ERR-752/Supabase Auth · OAuth redirects to localhost or wrong URL

Appears when: OAuth redirects to localhost or wrong URL

Supabase OAuth redirects to localhost or the wrong URL

Supabase uses the requested redirect only when it matches an allowed Redirect URL; otherwise the flow can fall back to the configured Site URL. Align the app’s redirectTo value, Supabase URL configuration, and the provider callback for the exact production origin.

Reviewed October 2026 · 6 min read · By Zenveus Engineering

How do I fix supabase oauth redirects to localhost or the wrong url?

production-fix-plan.txtrun in order
01# Document the intended URL chain
Separate the app start URL, provider callback, Supabase callback, and final return path.
02# Correct Supabase URL configuration
Set a production-safe Site URL and add only the approved application redirect patterns.
03# Generate redirectTo from trusted configuration
Use an explicit environment value or validated origin rather than a leftover localhost constant.
04# Test each environment independently
Verify preview, production platform URL, and custom domain without broad wildcard allowances.

Preserve the current working revision, change one proven boundary, and verify the published path in a clean session.

What if the quick fix does not work?

01Record the requested redirectTo

Inspect the browser request and note the exact protocol, host, port, path, and trailing slash.

What the result tells you: A value generated from a development origin will reliably send production users back to development.

02Compare Site URL and Redirect URLs

Confirm the requested destination matches an allowed entry and the fallback Site URL is production-safe.

What the result tells you: An unmatched redirect can cause Supabase to use the Site URL instead.

03Verify the provider callback

The OAuth provider should allow Supabase’s callback endpoint while Supabase controls the final app redirect.

What the result tells you: Confusing provider callback and application return URL creates loops or wrong destinations.

Likely causeWhat proves itFirst safe action
Site URL still points to localhostA value generated from a development origin will reliably send production users back to development.Document the intended URL chain
redirectTo is not allowlistedAn unmatched redirect can cause Supabase to use the Site URL instead.Correct Supabase URL configuration
App derives the wrong originConfusing provider callback and application return URL creates loops or wrong destinations.Generate redirectTo from trusted configuration
Provider callback is misconfiguredA value generated from a development origin will reliably send production users back to development.Test each environment independently

Why do AI-built apps hit this problem?

Supabase uses the requested redirect only when it matches an allowed Redirect URL; otherwise the flow can fall back to the configured Site URL. Align the app’s redirectTo value, Supabase URL configuration, and the provider callback for the exact production origin.

Site URL still points to localhost

The production fallback destination was never updated.

redirectTo is not allowlisted

The app requests a production path that does not match the configured redirect entries.

App derives the wrong origin

A hard-coded development URL or proxy header creates the redirect value.

When the built-in AI fix makes it worse

Freeze generated changes, restore the last known working version, reproduce one request, collect the browser and platform logs, and change one layer at a time.

How do I stop this problem recurring?

  • →Keep an OAuth URL matrix for local, preview, staging, and production.
  • →Include the final post-login URL in release acceptance checks.
  • →Keep production configuration in an explicit release checklist, not in chat history.
  • →Test the published URL in a clean browser session before calling the release complete.
  • →Keep a last-known-good deployment and a documented rollback step.
  • →Log the critical request path with enough context to identify the failing layer.

Still stuck with supabase oauth redirects to localhost or the wrong url?

AI prototype hardening

We restore the critical path and document the root cause.

  • Production failure reproduced with evidence
  • The smallest responsible layer repaired
  • Rollback and prevention guidance included
Discuss the production issue →

Supabase OAuth redirects to localhost or the wrong URL questions

Why is redirectTo ignored?

The requested value may not match an allowed Redirect URL, so the configured Site URL is used as a safe fallback.

Are the OAuth provider callback and app return URL the same?

Usually not. The provider calls Supabase, and Supabase then returns the user to an approved app URL.

Should I add a wildcard for every domain?

Prefer narrow patterns for controlled environments. Broad redirect permissions increase the risk of sending sessions to unintended origins.

About the guide

Zenveus Engineering works on production systems across product, data, authentication, infrastructure, and AI integrations. This guide is based on current official platform documentation and evidence-led repair practice.

Scroll to Top