PhxAuthPlus

Complete authentication generator for Phoenix 1.8+, aligned with the official phx.gen.auth templates from Phoenix 1.8.9.

Phoenix 1.8 replaced mix phx.gen.auth with a magic-link-only generator. PhxAuthPlus restores the full email + password experience — registration, password login, magic link login, password reset, account confirmation, "remember me", and settings — while using modern Igniter-based code generation and the Phoenix 1.8 scope system (current_scope).

Installation

Add to your mix.exs:

def deps do
[
{:phx_auth_plus, "~> 0.3.3", only: [:dev, :test]}
]
end

Then:

mix deps.get
mix phx_auth_plus.gen.auth Accounts User users

The generator adds the hashing library dependency, configures the test environment, generates all auth files, and updates your layout and router.

Quick start

# Generate auth (LiveView UI, bcrypt on Unix / pbkdf2 on Windows)
mix phx_auth_plus.gen.auth Accounts User users
# Then:
mix ecto.migrate
mix phx.server

Visit http://localhost:4000/users/register.

Generated features

FeatureDescription
RegistrationEmail + password signup with validation
Password loginSession-based with "remember me" cookie
Magic link loginToken-based passwordless login (Phoenix 1.8 style)
Password resetForgot password flow with email token
Account confirmationEmail verification with token
SettingsChange password and email (with confirmation)
Session trackingAll sessions stored in DB, invalidated on password change
Scope systemcurrent_scope assign throughout LiveViews and plugs
Layout menuDynamic auth links in the app header (login/register, email/settings/logout)
Auth testsGenerated test suite for UserAuth plug and hooks

Usage

# Default: LiveView UI, bcrypt on Unix / pbkdf2 on Windows
mix phx_auth_plus.gen.auth Accounts User users
# Controller-only UI (no LiveView)
mix phx_auth_plus.gen.auth Accounts User users --no-live
# Use argon2 hashing
mix phx_auth_plus.gen.auth Accounts User users --hashing-lib argon2
# Use binary UUID keys
mix phx_auth_plus.gen.auth Accounts User users --binary-id
# Custom table name
mix phx_auth_plus.gen.auth Accounts User users --table app_users
# Custom web module
mix phx_auth_plus.gen.auth Accounts User users --web MyAppWeb

Options

OptionDefaultDescription
--hashing-libbcrypt (Unix) / pbkdf2 (Windows)Password hashing library
--livetrueGenerate LiveView auth pages
--no-liveGenerate controller-based auth pages
--binary-idfalseUse binary UUID primary keys
--webMyAppWebWeb module name
--context-appapp nameContext app (umbrella projects)
--tableplural argDatabase table name

Generated files

lib/my_app/
├── user.ex # User schema with changesets
├── user_token.ex # Token schema (session, magic link, reset, confirm, change email)
├── user_notifier.ex # Email notification delivery (Swoosh)
├── accounts.ex # Accounts context with full auth functions
└── scope.ex # Scope struct for current user
lib/my_app_web/
├── user_auth.ex # Auth plug + LiveView on_mount hooks
├── user_session_controller.ex # Session controller (login, logout, update_password)
# With --live (default):
├── user_login_live.ex # Login page (password + magic link)
├── user_registration_live.ex # Registration page
├── user_settings_live.ex # Settings page (email + password)
├── user_confirmation_live.ex # Magic link / confirmation page
├── user_forgot_password_live.ex # Forgot password page (request reset email)
└── user_reset_password_live.ex # Reset password page (enter new password)
priv/repo/migrations/
└── *_create_users_auth_tables.exs
test/
├── support/accounts_fixtures.ex # Test fixtures
└── my_app_web/user_auth_test.exs # UserAuth tests

Routes

PathMethodDescription
/users/registerLiveViewRegistration
/users/log-inLiveView / POSTLogin (password or magic link)
/users/log-in/:tokenLiveViewMagic link login / account confirmation
/users/log-outDELETELogout
/users/forgot-passwordLiveViewRequest password reset email
/users/reset-password/:tokenLiveViewReset password with token
/users/settingsLiveViewSettings (auth required)
/users/settings/confirm-email/:tokenLiveViewConfirm email change
/users/update-passwordPOSTUpdate password from settings

Token validity

Token typeContextValidity
Sessionsession14 days
Magic linklogin15 minutes
Reset passwordreset_password1 day
Confirm accountconfirm7 days
Change emailchange:{old_email}7 days

Email delivery

The generated UserNotifier uses Swoosh to build emails. In development, the local adapter captures emails at /dev/mailbox.

To send real emails, configure a Swoosh adapter in config/runtime.exs. See the GUIDE for details.

Customization

See the GUIDE.md for:

vs Phoenix 1.8 built-in auth

FeaturePhoenix 1.8PhxAuthPlus
Email + passwordNot includedFull support
Magic link loginIncludedIncluded
Password resetNot includedToken-based reset
Account confirmationNot includedEmail confirmation
"Remember me"Not includedSecure cookies
Settings pageNot includedChange email + password
Session trackingNot includedDB-tracked sessions
Scope systemcurrent_scopecurrent_scope
Layout menuNot includedDynamic auth links in header
Code generationManualIgniter-based (AST)

License

MIT