> ## Documentation Index
> Fetch the complete documentation index at: https://usegately.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Allowed Redirect URLs

> Where Gately is allowed to send users after social login, magic links, and password resets

Social login, magic links, and password resets all send the user back to a URL you choose (`redirectTo` / `redirect_url`). Because that trip carries sign-in credentials, Gately only redirects to URLs your project owns. Anything else is rejected with an error before any email is sent or any session is issued.

## What's allowed

A redirect URL is accepted when its host is one of:

| Source | Example | Where it comes from |
| - | - | - |
| Local development | `http://localhost:3000`, `http://127.0.0.1:5173`, `*.localhost` | Always allowed (`http` is only allowed for these hosts) |
| Your Gately subdomain | `https://acme.cloud-cr.usegately.com` | Your project's help center / hosted pages subdomain |
| Your custom domains | `https://help.acme.com` | Domains you've connected to Gately, such as your help center's custom domain |
| Your redirect rules | `https://acme.com/welcome` | The host of any active [redirect rule](/docs/features/redirect-rules) |
| Allowed redirect origins | `https://app.acme.com` | **Settings → Social Sign-On → Allowed redirect origins** |

Everything else must use `https`.

<Note>
  Allowed redirect origins match the full origin: scheme, host, and port. `https://acme.com` does not allow `https://www.acme.com` or `https://shop.acme.com`; add each origin you redirect to.
</Note>

## Adding your site

If your login page lives on a domain that isn't already a custom domain or redirect rule (for example a Framer, Webflow, or Next.js site), add its origin:

1. Go to **Settings → Social Sign-On** in your dashboard
2. Under **Allowed redirect origins**, add each origin users sign in from, for example `https://acme.com` and `https://www.acme.com`
3. Save

Relative URLs passed to the SDK (`redirectTo: '/dashboard'`) are resolved against the current page, so they work as long as the current site's origin is allowed.

## When a redirect isn't allowed

The request fails with `400`:

```json theme={null}
{
  "error": "Redirect URL not allowed",
  "message": "https://example.com is not an allowed redirect for this project. Add it to your project's allowed redirect origins or custom domains."
}
```

* **Social login**: the error is returned when the login starts, before the user reaches Google or GitHub.
* **Magic links and password resets**: the request is rejected and no email is sent.

## How social login hands back the session

After Google or GitHub sign-in, Gately redirects to your URL with a short-lived, single-use `gately_code` parameter. The SDK exchanges it for the session automatically and removes it from the address bar, so access tokens never appear in URLs, browser history, or server logs. If you aren't using the SDK, see [Social Login → Without the SDK](/docs/sdk/auth/social-login#without-the-sdk).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.