Invalid login credentials 🔐 Authentication

Supabase Auth: AuthApiError: Invalid login credentials

Supabase rejected the email/password — wrong password, no such user, or the user signed up via OAuth/magic link without a password.

Seen on: REST API

Meaning

For security Supabase uses one message for wrong email and wrong password. Users created via Google/GitHub or magic link have no password unless they set one.

Common causes

  • Wrong email/password
  • User created with OAuth/magic link (no password)
  • User deleted or in another project (dev vs prod keys)

⚡ Quick fix

  1. Show a generic error and offer password reset
  2. Use the same provider the user signed up with
  3. Check the project URL/anon key environment

Detailed fix by platform

JavaScript

  1. javascript
    const { error } = await supabase.auth.signInWithPassword({ email, password });
    if (error?.message === "Invalid login credentials") setError("Email or password is incorrect.");

How to diagnose

  1. User — Exists in Auth users? Provider?
  2. Project — Correct URL/key?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.