Guide
The confirmation link in my sign-up email opens localhost instead of my app
A new person signs up, opens the confirmation email, taps the link, and gets "This site can't be reached", a localhost address, or your preview instead of your app. Most of them stop right there. You never see it, because you're already signed in.
It's one of the most common sign-up breaks in apps built with AI tools, and the fix is usually a setting, not code.
Why it happens
Your sign-in service decides where the email link sends people. It only sends them to addresses on an approved list, and when your app doesn't name one, it uses a single default address, the Site URL.
That default often still points to a developer's computer. Supabase's own guide says to change the Site URL "from http://localhost:3000 to your production URL", and calls the setting "critical for email confirmations and password resets". Bolt's help center says "By default, Bolt projects use localhost:3000 as the Site URL. This does not work for live applications", and that if the address isn't on the approved list, "Supabase falls back to the Site URL."
So you publish, the app moves to its real address, and the email link still points to the old one.
Check it in 2 minutes
- Open your live site in a private window, ideally on your phone.
- Sign up with an email address you've never used on the app.
- In the email, long-press the link (on a computer, hover over it) and read the address before you tap it.
- If it starts with
http://localhost,127.0.0.1or your preview address, this is the cause.
Fix it
Lovable, built-in backend (Cloud). Lovable sets the Site URL to your published lovable.app address when you publish, and adds a custom domain to the redirect URLs when you connect it. If the link is still wrong, ask Lovable in the chat to update them for your domain, or add your address under Auth settings → Advanced → Redirect URLs. An app that uses your own Supabase project gets no automatic updates, so use the Supabase steps below.
Supabase (including Bolt and most other AI tools that use it).
- In your Supabase project, open Authentication, then URL Configuration.
- Set Site URL to your live address, for example
https://myapp.com. - Under Redirect URLs, add each live address: your custom domain with and without
www, and the builder's published address if people use it. - Save, then sign up again with a fresh email and check the link.
If the setting is right and the link is still wrong, the address is written into the app's code. Paste this into your builder:
New users' confirmation emails link to localhost or the preview instead of my live site. Find every place the code sets a redirect or email redirect address for sign-up, sign-in and password reset, and make it use my live address: [your address]. Don't change anything else. Then tell me how to check it by signing up with a fresh email on the live site.
Then publish and check the link in a new sign-up email.
People who signed up while it was broken
Ask them to sign in on your live site. If the app says their email isn't confirmed, have them request a new confirmation email, or sign up again with the same address.
Check that new people can really sign up
Paste your app's link at vibe-fixer.com for a free sign-up check. An AI agent signs up to your live app as a brand-new person, with a real inbox, on a phone and a computer, and tells you whether a new person can finish. No account needed.
Related: Sign-up email not arriving · Sign-up or login broken after publishing · Test your live app like a real customer
Still stuck?
Paste your app’s link for a free test — no account. Your AI agent goes through it like a first customer, shows you what breaks, then fixes it while you watch.