Email authentication for your app
This page explains how to set up and adjust email sign-in for your app, including options for confirming emails, setting password rules, and using one-time codes instead of passwords. You can also customize the emails users receive and manage sending limits.
Anyone building an app with Lovable who wants users to sign in using their email address and a password or a one-time code.
Do this, in order
- 1
Ask Lovable to add login to your app with email and password, specifying any access restrictions.
This is the first step to enable email sign-in for your users and define who can access what.
- 2
Go to 'More' in your Lovable project, then 'Cloud', then 'Users', then 'Auth settings', and finally 'Email'.
This is where you will find all the settings to customize how email sign-in works.
- 3
Decide if users should confirm their email address after signing up, or if they should be signed in immediately.
Confirming emails ensures that every account belongs to a real, verified address, which is good for live apps. Skipping confirmation is faster for testing.
- 4
Set rules for user passwords, such as minimum length and required character types, and consider enabling the HIBP check.
Strong password rules protect user accounts, and the HIBP check helps block commonly compromised passwords without making rules too strict.
- 5
If you want users to sign in without a password, ask Lovable to build a magic link or one-time code flow, then adjust the expiration and length of these codes in the settings.
This offers a passwordless sign-in experience, which can be more convenient for users.
- 6
If users are not receiving emails, check the 'Rate limit for sending emails' under 'Advanced' in the email settings.
This limit caps how many authentication emails your project sends per hour, and exceeding it can prevent emails from being delivered.
Paste this into your project
Add login to the app with email and password. Require login before accessing the dashboard. Set minimum password length to 8 characters and require letters and numbers. Enable HIBP check for passwords. Allow users to sign in with a magic link sent to their email instead of a password, and set the magic link expiration to 5 minutes.
Words decoded
- Backend (Cloud)
- This is the part of your app that runs on Lovable's servers, handling things like user accounts and data storage, without you needing to set up your own servers.
- Magic link
- A special link sent to a user's email that, when clicked, automatically signs them into the app without needing a password.
- One-time code (OTP)
- A temporary, unique code sent to a user's email that they can enter into the app to sign in, instead of using a password.
- HIBP check
- This checks if a user's chosen password has been found in publicly known data breaches, helping to prevent them from using easily guessed or compromised passwords.
- Rate limit
- A restriction on how many times a specific action (like sending emails) can be performed within a certain period, to prevent abuse or overload.
Where people get stuck
- Not setting up custom emails can lead to confirmation emails landing in spam folders or hitting sending limits, making it harder for users to sign up.
- Turning off email confirmation for a live app means anyone can sign up with an email address they don't own, leading to unverified accounts.
- If your app is published and sign-in fails, the published URL might be missing from your project's redirect URLs.
- If a user is stuck unconfirmed, signing in again won't resend the confirmation email; they need to sign up again or be manually added as a confirmed user.
The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.