<authui />

Security notes

What Auth UI does and does not do with credentials and sessions.

Auth UI sign-in modal talking to your Appwrite endpoint from the page origin

  • No credentials leave your origin except to Appwrite. Passwords, codes and tokens go straight from the browser to your configured endpoint through the official SDK. Auth UI has no backend and phones home to nothing.
  • Sessions are managed by the Appwrite SDK. Auth UI never reads, stores or forwards the session secret. Whether it is a cookie or the SDK's localStorage fallback depends on your Appwrite setup, exactly as it would without Auth UI.
  • Redirect URLs are cleaned. After finishing an OAuth, magic URL, recovery or verification flow, Auth UI removes userId, secret and related parameters from the address bar before rendering.
  • Redirect targets are validated by Appwrite. Every URL Auth UI registers with Appwrite must be on a platform you configured in the Console, so tokens cannot be sent to an attacker's site.
  • OAuth uses the token flow. The provider returns a one-time token that the page redeems immediately; no session is created on a redirect.
  • MFA is enforced server side. Auth UI only renders what Appwrite requires. Protected actions that need a fresh factor trigger an inline challenge.
  • Content Security Policy. With npm the library is part of your bundle and needs no extra script-src. For the CDN, allow the script and stylesheet host (docs pin https://unpkg.com) and your Appwrite endpoint:
Content-Security-Policy:
  default-src 'self';
  script-src 'self' https://unpkg.com https://accounts.google.com;
  connect-src 'self' https://cloud.appwrite.io https://*.cloud.appwrite.io https://fra.cloud.appwrite.io https://accounts.google.com;
  style-src 'self' https://unpkg.com;
  img-src 'self' data: https:;
  frame-src https://accounts.google.com;

When Google One Tap is enabled (oneTap / one-tap), allow https://accounts.google.com in script-src, frame-src and typically connect-src. Without One Tap you can keep frame-src 'none' and omit the Google hosts from script-src / connect-src.

Replace the connect-src hosts with your Appwrite endpoint's origin. Allowlist the CDN host you pin in both script-src and style-src, or self-host fouc.css under 'self' and omit the CDN from style-src. The in-module FOUC guard uses document.adoptedStyleSheets (CSP-exempt). Browsers without constructable stylesheets fall back to an inline <style> tag and need style-src 'unsafe-inline' for that fallback and for Lit's own fallback. Prefer the shipped fouc.css in your page <head> (see <authui-show>); load it as a static stylesheet and drop 'unsafe-inline' from style-src if you can.

  • Pin versions in production. Use @getauthui/core@0.1.45 (or newer) on the CDN, or install from npm, so a release cannot change your login flow without a deploy.