← All guides

Auth rescue guide

Lovable + Supabase auth broke after changing domains

LovableSupabaseVPSDomain

Short answer

Auth flows working on the production domain with correct redirect URLs, env vars, and row-level security policies.

Why this matters

Login and signup worked in Lovable preview. After moving to a custom domain, every auth flow returns errors or redirects to the old URL.

Walkthrough

  1. 01

    Find every Supabase auth setting

    Auth depends on multiple settings across the Supabase dashboard and your app code.

    • List all auth providers enabled in your Supabase project.
    • Copy the current redirect URLs, callback URLs, and allowed origins.
    • Note which env vars the app uses for Supabase URL and keys.
  2. 02

    Update Supabase for the new domain

    Supabase will reject auth requests from any URL not in its allow list.

    • Add the production domain to Supabase auth redirect URLs.
    • Update OAuth provider callback URLs to the new domain.
    • Remove or keep old preview URLs depending on whether you still need them.
  3. 03

    Fix the app and test every flow

    After updating Supabase, the app also needs correct env vars and a rebuild.

    • Update Supabase URL and anon key env vars on the server.
    • Rebuild the app with production env vars loaded.
    • Test signup, login, password reset, OAuth, and magic links on the live domain.

Where RepoAssistant fits

RepoAssistant fixes Lovable + Supabase auth during deployment so users can actually log in on your production domain.