Supabase Auth: AuthApiError: Invalid login credentials
Supabase rejected the email/password — wrong password, no such user, or the user signed up via OAuth/magic link without a password.
Seen on:
REST API
Meaning
For security Supabase uses one message for wrong email and wrong password. Users created via Google/GitHub or magic link have no password unless they set one.
Common causes
- Wrong email/password
- User created with OAuth/magic link (no password)
- User deleted or in another project (dev vs prod keys)
⚡ Quick fix
- Show a generic error and offer password reset
- Use the same provider the user signed up with
- Check the project URL/anon key environment
Detailed fix by platform
JavaScript
- javascript
const { error } = await supabase.auth.signInWithPassword({ email, password }); if (error?.message === "Invalid login credentials") setError("Email or password is incorrect.");
How to diagnose
- User — Exists in Auth users? Provider?
- Project — Correct URL/key?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- auth/invalid-credential Firebase Auth: auth/invalid-credential (auth/wrong-password, auth/user-not-found, auth/invalid-login-credentials)
- bad auth : Authentication failed MongoDB: MongoServerError: bad auth : Authentication failed (code 8000 / 18)
- Could not load the default credentials Google Cloud: Error: Could not load the default credentials. Browse to https://cloud.google.com/docs/authentication/getting-started
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026