Integrations
Works with the tools you already use
- SupabaseAuthPhone sign-in codes through the Send SMS hook. No code to write.
- Auth0AuthPasswordless and MFA codes from a custom phone provider Action.
- Better AuthAuthSend codes from the phone number plugin with a few lines of the SDK.
- FirebaseAuthVerify phone numbers with Bridge Verify next to Firebase Auth.
- ClerkAuthDeliver the SMS Clerk generates from its webhook.
- TwilioSMS providerA fallback when no phone can send, or the main route.
- VonageSMS providerSend through the Vonage SMS API, with delivery reports.
- MSG91SMS providerDLT-registered templates for sending in India.
- PlivoSMS providerSend through the Plivo Message API, with delivery reports.
- n8nWorkflowsSend SMS and codes with HTTP requests; start workflows from webhooks.
- ZapierWorkflowsSend an SMS from any Zap, and react to deliveries and incoming SMS.
- MakeWorkflowsAn HTTP module to send, and a custom webhook to receive events.
Bridge works with auth platforms and automation tools in three ways:
| How | Who generates and checks the code | Guides |
|---|---|---|
| Built-in hook. The other service calls a URL Bridge gives you. No code to write. | The other service | Supabase Auth |
| A few lines of code in the other service's callback, using the SDK or HTTP. | The other service, or Bridge Verify | Better Auth, Auth0 |
| HTTP requests and webhooks from a workflow tool. | Bridge Verify, or none | n8n, Zapier and Make |
Firebase does not let you replace the SMS sender for its own phone sign-in; use Bridge Verify next to it. Clerk lets you deliver its SMS yourself from a webhook. Both are in Firebase and Clerk.
Whichever way a message reaches Bridge, it is routed like any other: through your phones, or an SMS provider when routing says so.
Codes and privacy
- Codes that go through Verify or the Supabase hook are sent as one-time-password messages
(
purpose: otp): the API, dashboard and webhooks show them masked (•••••• is your Acme code…), and the stored text is erased once the SMS is sent. - Codes you send yourself with
POST /v1/messages(Better Auth, Auth0, Clerk, workflow tools) are ordinary messages. Bridge does not know the text contains a code, so it is shown in full and kept forBRIDGE_MESSAGE_RETENTIONlike any other message. Prefer Verify where the platform allows it.
Integrations in the API
Built-in hooks are managed under Integrations in the dashboard, or with these session-authenticated routes. Only owners and admins can change them.
| Method and path | Purpose |
|---|---|
GET, POST /v1/projects/{projectId}/integrations | List, or create (kind, environment). |
PATCH /v1/projects/{projectId}/integrations/{integrationId} | Store the other service's signing secret (write-only), or switch environment. |
DELETE /v1/projects/{projectId}/integrations/{integrationId} | Remove it. The hook URL stops working. |
An integration's environment is live (sends real SMS) or test (nothing is sent; messages go
to the simulator). Creating one needs BRIDGE_SECRET_KEY, because the signing secret is stored
encrypted like provider credentials. Changes are
audit-logged as integration.created, integration.updated and integration.deleted.
Webhooks
Bridge tells your application when something happens: a message is delivered, a message fails, a phone receives an SMS, a phone goes offline.
Supabase
Supabase Auth can send phone sign-in codes through Bridge with its Send SMS hook. Supabase still generates the code and checks it when the user types it in; Bridge only delivers…