Blog
Practical notes on Supabase security: RLS, keys, functions and the mistakes we see in real projects.
Is it safe to expose your Supabase anon key?
Yes, the Supabase anon (publishable) key is meant to be public. Whether your data is safe depends entirely on Row Level Security. Here's what the key can reach and how to check.
How to check if your Supabase secret key leaked (and what to do if it did)
Find out whether your Supabase secret or service_role key ended up in your frontend bundle, repo or environment variables, and rotate it in the order Supabase recommends.
SECURITY DEFINER functions: the Supabase RLS bypass hiding in your RPC endpoints
A SECURITY DEFINER function in an exposed Supabase schema runs with its owner's rights and ignores RLS. How to find them, why they're risky, and the safe pattern Supabase recommends.