NexaAuth

NewWhatsApp OTP in developer preview

Customer identity, built for developers.

Add sign-in to your apps with passwordless OTP over email, SMS or WhatsApp, passwords and social login. Isolated user pools per Realm.

npm install @nexaauth/react

Illustration of sign-in: choose Email, SMS or WhatsApp (Preview), enter a six-digit code, then sign in. No code is sent.

Authentication methods

Every sign-in method your users expect, configured per Realm.

Turn methods on or off from the console. Your hosted sign-in page updates automatically and only shows what's enabled.

Passwordless

  • Email OTPBuilt-in delivery
  • SMS OTPGlobal coverage
  • WhatsApp OTPPreview

Users pick the channel that works for them. Codes expire, retries are limited, and delivery failures show a clear message.

Password

  • Email + password
  • Phone + password
  • Forgot & reset password

Classic credentials with a reset flow that never reveals whether an account exists.

Social

  • Google
  • Apple
  • Facebook

Bring your own OAuth credentials and enable providers one by one.

On the roadmap:PasskeysTOTPMFAEnterprise SSO

Delivery channels

Send codes where your users actually are.

Each verification code travels over a channel: email, SMS or WhatsApp. You choose which channels are available per Realm, and your users choose the one they prefer at sign-in.

Email

Available

Codes sent from your own verified domain, so messages come from your brand.

  • Custom sender address
  • Domain verification (SPF, DKIM)
  • Test send from the console

SMS

Available

Text messages to any mobile number, with your company name as the sender.

  • Branded sender ID
  • Sandbox and production modes
  • Test send from the console

WhatsApp

Preview

Codes delivered in WhatsApp, where many users already spend their day.

  • Approved message template
  • Your WhatsApp Business number
  • Test numbers during preview

User picks the channel

Only enabled channels are shown on the sign-in page.

Switch channel anytime

If a code doesn't arrive, users resend it or change method.

Delivery status per channel

Track delivery rate and failures for each channel in the console.

Developers

From zero to a working sign-in in a few lines.

Create an Application, copy its Client ID, drop in the SDK. Use the hosted pages or build your own UI on the same API.

  1. Create a Realm

    An isolated user pool, provisioned in seconds.

  2. Add an Application

    SPA, server-side, mobile or machine-to-machine.

  3. Install the SDK

    JavaScript, React, Next.js and TanStack Start.

JavaScript

import { NexaAuth } from "@nexaauth/js";

const nexa = new NexaAuth({
  clientId: "6f2a9c1e-88b1",
});

await nexa.signIn.withOtp({
  identifier: "marie@acme.com",
  channel: "email",
});

React

import { NexaAuthProvider, SignIn } from "@nexaauth/react";

export default function App() {
  return (
    <NexaAuthProvider clientId="6f2a9c1e-88b1">
      <SignIn />
    </NexaAuthProvider>
  );
}

Next.js

// app/api/auth/[...nexa]/route.ts
import { NexaAuth } from "@nexaauth/next";

export const { GET, POST } = NexaAuth({
  clientId: process.env.NEXA_CLIENT_ID,
});

TanStack Start

// app.config.ts
import { nexaAuthPlugin } from "@nexaauth/tanstack-start";

export default defineConfig({
  plugins: [nexaAuthPlugin({ clientId: "6f2a9c1e-88b1" })],
});

How it's organized

A clear model for multi-product, multi-brand identity.

  1. Tenant

    Your company account. Team members, billing and environments live here.

  2. Realm

    An isolated user pool with its own users, settings and keys. Separate Realms never share users.

  3. Application

    An app client inside a Realm. Your web and mobile apps in the same Realm share one set of users.

Console

See which Realm, which app, which methods — at a glance.

Provider status, OTP delivery rate and auth success rate per Realm, with Production and Sandbox kept apart.

Production Realm

ActiveProduction

Realm ID: rlm_8f2c4a91e0

Applications
2
Active sessions
342
Auth success
99.2%
OTP delivery
97.8%
  • Email OTPEnabled
  • SMS OTPEnabled
  • WhatsApp OTPPreview

For CTOs & security teams

Infrastructure you can reason about.

Every Realm is its own user pool, so isolation is structural, not a filter in a query.

Isolated user pools

A dedicated user pool per Realm. Users never leak between brands or products.

Separate environments

Production and Sandbox are kept apart, with their own Realms and credentials.

Audit logs

Every sign-in, config change and admin action is logged and searchable.

Managed deliveryWhatsApp Preview

Email, SMS and WhatsApp codes sent for you, with delivery status per channel.

Book a demoRead the architecture docs

Pricing

Start free. Talk to us when you grow.

Build and test at no cost. When you're ready for production scale, we'll put together a plan that fits your volume.

Free

$0

Everything you need to build and test.

  • Realms & Applications
  • Email & SMS OTP, password, social login
  • Hosted sign-in pages
  • Production & Sandbox environments
Start for free

Business

Custom

For teams running identity in production.

  • Pricing based on your volume
  • WhatsApp OTP Preview
  • Enterprise SSO & custom domains
  • SLA & dedicated support
Book a demo

Questions

A Realm is an isolated pool of users, with its own users, settings and keys. Applications in the same Realm share users; separate Realms never do. Use one Realm per brand or product line that needs its own user base.

Yes. Use the hosted pages to get started quickly, or build your own screens with the SDK and API. Both use the same Realm configuration.

WhatsApp OTP is currently in developer preview and only delivers to registered test numbers. Email and SMS OTP are available in production.

JavaScript, React, Next.js and TanStack Start today. The REST API works from any backend.

Each environment has its own Realms, Applications and credentials, so testing never touches real users.

Ship sign-in this afternoon.

Start building for free, or talk to us about your production needs.