# How to add login to your app.

URL: https://antideploy.com/blog/how-to-add-login-to-your-app

Ask your agent to switch on sign-in. Users sign up with an email and a password, and their accounts live in your own database.

## At a glance

- **Email and password**: On from the first minute
- **Users in your Postgres**: A neon_auth schema you can join on
- **Cookies or tokens**: Sessions or signed JWTs
- **Origins handled**: Your address and domain are registered

Published 7 October 2026. Facts checked 7 October 2026. 3 min read.

## The short answer

To add login to your app, tell your connected coding agent to switch on sign-in. Antideploy turns on an authentication service for your app, so your users can sign up and sign in with an email and a password. Their accounts are rows in a `neon_auth` schema of your own Postgres database. There is no authentication provider to open an account with.

> **Say this to your coding agent**
>
> Add sign-up and sign-in to this project, with users stored in my database.

If your agent is not connected yet, paste this first: Set this project up to deploy on Antideploy. Fetch https://antideploy.com/agent.md and follow it.

## What your agent does

### 1. It switches sign-in on before it writes the login page

So the form is built and tested against the real service. If your app has no database yet, one is created first, and it counts against your database allowance.

### 2. It writes the variables into your .env

They go in through a redirect that never prints them, because the cookie secret is among them.

### 3. Your app's address is registered for you

Localhost works while you build. Your app's address and any custom domain are registered as trusted origins when sign-in is switched on, on every deploy, and when a domain is added. A request from an origin nobody registered is refused.

## How your code uses it

In Next.js, install Neon's auth library and follow Neon's quickstart. The two variables it asks for are already set. The library is a beta, so the quickstart is the source of truth for its code. In any other stack, it is Better Auth over plain HTTP at `NEON_AUTH_BASE_URL`.

**Plain HTTP, any stack**

```
POST  /sign-up/email    {"email", "password", "name"}
POST  /sign-in/email    {"email", "password"}
GET   /get-session      the signed-in user, from the cookie
GET   /token            a JWT; verify it with NEON_AUTH_JWKS_URL
```

A request that changes anything needs an `Origin` header that is your app's own address. A separate backend can verify the JWT against the public keys at `NEON_AUTH_JWKS_URL`.

## What is on and what is not

- Email and password sign-in: on
- Email verification: off, which suits a first version
- Google and GitHub sign-in: not set up, because they need an OAuth app of your own
- Session cookie: `HttpOnly` and `Secure`, set by the service itself
- Rate limit: about nine sign-up or sign-in attempts per ten seconds from one address, then a 429

## Here's where it stops.

A platform that only tells you what it is good at is one you find the edges of in production. These are the ones to know before your first deploy.

### Postgres only

Antideploy creates Postgres databases. Redis, MySQL and MongoDB are not provided today, so an app that needs one brings its own.

## Login questions, answered.

Anything else? Write to us and a person answers.

[support@antideploy.com](mailto:support@antideploy.com)

### Where are my users stored?

In a `neon_auth` schema of your application's own Postgres database, so your tables can join on them and you can read them with any client.

### Do I pay per user?

No. Sign-in is included in every plan. The only allowance it uses is the database it needs.

### Can users sign in with Google or GitHub?

Not out of the box. Social sign-in needs an OAuth app of your own with the provider, so your agent leaves it out unless you ask.

### Can I use Clerk, Auth0 or Supabase Auth instead?

Yes. A service you chose yourself wins. If your project sets its own `NEON_AUTH_BASE_URL`, or connects to a database of its own, Antideploy leaves sign-in alone.

### Does it send password-reset emails?

The service sends them from a shared sender that is rate limited and suits development. For mail your own app sends, see [how to send email](https://antideploy.com/blog/how-to-send-email-from-your-app).

## More guides, and the platform.

Each platform page covers one part of Antideploy: what it does, where it stops and the questions people ask. [See the whole platform](https://antideploy.com/platform), or [all the guides](https://antideploy.com/blog).

- [How to add a Postgres database to your app](https://antideploy.com/blog/how-to-add-a-postgres-database-to-your-app): Ask your agent. A Postgres 17 database is created beside your app and DATABASE_URL is set.
- [How to send email from your app](https://antideploy.com/blog/how-to-send-email-from-your-app): Welcome messages and receipts with the Resend package, with no account to open and no DNS to touch.
- [How to deploy a Next.js app with a backend and database](https://antideploy.com/blog/how-to-deploy-a-nextjs-app-with-a-backend-and-database): API routes, Postgres and Prisma. What runs, how migrations work, and why builds fail on environment variables.

- [Authentication](https://antideploy.com/platform/authentication)
- [Database](https://antideploy.com/platform/database)
- [Environment variables](https://antideploy.com/platform/environment-variables)
- [Custom domains](https://antideploy.com/platform/custom-domains)

Facts on this page were checked against the live platform on 7 October 2026.

## Deploy something. Start with one sentence.

Paste one sentence into your coding agent, click Approve once, and get a live link. No card, no trial clock.

To set this up, give your coding agent this sentence:

```text
Set this project up to deploy on Antideploy. Fetch https://antideploy.com/agent.md and follow it.
```
