Logins, signups, social OAuth, MFA, roles, and invites, built in.
The Analytics tab in your Auth section shows how your user base is doing: how many people sign up, how many come back, how they log in, and the most common login problems. Nothing to set up.
Full audit trail of auth events, logins, signups, role changes, MFA enrollment, failed attempts. Useful for debugging or compliance review.
Keeps bots off your sign in, sign up, and password reset screens. Turn it on in Auth, Settings and we handle the rest. Most real visitors pass without seeing a puzzle.
Sign in with email and password, or with a magic link, comes ready to use. Forgot password is built into the same sign-in form: your users enter their email, get a code, and set a new password without leaving the page.
User accounts are part of every project from the start, so there is nothing to build and nothing to pay for. Use them when your app needs them, or leave them out and keep your app fully public.
Define roles (admin, customer, driver, etc.) and assign them to end-users. Roles are available to your app code as claims on the auth session. Configure in Auth → Roles.
Minimum password strength, rotation rules, and multi-factor authentication (TOTP). Configured in Auth → Credentials. MFA enrollment UI is built into the platform, no code needed.
Set how long users stay logged in and whether remember-me is enabled. Configured in Auth → Settings, enforced server-side by the platform.
Control who can sign up: open registration, invite-only, email domain allowlists, required email verification. Configured in Auth → Settings, applied automatically across all login methods.
OAuth social login is built into DontCode. Users toggle providers in Auth → OAuth, no integration code, env keys, webhook secrets, or callback handlers needed. The platform manages keys, redirect URIs, and token exchange.
Send token-based invitations to end-users with a preassigned role. Recipients click the link and complete signup. Configured in Auth → People.