← All guides
Auth rescue guide
Lovable + Supabase auth broke after changing domains
LovableSupabaseVPSDomain
Short answer
Auth flows working on the production domain with correct redirect URLs, env vars, and row-level security policies.
Why this matters
Login and signup worked in Lovable preview. After moving to a custom domain, every auth flow returns errors or redirects to the old URL.
Walkthrough
- 01
Find every Supabase auth setting
Auth depends on multiple settings across the Supabase dashboard and your app code.
- List all auth providers enabled in your Supabase project.
- Copy the current redirect URLs, callback URLs, and allowed origins.
- Note which env vars the app uses for Supabase URL and keys.
- 02
Update Supabase for the new domain
Supabase will reject auth requests from any URL not in its allow list.
- Add the production domain to Supabase auth redirect URLs.
- Update OAuth provider callback URLs to the new domain.
- Remove or keep old preview URLs depending on whether you still need them.
- 03
Fix the app and test every flow
After updating Supabase, the app also needs correct env vars and a rebuild.
- Update Supabase URL and anon key env vars on the server.
- Rebuild the app with production env vars loaded.
- Test signup, login, password reset, OAuth, and magic links on the live domain.
Where RepoAssistant fits
RepoAssistant fixes Lovable + Supabase auth during deployment so users can actually log in on your production domain.