Why preview login lies to you
On r/lovable the thread is always the same: Google works on *.lovable.app, then “Redirect URI mismatch” or a 404 the day the custom domain goes live. Supabase already allows the preview host. Your domain is a new origin. Nothing in the Lovable chat can add it to Google Cloud for you.
This wizard writes the allowlist. You paste it. Then you click the happy path on the real URL. Asking Lovable “does login work?” is not a test.
What to paste where
- Supabase Site URL: the origin people will bookmark, usually
https://yourapp.com. - Supabase Redirect URLs: every origin that may finish login, each with
/**. Production, www, preview, localhost. - Google JavaScript origins: those same origins, without the path.
- Google / GitHub callback:
https://YOUR_PROJECT_REF.supabase.co/auth/v1/callback. Not your domain.
The callback people get wrong
Google does not send the user to https://yourapp.com/auth/callback. It sends them to Supabase. Supabase then redirects to a URL on your allowlist. If Google still has the preview callback, or your app URL, you get the mismatch. The prompt library has the “fix login on the custom domain” prompt for the client side. This page is the dashboard side.
Frequently asked questions
Why does Lovable login work on preview but fail on the custom domain?
Supabase already allows *.lovable.app. Your domain is new. Add it to Site URL, Redirect URLs, and the OAuth provider before you tweet the link.
What is the Google redirect URI for a Lovable Supabase app?
https://YOUR_PROJECT_REF.supabase.co/auth/v1/callback. Putting the production domain there is the usual mismatch.
Do I need localhost in Supabase redirect URLs?
Yes if you export to GitHub and run Vite. The default is http://localhost:5173/**.
What is the difference between Site URL and Redirect URLs?
Site URL is the default return. Redirect URLs is the allowlist. You need both. A missing /** or a www mismatch is enough to bounce.
Is this official documentation?
No. Confirm the screens in your dashboards if they have moved. It is not affiliated with Lovable, Supabase, Google or GitHub.
After auth works on the custom domain, walk the launch checklist and run the security checker. If you still need a /privacy page that names Supabase and Google, use the privacy generator.