---
title: "Signs a user up."
method: POST
path: "/signup"
tags: ["auth"]
---

# Signs a user up.

`POST /signup`

Creates a new user.

## Request body

- object
  - `email` string, email
  - `phone` string, phone
  - `channel` 'sms' | 'whatsapp'
  - `password` string
  - `data` object
  - `code_challenge` string
  - `code_challenge_method` 'plain' | 's256'
  - `gotrue_meta_security` GoTrueSecurity — Use this property to pass a CAPTCHA token only if you have enabled CAPTCHA protection.
    - `captcha_token` string

## Response `200`

A user already exists and is not confirmed (in which case a user object is returned). A user did not exist and is signed up. If email or phone confirmation is enabled, returns a user object. If confirmation is disabled, returns an access token and refresh token response.

- union
  - AccessTokenResponseSchema
    - `access_token` string — A valid JWT that will expire in `expires_in` seconds.
    - `refresh_token` string — An opaque string that can be used once to obtain a new access and refresh token.
    - `token_type` string — What type of token this is. Only `bearer` returned, may change in the future.
    - `expires_in` integer — Number of seconds after which the `access_token` should be renewed by using the refresh token with the `refresh_token` grant type.
    - `expires_at` integer — UNIX timestamp after which the `access_token` should be renewed by using the refresh token with the `refresh_token` grant type.
    - `weak_password` object — Only returned on the `/token?grant_type=password` endpoint. When present, it indicates that the password used is weak. Inspect the `reasons` and/or `message` properties to identify why.
      - `reasons` string[]
      - `message` string
    - `user` UserSchema — Object describing the user related to the issued access and refresh tokens.
      - `id` string, uuid
      - `aud` string
      - `role` string
      - `email` string — User's primary contact email. In most cases you can uniquely identify a user by their email address, but not in all cases.
      - `email_confirmed_at` string, date-time
      - `phone` string, phone — User's primary contact phone number. In most cases you can uniquely identify a user by their phone number, but not in all cases.
      - `phone_confirmed_at` string, date-time
      - `confirmation_sent_at` string, date-time
      - `confirmed_at` string, date-time
      - `recovery_sent_at` string, date-time
      - `new_email` string, email
      - `email_change_sent_at` string, date-time
      - `new_phone` string, phone
      - `phone_change_sent_at` string, date-time
      - `reauthentication_sent_at` string, date-time
      - `last_sign_in_at` string, date-time
      - `app_metadata` object
      - `user_metadata` object
      - `factors` MFAFactorSchema[]
        - `id` string, uuid
        - `status` string — Usually one of: - verified - unverified
        - `friendly_name` string
        - `factor_type` string — Usually one of: - totp - phone - webauthn
        - `webauthn_credential` string
        - `phone` string, phone, nullable
        - `created_at` string, date-time
        - `updated_at` string, date-time
        - `last_challenged_at` string, date-time, nullable
      - `identities` IdentitySchema[]
        - `identity_id` string, uuid
        - `id` string, uuid
        - `user_id` string, uuid
        - `identity_data` object
        - `provider` string
        - `last_sign_in_at` string, date-time
        - `created_at` string, date-time
        - `updated_at` string, date-time
        - `email` string, email
      - `banned_until` string, date-time
      - `created_at` string, date-time
      - `updated_at` string, date-time
      - `deleted_at` string, date-time
      - `is_anonymous` boolean
  - UserSchema — Object describing the user related to the issued access and refresh tokens.
    - `id` string, uuid
    - `aud` string
    - `role` string
    - `email` string — User's primary contact email. In most cases you can uniquely identify a user by their email address, but not in all cases.
    - `email_confirmed_at` string, date-time
    - `phone` string, phone — User's primary contact phone number. In most cases you can uniquely identify a user by their phone number, but not in all cases.
    - `phone_confirmed_at` string, date-time
    - `confirmation_sent_at` string, date-time
    - `confirmed_at` string, date-time
    - `recovery_sent_at` string, date-time
    - `new_email` string, email
    - `email_change_sent_at` string, date-time
    - `new_phone` string, phone
    - `phone_change_sent_at` string, date-time
    - `reauthentication_sent_at` string, date-time
    - `last_sign_in_at` string, date-time
    - `app_metadata` object
    - `user_metadata` object
    - `factors` MFAFactorSchema[]
      - `id` string, uuid
      - `status` string — Usually one of: - verified - unverified
      - `friendly_name` string
      - `factor_type` string — Usually one of: - totp - phone - webauthn
      - `webauthn_credential` string
      - `phone` string, phone, nullable
      - `created_at` string, date-time
      - `updated_at` string, date-time
      - `last_challenged_at` string, date-time, nullable
    - `identities` IdentitySchema[]
      - `identity_id` string, uuid
      - `id` string, uuid
      - `user_id` string, uuid
      - `identity_data` object
      - `provider` string
      - `last_sign_in_at` string, date-time
      - `created_at` string, date-time
      - `updated_at` string, date-time
      - `email` string, email
    - `banned_until` string, date-time
    - `created_at` string, date-time
    - `updated_at` string, date-time
    - `deleted_at` string, date-time
    - `is_anonymous` boolean

## Other responses

- `400` — HTTP Bad Request response. Can occur if the passed in JSON cannot be unmarshalled properly or when CAPTCHA verification was not successful. In certain cases can also occur when features are disabled on the server (e.g. sign ups). It may also mean that the operation failed due to some constraint not being met (such a user already exists for example).
- `429` — HTTP Too Many Requests response, when a rate limiter has been breached.

---

[API](https://skmtc.net/supabase/apis/supabase-auth-rest-api.md) · [All operations](https://skmtc.net/supabase/apis/supabase-auth-rest-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/supabase/supabase-auth-rest-api/versions/2664b89bee49/schema)
