> when endpoint or project is missing; clears loading and sets configError.
reset()void. Test helper: clear client, config, state and listeners.

Sign in

MethodDescription
signInWithEmailPassword(email, password)createEmailPasswordSession
signUp(email, password, name?)create then createEmailPasswordSession
signInAnonymously()createAnonymousSession
signInWithOAuth(provider)createOAuth2Token; navigates away
sendMagicUrl(email)createMagicURLToken; returns the token with its phrase
sendEmailOtp(email)createEmailToken
sendPhoneOtp(phone)createPhoneToken
signInWithToken(userId, secret)createSession; redeems any token
createIdTokenSession({ provider, idToken, nonce?, accessToken?, accessTokenExpiry?, name? })Native OIDC ID token session (Capacitor / WebView / One Tap bridges). Soft-detects missing routes. Not a sign-in button.
signOut(sessionId = "current")deleteSession
signOutEverywhere()deleteSessions

MFA

MethodDescription
listMfaFactors()factors available to the account
createMfaChallenge(factor)factor is totp, email, phone or recoverycode
completeMfaChallenge(challengeId, otp, { signIn })verify; with signIn: false it acts as a step-up only
setMfaEnabled(enabled)updateMFA
addAuthenticator()returns { secret, uri }
verifyAuthenticator(otp)activates the authenticator
removeAuthenticator()needs a recent challenge
createRecoveryCodes() / getRecoveryCodes() / regenerateRecoveryCodes()the last two need a recent challenge

Recovery and verification

MethodDescription
sendPasswordRecovery(email)prefers recovery OTP (createRecoveryOTP); falls back to a reset link when the route is missing. Returns { mode: "otp", token } or { mode: "link" }
completePasswordRecovery(userId, secret, password, { otp? })sets the new password via updateRecoveryOTP when otp: true, otherwise updateRecovery
sendEmailVerification()prefers email verification OTP; falls back to a verification link. Returns { mode: "otp", token } or { mode: "link" }
confirmEmailVerification(otp)updateEmailVerificationOTP
sendPhoneVerification() / confirmPhoneVerification(otp)SMS verification

Account

MethodDescription
updateName(name), updateEmail(email, password), updatePhone(phone, password), updatePassword(password, oldPassword?)profile updates
convertGuest(email, password, name?)upgrade an anonymous account
listSessions(), listIdentities(), deleteIdentity(id), listLogs(), listConsents(), deleteConsent(id), listConsentTokens(consentId), deleteConsentToken(consentId, tokenId)lists
deleteAccount()updateStatus; blocks the account and signs out

Redirects

MethodDescription
redirectUrl(action)the URL registered with Appwrite for a flow, with the authui marker
handleRedirect()finish a flow present in location.search (including team invites with or without authui=team-invite); returns true if one was handled
setPending(action)set or clear the pending action shown by the UI

On this page