QuotaGuard and Lovable Integration Guide
A Lovable application’s outbound identity depends on which server-side component opens the connection. That may be a Lovable custom connector, a Lovable Cloud server-side function, a Supabase Edge Function, or a backend deployed on another platform. Never place proxy credentials in browser-delivered React code.
What Is Actually Making the Outbound Call
Lovable now provides a Cloud backend, server-side functions, and custom connectors in addition to the generated frontend. Identify the component making the protected request before choosing an egress route. The browser’s IP belongs to the end user and is not a stable application identity.
Lovable’s custom-connector gateway publishes shared fixed IPv4 185.41.150.0/25 and IPv6 2a07:8241:fca::/48 ranges. Use that native route when the destination accepts the shared ranges and the connector supports the request and authentication model.
Use QuotaGuard when the destination needs a much smaller portable allowlist, when selected server-side code must use a managed proxy route, or when Enterprise dedicated infrastructure is required for customer-only source addresses. QuotaGuard operates the proxy infrastructure, availability, failover, monitoring, capacity, maintenance, support, and incident response.
The Confirmed Lovable and Supabase Path
Lovable’s Supabase integration is available on every Lovable plan. When a project is connected to Supabase, Lovable deploys its server-side code as Supabase Edge Functions. Supabase documents that Edge Functions do not have stable outbound addresses and recommends an outbound proxy when an external service requires IP allowlisting.
Supabase Edge Functions run on a Deno-compatible runtime. QuotaGuard has verified Deno.createHttpClient() with authenticated Static HTTP, Static SOCKS5, and Shield HTTPS proxies on current Supabase Edge Runtime versions. That gives Lovable applications a direct selective route:
Lovable frontend
-> Supabase Edge Function generated by Lovable
-> QuotaGuard
-> IP-allowlisted API or service
Store QUOTAGUARDSTATIC_URL in Supabase Edge Function secrets, then configure the exact fetch() call that opens the protected connection with a proxy-aware Deno client. Only those selected calls use QuotaGuard; unrelated application traffic keeps its normal route. Storing the URL as a secret protects the credential, but does not route traffic by itself.
Follow the complete code and production verification procedure in the QuotaGuard and Supabase Edge Functions Integration Guide.
Choose the Right Address Model
Standard QuotaGuard subscriptions provide a stable pair of addresses on shared managed proxy infrastructure. Allowlist both addresses. When the firewall requires source addresses that are not shared with other customers, use an Enterprise dedicated configuration.
For Lovable’s built-in Cloud backend, put the protected call in server-side Edge Function code, keep the connection URL in Lovable Secrets, and configure the request client explicitly. For a separately deployed backend, use the proxy support provided by that runtime’s HTTP client. The Lovable React frontend must call the server-side operation rather than receiving either the destination secret or QuotaGuard credentials.
Keep destination authentication and authorization in place. A matching source address is an additional security layer, not proof of application or user identity.
If You Exported and Self-Host
If you exported your Lovable project to GitHub and self-host the app, the static IP attaches to whatever host runs your server-side code. Follow that platform’s guide:
A QuotaGuard identity can remain portable when the backend moves between supported platforms, but each runtime and HTTP client must be configured explicitly.
Ready to Get Started?
Get in touch or create a free trial account.