Supabase phone sign-in, with a code that reaches every Saudi mobile number.
Supabase makes the code and checks it. Tawked delivers it in an SMS that names your approved application, under Tawked's sender ID. Connect it in your project's Auth Hooks; no line of your code changes.
- Your code stays as it issignInWithOtp works as before; Supabase still checks the code.
- Tawked's sender IDAn Arabic or English SMS that names your approved app.
- One-tap fillThe autofill line carries your approved website's domain.
Supabase's Auth Hooks screen, with the Send SMS hook enabled on Tawked's address and a Secret.
From asking for the code to an open session.
Supabase keeps the code and the check. Tawked carries it to the Saudi phone. No extra server in your project, no new library.
Your app asks
The user types a phone number.
signInWithOtp({ phone })Supabase makes the code
and sends it to the hook, signed.
POST /webhooks/supabaseTawked checks and sends
It verifies the signature and writes the SMS.
200 {}The SMS arrives
Under Tawked's sender ID, naming your app.
Your Alnada Store verification code is: 482913Supabase checks it
and opens the session as it does today.
verifyOtp → session
A number outside Saudi Arabia?
Tawked answers with a clear message that Supabase returns to your app, so you can show it or route the number to another provider.
Connected in settings, without code.
Three steps between the Tawked console and the Supabase dashboard. Whoever manages the application's API keys creates the connection and sees the Secret.
Create the connection in Tawked
Application › Integrations › Supabase › Create the connectionPaste the hook URL and the Secret into Supabase
Authentication › Auth Hooks › Send SMS hookTurn on phone sign-in
Authentication › Sign In / Providers › Phone
Your code, as it is.
You ask for the code and check it with Supabase's own functions. No Tawked key in your app and no extra request: the whole connection lives in your project's settings.
- With Supabase's official libraries: JavaScript, Flutter, Swift, Kotlin.
- With Lovable or Bolt projects connected to a Supabase project of their own.
- With the Supabase CLI locally, from config.toml.
// Supabase sends the code through Tawked
const { error } = await supabase.auth.signInWithOtp({
phone: '+966512345678',
})
// Supabase checks it and opens the session
const { data } = await supabase.auth.verifyOtp({
phone: '+966512345678',
token: '482913',
type: 'sms',
})// Supabase sends the code through Tawked
await supabase.auth.signInWithOtp(phone: '+966512345678');
// Supabase checks it and opens the session
final res = await supabase.auth.verifyOTP(
phone: '+966512345678',
token: '482913',
type: OtpType.sms,
);# Supabase CLI: the hook while you develop locally
[auth.sms]
enable_signup = true
[auth.hook.send_sms]
enabled = true
uri = "https://tawked.com/webhooks/supabase/<connection>"
secrets = "env(TAWKED_HOOK_SECRET)"Before approval, and after.
We review your app’s name and website once, because the name appears in every message. Until then, you test on your own phone.
Your phone only
Up to 10 test messages reach the account owner’s phone, each starting with the [TEST] stamp.
[TEST] Your Alnada Store verification code is: 104822Every Saudi mobile number
The SMS names your approved app, and each send takes the code’s price from your balance. Nothing changes on your side in Supabase.
Your Alnada Store verification code is: 482913@alnada.sa #482913
- Prepaid credit, no subscription, no contract
- A send that fails is not charged
- A cap per number per hour, and a daily spend cap you choose
- Every code in the Verify log, with the Supabase user who asked for it
Developer questions
Do I need to change my app’s code?
No. Your app asks for the code with signInWithOtp and checks it with verifyOtp, as it does today. The whole connection lives in your project’s Auth Hooks settings.
Who checks the code?
Supabase. It makes the code and checks it; Tawked only delivers it. Tawked does not keep the code itself, only a one-way hash of it.
What happens before my app is approved?
Codes reach only the account owner’s phone, up to 10 test messages, each starting with the [TEST] stamp. Once approved, they reach every Saudi mobile number with no change on your side.
What does it cost?
0.09 SAR per delivered code, from prepaid credit, and a send that fails is not charged. Every new account starts with 10 SAR of free credit.
What if the user’s number is outside Saudi Arabia?
Tawked sends to Saudi numbers only. For any other number it answers with a clear message that Supabase returns to your app, so you can show it or route the number to another provider.
How do I know a request came from my project?
Every request from Supabase is signed with the connection’s Secret under the Standard Webhooks spec, and Tawked refuses any request whose signature is wrong or older than 5 minutes.
Does it work with Lovable projects?
Yes, when the project is connected to a Supabase project of your own: the whole connection lives in that project’s Auth Hooks settings.
Is the code sent twice if Supabase retries?
No. Tawked recognises the retried request and sends the code only once.
Make phone sign-in work in Saudi Arabia.
Create your account and your application, then connect your Supabase project from Integrations.
Supabase is a trademark of its owner; Tawked is not affiliated with it.