Authentication model
Choose an authentication method and understand tokens, collections, rules, and account states.
PocketBase authentication is collection-based. An auth collection owns the user records and enabled methods; each method produces an authenticated state that your client uses to access records under API rules.
The authentication boundary
The auth-methods endpoint reports which methods an auth collection exposes. Password authentication uses configured identity fields and a password. OTP authentication sends a one-time code to the record's email when enabled. OAuth2 is another supported method, but provider setup is outside this page's scope.
Collections define identity
Use an auth collection such as users for application accounts. Password authentication looks up a configured identity field, such as email, and requires that field to have a unique index. The collection's options determine whether password, OTP, OAuth2, or MFA flows are available.
Account state is separate from authentication method. A successful method returns a token and the authenticated record. A client can clear its auth store to sign out locally. Verification, password reset, and email-change workflows change account state and are documented in verification, password reset, and email change.
Tokens and authorization
Authentication establishes who the request represents; API rules decide what that identity may read or change. Keep those decisions separate. A valid token does not override a collection's View, List, Create, Update, or Delete API rules. Protected files add a short-lived file token and still require the record View API rule.
Choose a method
| Method | Use when | Important condition |
|---|---|---|
| Password | Users manage a stable secret | Enable Identity/Password and configure a unique identity field. |
| OTP | Users can receive a one-time code | Enable One-time password and configure email delivery. |
| OAuth2 | An external identity provider is required | Configure the provider and redirect flow separately. |
| MFA | A second method is required | The user completes two different enabled methods. |
OTP can be convenient but its short numeric codes can be guessed or enumerated; use it with another method for security-critical applications. When MFA is enabled, the first successful method returns an MFA session identifier and the second method must submit it before PocketBase returns the regular authenticated response.
Apply the model
Start with Password authentication for a conventional account flow. Use One-time-password authentication when email codes fit your risk model, then define authorization in API rules and filters. The Authentication API reference lists the available operations.