Start watching free

Error library · Signed-in sessions expiring

Supabase “JWT expired”

The app is sending the database a sign-in pass that has already expired. Supabase refreshes these automatically — unless the app keeps an old copy and reuses it, which is what's happening here.

Who it affects

People who keep the app open for a while start getting errors or empty screens until they sign out and back in — 5 sessions so far.

Numbers here are from an example app where 5 visitors hit it. How serious: High — an important part of the app is broken for some people.

How to fix it

Give this to the AI that builds your app. It’s the prompt Vigilia writes for this error — shown here for an example app (an orders table, a /checkout page); for your app, Vigilia fills in the real details from what your visitors hit.

For Lovable
Lovable: Bug: requests to Supabase fail with "JWT expired" for users who have had the app open for a while.

Evidence: "AuthApiError: JWT expired" — seen 12 times across ~5 sessions, on /checkout.

What to change:
1. Use a single Supabase client for the whole app and let it manage the session: don't copy the access token into state, local storage or custom headers and reuse it later.
2. Keep automatic token refresh on (the default), and read the current session from the client each time instead of caching it.
3. If a request still fails because the session ended, send the user to sign in again with a short explanation, rather than showing an error or an empty page.

Acceptance criteria: sign in, leave the app open for longer than an hour, then use it — requests keep working without signing in again.
For Bolt
Bolt: Bug: requests to Supabase fail with "JWT expired" for users who have had the app open for a while.

Evidence: "AuthApiError: JWT expired" — seen 12 times across ~5 sessions, on /checkout.

What to change:
1. Use a single Supabase client for the whole app and let it manage the session: don't copy the access token into state, local storage or custom headers and reuse it later.
2. Keep automatic token refresh on (the default), and read the current session from the client each time instead of caching it.
3. If a request still fails because the session ended, send the user to sign in again with a short explanation, rather than showing an error or an empty page.

Acceptance criteria: sign in, leave the app open for longer than an hour, then use it — requests keep working without signing in again.
For Cursor
Cursor: Bug: requests to Supabase fail with "JWT expired" for users who have had the app open for a while.

Evidence: "AuthApiError: JWT expired" — seen 12 times across ~5 sessions, on /checkout.

What to change:
1. Use a single Supabase client for the whole app and let it manage the session: don't copy the access token into state, local storage or custom headers and reuse it later.
2. Keep automatic token refresh on (the default), and read the current session from the client each time instead of caching it.
3. If a request still fails because the session ended, send the user to sign in again with a short explanation, rather than showing an error or an empty page.

Acceptance criteria: sign in, leave the app open for longer than an hour, then use it — requests keep working without signing in again.
For Claude Code
Claude Code: Bug: requests to Supabase fail with "JWT expired" for users who have had the app open for a while.

Evidence: "AuthApiError: JWT expired" — seen 12 times across ~5 sessions, on /checkout.

What to change:
1. Use a single Supabase client for the whole app and let it manage the session: don't copy the access token into state, local storage or custom headers and reuse it later.
2. Keep automatic token refresh on (the default), and read the current session from the client each time instead of caching it.
3. If a request still fails because the session ended, send the user to sign in again with a short explanation, rather than showing an error or an empty page.

Acceptance criteria: sign in, leave the app open for longer than an hour, then use it — requests keep working without signing in again.
For any other tool
Bug: requests to Supabase fail with "JWT expired" for users who have had the app open for a while.

Evidence: "AuthApiError: JWT expired" — seen 12 times across ~5 sessions, on /checkout.

What to change:
1. Use a single Supabase client for the whole app and let it manage the session: don't copy the access token into state, local storage or custom headers and reuse it later.
2. Keep automatic token refresh on (the default), and read the current session from the client each time instead of caching it.
3. If a request still fails because the session ended, send the user to sign in again with a short explanation, rather than showing an error or an empty page.

Acceptance criteria: sign in, leave the app open for longer than an hour, then use it — requests keep working without signing in again.

Vigilia catches this automatically

When this happens on your live app, Vigilia recognises it at once — no waiting, no AI credits — tells you who it affects, hands your AI the fix, and confirms it held with real visitors.

More errors, explained