Skip to content
d3 Wiki
08.01

Supabase Auth setup standard

Every tool's login works the same way and is configured the same way.

Updated
Oct 3, 2026
On this page

Purpose

Every tool's login works the same way and is configured the same way.

The standard

  • Provider: Email + password by default. Magic link optional. SSO per 08.05 when required.

  • Public sign-up off for internal tools; users are invited from the dashboard or by an admin action in the app. On for tools with external users only after an ADR.

  • Email confirmation on in prod (may be off in dev). Custom SMTP ([TEAM: Resend/Postmark]) so emails aren't rate-limited.

  • Site URL and Redirect URLs include local, preview wildcard, and production domains.

  • Auth emails use the team template; sender is [TEAM: no-reply@domain].

  • A profiles table with a role column is created by trigger on sign-up (see 08.02).

Procedure

  1. Supabase → Authentication → Providers → Email → enable; set confirm/sign-up per above.

  2. URL Configuration → Site URL + redirects: http://localhost:3000/**, https://*-[TEAM]-team.vercel.app/**, https://tool.domain.com/**.

  3. SMTP settings → custom provider.

  4. Apply the profiles migration from the template (09.03).

  5. Test: invite yourself, set password, log in, confirm a profile row exists.

Owner: Matt · Last reviewed: 2026-09