© 2026 Hedgehog Software, LLC

TwitterGitHubDiscord
More
CommunitiesDocsAboutTermsPrivacy
Search
Star
Setup for Free
SupabaseS
Supabase•13mo ago•
25 replies
meer

How to secure provider_token, provider_refresh_token when using google oauth?

Hi,
I am using react-router (remix) with supabase-ssr for auth, with google oauth. Following the guidelines at https://supabase.com/docs/guides/auth/social-login/auth-google?queryGroups=framework&framework=remix, I found that the access and refresh tokens from google are getting stored in the cookie, which I presume can be risky.
Any suggestions on how to handle this? I would also be needing token rotation, invalidation, etc., any pointers on the same will also be very helpful!
Thanks in advance!
Login with Google | Supabase Docs
Use Sign in with Google on the web, in native apps or with Chrome extensions
Login with Google | Supabase Docs
Supabase banner
SupabaseJoin
Supabase gives you the tools, documentation, and community that makes managing databases, authentication, and backend infrastructure a lot less overwhelming.
45,816Members
Resources

Similar Threads

Was this page helpful?
Recent Announcements

Similar Threads

Unable to Get Provider Refresh Token for Google
SupabaseSSupabase / help-and-questions
4y ago
How to refresh session for Google oAuth?
SupabaseSSupabase / help-and-questions
3y ago
google oauth issue /#access_token=
SupabaseSSupabase / help-and-questions
6mo ago
How to refresh access token using refresh token in supabase c# api?
SupabaseSSupabase / help-and-questions
4mo ago