Every way to sign in
Email and password, username, passwordless email codes, and Google, Microsoft, Apple, GitHub, Facebook, LinkedIn or X. One user either way.
What you get
Email and password, username, passwordless email codes, and Google, Microsoft, Apple, GitHub, Facebook, LinkedIn or X. One user either way.
Credential sign-ups confirm their email with a 6-digit code before a password works. Codes are hashed, short-lived and rate-limited.
user, support, admin and super-admin, expressed as resource:action keys your app can check with one call.
Organisations with owners and members. Every account belongs to UnityHUB (tid unityx), the default tenant.
HttpOnly cookie sessions with device, IP and approximate location. Users can sign any device out.
Sign-ins, resets, role changes and refused admin actions land in an append-only audit log.
How it fits
Users sign in on auth.unx.ng. Your app reads the session from a cookie on the same site, then asks UnityAuth what the user may do. Identity, sessions and tenants live in UnityAuth; your app keeps its own data, linked by immutable ids such as usr_… and org_….
// Same-origin fetch from your app's BFF or browser code
const res = await fetch("/v1/auth/get-session", { credentials: "include" });
const session = await res.json(); // { user, session } or null
if (!session) location.assign("https://auth.unx.ng/");Every endpoint, request body and error, on one page.
Open documentation