Manual Approval for Domain

Our OAuth redirect and deauthorization webhook endpoints are hosted on our Backend-as-a-Service provider, Supabase, under a project-specific subdomain assigned to our account. We have full administrative control over that specific subdomain through our provider account, but cannot verify the provider’s root domain itself, since it’s owned and operated by the Backend-as-a-Service company, not us. This is a standard pattern for applications built on backend-as-a-service platforms such as this one, Firebase, Auth0, or AWS.