Email and password sign-up with email verification
Email/password authentication in ShipAny with better-auth — enabled by default, with optional email verification, password reset and invite-code-only sign-up.
Last updated: Oct 8, 2026
Email and password sign-up works in every ShipAny project from the first run — no third-party service needed. Turn on verification when you're ready to stop fake sign-ups.
What ShipAny handles
- Sign-up and sign-in with hashed passwords, powered by better-auth.
- Email verification (optional): new users get a verification link that expires after 24 hours; resending is rate-limited to once per 60 seconds.
- Password reset, available automatically once an email provider is configured.
- Invite-code-only sign-up (optional) for private betas.
- Sign-up credits and roles: optionally grant welcome credits and a default role to every new user.
Setup
- Email/password is on by default (
email_auth_enabled). Toggle it in Admin → Settings → Auth → Email Auth. - To require verification, first configure an email provider — Resend or Cloudflare Email — then switch on Require email verification on sign up.
- For a private beta, switch on Require invite code on sign up.
- Under Settings → General, optionally enable Grant credits on signup and Auto-assign role for new users.
Tips
- Without verification, anyone can register any address (including ones that can't receive mail). Turn it on before you offer free credits on sign-up.
- Configure another login method before disabling email auth, or nobody — including you — can sign in.
- Make your first account a super admin right after sign-up so you can reach the admin panel.
