← All guides

Lovable + Supabase guide

Deploy a Lovable + Supabase app without breaking auth or data

LovableSupabaseVPSDomain

Short answer

A Lovable + Supabase app with production domain settings, env vars, auth redirects, database safety, and backup expectations checked.

Why this matters

The app works in the builder, but signup, login, callback URLs, database writes, or file uploads break after moving domains.

Walkthrough

  1. 01

    Capture every Supabase dependency

    Most production bugs come from missing keys or URLs that still point to a preview domain.

    • Collect Supabase project URL, anon key, service role key, JWT secret, and storage bucket names.
    • List auth providers and allowed redirect URLs.
    • Check whether the app uses edge functions, storage, realtime, or direct Postgres access.
  2. 02

    Fix auth and domain settings

    Changing domains without updating auth settings is the fastest way to break a Lovable app.

    • Set the final site URL in Supabase auth settings.
    • Add production callback URLs for login, magic links, OAuth, and password reset.
    • Test signup, login, logout, password reset, and protected pages on the final domain.
  3. 03

    Check data safety before launch

    A working form is not enough. Make sure users can only access the data they should access.

    • Review row-level security policies for user-owned tables.
    • Confirm service role keys are never exposed to the browser.
    • Plan backups and export strategy before real users create data.

Where RepoAssistant fits

RepoAssistant can deploy Lovable + Supabase apps with domain, auth, env vars, and database handover checked.