The short version
NextAuth (Auth.js) creates 4 tables in your database: users, accounts, sessions, and verification_tokens. The users and accounts tables have a one-to-one relationship via accounts.user_id. Sessions link to users via sessions.user_id. Verification tokens are short-lived and self-cleaning.
The 4 tables
users
| Column | Type | What it means |
|---|---|---|
id | text / UUID | Primary key. Generated by NextAuth. |
name | text | Display name from the OAuth provider. |
email | text | User's email. May be null if the provider doesn't share it. |
email_verified | timestamp | When the email was verified. Null if never verified. |
image | text | Profile picture URL from the provider. |
created_at | timestamp | When the user first signed in. |
updated_at | timestamp | Last profile sync from the provider. |
accounts
Links a user to an OAuth provider. One user can have multiple accounts (Google + GitHub).
| Column | Type | What it means |
|---|---|---|
id | text / UUID | Primary key. |
user_id | text | Foreign key → users.id. |
provider | text | "google", "github", "discord", etc. |
provider_account_id | text | The provider's unique ID for this user. |
access_token | text | OAuth access token (encrypted in production). |
refresh_token | text | OAuth refresh token (encrypted in production). |
expires_at | integer | When the access token expires (Unix timestamp). |
sessions
| Column | Type | What it means |
|---|---|---|
id | text / UUID | Primary key. |
session_token | text | The session token stored in the user's cookie. |
user_id | text | Foreign key → users.id. |
expires | timestamp | When this session expires. |
verification_tokens
Short-lived tokens for email verification and password reset. Self-cleaning.
| Column | Type | What it means |
|---|---|---|
identifier | text | Email or user ID the token is for. |
token | text | The actual token value. |
expires | timestamp | When this token expires. |
How they connect
users → accounts is one-to-one per provider. users → sessions is one-to-many (different devices). verification_tokens is temporary and doesn't have a foreign key.
FAQ
Does NextAuth store passwords?
No. NextAuth is OAuth-first. If you need email/password, use next-auth/providers/credentials with bcrypt.
Can I add custom fields to the users table?
Yes. Add columns directly. NextAuth ignores columns it doesn't know about.
What happens when a user deletes their account?
NextAuth doesn't cascade deletes. Manually delete from users, accounts, and sessions.