Vovy adds passwordless magic link login with Supabase, customizes the email, and tests that the link opens your app already logged in.
Make my app log people in with an email link instead of a password
How it works
- Add an email-only login form: In Cursor Vovy adds a single email field that calls signInWithOtp, which emails the user a one-time login link, with emailRedirectTo pointing back to your app.
- Allow your redirect URL: It adds your app's URL under Authentication, URL Configuration, Redirect URLs. Without it, the link sends people to your Site URL instead.
- Rewrite the Magic Link email: Vovy opens Authentication, Emails, Magic Link template and rewrites it in your voice, keeping the {{ .ConfirmationURL }} tag that holds the actual link.
- Send yourself a link: It requests a link for your email and waits while you click it in your inbox, then checks you land logged in.
- Explain the limits: A card covers link expiry, the built-in email limit, and why some inbox scanners click links early and cause "Email link is invalid or has expired".
What you provide
- A Supabase project
- An inbox to test with
What you get
- Passwordless login that works
- A branded magic link email
- Redirect URLs configured
- A card on common magic link errors
FAQ
Why do links say they expired when I just clicked them?
Some work email security tools open links to scan them, which uses up the one-time link. Offering a 6-digit code using the {{ .Token }} tag avoids this.
Can I send lots of magic links on the free setup?
No. Supabase's built-in email sender is limited to a couple of emails per hour, so real apps need custom SMTP like Resend.
Is passwordless less secure?
Not really. It moves security to the user's inbox, and removes weak and reused passwords.
Related tasks
All tasks