Google OAuth setup
Configure Google sign-in for Claire without committing provider credentials.
Google sign-in runs through Supabase Auth. Most of the work is in two consoles, and almost every failure is a redirect URI that does not match exactly.
Prerequisites#
- A Google Cloud Console account
- Access to your Supabase project dashboard
- Claire running locally
Google Cloud Console#
Create or select a project
In the Google Cloud Console, create a new project or pick an existing one.
Enable the Google+ API
APIs & Services → Library → search for “Google+ API” → Enable.
Configure the OAuth consent screen
Choose External for the user type, fill in the app name and support email, and add your own address to the test users.
Create an OAuth client ID
APIs & Services → Credentials → Create Credentials → OAuth client ID. Application type Web application.
Field Value Authorized JavaScript origin https://<your-project-ref>.supabase.coAuthorized redirect URI https://<your-project-ref>.supabase.co/auth/v1/callbackCopy the client ID and secret
You will paste both into Supabase in the next section.
Supabase#
Open Authentication → Providers and enable Google
Paste the client ID and secret
Configure the redirect URLs
Setting Value Site URL claire://auth/callbackAdditional redirect http://localhost:3000Additional redirect claire://auth/callbackAdditional redirect exp://<your-lan-ip>:8081Save
Test the integration#
bun run iosOpen the sign-in screen and choose “Sign in with Google”. A browser opens with Google’s login page, and a successful authentication redirects back into the app.
Going to production#
- Set the OAuth consent screen to Published in Google Cloud Console.
- Add your production domain to the authorized origins and redirect URIs.
- Update the Supabase redirect URLs with the production values.
- Confirm deep linking is configured in the mobile app.
Troubleshooting#
| Symptom | Cause and fix |
|---|---|
| Redirect URI mismatch | The app’s redirect URI must match Google’s configuration exactly, and the Supabase URL must be an authorized JavaScript origin. |
| “User cancelled login” | Normal when the browser is closed before authenticating. No action needed. |
| Deep link does not open the app | Check the claire scheme in app.json; iOS may need associated domains and Android needs the intent filter. |
| Token missing after redirect | The redirect URL must carry the hash fragment; verify the parsing in googleAuth.ts. |