[{"data":1,"prerenderedAt":966},["ShallowReactive",2],{"blog-en-download-your-supabase-backup":3,"blog-index-en":620},{"id":4,"title":5,"body":6,"category":577,"cover":578,"coverAlt":579,"description":580,"draft":581,"extension":582,"faq":583,"image":598,"keywords":599,"meta":609,"navigation":610,"ogTitle":5,"path":611,"published":612,"seo":613,"stem":614,"tldr":615,"updated":612,"__hash__":619},"blog_en\u002Fblog\u002Fdownload-your-supabase-backup.md","Why you can't download your Supabase backup",{"type":7,"value":8,"toc":563},"minimark",[9,13,21,24,29,46,127,135,139,147,150,163,169,173,181,202,205,235,240,244,247,255,258,262,265,271,291,305,309,318,328,335,342,366,369,373,376,393,398,401,415,423,427,430,443,450,458,462,493,497,502,543,556],[10,11,12],"p",{},"You are on a paid Supabase plan, so you have backups. You open Database, then\nBackups, and there they are: a list of dated daily copies, each with a Restore\nbutton. You go looking for the button that lets you download your Supabase\nbackup and keep it somewhere of your own, and there isn't one.",[10,14,15,16,20],{},"Nothing is broken. Here is the part older guides still get wrong: ",[17,18,19],"strong",{},"on a current\nproject there is no daily backup to download."," Supabase moved its daily copies\nto a different kind of backup, one it can restore for you and cannot hand over.\nThe download button those guides describe belonged to the older kind. A file you\nhold is something you now make yourself, and it is a different kind of file.",[10,22,23],{},"Your phone is the easiest way to picture the difference. The backup it takes of\nitself every night is complete and exact, and it comes back onto a phone signed\ninto the same account in one step. You cannot open it on a laptop and take your\nphotos out of it. For photos you can keep anywhere, you export them, and what you\nget is a folder of ordinary files. Supabase's daily backup is now the first kind.\nThe file you can hold is the second.",[25,26,28],"h2",{"id":27},"can-i-download-my-supabase-backup","Can I download my Supabase backup?",[10,30,31,32,39,40,45],{},"Not the daily one, if your project runs Postgres 15.8.1.079 or newer. Supabase's\nbackup documentation says\n",[33,34,38],"a",{"href":35,"rel":36},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fplatform\u002Fbackups",[37],"nofollow","all projects on that version and newer use physical backups",",\nand its troubleshooting notes say that once physical backups are on, Supabase\n",[33,41,44],{"href":42,"rel":43},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Ftroubleshooting\u002Fdownload-logical-backups",[37],"no longer generates the downloadable backup file",".\nYou can restore those copies whenever you like. You can't take one with you.",[47,48,49,64],"table",{},[50,51,52],"thead",{},[53,54,55,58,61],"tr",{},[56,57],"th",{},[56,59,60],{},"The daily Supabase backup (physical)",[56,62,63],{},"A dump you take yourself (logical)",[65,66,67,79,95,106,117],"tbody",{},[53,68,69,73,76],{},[70,71,72],"td",{},"What it is",[70,74,75],{},"A snapshot of the files Postgres keeps on disk",[70,77,78],{},"SQL: instructions to rebuild every table, then the rows",[53,80,81,84,87],{},[70,82,83],{},"Who restores it",[70,85,86],{},"Supabase, when you press Restore",[70,88,89,90,94],{},"You, with ",[91,92,93],"code",{},"psql",", into any Postgres",[53,96,97,100,103],{},[70,98,99],{},"Where it can go",[70,101,102],{},"This project, or a new one in the same region",[70,104,105],{},"Another project, another account, your laptop, your server",[53,107,108,111,114],{},[70,109,110],{},"Can you download it",[70,112,113],{},"No",[70,115,116],{},"It is already a file",[53,118,119,122,124],{},[70,120,121],{},"Survives losing access to the account",[70,123,113],{},[70,125,126],{},"Yes, if you keep it somewhere else",[10,128,129,130,134],{},"The last row is the one to read twice. Supabase says that when a project is\ndeleted it removes all associated data,\n",[33,131,133],{"href":35,"rel":132},[37],"including any backups stored in S3",".\nDelete the project and its daily copies go in the same step.",[25,136,138],{"id":137},"what-is-the-difference-between-a-physical-and-a-logical-backup","What is the difference between a physical and a logical backup?",[10,140,141,142,146],{},"Where the copy is taken from. A physical backup copies the files Postgres itself\nwrites to disk, which Supabase describes as\n",[33,143,145],{"href":35,"rel":144},[37],"a snapshot of the underlying directory of the database",".\nA logical backup asks the database to describe itself in SQL, table by table and\nrow by row, and writes that description to a text file.",[10,148,149],{},"Each is good at something different. A physical copy is quick to take and quick\nto put back, and it comes back exactly as it was. It can only be read by the same\nkind of Postgres setup it came from, which on Supabase means Supabase's own\nmachines. A logical copy is slower to replay and bulkier to store, and any\nPostgres of the same version or newer can load it. It is the phone backup and\nthe exported folder again, and only the second is a file you can hold.",[10,151,152,153,158,159,162],{},"The download button people remember was the logical kind. Supabase's\n",[33,154,157],{"href":155,"rel":156},"https:\u002F\u002Fgithub.com\u002Fsupabase\u002Fsupabase\u002Fblob\u002Fb34da8d7eca562be5e1341413d140dd76ee19f25\u002Fapps\u002Fdocs\u002Fcontent\u002Fguides\u002Fplatform\u002Fbackups.mdx",[37],"own documentation from 2025","\nsaid the daily job ran ",[91,160,161],{},"pg_dumpall",", zipped the SQL file and stored it, and that\nphysical backups put less load on the database and avoid holding locks on your\ntables for long periods. The same page said physical copies cannot be downloaded\nfrom the Backups section of the dashboard.",[164,165],"diagram",{"alt":166,"caption":167,"src":168},"Two lanes. In the upper one a sealed snapshot inside a dashed Supabase boundary reaches two projects inside it, both ticked, and a third arrow is crossed at the boundary, short of a Supabase project, a laptop and a server drawn in grey. In the lower one a plain file outside any boundary reaches the same three, lit and ticked.","The daily copy can go back into Supabase and nowhere else. A dump you take yourself goes wherever a Postgres runs.","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fwhere-each-copy-can-go-1600x640.png",[25,170,172],{"id":171},"how-do-i-tell-which-one-my-project-has","How do I tell which one my project has?",[10,174,175,176,180],{},"Look for a download option on the Backups page. Open Database, then Backups, in\nyour Supabase dashboard. If each dated copy has a way to download it, your\nproject is still on logical backups. If each one offers Restore and nothing else,\nit is on physical backups, and Supabase's\n",[33,177,179],{"href":155,"rel":178},[37],"older documentation used exactly that test",".",[10,182,183,184,187,188,191,192,195,196,199,200,180],{},"The second check is the version number. It is printed under Project Settings,\nthen General. Anything from ",[91,185,186],{},"15.8.1.079"," upwards means physical backups. Read it\nleft to right: a version starting ",[91,189,190],{},"17"," is newer than any ",[91,193,194],{},"15",", and ",[91,197,198],{},"15.8.1.100","\nis newer than ",[91,201,186],{},[10,203,204],{},"Two cases need no checking at all:",[206,207,208,224],"ul",{},[209,210,211,218,219,223],"li",{},[17,212,213,217],{},[33,214,216],{"href":215},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Point-in-time recovery"," is on."," It\nruns on physical backups by definition. Supabase also says that if you\n",[33,220,222],{"href":35,"rel":221},[37],"switch point-in-time recovery off",",\nit keeps taking physical backups, so the download does not come back.",[209,225,226,229,230,234],{},[17,227,228],{},"You are on the free plan."," The Backups page has nothing on it to download or\nrestore, because the free plan gives you no daily backups to use.\n",[33,231,233],{"href":232},"\u002Fblog\u002Fback-up-supabase-free-tier","Making a copy without a terminal"," is the\nplace to start.",[164,236],{"alt":237,"caption":238,"src":239},"Two lists of five dated copies side by side, one headed by a plain file and the other by a sealed snapshot. In the left list every row carries a restore mark and a download mark. In the right list every row carries the same restore mark, and the space where the download mark sat is an empty dashed outline.","The same page on two projects. On the left, the older logical backups, each with a download. On the right, physical backups: restore only.","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fwhich-one-you-have-1600x620.png",[25,241,243],{"id":242},"what-does-each-one-protect-me-from","What does each one protect me from?",[10,245,246],{},"The daily backup protects you from something going wrong inside the project. A\nfile you hold also covers losing the project itself.",[10,248,249,250,254],{},"The first kind of loss is the one you cause yourself. A delete that caught more\nrows than you meant, a migration an AI agent wrote and you approved, a script\npointed at the wrong table. The daily copy is exactly the tool for that: pick yesterday,\npress Restore, and the project is put back. How far back it can reach depends on\nyour plan, and\n",[33,251,253],{"href":252},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","which plan you are on"," settles it in\nabout two minutes.",[10,256,257],{},"The second kind does not involve a mistake in the database at all. A card that\nexpired while you were away, a login you cannot recover, a project somebody\ndeleted. The copies are on the far side of the same door as the project, and\nthe door is the thing that closed. Your phone's backup behaves the same way: it\nrescues you from a phone dropped in the sea, and it is no help on the day you\ncannot sign in to the account it lives in. Supabase keeps its backups with the\nplatform because that is what lets a restore take one button. A copy that\nsurvives the account has to be stored somewhere else, which on Supabase means a\nlogical dump taken out of it.",[25,259,261],{"id":260},"what-does-restore-mean-for-each-one","What does restore mean for each one?",[10,263,264],{},"For the daily copy, Supabase does the work and you choose where it lands. For a\nfile you hold, you do the work, and it can land anywhere.",[10,266,267,270],{},[17,268,269],{},"Restoring the daily copy into the same project"," replaces the database with\nthe copy you pick. Supabase says the project is inaccessible while it runs, and\nthat a bigger database takes longer.",[10,272,273,276,277,282,283,286,287,290],{},[17,274,275],{},"Restoring it into a new project"," is a paid feature Supabase calls\n",[33,278,281],{"href":279,"rel":280},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fplatform\u002Fclone-project",[37],"Restore to a New Project",",\nstill marked beta. It creates a separate project in the same region, with your\nusers and their hashed passwords, and it bills as a second project. One caution\nfrom the same page is easy to miss. It copies the entire database, including\nextensions that act on the outside world such as ",[91,284,285],{},"pg_cron"," and ",[91,288,289],{},"pg_net",", and\nthose jobs start running as soon as the restore completes. If a scheduled job in\nyour app sends email or calls a payment API, the new project starts doing that\ntoo, the moment it exists.",[10,292,293,296,297,299,300,304],{},[17,294,295],{},"Restoring a file you hold"," means replaying it with ",[91,298,93],{}," into whatever you\npoint it at: a new Supabase project, one on a different account, or a Postgres\non your own computer.\n",[33,301,303],{"href":302},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup"," goes\nthrough the commands, and through what is still broken after it finishes.",[25,306,308],{"id":307},"how-do-i-get-a-file-copy-of-my-supabase-database","How do I get a file copy of my Supabase database?",[10,310,311,312,317],{},"Take a logical dump yourself. Supabase publishes it in its\n",[33,313,316],{"href":314,"rel":315},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fplatform\u002Fmigrating-within-supabase\u002Fbackup-restore",[37],"backup and restore guide","\nas three commands, each writing one file:",[319,320,325],"pre",{"className":321,"code":323,"language":324},[322],"language-text","supabase db dump --db-url \"postgresql:\u002F\u002F…\" -f roles.sql --role-only\nsupabase db dump --db-url \"postgresql:\u002F\u002F…\" -f schema.sql\nsupabase db dump --db-url \"postgresql:\u002F\u002F…\" -f data.sql --use-copy --data-only\n","text",[91,326,323],{"__ignoreMap":327},"",[10,329,330,331,334],{},"The connection string comes from the Connect button at the top of your project,\nwith your database password in place of the placeholder. The Supabase CLI needs\nDocker installed, because it runs ",[91,332,333],{},"pg_dump"," inside a container rather than\nusing one from your computer.",[10,336,337,338,180],{},"Keep all three files. The second on its own is the shape of your tables with no\nrows in it, and\n",[33,339,341],{"href":340},"\u002Fblog\u002Fsupabase-backup-auth-users","your users are only in the third",[10,343,344,345,347,348,353,354,356,357,362,363,365],{},"You can also run ",[91,346,333],{}," directly. Two things to know first.\n",[33,349,352],{"href":350,"rel":351},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fself-hosting\u002Frestore-from-platform",[37],"Supabase says","\na raw ",[91,355,333],{}," takes Supabase's own internal schemas along with yours, and that\nreplaying those causes permission errors on the way back in. And\n",[33,358,361],{"href":359,"rel":360},"https:\u002F\u002Fwww.postgresql.org\u002Fdocs\u002Fcurrent\u002Fapp-pgdump.html",[37],"Postgres documents","\nthat ",[91,364,333],{}," will not dump from a server newer than its own major version, so\nan older copy on your computer refuses to start rather than making a bad file.",[10,367,368],{},"Put the files somewhere that is not your Supabase account, and not only your\nlaptop.",[25,370,372],{"id":371},"can-i-restore-a-supabase-backup-on-my-own-machine","Can I restore a Supabase backup on my own machine?",[10,374,375],{},"A logical one, yes, into a Postgres of the same major version or newer. The\ndaily physical copy cannot be restored anywhere except Supabase.",[10,377,378,379,383,384,388,389,392],{},"The version rule comes from Postgres itself. Its documentation says a dump\n",[33,380,382],{"href":359,"rel":381},[37],"can be expected to load into newer versions","\nand is not guaranteed to load into an older one, even one the dump came from.\nSupabase's guide to\n",[33,385,387],{"href":350,"rel":386},[37],"moving a platform project to self-hosted Supabase","\nshows what that looks like. The platform can run Postgres 17 while the\nself-hosted image defaults to 15, and the data file then carries a line,\n",[91,390,391],{},"SET transaction_timeout = 0",", that Postgres 15 does not recognise.",[164,394],{"alt":395,"caption":396,"src":397},"Two lanes. In the upper one a file leaves a database marked 15 and arrives in a database marked 17, ticked. In the lower one a file leaves a database marked 17 and stops at a database marked 15, crossed.","A dump moves forward. Loading it into an older Postgres than the one it came from is where the errors start.","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fforwards-not-backwards-1600x560.png",[10,399,400],{},"The same three files are also the way off Supabase entirely. That guide is the\nroute to running Supabase on a server of your own, and the version mismatch is\nthe first thing it warns about.",[10,402,403,404,407,408,410,411,414],{},"On your own computer, the Supabase CLI runs a local copy of Supabase in Docker\nwhen you type ",[91,405,406],{},"supabase start",". Replay the three files into it with the ",[91,409,93],{},"\ncommand from Supabase's backup and restore guide, pointed at\n",[91,412,413],{},"postgresql:\u002F\u002Fpostgres:postgres@localhost:54322\u002Fpostgres",", and your data is\nreadable on your own computer with no account involved.",[10,416,417,418,422],{},"There is one place Supabase still offers a backup to download. A free project\npaused past its restore window swaps the Restore button for a download of the\nlast copy taken before it paused, and\n",[33,419,421],{"href":420},"\u002Fblog\u002Fsupabase-project-paused-recover","what to do with that file"," is its own\narticle.",[25,424,426],{"id":425},"what-is-in-neither-copy","What is in neither copy?",[10,428,429],{},"Your uploaded files, your Edge Functions, and most of your project's settings.",[10,431,432,433,437,438,442],{},"Supabase says database backups\n",[33,434,436],{"href":35,"rel":435},[37],"do not include objects stored via the Storage API",".\nThe database holds a row describing each file, and the file itself lives\nsomewhere else, so no backup of the database on any plan contains your users'\nuploads.\n",[33,439,441],{"href":440},"\u002Fblog\u002Fsupabase-storage-backup","Backing up Storage"," is a job of its own.",[10,444,445,446,449],{},"The list Supabase gives for\n",[33,447,281],{"href":279,"rel":448},[37],"\nis a good inventory of the rest: Edge Functions, auth settings and API keys,\nRealtime settings, extension settings and read replicas all have to be set up\nagain by hand.",[10,451,452,453,457],{},"One gap is specific to the file you hold. If your app keeps secrets in Supabase\nVault or uses encrypted columns, Supabase says\n",[33,454,456],{"href":314,"rel":455},[37],"backup files never contain the root key",",\nonly the encrypted data. A new project starts with its own key, so those values\ncome across unreadable until the old key is copied over. And the old key can\nonly be fetched while the old project is still active. Once that project is\npaused or deleted, the key cannot be retrieved, and neither can anything\nencrypted with it.",[25,459,461],{"id":460},"what-to-do-this-week","What to do this week",[463,464,465],"key-takeaways",{},[206,466,467,470,473,484,487,490],{},[209,468,469],{},"Open Database, then Backups, and look for a download option. If every copy offers only Restore, you have physical backups and nothing there to take away.",[209,471,472],{},"Take one logical dump today with the three commands, and keep all three files together.",[209,474,475,476,479,480,483],{},"Search ",[91,477,478],{},"data.sql"," for ",[91,481,482],{},"auth.users"," before you rely on it. That is the file your accounts are in, when they are in it at all.",[209,485,486],{},"Store the files somewhere that is not your Supabase account.",[209,488,489],{},"If you use Supabase Vault or encrypted columns, read how the root key moves before you need it. It is not in the file.",[209,491,492],{},"Replay the dump once into a throwaway project or a local Supabase, so the first time you open it is not the day you need it.",[25,494,496],{"id":495},"where-reeve-care-fits","Where Reeve Care fits",[10,498,499],{},[17,500,501],{},"Care takes the logical copy for you, keeps it off Supabase, and every copy is a\nfile you can download.",[206,503,504,521,527,533],{},[209,505,506,509,510,513,514,516,517,520],{},[17,507,508],{},"Download any copy as a zip."," Inside are ",[91,511,512],{},"schema.sql",", ",[91,515,478],{}," and\n",[91,518,519],{},"roles.sql",", a manifest counting the rows in every table, and a note on how to\nload it into any Postgres. It is a standard dump, so any developer can open it,\nand so can any other host.",[209,522,523,526],{},[17,524,525],{},"Stored outside your Supabase account",", encrypted, so it is still there on a\nday the account is not.",[209,528,529,532],{},[17,530,531],{},"Read back before it counts."," The date on your dashboard is the last copy\nthat was opened and verified, never the last one attempted.",[209,534,535,538,539,542],{},[17,536,537],{},"Your users are in it."," The ",[91,540,541],{},"auth"," schema travels with your tables, and the\nfiles your users uploaded come too once you connect a Storage credential.",[10,544,545,546,550,551,555],{},"Care keeps a copy of your Supabase database. Leave the daily Supabase backups\nswitched on beside it: they are the fastest way back from a bad migration, and\nthe file is what is left if you lose the account. How a copy is taken, checked and downloaded is drawn step by step on\nthe ",[33,547,549],{"href":548},"\u002Fsupabase-backups","Supabase backups page",", and\n",[33,552,554],{"href":553},"\u002Fpricing","what each plan includes"," is on the pricing page.",[10,557,558,559,562],{},"Before you close this tab, open Database, then Backups, and look beside your\nnewest copy. If there is nothing there to download, the next file you hold is\nthe one you make, and\n",[33,560,561],{"href":340},"what makes a dump complete"," is the thing to\nread before you make it.",{"title":327,"searchDepth":564,"depth":564,"links":565},3,[566,568,569,570,571,572,573,574,575,576],{"id":27,"depth":567,"text":28},2,{"id":137,"depth":567,"text":138},{"id":171,"depth":567,"text":172},{"id":242,"depth":567,"text":243},{"id":260,"depth":567,"text":261},{"id":307,"depth":567,"text":308},{"id":371,"depth":567,"text":372},{"id":425,"depth":567,"text":426},{"id":460,"depth":567,"text":461},{"id":495,"depth":567,"text":496},"Backups","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fcover-1200x630.png","Four daily database snapshots stacked inside a Supabase enclosure, the front one lit and sealed, beside an empty download tray in grey.","You can't download your Supabase backup on a current project, because the daily copy is a physical snapshot. How to tell, and how to hold a copy of your own.",false,"md",[584,586,588,591,593,595],{"q":28,"a":585},"Not the daily one, if your project runs Postgres 15.8.1.079 or newer. Supabase says every project on those versions uses physical backups, and that once physical backups are on it no longer produces the downloadable backup file. You can still restore those copies from the dashboard. To get a file you can keep, take a logical dump yourself with the Supabase CLI or pg_dump.",{"q":138,"a":587},"A physical backup copies the files Postgres keeps on disk. It restores quickly and exactly, and only onto the same kind of Postgres setup it came from, which on Supabase means Supabase restores it for you. A logical backup is SQL: the instructions to rebuild each table, followed by the rows. It is slower to replay, and it loads into any Postgres of the same version or newer, including one on your own computer.",{"q":589,"a":590},"Why is the download button gone?","Because the thing it downloaded is no longer made. The button belonged to the older logical daily backups, which were SQL files Supabase zipped and stored. When a project moves to physical backups, Supabase stops producing that file, and the Backups page offers Restore without a download beside it. Turning point-in-time recovery off does not bring it back, because Supabase keeps taking physical backups after that too.",{"q":308,"a":592},"Run the three commands Supabase publishes in its backup and restore guide: supabase db dump with --role-only, then with no flags for the schema, then with --data-only and --use-copy for the rows. The CLI needs Docker, because it runs pg_dump inside a container. Keep all three files together, and store them somewhere that is not your Supabase account.",{"q":372,"a":594},"A logical one, yes, into a Postgres of the same major version or newer. Postgres documents that a dump loads forwards and is not guaranteed to load into an older version, and Supabase gives an example: its platform can run Postgres 17 while self-hosted Supabase defaults to 15. A physical daily copy cannot be restored anywhere except Supabase.",{"q":596,"a":597},"Does the Pro plan give me a downloadable backup?","Not on a project running Postgres 15.8.1.079 or newer. There, Pro gives you daily physical backups kept for seven days, which you can restore into the same project or, while the feature is in beta, into a new project in the same region. Neither route gives you a file. A downloadable copy is something you take yourself, or pay somebody to take for you.","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fcard-800x500.png",[600,601,602,603,604,605,606,607,608],"download supabase backup","supabase backup download","supabase physical backup","supabase logical backup","supabase backup file","get a copy of my supabase database","supabase backup not downloadable","supabase daily backup download","supabase backup export",{},true,"\u002Fblog\u002Fdownload-your-supabase-backup","2026-09-26",{"title":5,"description":580},"blog\u002Fdownload-your-supabase-backup",[616,617,618],"You can't download your Supabase backup on a project running Postgres 15.8.1.079 or newer. The daily copies there are physical snapshots, which Supabase can restore for you and you cannot download.","The download button older guides describe belonged to logical backups, which were SQL files. Only projects still on the older versions have it.","To hold a file of your own, you take a logical dump yourself with the Supabase CLI or pg_dump. It is the only copy that survives losing access to the account.","RCUAz11TttWXGIf7QTEw9nuFJdT3lPVaqNj7ueei41s",[621,628,634,640,646,652,658,664,670,676,682,688,694,700,706,707,712,718,724,729,735,741,747,753,759,765,771,777,782,787,792,798,804,810,816,822,828,834,840,846,852,858,864,869,875,881,887,893,899,904,910,916,922,928,933,939,944,950,955,961],{"path":622,"title":623,"description":624,"published":625,"category":626,"image":627,"draft":581},"\u002Fblog\u002Fbase44-security-scan","Base44 security scan: the one thing only it can see","The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.","2026-10-10","Security basics","\u002Fblog\u002Fbase44-security-scan\u002Fcard-800x500.png",{"path":629,"title":630,"description":631,"published":632,"category":626,"image":633,"draft":581},"\u002Fblog\u002Fapi-key-leaked-what-to-do","Your API key leaked. Here is the order to do things in","An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.","2026-10-09","\u002Fblog\u002Fapi-key-leaked-what-to-do\u002Fcard-800x500.png",{"path":635,"title":636,"description":637,"published":638,"category":626,"image":639,"draft":581},"\u002Fblog\u002Finfinite-recursion-in-policy-for-relation","\"Infinite recursion detected in policy\" without disabling RLS","\"Infinite recursion detected in policy for relation\" means your Supabase policy asked the table it protects. Here is how to break the circle.","2026-10-08","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fcard-800x500.png",{"path":641,"title":642,"description":643,"published":644,"category":626,"image":645,"draft":581},"\u002Fblog\u002Fno-api-key-found-in-request","\"No API key found in request\" in Supabase, and the wrong fix","\"No API key found in request\" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.","2026-10-07","\u002Fblog\u002Fno-api-key-found-in-request\u002Fcard-800x500.png",{"path":647,"title":648,"description":649,"published":650,"category":626,"image":651,"draft":581},"\u002Fblog\u002Fis-base44-safe","Is Base44 safe? What 5,442 live Base44 apps showed","Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.","2026-10-06","\u002Fblog\u002Fis-base44-safe\u002Fcard-800x500.png",{"path":653,"title":654,"description":655,"published":656,"category":626,"image":657,"draft":581},"\u002Fblog\u002Fmove-a-secret-to-an-edge-function","Hide an API key: move it to a Supabase Edge Function","Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.","2026-10-05","\u002Fblog\u002Fmove-a-secret-to-an-edge-function\u002Fcard-800x500.png",{"path":659,"title":660,"description":661,"published":662,"category":626,"image":663,"draft":581},"\u002Fblog\u002Fenv-file-exposed-on-your-server","Is your .env file exposed? The twelve paths to check","Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.","2026-10-04","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Fcard-800x500.png",{"path":665,"title":666,"description":667,"published":668,"category":626,"image":669,"draft":581},"\u002Fblog\u002Fis-v0-safe","v0 security: all 1,790 v0 apps we scanned got an A","v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.","2026-10-03","\u002Fblog\u002Fis-v0-safe\u002Fcard-800x500.png",{"path":671,"title":672,"description":673,"published":674,"category":626,"image":675,"draft":581},"\u002Fblog\u002Fis-bolt-safe","Is Bolt safe? What 1,123 live Bolt apps showed","Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.","2026-10-02","\u002Fblog\u002Fis-bolt-safe\u002Fcard-800x500.png",{"path":677,"title":678,"description":679,"published":680,"category":626,"image":681,"draft":581},"\u002Fblog\u002Fis-supabase-down-or-your-app","Is Supabase down, or is it your app? How to tell","Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.","2026-10-01","\u002Fblog\u002Fis-supabase-down-or-your-app\u002Fcard-800x500.png",{"path":683,"title":684,"description":685,"published":686,"category":626,"image":687,"draft":581},"\u002Fblog\u002Fdoes-supabase-encrypt-my-data","Does Supabase encrypt my data? Yes. Here is what it stops","Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.","2026-09-30","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fcard-800x500.png",{"path":689,"title":690,"description":691,"published":692,"category":626,"image":693,"draft":581},"\u002Fblog\u002Fsupabase-free-plan-limits","Supabase free plan limits, and what happens at each one","The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.","2026-09-29","\u002Fblog\u002Fsupabase-free-plan-limits\u002Fcard-800x500.png",{"path":695,"title":696,"description":697,"published":698,"category":577,"image":699,"draft":581},"\u002Fblog\u002Ftest-your-supabase-backup","Test your Supabase backup before the day you need it","How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.","2026-09-28","\u002Fblog\u002Ftest-your-supabase-backup\u002Fcard-800x500.png",{"path":701,"title":702,"description":703,"published":704,"category":577,"image":705,"draft":581},"\u002Fblog\u002Fsupabase-backup-github-action","Free Supabase backup with a GitHub Action, and the catch","A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.","2026-09-27","\u002Fblog\u002Fsupabase-backup-github-action\u002Fcard-800x500.png",{"path":611,"title":5,"description":580,"published":612,"category":577,"image":598,"draft":581},{"path":708,"title":709,"description":710,"published":612,"category":626,"image":711,"draft":581},"\u002Fblog\u002Fsupabase-permission-denied-for-table","Supabase \"permission denied for table\": the missing grant","From October 30, a new Supabase table answers \"permission denied for table\" until you grant access. The grant the email shows is half the fix.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fcard-800x500.png",{"path":713,"title":714,"description":715,"published":716,"category":626,"image":717,"draft":581},"\u002Fblog\u002Fopen-api-endpoint-exposed","Is an open API endpoint a security problem? Look at the JSON","Your scan flagged an open API endpoint. Whether it matters depends on what came back, and most of the ones we found were the platform's own.","2026-09-25","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fcard-800x500.png",{"path":719,"title":720,"description":721,"published":722,"category":626,"image":723,"draft":581},"\u002Fblog\u002Flovable-security-scan","Lovable security scan: the one thing it cannot prove","Lovable security scan: what the Quick and Deep scans check, when each one runs, and the one thing no scan from inside your project can prove.","2026-09-24","\u002Fblog\u002Flovable-security-scan\u002Fcard-800x500.png",{"path":340,"title":725,"description":726,"published":727,"category":577,"image":728,"draft":581},"Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":730,"title":731,"description":732,"published":733,"category":626,"image":734,"draft":581},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":736,"title":737,"description":738,"published":739,"category":626,"image":740,"draft":581},"\u002Fblog\u002Fis-lovable-safe","Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":742,"title":743,"description":744,"published":745,"category":626,"image":746,"draft":581},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":748,"title":749,"description":750,"published":751,"category":626,"image":752,"draft":581},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":754,"title":755,"description":756,"published":757,"category":626,"image":758,"draft":581},"\u002Fblog\u002Fvite-and-next-public-env-vars","Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":760,"title":761,"description":762,"published":763,"category":626,"image":764,"draft":581},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":766,"title":767,"description":768,"published":769,"category":626,"image":770,"draft":581},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":772,"title":773,"description":774,"published":775,"category":626,"image":776,"draft":581},"\u002Fblog\u002Fis-replit-safe","Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":440,"title":778,"description":779,"published":780,"category":577,"image":781,"draft":581},"Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":215,"title":783,"description":784,"published":785,"category":577,"image":786,"draft":581},"Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":420,"title":788,"description":789,"published":790,"category":577,"image":791,"draft":581},"Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":793,"title":794,"description":795,"published":796,"category":626,"image":797,"draft":581},"\u002Fblog\u002Fsafest-ai-app-builder","Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":799,"title":800,"description":801,"published":802,"category":626,"image":803,"draft":581},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":805,"title":806,"description":807,"published":808,"category":626,"image":809,"draft":581},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":811,"title":812,"description":813,"published":814,"category":626,"image":815,"draft":581},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":817,"title":818,"description":819,"published":820,"category":626,"image":821,"draft":581},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":823,"title":824,"description":825,"published":826,"category":626,"image":827,"draft":581},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":829,"title":830,"description":831,"published":832,"category":626,"image":833,"draft":581},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":835,"title":836,"description":837,"published":838,"category":626,"image":839,"draft":581},"\u002Fblog\u002Fmissing-security-headers","Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":841,"title":842,"description":843,"published":844,"category":626,"image":845,"draft":581},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":847,"title":848,"description":849,"published":850,"category":626,"image":851,"draft":581},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":853,"title":854,"description":855,"published":856,"category":577,"image":857,"draft":581},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":859,"title":860,"description":861,"published":862,"category":626,"image":863,"draft":581},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":232,"title":865,"description":866,"published":867,"category":577,"image":868,"draft":581},"Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":870,"title":871,"description":872,"published":873,"category":626,"image":874,"draft":581},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":876,"title":877,"description":878,"published":879,"category":626,"image":880,"draft":581},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":882,"title":883,"description":884,"published":885,"category":626,"image":886,"draft":581},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":888,"title":889,"description":890,"published":891,"category":626,"image":892,"draft":581},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":894,"title":895,"description":896,"published":897,"category":577,"image":898,"draft":581},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":302,"title":900,"description":901,"published":902,"category":577,"image":903,"draft":581},"How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":905,"title":906,"description":907,"published":908,"category":626,"image":909,"draft":581},"\u002Fblog\u002Fsupabase-storage-bucket-public","Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":911,"title":912,"description":913,"published":914,"category":626,"image":915,"draft":581},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":917,"title":918,"description":919,"published":920,"category":577,"image":921,"draft":581},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":923,"title":924,"description":925,"published":926,"category":626,"image":927,"draft":581},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":929,"title":930,"description":931,"published":926,"category":626,"image":932,"draft":581},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":934,"title":935,"description":936,"published":937,"category":626,"image":938,"draft":581},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":252,"title":940,"description":941,"published":942,"category":577,"image":943,"draft":581},"Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":945,"title":946,"description":947,"published":948,"category":626,"image":949,"draft":581},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":951,"title":952,"description":953,"published":948,"category":577,"image":954,"draft":581},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":956,"title":957,"description":958,"published":959,"category":577,"image":960,"draft":581},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":962,"title":963,"description":964,"published":959,"category":626,"image":965,"draft":581},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1791618966336]