Guide
New users sign up, then land back on the login page (or see an error)
Someone signs up to your app, and instead of getting in they end up back on the sign-up or login page. Or they try to log in and get an error. They try again, it happens again, and they leave.
You don't see it, because you're already signed in. Here are the usual reasons in apps built with AI tools, and how to fix each one.
First, find out which one it is
Open your live site in a private window, ideally on your phone, and sign up with an email address you've never used on the app. Then note:
- Did a confirmation email arrive? If not, see Sign-up email not arriving.
- Where did the link in that email take you? If it opened
localhostor your preview, see Confirmation link opens localhost. - What does the screen say when you try to log in? Write down the exact error text. It tells you which reason below applies.
Reason 1: the account isn't confirmed yet
Most sign-in services make new people confirm their email before they can sign in. Supabase's docs say that on hosted projects "this is true by default". Lovable's docs say the same: with auto-confirm off, users "must verify the address before signing in".
So if the confirmation email never arrives, or the person tries to log in before clicking it, the login is refused (Supabase's error code is email_not_confirmed), and to them it looks like a loop.
Fix: make the confirmation email reliable first; this guide covers it. For someone already stuck, Lovable's docs note that "signing in again does not resend it". They get a new email by signing up again with the same address. On Lovable's built-in backend you can also add them under More → Cloud → Users → Add user → Create new user, and accounts added that way are confirmed automatically.
Reason 2: the live address isn't on the allowed list
After sign-up or sign-in, the sign-in service sends people back to your app, but only to addresses on its allowed list. Otherwise it uses its default address, which for Supabase starts as localhost:3000. Lovable's docs put it plainly: "If sign-in works in preview but breaks on your published app or custom domain, these URLs are usually the reason."
Fix:
- Supabase (including Bolt and most AI tools that use it): open Authentication → URL Configuration. Set Site URL to your live address, and add every live address under Redirect URLs (with and without
www). - Lovable: ask Lovable in the chat to update them for your domain, or add your address under Auth settings → Advanced → Redirect URLs. If the app uses your own Supabase project, use the Supabase steps above.
- Firebase: if the error says the domain "is not authorized to run this operation", add your live domain under Authentication → Settings → Authorized Domains → Add Domain.
Reason 3: the app never finishes signing the person in
Some apps (especially ones with server-side pages) use a sign-in flow where the email link brings back a one-time code, and the app has to swap that code for a signed-in session on the page it lands on. Supabase's docs say that code "can only be exchanged for an access token once", is valid for 5 minutes, and the swap "must be initiated on the same browser and device where the flow was started".
So if the landing page doesn't do the swap, or the person opens the email link in a different browser (for example inside their email app), they arrive signed out and are sent back to login.
Fix: paste this into your builder:
New users sign up but end up back on the login page instead of signed in. Check the page the sign-up and sign-in links return to: it must turn the code in the link into a signed-in session, then send the person into the app. Also check that the session is kept after the next page load. Don't change anything else. Then tell me how to test it with a fresh email on the live site, opening the email link on the same phone.
Reason 4: sign-up is switched off
It sounds obvious, but it happens. Supabase has an Allow new users to sign up setting, and Lovable has Disable sign-up. With sign-up off, only existing users can get in, and Supabase answers new sign-ups with signup_disabled.
Fix: check that setting in your sign-in service and turn new sign-ups back on.
Check that new people can really sign up
Paste your app's link at vibe-fixer.com for a free sign-up check. An AI agent signs up to your live app as a brand-new person, with a real inbox, on a phone and a computer, and tells you whether a new person can finish. No account needed.
Related: Sign-up email not arriving · Confirmation link opens localhost · Google sign-in fails on the live site
Still stuck?
Paste your app’s link for a free sign-up check, no account needed. An AI agent signs up to your live app as a brand-new person, on a phone and a computer, and tells you whether a new person can finish.