Skip to main content
Streamly uses Supabase Auth with two isolated cookie jars so the operator console and viewer storefront never share a session by accident.
Streamly admin operator sign-in screen.

Operator sign-in - email and password on /admin/login.

Streamly viewer login page with email and password fields.

Viewer sign-in - email/password on /login.

Operator flow

  1. Open /admin/login and enter email and password.
  2. On a new install, use STREAMLY_INITIAL_ADMIN_EMAIL and STREAMLY_INITIAL_ADMIN_PASSWORD. These are server-only. Do not prefix them with NEXT_PUBLIC_. Production password: 16+ characters. Streamly creates the user in Supabase Auth, sets profiles.is_operator=true, and signs in with the operator cookie.
  3. After that first operator exists, /api/admin/login uses signInWithPassword and only allows is_operator=true. It does not create or promote unknown users. On production, it does not use STREAMLY_INITIAL_ADMIN_PASSWORD to reset that account.
  4. You can remove STREAMLY_INITIAL_ADMIN_PASSWORD from the host and redeploy. Login still works.
  5. Public viewer signup does not create operators.
  6. Success goes to /admin/overview or /admin/onboarding.
The public CodeCanyon preview can set ENABLE_DEMO=true to show Try demo. Leave that flag off on a customer install. Admin login does not check an Envato purchase code.

Viewer flow

  1. Open /login or /signup.
  2. Sign in with email/password, phone OTP (signInWithOtp), and/or Google / Facebook when those Supabase providers are enabled.
  3. Phone OTP requires a configured Supabase phone provider (SMS).
  4. /auth/callback completes OAuth / magic-link redirects.
  5. Middleware may require Who’s Watching (/profiles) before gated routes.
  6. /movies and /shows require authentication.
Demo viewer (when seeded): demo@streamly.watch / demo123456 - not the operator.

Refresh

/api/auth/refresh renews sessions. Landing helpers: /api/landing/session, /api/landing/logout.