# Google sign-in setup

Google verifies the sign-in. Supabase Authentication stores the Google identity in `auth.users` and `auth.identities`. The app saves the matching Supabase Auth user ID on its `public.auth_accounts` row so repeat sign-ins resolve the same app user even if the Google email changes. Existing `profiles` IDs, the signed `hha_session` cookie, and server-side role checks continue to authorize app data. Admin accounts keep their existing login and MFA path. Google passwords, access tokens, and the OAuth client secret are never saved in app user rows.

## Configure the providers

1. In Google Cloud, create an OAuth client for a web application. Add the Supabase callback URL shown in **Supabase → Authentication → Providers → Google** as an authorized redirect URI. It is normally `https://<project-ref>.supabase.co/auth/v1/callback`. Add the required `openid`, email, and profile scopes in the Google consent screen.
2. Enable the Google provider in Supabase Auth and enter the Google client ID and secret there. Add `https://heavyhaulgbt.com/api/auth/google/callback*` to **Authentication → URL Configuration → Redirect URLs**. The trailing wildcard is required because the PKCE flow adds `sb_flow_id` to the callback URL. Add the corresponding localhost or staging callback pattern for each environment you use. `heavyhaulagent.com` is the email sending domain, not the Workspace app host.
3. Apply database migration `0051_google_auth_account_link.sql` to add the durable app-account link. Authorize `heavyhaulgbt.com` for the production reCAPTCHA **v3** key; use a separate key with `localhost` authorized for local tests. Set `NEXT_PUBLIC_RECAPTCHA_SITE_KEY` and `RECAPTCHA_SECRET_KEY` in the app environment. Set `NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY` from the Supabase project's API settings. Set `NEXT_PUBLIC_APP_URL` to the actual public origin of that environment.
4. Restart the app. The Google buttons on `/signup` and `/login` become enabled after the public keys are available. A new customer chooses their role on `/signup`; `/login` signs in an existing app account. Test signup, repeat sign-in, and an admin address in a non-production environment before enabling production keys.

The app verifies each reCAPTCHA v3 token with Google on the server, including its action, hostname, and score (minimum 0.5). Supabase Auth's built-in CAPTCHA setting supports hCaptcha and Cloudflare Turnstile, not reCAPTCHA v3. This integration therefore checks reCAPTCHA at the app entry points; it does not configure Supabase's built-in CAPTCHA setting.

The current username/password and emailed-code login paths remain available. When both reCAPTCHA keys are configured, the app also checks v3 on password sign-in, emailed-code requests, and both early-access forms. Google signup creates a real customer account immediately; the existing email form on `/signup` still submits a pilot activation request.

Provider references: [Supabase Google sign-in](https://supabase.com/docs/guides/auth/social-login/auth-google), [Supabase identities](https://supabase.com/docs/guides/auth/identities), [Supabase CAPTCHA support](https://supabase.com/docs/guides/auth/auth-captcha), [Google reCAPTCHA v3](https://developers.google.com/recaptcha/docs/v3).
