Skip to main content
Neon Postgres Docs
current

Search documentation

Type to search this documentation.

On this pageOverview

Auth production checklist

Complete these steps before taking your application to production with Managed Better Auth. Add your production domain(s) to enable OAuth and email verification redirects. Replace shared SMTP (auth@ma...

Complete these steps before taking your application to production with Managed Better Auth.

0%

  • 1. Configure trusted domains

    Add your production domain(s) to enable OAuth and email verification redirects.

  • 2. Set up custom email provider

    Replace shared SMTP (auth@mail.myneon.app) with your own email service for reliable delivery and higher limits. A custom email provider is also required if you want to use verification links instead of verification codes.

  • 3. Customize application name

    Set the name your users see in user-facing auth messages. Applies to Managed Better Auth integrations. Defaults to the Neon project name.

  • 4. Configure OAuth credentials (if using OAuth)

    Set up your own Google and GitHub OAuth apps to replace shared development keys.

  • 5. Enable email verification (recommended)

    Email verification is not enabled by default. Since anyone can sign up for your application, enabling email verification adds an important verification step to ensure users own their email address.

  • 6. Disable localhost access

    Disable the "Allow Localhost" setting in your project's Settings → Auth page. This setting is enabled by default for development but should be disabled in production to improve security.

Managed Better Auth uses a shared SMTP provider (auth@mail.myneon.app) by default for development and testing. For production, configure your own email provider for better deliverability and higher sending limits.

A custom SMTP provider uses your sender address but still sends Neon's default email templates. For full control over email branding, content, and HTML templates, use webhooks to intercept email events and send through your own email service. See Customize emails.

In your project's Settings → Auth page, configure your email provider:

  1. Select Custom SMTP provider
  2. Enter your SMTP credentials:
    • Host: Your SMTP server hostname (for example, smtp.gmail.com)
    • Port: SMTP port (typically 465 for SSL or 587 for TLS)
    • Username: Your SMTP username
    • Password: Your SMTP password or app-specific password
    • Sender email: Email address to send from
    • Sender name: Display name for sent emails
  3. Click Save

Configure a standard SMTP provider with neon neon-auth config email-provider update:

Bash
neon neon-auth config email-provider update --type standard --host smtp.example.com --port 587 --username example_username --password AbC123dEf --sender-email noreply@example.com --sender-name "Example App"

Update the provider with the Update email provider configuration endpoint. Replace {project_id} and {branch_id} with your project and branch IDs:

Bash
curl -X PATCH 'https://console.neon.tech/api/v2/projects/{project_id}/branches/{branch_id}/auth/email_provider' \
  -H 'Authorization: Bearer $NEON_API_KEY' \
  -H 'Content-Type: application/json' \
  -d '{"type": "standard", "host": "smtp.example.com", "port": 587, "username": "example_username", "password": "AbC123dEf", "sender_email": "noreply@example.com", "sender_name": "Example App"}'
  • Verification links: Require a custom email provider
  • Verification codes: Work with shared or custom email providers
  • Password reset: Works with shared or custom email providers

Managed Better Auth uses the application name in user-facing auth messages, such as verification emails and password resets. By default, this is set to the Neon project name. This setting is available for Managed Better Auth integrations only.

To set a custom application name:

  1. Go to Auth in your Neon project
  2. Select the Configuration tab
  3. In the Project Info panel, edit the Application Name field

Each branch manages its own application name independently, so preview and development branches can use different names than production.

You can also update the application name via the API. See Update auth configuration.

The "Allow Localhost" setting in your project's Settings → Auth page is enabled by default to allow authentication requests from localhost during development.

For production environments, disable this setting to improve security:

  1. Go to Settings → Auth in your Neon project
  2. Find the Allow Localhost toggle
  3. Disable the toggle

Join our Discord Server to ask questions or see what others are doing with Neon. For paid plan support options, see Support.

Suggest an edit

Propose a replacement for this page. The site team reviews it before applying any changes.

Export
Documentation menu