Supabase OAuth redirect_uri_mismatch: the provider console and Supabase disagree
Guide Supabase OAuth redirect_uri_mismatch: the provider console and Supabase disagree: # redirect_uri_mismatch: fix it in the provider console This error is issued by Google, GitHub, or whichever provider you use, before Supabase is even involved. Use this when you hit exactly this in Supabase OAuth redirect_uri_mismatch. Not for different errors or different tools.
TL;DR: # redirecturimismatch: fix it in the provider console This error is issued by Google, GitHub, or whichever provider you use, before Supabase is even involved. Editing Supabase's Redirect URLs does nothing for it. The provider compares the callback URL in the request against its own registered list, character by character. ## Symptom to cause to confirmation to fix 1.
redirecturimismatch: fix it in the provider console
This error is issued by Google, GitHub, or whichever provider you use, before Supabase is even involved. Editing Supabase's Redirect URLs does nothing for it. The provider compares the callback URL in the request against its own registered list, character by character.
Symptom to cause to confirmation to fix
- Read the error source. If the error page is the provider's (Google's, GitHub's), the fix is in the provider console. If it is Supabase's or your app's, it is the Supabase allowlist instead.
- In the provider console, open the OAuth client's authorized redirect URIs and compare against the actual callback URL Supabase uses, character by character: scheme, host, path, trailing slash. A missing trailing slash is enough to fail.
- Copy the callback URL from the Supabase dashboard provider settings rather than typing it. Typos in the project ref are the most common mismatch.
- Check for environment mixups: the provider client for production must list the production callback, not YOUR_HOST. Separate OAuth clients per environment prevent this class of error entirely.
- After changing the provider console, test in incognito. Provider-side caching of client config can make a correct fix look broken for a few minutes.
Verification
Complete the flow in incognito with a fresh provider account. Success means the exact strings now agree. Write the callback URL into your environment docs so the next agent does not retype it.
When to use
You hit exactly this: Supabase OAuth redirecturimismatch: the provider console and Supabase disagree in Supabase OAuth redirecturimismatch.
When not to use
A different error, or the same symptom in a different tool. This page only covers the failure above.
Compatibility
Supabase OAuth redirecturimismatch.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.