KBAISE/ for lovable
Library
Docs

Users and authentication

about 10 minBuildingchecked 4d agoOfficial page
The short version

Lovable automatically handles user sign-up and login for your app, including various sign-in methods like email, Google, and Apple. You can manage users, customize login options, and control who can access your app directly within Lovable.

Anyone building an app that needs users to sign in will use this feature to set up and manage how people access their app.

Do this, in order

  1. 1

    Tell Lovable to add login to your app, specifying any particular sign-in methods you want, like 'Sign in with Google'.

    This automatically creates the necessary login pages and connects them to your app's backend, protecting user data.

  2. 2

    To see or manage your app's users, go to 'More' then 'Cloud' and then 'Users'.

    This view shows you a list of all users, their sign-up details, and allows you to add or remove users manually.

  3. 3

    To change how users sign in, click 'Auth settings' in the 'Users' view or ask Lovable in the project chat.

    This lets you enable or disable different sign-in options like email, phone, or social logins, and configure specific rules for each.

  4. 4

    If you want to stop new people from signing up, go to 'Auth settings' and disable 'Sign-up'.

    This prevents new users from creating accounts while still allowing existing users to log in.

  5. 5

    If sign-in isn't working on your published app, ask Lovable in the project chat to update your redirect URLs for your domain.

    Incorrect redirect URLs are a common reason for login issues, especially when moving from preview to a live app or custom domain.

Paste this into your project

Add login to the app. Require login before accessing the CRM dashboard. Also, add a 'Sign in with Google' button so users can log in with their Google accounts. If sign-in fails on my published app, please update the redirect URLs for my domain.

Words decoded

Backend (Cloud)
This is the part of your app that runs on Lovable's servers, handling things like storing data, managing users, and processing information, without you needing to set up your own servers.
Row level security
This is a security feature that makes sure each user can only see and interact with the data that belongs to them, preventing them from accessing other users' information.
SAML SSO
This is a way for users to sign in to your app using their existing company or organization login, so they don't need a separate username and password for your app.
OAuth credentials
These are like digital keys that allow your app to securely connect with services like Google or Apple for sign-in, ensuring that user information is shared safely and with permission.
Redirect URLs
These are specific web addresses that Lovable or other sign-in providers (like Google) are allowed to send users back to after they've successfully logged in. If these aren't correct, sign-in won't work.

Where people get stuck

  • Forgetting to update redirect URLs when your app goes live or uses a custom domain can break sign-in.
  • Not configuring your own Google OAuth credentials in Google Cloud Console if you want custom branding for Google sign-in and are using your own credentials.
  • Trying to enable a sign-in method that has been blocked by a workspace administrator's policy on Business and Enterprise workspaces.

The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.