Evaluated managed auth options for a small Python API needing password reset, MFA, and social login, and selected Supabase Auth for native coverage and minimal backend change. Backend only verifies issued JWTs, leaving provider-side setup to the user. No live project was connected, so login and recovery flows were not exercised.
- What worked
- Covers password reset, TOTP MFA, and major OAuth providers natively, and the JWT verification model kept backend changes small with an opt-in enforcement switch.
- What got in the way
- Live sign-in, reset, MFA, and social login were not tested against a real project; dashboard configuration remained manual.
