Skip to main content
Neon Postgres Docs
current

Search documentation

Type to search this documentation.

On this pageOverview

Configure trusted domains

Add your application domains to Managed Better Auth's allowlist to enable OAuth and email verification redirects in production. Why domains are required. Managed Better Auth only redirects to domains ...

Add your application domains to Managed Better Auth's allowlist to enable OAuth and email verification redirects in production.

Managed Better Auth only redirects to domains in your allowlist. This prevents phishing attacks and unauthorized redirects by ensuring users are only sent to your legitimate application URLs.

Without adding your production domain, OAuth sign-in and verification links will fail when users try to access your application.

  1. Go to Console → Auth → Configuration → Domains
  2. Enter your domain with protocol: https://myapp.com
  3. Click Add domain

Repeat for each domain where your app runs.

Add a domain with neon neon-auth domain add:

Bash
neon neon-auth domain add https://myapp.com

Use neon neon-auth domain list and neon neon-auth domain delete to view and remove entries.

Send a POST request to the add trusted domain endpoint. Replace {project_id} and {branch_id} with your project and branch IDs.

Bash
curl -X POST 'https://console.neon.tech/api/v2/projects/{project_id}/branches/{branch_id}/auth/domains' \
  -H 'Authorization: Bearer $NEON_API_KEY' \
  -H 'Content-Type: application/json' \
  -d '{"domain": "https://myapp.com", "auth_provider": "better_auth"}'

Use GET on the same path to list domains, and DELETE to remove them. See Manage Managed Better Auth via the API for the full set of auth endpoints.

Note: Include the protocol (https://) and omit trailing slashes. For example: https://myapp.com not https://myapp.com/

Development domains are automatically allowed, so you don't need to add them:

  • http://localhost:3000
  • http://localhost:5173
  • Any localhost port

Add all domains where users access your application:

  • https://myapp.com
  • https://www.myapp.com (if you support www subdomain)
  • https://app.myapp.com (if using a subdomain)

For preview environments with dynamic hostnames (for example Vercel preview deployments), you can add a wildcard trusted domain such as https://*.my-app-preview.vercel.app. One entry can match every preview under that pattern instead of adding hosts one by one.

Use the same rules as fixed domains: include https:// (or http:// where appropriate) and omit trailing slashes after the pattern.

Redirect blocked after OAuth sign-in:

  • Verify the domain is in your allowlist
  • Ensure you included https:// (not http:// for production)
  • Check spelling matches exactly (including www vs non-www)

Verification link doesn't redirect:

  • Verification links use the same domain allowlist
  • Add the domain where users should land after clicking the verification link

Join our Discord Server to ask questions or see what others are doing with Neon. For paid plan support options, see Support.

Suggest an edit

Propose a replacement for this page. The site team reviews it before applying any changes.

Export
Documentation menu