Enable Authentication for a Table
Authentication starts with enabling the function on a table that contains user data. Typically, this would just be youruser table. You can also enable authentication on multiple tables if you want separate authentication methods for different user groups, such as normal users and administrators.
Click the ⋮ icon in the database table view and choose Settings.

Use the dropdown to enable authentication.

Enable Authentication on an API Request
Once you’ve enabled authentication on a table, you can use each API endpoint’s settings to note whether or not it requires authentication. When a request is sent to API endpoints that require authentication, an authorization token is sent in the headers of the request, which Xano checks against the table with authentication enabled, before allowing the request to continue.Click … to access the settings of the API you'd like to enable authentication on.

Enable authentication for the endpoint in the dropdown.

How does authentication work?
Authentication in Xano is powered by industry-standard JWE (JSON Web Encryption) tokens. Once a token is generated (after login or signup), your app or website will send that token back to Xano for requests that require authentication. A token is generated using the Create Authentication Token function, and is typically used in conjunction with a standard login or signup authentication flow.Adding Pre-built Authentication Endpoints
Create an API group to hold your authentication endpoints.
Click '+ Add API Endpoint' and choose Authentication to pick from the pre-built API endpoints.

Choose the API that you'd like to add.
-
Login
- Accepts an email or username and password, and allows a user to log in
-
Signup
- Accepts user information and creates an account for them
-
auth/me
- Checks an authentication token and returns user information
Building Sign-up and Login APIs
Below, you can review a typical login and signup flow — you are free to modify them to suit your needs. These are the same that Xano can add for you during signupLogin

Get Record From user
Precondition: user ≠ null
Validate Password
true or false depending on the result.Precondition: pass_result = true
Create Authentication Token
Signup

Get Record From user
Precondition: user = null
Add Record In user
user tableCreate Authentication Token