AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Phone Provider Enabled In Dashboard But Runtime Still Reports Phone=False And Returns Phone_provider_disabled

In a managed Supabase Cloud project, the Phone Provider is toggled ON and SMS Provider set to Twilio Verify in the Dashboard, but the Auth runtime settings endpoint still reports phone=false and sms_provider='twilio'. Consequently, POST /auth/v1/otp fails with HTTP 400 and error_code phone_provider_disabled. The user has verified Twilio credentials work directly and there are no environment variable overrides or application-level configurations. This indicates a configuration propagation bug between the Dashboard and the Auth runtime.

highConfidence 75%Supabase Auth (GoTrue)

Origin Analysis

The Auth runtime configuration is not being updated when the Phone Provider is enabled via the Dashboard. The runtime still holds the old configuration (phone=false, sms_provider='twilio'), even though the Dashboard UI reflects the intended changes. This could be caused by a failed or silently ignored configuration update, a stale cache in the managed Auth service, or a mismatch between the Dashboard's internal representation and the runtime's expected configuration schema (e.g., Twilio Verify may require sms_provider='twilio_verify' instead of 'twilio', and the phone flag may be derived from the provider setting).
1. On a managed Supabase Cloud project, navigate to Authentication > Providers > Phone. 2. Toggle Phone Provider ON and set SMS Provider to Twilio Verify. 3. Save the configuration. 4. Call GET /auth/v1/settings and observe phone=false and sms_provider='twilio'. 5. Call POST /auth/v1/otp with a valid phone number; receive HTTP 400 with error_code phone_provider_disabled. 6. Toggle Phone Provider OFF then ON again; the runtime configuration remains unchanged.

Fixing Code Block

Edge Case Audit

Applying this fix without proper testing could inadvertently enable phone authentication for projects that rely on email-only signups. The mapping change from 'twilio' to 'twilio_verify' should be backward-compatible and only applied when the Dashboard explicitly selects Twilio Verify. The fix should be rolled out gradually with monitoring for unexpected configuration changes or increased SMS costs. A rollback plan should include restoring the original config loader logic and invalidating any caches to revert to previous behavior.

Ecosystem Topology