Vovy creates the Apple Services ID, signing key and client secret, connects them to Supabase, and tests the Apple login flow on your site.
Set up Sign in with Apple for my app on Supabase
How it works
- Sign in to Apple Developer: Vovy opens Certificates, Identifiers and Profiles and pauses while you sign in yourself. Sign in with Apple needs a paid Apple Developer membership.
- Create an App ID and Services ID: It turns on the Sign in with Apple capability on your App ID, then creates a Services ID, which is the identifier Apple uses for websites, with your domain and Supabase callback URL.
- Make a signing key: Vovy creates a key with Sign in with Apple enabled and downloads the .p8 file. Apple lets you download it only once, so Vovy saves it to 1Password.
- Generate the client secret: It uses your Team ID, Key ID and Services ID to generate the secret, then pastes it into Authentication, Sign In / Providers, Apple in Supabase.
- Add the button and test it: In Cursor it adds a Sign in with Apple button, then tests it in Chrome and sets a reminder, because this secret expires after six months.
What you provide
- An Apple Developer membership
- Your domain
- A Supabase project
What you get
- Working Sign in with Apple
- The .p8 key stored safely
- A calendar reminder for the 6-month rotation
- A card explaining each Apple ID
FAQ
What does this cost?
The Apple Developer Program is $99 per year. Supabase does not charge extra for the Apple provider.
Why does Apple login break after six months?
For web sign-in, Apple caps the client secret at six months. When it expires users get "invalid_client" until you generate a new one.
Do I need this if I have an iPhone app?
Apple requires Sign in with Apple in iOS apps that offer other social logins like Google, with some exceptions. On the web it's optional.
Related tasks
All tasks