Vovy diagnoses a broken Sign in with Apple, generates a fresh client secret from your .p8 key, updates Supabase, and schedules the next renewal.
Apple sign in is failing with invalid_client, fix it
How it works
- Read the auth logs: Vovy opens Supabase logs for Auth and finds "invalid_client" errors from Apple, which almost always mean the six-month secret expired.
- Find your .p8 key: It pulls the Sign in with Apple key from 1Password. If it's lost, Vovy creates a new key in Apple Developer after you sign in.
- Collect the Apple IDs: Vovy copies your Team ID, Key ID and Services ID from Certificates, Identifiers and Profiles.
- Generate and save the new secret: It generates a fresh signed secret and pastes it into the Apple provider in Supabase. This affects live logins, so it asks first.
- Test and set the next reminder: Vovy logs in with Apple on your live site, then adds a calendar reminder five months out so it never lapses again.
What you provide
- Your Apple Developer login
- Your .p8 key, or permission to make a new one
What you get
- Apple login working again
- A fresh six-month secret
- Your key stored safely
- A reminder before the next expiry
FAQ
Why does this happen?
For web sign-in, Apple limits the client secret to six months. It's by design, not a bug in your app.
Does my iPhone app have the same problem?
Native iOS sign-in using Apple's own button doesn't need this secret, so it keeps working. Web and Android flows do.
Can this be automated?
Yes, with a scheduled function that signs a new secret and updates Supabase. Vovy can set that up as a follow-up.
Related tasks
All tasks