Sign-in methods
What each method does, what Appwrite needs for it, and how the user experiences it.
Email and password
The default. The sign-in screen shows email and password fields with a "Forgot password?" link and, when signUp is enabled, a link to the sign-up screen. Sign up creates the account with account.create() and immediately signs in. Set identifierFirst to split sign-in into email → Continue → password (see below); sign-up stays one step.
Password rules come from your project: minimum length, dictionary check, personal data check, password history and the breached-password check are all enforced by Appwrite. Auth UI maps each rejection to a specific message.
Password recovery prefers an in-panel OTP (createRecoveryOTP / updateRecoveryOTP) when the Appwrite server supports it: the user enters a code, then a new password. On older servers the UI falls back to createRecovery() and emails a link that opens the Reset password screen. Deep links with userId and secret still complete via updateRecovery.
Magic URL
The user enters an email and receives a link. Opening the link on the same device signs them in. Auth UI requests a security phrase by default and shows it under the confirmation, so the user can check that the email they received is the one they asked for. Disable it with securityPhrase: false.
Email OTP
The user enters an email and receives a six-digit code, then types it into Auth UI. No page navigation involved, which makes it a good fit for mobile web. The security phrase is shown here too.
Phone
The phone step includes a country dial-code picker and a national number field. Auth UI composes an E.164 value for Appwrite, then the user receives an SMS code and types it in. The default country follows navigator.language when possible, otherwise +1. Appwrite needs an SMS provider configured under Messaging. On Appwrite Cloud, phone authentication is metered.
Anonymous (guest)
Creates a session without any identifier. The account screen detects guest accounts and offers a Create your account form that attaches an email and password to the same user with account.updateEmail(), so any data they created stays with them.
OAuth2
Each provider you list renders a "Continue with ..." button with a brand icon for the common providers and a generic one for the rest. Clicking it redirects to the provider using Appwrite's token endpoint and returns to your redirectUrl, where Auth UI exchanges the token for a session.
Configure the provider's client ID and secret in the Appwrite Console under Auth → Settings, and add the callback URL Appwrite shows there to the provider's own configuration.
Signed-in users can connect additional providers from the Connections tab of the account screen and disconnect them again. Third-party apps the user has authorized appear under Authorized apps (OAuth2 consents) when the server exposes /account/consents.
Google One Tap
Optional auto-prompt on signed-out sign-in and sign-up mounts. Enable with oneTap: true and pass your Google OAuth Web client ID as googleClientId (from Google Cloud Console → Credentials). Appwrite stores Google provider secrets server-side and does not expose them to the browser, so the client ID must be set explicitly.
<authui-config
endpoint="https://cloud.appwrite.io/v1"
project="YOUR_PROJECT_ID"
methods="email-password oauth:google"
one-tap="true"
google-client-id="YOUR_GOOGLE_WEB_CLIENT_ID.apps.googleusercontent.com"
></authui-config>Auth UI loads https://accounts.google.com/gsi/client once, generates a cryptographically random nonce per prompt, passes it to google.accounts.id.initialize, and on credential forwards the ID token plus the same raw nonce into createIdTokenSession({ provider: "google", idToken, nonce }) (required by Appwrite when the JWT carries a nonce claim). The token and nonce are discarded after the session call. Keep oauth:google as a visible fallback: One Tap is passive and browsers may hide it (FedCM cool-down, dismissed, third-party cookies). Soft-fails never break email/password or OAuth buttons. Requires project via Client (appwrite@28 ships native createIdTokenSession with X-Appwrite-Project; REST fallback still sends it for older SDKs).
CSP: allow https://accounts.google.com in script-src and frame-src (and often connect-src). See Security notes.
Manual QA: signed-out mount with Google account in the browser → One Tap chrome appears → credential creates an Appwrite session. Dismiss or block GIS → form still works. Missing googleClientId → console warning, no prompt.
Native ID token (bridges)
For Capacitor, WebView or custom One Tap bridges, call authStore.createIdTokenSession({ provider, idToken, nonce?, accessToken?, accessTokenExpiry?, name? }) after the native SDK returns an OIDC JWT. The built-in oneTap attribute covers the browser GIS prompt; use this API for native shells. Soft-detects missing routes on older Appwrite.
Identifier-first sign-in
When identifierFirst is true (attribute identifier-first), sign-in shows email → Continue → password instead of both fields at once. OAuth, magic URL, email OTP, phone and guest stay on step 1. The password step shows the email (read-only), password, Sign in, and a "Use a different email" control. Sign-up keeps email and password together so account creation stays a single form. Pure client progressive disclosure; no Appwrite user-lookup API.
MFA
Not a method on its own. When an account has MFA enabled, every method above is followed by a second-factor challenge. See Multi-factor authentication.