# Swift iOS + Supabase: closing the OAuth return loop

supabase-swift handles the token exchange, but iOS decides whether your app ever sees the callback. That decision lives in two places agents forget: the URL scheme in `Info.plist` and the Redirect URLs in the dashboard.

## Checkable procedure

1. Choose a custom URL scheme for your app and register it under `CFBundleURLTypes` in `Info.plist`.
2. Add the matching redirect URL to the dashboard auth Redirect URLs. The scheme must match exactly; a typo here fails silently with the browser stuck on a blank page.
3. Start OAuth with `ASWebAuthenticationSession` (or the supabase-swift helper that wraps it) using your scheme as the callback. Confirm the callback handler exchanges the code for a session and stores it.
4. On first launch, treat the session as unknown until the client finishes loading it from the keychain. Do not flash the login screen for a stored session.
5. Observe auth state changes to drive the root view switch (logged in vs logged out) rather than checking once in `onAppear`.

## Quick test

Run on a real device, sign in with OAuth, and confirm the browser dismisses back into the app with an active session. If Safari stays open on a success page, the scheme or redirect URL is wrong.