KBAISE/ for lovable
Library
Docs

Phone authentication for your app

about 15 minBuildingchecked 4d agoOfficial page
The short version

You can let people sign into your app using their phone number and a one-time code sent via text message. You'll need to connect your own text message provider for this to work.

Anyone building an app where users might not have email or prefer signing in with their phone number.

Do this, in order

  1. 1

    Create an account with a supported text message provider like Twilio, TextLocal, Vonage, or MessageBird.

    Lovable doesn't send text messages directly; you need your own provider to send the one-time codes to users.

  2. 2

    Collect the specific credentials (like API keys or SIDs) from your chosen text message provider's account.

    These credentials are what Lovable uses to connect to your provider and send messages on your behalf.

  3. 3

    Go to 'More → Cloud → Users → Auth settings → Phone' in Lovable, turn on 'Enable phone sign-in', select your provider, and enter the credentials you collected.

    This tells Lovable which provider to use and how to access it for sending sign-in codes.

  4. 4

    Ask Lovable to build the phone sign-in part of your app by pasting the prompt: 'Let users sign in with their phone number using an SMS code.'

    This generates the necessary screens and logic for users to enter their phone number and the code.

  5. 5

    Test the sign-in process by using a real phone number in your app, checking if the code arrives, and confirming the new user appears in 'More → Cloud → Users'.

    This ensures everything is set up correctly and users can successfully sign in with their phone.

Paste this into your project

Let users sign in with their phone number using an SMS code.

Words decoded

SMS provider
A company that sends text messages for you, like Twilio or Vonage. You pay them for each message sent.
OTP
Stands for One-Time Password, which is the temporary code sent to a user's phone to verify their identity.
Credentials
The secret keys and IDs that allow Lovable to securely connect to your text message provider.
Account SID
A unique identifier for your account with a text message provider, like a username.
Auth token
A secret key that acts like a password for your text message provider account.
API key
A unique code that allows your app to communicate with a service, like a text message provider.

Where people get stuck

  • Forgetting that you pay your SMS provider directly for messages, not Lovable, and costs can increase with high sign-up volume.
  • Not checking your SMS provider's dashboard first when codes aren't arriving, as issues like failed deliveries or exhausted balances show up there.
  • Using 'Auto-confirm SMS' in production, as it removes the security check that the user owns the phone number.
  • Not realizing that different countries have different rules about who can appear as the SMS sender, which can affect delivery.
  • Not confirming that the SMS provider credentials in your auth settings are current if codes stop working.

The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.