AI app builder
Updated
Add email to your Lovable app with Lumail
Lovable apps are React front ends backed by Supabase. The browser cannot hold an email API key, so the send has to happen in a Supabase Edge Function. Ask for exactly that, and give the function the key as a secret.
TL;DR
send-welcome that reads LUMAIL_API_KEY from function secrets, gets the signed-in user with supabase.auth.getUser(), and POSTs to https://lumail.io/api/v2/emails with an Idempotency-Key. The React app calls it with supabase.functions.invoke.1. Prompt Lovable
Connect Supabase to your Lovable project first, then paste this into the chat. It pins the send to an Edge Function and to the signed-in user's own address, so nobody can use your function to email strangers.
2. Put the API key in the right place
Create a lum_ token in Lumail under API tokens. In a Lovable project connected to Supabase, the key belongs in the Edge Function secrets, not in the project code. Lovable usually asks you to add the secret when it writes a function that needs one; you can also add it in the Supabase dashboard under the function secrets.
Add LUMAIL_FROM the same way, so the sender address is not hard-coded.
3. The code Lovable should generate
The function should look like this. It sends only to the authenticated user, uses their id in the idempotency key so a double click cannot send twice, and returns Lumail's error name to the app.
4. Lumail MCP server and agent plugins
Lovable builds and hosts your app in the cloud, so your app talks to Lumail through the API with a token, not through MCP. The Lumail MCP server is for agents that run where you work: Claude Code, Codex, ChatGPT, Cursor or the Lumail CLI.
That split is useful once the app is live. Ask Claude Code or ChatGPT to check your domain's DNS status, look up a subscriber who did not get their email, or draft the next newsletter, while the app keeps sending through the API.
- Lumail for AI agents - Every way an agent can work with Lumail.
- In-app integration - One prompt that wires Lumail into a codebase.
- Claude Code plugin - MCP server and skill for Claude Code.
- Codex plugin - MCP server and skill for OpenAI Codex.
- ChatGPT app - Drive Lumail from a ChatGPT conversation.
- Lumail CLI - Terminal access for scripts and agents.
5. Verify your sending domain
Lumail only sends from a domain you have verified. Add the domain in your organization's Domains settings, then publish the SPF, DKIM and DMARC records it shows at your DNS provider. Until the domain verifies, every send fails with an error saying the domain is not authorized or verified.
Use a subdomain such as mail.yourdomain.com if your root domain already sends from another provider. Start DMARC at p=none, then tighten it once reports look clean.
- Email domains - Add a domain and the SPF, DKIM and DMARC records.
- Add a DMARC record - Publish a policy, then tighten it safely.
- Mail tester - Send a real email and check authentication and spam signals.
Common pitfalls
- An open relay. A function that sends to whatever
tothe browser posts lets anyone email anyone from your domain. Send to the authenticated user, or to a fixed address you own. - Missing CORS handling. Without the
OPTIONSbranch and CORS headers,supabase.functions.invokefails in the browser even though the function works from curl. - Import path of the Supabase client. The client path in the second snippet is where Lovable projects commonly keep it; use whatever path your project already imports.
- Client-side sends. If the AI imports
lumailin a React component or usesfetchto the Lumail API from the browser, the key ships to every visitor. Move it to a server route or function and rotate the token. - Unverified `from` domain. Sends from a domain that is not verified in the same organization are rejected with a 400 that names the domain. Verify it first, or use the exact address Lumail shows you.
- Treating `{ error }` as an exception. The SDK never throws on HTTP errors. Code that only wraps the call in
try/catchsilently drops failures. - Duplicate emails on retry. Without an idempotency key, a retried request or double-clicked button can send twice.
Frequently asked questions
Can a Lovable app send email without a backend?
Not safely. Any key in the React app is visible to every visitor. Use a Supabase Edge Function, which runs on the server and reads the key from its secrets.
Where do I put the Lumail API key in Lovable?
As a Supabase Edge Function secret named LUMAIL_API_KEY. Lovable typically prompts for it when it creates a function that needs it. Never store it in a VITE_ variable.
Why use fetch instead of the lumail npm package?
Edge Functions run on Deno, and a single fetch call to POST https://lumail.io/api/v2/emails needs no dependency. The request body is the same as the SDK's send parameters.
Can I use the Lumail MCP server inside Lovable?
Lovable is a cloud builder, so connect the MCP server to a local agent such as Claude Code, Codex or ChatGPT instead. Your Lovable app keeps sending through the API.
Does Supabase Auth send its emails through Lumail too?
Not by default. Supabase Auth sends confirmation and reset emails through its own mailer unless you configure custom SMTP. Lumail's SMTP relay at smtp.lumail.io on port 587 accepts a lum_ token as the password.
Keep building
- AI app builderAdd email to your Bolt appA server route or function that sends with Lumail, with the key in .env and never behind VITE_.
- AI app builderAdd email to your v0 appA Next.js server action that sends with Lumail, with the key in project env vars, never NEXT_PUBLIC_.
- AI app builderAdd email to your Replit appReplit Agent prompt for Node or Python, with the API key in Secrets and checked on the deployment.
- DocsSMTP relayUse Lumail as custom SMTP for auth emails.
- DocsSend Email API referenceEvery field and error for POST /api/v2/emails.
- DocsTest-mode recipientsFixture addresses that never send real email.
- DocsVerify a sending domainDNS records and verification steps.
- Free toolMail testerCheck SPF, DKIM, DMARC and spam signals on a real send.
Ship email from your Lovable app today.
3,000 emails a month free. Transactional and marketing email on one verified domain, with unlimited subscribers on every plan.