Authentication runs against the local self-hosted Supabase Auth service. Roles are never read from the browser; the backend loads them from user_roles.
Local development accounts are provisioned with scripts/provision-test-users.sh. Passwords are read from ignored environment variables and are never committed.
scripts/provision-test-users.sh