Passwordless
- Email OTPBuilt-in delivery
- SMS OTPGlobal coverage
- WhatsApp OTPPreview
Users pick the channel that works for them. Codes expire, retries are limited, and delivery failures show a clear message.
NewWhatsApp OTP in developer preview
Add sign-in to your apps with passwordless OTP over email, SMS or WhatsApp, passwords and social login. Isolated user pools per Realm.
npm install @nexaauth/react
Authentication methods
Turn methods on or off from the console. Your hosted sign-in page updates automatically and only shows what's enabled.
Users pick the channel that works for them. Codes expire, retries are limited, and delivery failures show a clear message.
Classic credentials with a reset flow that never reveals whether an account exists.
Bring your own OAuth credentials and enable providers one by one.
Delivery channels
Each verification code travels over a channel: email, SMS or WhatsApp. You choose which channels are available per Realm, and your users choose the one they prefer at sign-in.
Codes sent from your own verified domain, so messages come from your brand.
Text messages to any mobile number, with your company name as the sender.
Codes delivered in WhatsApp, where many users already spend their day.
Only enabled channels are shown on the sign-in page.
If a code doesn't arrive, users resend it or change method.
Track delivery rate and failures for each channel in the console.
Developers
Create an Application, copy its Client ID, drop in the SDK. Use the hosted pages or build your own UI on the same API.
An isolated user pool, provisioned in seconds.
SPA, server-side, mobile or machine-to-machine.
JavaScript, React, Next.js and TanStack Start.
JavaScript
import { NexaAuth } from "@nexaauth/js";
const nexa = new NexaAuth({
clientId: "6f2a9c1e-88b1",
});
await nexa.signIn.withOtp({
identifier: "marie@acme.com",
channel: "email",
});React
import { NexaAuthProvider, SignIn } from "@nexaauth/react";
export default function App() {
return (
<NexaAuthProvider clientId="6f2a9c1e-88b1">
<SignIn />
</NexaAuthProvider>
);
}Next.js
// app/api/auth/[...nexa]/route.ts
import { NexaAuth } from "@nexaauth/next";
export const { GET, POST } = NexaAuth({
clientId: process.env.NEXA_CLIENT_ID,
});TanStack Start
// app.config.ts
import { nexaAuthPlugin } from "@nexaauth/tanstack-start";
export default defineConfig({
plugins: [nexaAuthPlugin({ clientId: "6f2a9c1e-88b1" })],
});How it's organized
Your company account. Team members, billing and environments live here.
An isolated user pool with its own users, settings and keys. Separate Realms never share users.
An app client inside a Realm. Your web and mobile apps in the same Realm share one set of users.
Console
Provider status, OTP delivery rate and auth success rate per Realm, with Production and Sandbox kept apart.
Realm ID: rlm_8f2c4a91e0
For CTOs & security teams
Every Realm is its own user pool, so isolation is structural, not a filter in a query.
A dedicated user pool per Realm. Users never leak between brands or products.
Production and Sandbox are kept apart, with their own Realms and credentials.
Every sign-in, config change and admin action is logged and searchable.
Email, SMS and WhatsApp codes sent for you, with delivery status per channel.
Pricing
Build and test at no cost. When you're ready for production scale, we'll put together a plan that fits your volume.
$0
Everything you need to build and test.
Custom
For teams running identity in production.
A Realm is an isolated pool of users, with its own users, settings and keys. Applications in the same Realm share users; separate Realms never do. Use one Realm per brand or product line that needs its own user base.
Yes. Use the hosted pages to get started quickly, or build your own screens with the SDK and API. Both use the same Realm configuration.
WhatsApp OTP is currently in developer preview and only delivers to registered test numbers. Email and SMS OTP are available in production.
JavaScript, React, Next.js and TanStack Start today. The REST API works from any backend.
Each environment has its own Realms, Applications and credentials, so testing never touches real users.
Start building for free, or talk to us about your production needs.