The short answer
To add login to your app, tell your connected coding agent to switch on sign-in. Antideploy turns on an authentication service for your app, so your users can sign up and sign in with an email and a password. Their accounts are rows in a neon_auth schema of your own Postgres database. There is no authentication provider to open an account with.
Say this to your coding agent
Add sign-up and sign-in to this project, with users stored in my database.
If your agent is not connected yet, paste this first: Set this project up to deploy on Antideploy. Fetch https://antideploy.com/agent.md and follow it.
What your agent does
-
It switches sign-in on before it writes the login page
So the form is built and tested against the real service. If your app has no database yet, one is created first, and it counts against your database allowance.
-
It writes the variables into your
.envThey go in through a redirect that never prints them, because the cookie secret is among them.
-
Your app's address is registered for you
Localhost works while you build. Your app's address and any custom domain are registered as trusted origins when sign-in is switched on, on every deploy, and when a domain is added. A request from an origin nobody registered is refused.
How your code uses it
In Next.js, install Neon's auth library and follow Neon's quickstart. The two variables it asks for are already set. The library is a beta, so the quickstart is the source of truth for its code. In any other stack, it is Better Auth over plain HTTP at NEON_AUTH_BASE_URL.
POST /sign-up/email {"email", "password", "name"}
POST /sign-in/email {"email", "password"}
GET /get-session the signed-in user, from the cookie
GET /token a JWT; verify it with NEON_AUTH_JWKS_URL
A request that changes anything needs an Origin header that is your app's own address. A separate backend can verify the JWT against the public keys at NEON_AUTH_JWKS_URL.
What is on and what is not
- Email and password sign-in: on
- Email verification: off, which suits a first version
- Google and GitHub sign-in: not set up, because they need an OAuth app of your own
- Session cookie:
HttpOnlyandSecure, set by the service itself - Rate limit: about nine sign-up or sign-in attempts per ten seconds from one address, then a 429