AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Email Send Rate Limit Applied Even When Auth Email Hook Is Enabled

Users using Supabase Auth Email Hook are still subject to the internal email send rate limit (over_email_send_rate_limit), causing HTTP 429 errors despite delegating email sending to an external Edge Function. The rate limiter should be bypassed when a custom email hook is configured.

highConfidence 85%GoTrue

Origin Analysis

In Supabase Auth (GoTrue), the email sending flow applies the internal rate limiter before checking whether a custom email hook is enabled. The `over_email_send_rate_limit` error is raised by the rate limiter regardless of the hook configuration, because the hook bypass logic is missing or placed after the rate limit check.
1. Configure an Auth Email Hook in Supabase Dashboard pointing to an Edge Function. 2. Set sign-up/sign-in rate limit to high (e.g., 60/5min). 3. Repeatedly attempt sign-up with the same email address more than the email send rate limit (commonly 30 per minute or 2 per minute in free tier). 4. Observe HTTP 429 response with error code `over_email_send_rate_limit` even though the hook should handle email sending.

Fixing Code Block

Edge Case Audit

This fix may remove an important safety net: if the custom email hook fails to enforce its own rate limits, the system could be flooded with email send requests. Ensure the hook implementation has adequate rate limiting. Rollback: revert this commit or set the `MAILER_RATE_LIMIT` environment variable to a safe value until a proper fix is released.

Ecosystem Topology