Mobile Starter Kit

Authentication and data

Activate the included Supabase OTP, Apple, Google, session, profile, and RLS path.

Vela already contains the mobile auth screens and the production Supabase adapter. You are configuring the included path, not replacing the auth layer.

Ask your AI

Read PRODUCTION-SETUP.md, agent-skills/wire-auth.md, and
agent-skills/wire-account-deletion.md. Activate Supabase authentication and data
using the existing adapters. Configure email OTP, Google, and Apple for my final
identifiers and callbacks. Apply the included migration, verify RLS, and keep
mock mode available. Never use a service-role key in the app.

What is included

  • email OTP,
  • browser PKCE OAuth for Google,
  • native Apple sign-in with nonce handling,
  • persisted React Native session and foreground refresh,
  • profile sync and user-scoped app data,
  • provider identity/reset across analytics, push, and caches,
  • biometric local re-entry gate,
  • sign-out, account switching, and deletion calls.

Biometrics protect local re-entry; they are not the user's server identity.

Setup shape

  1. Replace app scheme, bundle/package IDs, link domain, and legal origin.
  2. Create/link Supabase and apply the included migration.
  3. Configure site URL and allow the custom-scheme and final HTTPS callbacks.
  4. Configure email OTP, Google, and Apple provider settings.
  5. Deploy the Apple credential-registration and deletion functions.
  6. Add the Supabase URL and publishable key to the mobile environment.
  7. Run pnpm verify:supabase, then switch auth/backend adapters one at a time.
  8. Rebuild and test real accounts on physical devices.

Verification that matters

Test fresh install, correct/wrong/expired OTP, OAuth cancel, link resume, background refresh, offline launch, sign-out, account switch, and cache isolation. Prove that one user cannot read or write another user's database rows or Storage objects. Sign in on a second device and confirm a synced record survives.

Keep Sign in with Apple on iOS whenever another third-party sign-in option is offered.

On this page