KBAISE/ for lovable
Library
Docs

Integration security

about 10 minBuildingchecked 3d agoOfficial page
The short version

Lovable protects your connection details by storing them securely and using a special gateway for most connections. This gateway acts as a middleman, handling authentication and ensuring your app only sees what the connected account can see.

Anyone building an app with Lovable needs to understand this to ensure their app's connections are secure and function correctly.

Do this, in order

  1. 1

    When setting up a connection to an external service, understand that Lovable stores your connection details securely and out of sight.

    This means your sensitive information, like passwords or tokens, is protected and not directly accessible to anyone, including you or Lovable staff.

  2. 2

    If your external service has an IP allowlist or firewall, add Lovable's specific IP ranges to allow traffic from your app.

    This ensures your Lovable app can communicate with your external service, as requests from most Lovable connections come from these known IP addresses.

  3. 3

    If you are using a key in your app's frontend code that supports domain restrictions, add Lovable's domains and your own production domain to the allowed list.

    This prevents unauthorized use of your key by ensuring it only works when your app is served from the specified web addresses.

  4. 4

    When you no longer need a connection, delete it from your Lovable workspace.

    This immediately removes the stored connection details, preventing any further access to the external service through that connection.

Paste this into your project

I need to ensure my Lovable app can securely connect to external services. Can you tell me the specific IP ranges I should allowlist for Lovable's gateway connectors and the domains I should add for frontend keys with domain restrictions?

Words decoded

Connector gateway
A secure middleman system that handles communication between your Lovable app and external services, managing security and authentication.
IP allowlisting
A security measure where you create a list of approved internet addresses (IPs) that are allowed to access your service, blocking all others.
Domain restrictions
A security feature that limits where a special key or access token can be used, typically to specific website addresses (domains).
OAuth
A common way for apps to get limited access to user accounts on other services without needing their password.
Refresh token
A special key that allows an app to get new access tokens without asking the user to log in again, keeping the connection active.

Where people get stuck

  • Forgetting to delete unused connections, which keeps their secrets stored even if not actively used.
  • Not adding Lovable's IP ranges to your external service's allowlist, which will prevent your app from connecting.
  • Not adding your app's domains to domain restrictions for frontend keys, potentially allowing unauthorized use of the key.

The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.