Supabase Auth: AuthApiError: Email not confirmed
The account exists, but email confirmation is enabled and the user hasn’t clicked the confirmation link.
Seen on:
REST API
Meaning
Confirmation emails may land in spam, use Supabase’s rate-limited default SMTP, or redirect to a wrong Site URL. You can resend, configure custom SMTP, or disable confirmation for development.
Common causes
- User hasn’t confirmed
- Email not delivered (default SMTP rate limit, spam)
- Confirmation link redirect URL not allowed
⚡ Quick fix
- Resend confirmation (supabase.auth.resend)
- Configure custom SMTP
- Add your site URL/redirect URLs in Auth settings
Detailed fix by platform
JavaScript
await supabase.auth.resend({ type: "signup", email, options: { emailRedirectTo: "https://app.example.com/welcome" } });
How to diagnose
- User — email_confirmed_at null?
- Email — Delivered?
- URLs — Site URL/redirect allow list
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- auth/invalid-credential Firebase Auth: auth/invalid-credential (auth/wrong-password, auth/user-not-found, auth/invalid-login-credentials)
- auth/network-request-failed Firebase Auth: auth/network-request-failed — A network AuthError (such as timeout, interrupted connection or unreachable host) has occurred
- Illegal arguments: undefined, string bcrypt error: Illegal arguments: undefined, string / data and salt arguments required / data and hash arguments required
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026