Authentication & Authorization
Phoenix ships with phx.gen.auth — a built-in authentication generator with secure defaults, sessions, and email confirmation. For JWT-based auth, Guardian handles token generation and verification. Ueberauth adds OAuth strategies for social login. Bodyguard provides policy-based authorization. No external auth service required.
phx.gen.auth
libraryNeed user authentication?
Built-in Phoenix authentication generator with secure defaults, sessions, and confirmation
Guardian
libraryNeed JWT/token authentication?
Token-based authentication with JWT support, pluggable serializers, and refresh tokens
Ueberauth
libraryNeed social login / OAuth?
Composable OAuth authentication with strategies for Google, GitHub, Facebook, and more
Pow
libraryNeed full-featured user management?
Robust, modular user authentication and management with email confirmation and password reset
Bcrypt Elixir
libraryNeed secure password hashing?
Bcrypt password hashing for Elixir with NIF bindings for performance
Bodyguard
libraryNeed role-based authorization?
Simple, policy-based authorization that integrates with Phoenix controllers and LiveView
Tango
libraryNeed OAuth integrations with third-party services?
Drop-in OAuth integration for Phoenix with encrypted tokens, PKCE, and 500+ pre-configured providers