Send emails from Bolt.new with Brevo

Use Brevo to send both app-triggered emails (order confirmations, notifications) and Supabase-powered authentication emails from a Bolt.new project.

View as Markdown

Overview

Bolt doesn’t have a dedicated Brevo integration in its catalog — it supports any email provider that exposes an HTTP API through server functions and secrets. Bolt.new documents this generic pattern using Resend as the example; this guide swaps in Brevo. There are two separate things you might want to do, and you can set up one or both:

  1. Send transactional emails from your own app code (order confirmations, notifications) — Part 1.
  2. Send Supabase Auth emails (signup, password reset, magic link) from your own domain — Part 2.

Both parts assume your project already has a database enabled. If it doesn’t yet, Bolt shows a “Power up your backend with Bolt Database” screen with two options: “Ask Bolt to create a database” (a Bolt-managed database) or “Connect to Supabase” (link an existing Supabase project directly). Either gets you a database; Part 2 below still applies if you started from a Bolt-managed one and need to move it into your own Supabase account.

Prerequisites

  • A Bolt project with a Bolt database enabled
  • A Brevo account
  • For Part 2: a published project with a custom domain attached

Part 1: Send app emails with the Brevo API

1

Create a Brevo API key

  1. In Brevo, click Settings (gear icon) in the left sidebar, then open SMTP & API > API keys & MCP (direct link: app.brevo.com/settings/keys/api).
  2. Click + Generate API key, name it (e.g. Bolt integration), and copy it.
2

Store the key as a Bolt secret

  1. In your Bolt project, click the Database button at the top, then the Secrets tab (it’s one of a row of tabs: Tables, Security, Authentication, User Management, Server Functions, File Storage, Secrets, Logs, Advanced).
  2. Under Name / Value, create a secret named BREVO_API_KEY with your API key as the value.
  3. Click Create secret.
3

Call the Brevo API from a server function

Add a server function that calls Brevo’s transactional email endpoint:

const res = await fetch("https://api.brevo.com/v3/smtp/email", {
method: "POST",
headers: {
"api-key": BREVO_API_KEY,
"Content-Type": "application/json",
},
body: JSON.stringify({
sender: { name: "Your App", email: "no-reply@yourdomain.com" },
to: [{ email: recipientEmail }],
subject: "Order confirmed",
htmlContent: "<p>Thanks for your order!</p>",
}),
});

You can ask Bolt directly in chat, e.g. “Send an email through the Brevo API when an order is placed, using the BREVO_API_KEY secret.”

4

Test it

Trigger the event in your app and confirm delivery in Brevo > Transactional > Email logs.

Part 2: Send Supabase auth emails through Brevo

Bolt’s authentication runs on Supabase, which by default sends auth emails (password reset, verification, magic links) from its own shared address. To send these from your domain via Brevo:

1

Claim your database

Custom SMTP requires your own Supabase account (not Bolt’s shared infrastructure).

  1. Before claiming, make sure your Supabase account is linked under Account Settings > Applications — Bolt’s Advanced Settings page calls this out as a requirement.
  2. Click the Database button, then the Advanced tab.
  3. Under Claim in Supabase (“Move this database into your own Supabase account”), click Claim and follow the prompts.

Skip this step if your project already runs on your own Supabase account (for example, if you started from “Connect to Supabase” rather than “Ask Bolt to create a database”).

The same Advanced page also has a separate “Connect to a Supabase project” action with a Change database button — that’s a different, destructive operation that replaces your current database with a different existing Supabase project (with a data-loss warning). Don’t confuse it with Claim, which keeps your current data and just moves ownership.

Bolt’s own warning here notes that claiming this database to a Supabase account on the Free plan turns off leaked password protection, a Supabase Auth security feature — it requires a Supabase Pro plan or higher to keep that protection on. This doesn’t block custom SMTP, but it’s worth knowing before you claim.

2

Authenticate a domain and get an SMTP key in Brevo

  1. In Brevo, verify a sending domain under Senders, Domains & Dedicated IPs (SPF/DKIM records).
  2. Generate an SMTP key under Settings > SMTP & API > SMTP (direct link: app.brevo.com/settings/keys/smtp; click + Generate SMTP key). Optional but recommended: list your server’s IP under Security > Authorized IPs, then toggle Activate for SMTP keys on the same SMTP tab to restrict sending to it.
3

Configure custom SMTP in Supabase

In your Supabase project, go to Authentication > Emails > SMTP Settings, enable Custom SMTP, and enter:

FieldValue
Sender email addressAn address on your verified domain
Sender nameYour app or company name
Hostsmtp-relay.brevo.com
Port number587
Minimum interval per userDefault (60 seconds) is fine to start
UsernameYour Brevo account login email
PasswordYour Brevo SMTP key
4

Test it

Trigger a password reset or signup confirmation and confirm it arrives from your domain.

Troubleshooting

  • BREVO_API_KEY missing error: confirm the secret name matches exactly (case-sensitive) and redeploy.
  • Auth emails still come from Supabase’s address: your project is likely still on Bolt-managed Supabase infrastructure — complete the Claim step first.
  • Emails rejected or marked spam: verify SPF/DKIM propagated for your sending domain (can take up to a day).