[{"data":1,"prerenderedAt":919},["ShallowReactive",2],{"blog-en-no-api-key-found-in-request":3,"blog-index-en":566},{"id":4,"title":5,"body":6,"category":523,"cover":524,"coverAlt":525,"description":526,"draft":527,"extension":528,"faq":529,"image":545,"keywords":546,"meta":554,"navigation":555,"ogTitle":556,"path":557,"published":558,"seo":559,"stem":560,"tldr":561,"updated":558,"__hash__":565},"blog_en\u002Fblog\u002Fno-api-key-found-in-request.md","\"No API key found in request\" in Supabase, and the wrong fix",{"type":7,"value":8,"toc":510},"minimark",[9,13,24,27,35,40,43,50,53,56,62,66,69,85,102,108,118,122,128,134,144,152,156,159,162,176,193,196,201,205,208,211,279,282,285,292,299,306,311,318,322,325,334,341,347,359,378,382,385,394,402,406,412,421,437,447,464,468,497],[10,11,12],"p",{},"Your app worked yesterday. Today a list that used to fill with rows is empty, and\nwhen you open the browser console there is a short reply from Supabase sitting\nwhere the data should be:",[14,15,20],"pre",{"className":16,"code":18,"language":19},[17],"language-text","{\n  \"message\": \"No API key found in request\",\n  \"hint\": \"No `apikey` request header or url param was found.\"\n}\n","text",[21,22,18],"code",{"__ignoreMap":23},"",[10,25,26],{},"That is all you get. It does not say which table you were reading, what you sent,\nor what to change.",[10,28,29,30,34],{},"Here is the part that guide after guide gets wrong: ",[31,32,33],"strong",{},"\"No API key found in\nrequest\" is about a missing header, and most of the advice you will find is about\nyour database rules."," On Supabase's own discussion board this message has a\nthread to itself, sixteen people offer eight different remedies in it, and three\nof them say to add or loosen a rule on one of your tables. Everyone who tried\nthat reports the message stopped. Whether a rule was ever the cause is a separate\nquestion, and the thread never settles it. What is certain afterwards is that more\npeople can read the table than could before.",[36,37,39],"h2",{"id":38},"what-no-api-key-found-in-request-means","What \"No API key found in request\" means",[10,41,42],{},"Supabase turned your request away at the front door, before your database was\nasked for anything.",[10,44,45,46,49],{},"Every request to your project arrives first at a gateway that Supabase runs in\nfront of everything else. Its job at that moment is narrow: read the ",[21,47,48],{},"apikey","\nheader, check the value against the keys your project has, and pass the request\non. With no key to read it stops there and answers 401, the status code for \"I do\nnot know who you are\". Supabase's own gateway reference says a missing or invalid\nkey is refused that way.",[10,51,52],{},"Think of the gateway as a doorman at the street door rather than a lock on a\nfiling cabinet. The doorman asks everyone arriving to show a pass. The rules that\ndecide who may open which cabinet live two floors up, and in this case nobody\nconsulted them, because nothing got past the entrance.",[10,54,55],{},"So as errors go, this one is mild. Nothing was read, nothing was written, and\nyour data is exactly as it was. A request was refused.",[57,58],"diagram",{"alt":59,"caption":60,"src":61},"A route drawn left to right from an app to a tall gateway. The gateway carries an empty dashed slot and an amber bar, the arrow stops at it, and a short dashed line leaving the far side goes nowhere. A padlock and a table sit further right in grey, inside a dashed panel.","The gateway reads the key. Your table's rules are a stage further in, and a refused request never reaches them.","\u002Fblog\u002Fno-api-key-found-in-request\u002Fwhere-it-stops-1600x620.png",[36,63,65],{"id":64},"why-did-my-request-arrive-without-a-key","Why did my request arrive without a key?",[10,67,68],{},"Because the value your app was supposed to send was not in the request your\nbrowser actually made. Four causes cover nearly all of these.",[10,70,71,74,75,78,79,84],{},[31,72,73],{},"The key never made it into the built app."," Your code reads it from an\nenvironment variable, the build that produced your live site did not have that\nvariable set, and ",[21,76,77],{},"createClient"," was handed an empty string. Everything compiles,\nthe app loads, and every request leaves without a key. In a Vite or Next project\nthe variable also has to carry the prefix that marks it safe for the browser,\nwhich is ",[80,81,83],"a",{"href":82},"\u002Fblog\u002Fvite-and-next-public-env-vars","a trap of its own",".",[10,86,87,90,91,94,95,98,99,101],{},[31,88,89],{},"You are calling the REST path by hand."," A ",[21,92,93],{},"fetch"," written against\n",[21,96,97],{},"\u002Frest\u002Fv1\u002Fyour_table"," sends the headers you typed and nothing else. Supabase's\nclient library adds ",[21,100,48],{}," for you; a hand-written request has whatever you gave\nit.",[10,103,104,107],{},[31,105,106],{},"Something in between dropped it."," A rewrite rule, a proxy or an API gateway of\nyour own sits between your app and Supabase and forwards the request without the\nheader.",[10,109,110,113,114,117],{},[31,111,112],{},"You are looking at a redirect rather than a data request."," If the message\nappears after somebody signs in or clicks a confirmation link, and the address bar\nstill shows your Supabase URL, the setting to look at is the Site URL under Auth.\nThe most reacted answer on that whole Supabase thread is\nsomebody who had written their site address there without the ",[21,115,116],{},"https:\u002F\u002F"," in front\nof it.",[36,119,121],{"id":120},"the-fix-in-one-line","The fix, in one line",[10,123,124,125,127],{},"Send your publishable key in the ",[21,126,48],{}," header.",[14,129,132],{"className":130,"code":131,"language":19},[17],"import { createClient } from '@supabase\u002Fsupabase-js'\n\nexport const supabase = createClient(\n  'https:\u002F\u002Fyour-project.supabase.co',\n  'sb_publishable_…',\n)\n",[21,133,131],{"__ignoreMap":23},[10,135,136,137,139,140,143],{},"Create the client that way and the library puts the key in the right header on\nevery request it makes, so you never type the header at all. Supabase's reference\nis specific about which header that is: publishable and secret keys travel on\n",[21,138,48],{}," rather than on ",[21,141,142],{},"Authorization: Bearer",", because they are short opaque\nstrings and anything that tries to verify one as a JWT fails.",[10,145,146,147,151],{},"That key is supposed to be in your app. It says which project a request belongs\nto, and what a visitor holding it can reach is decided by the rules on your\ntables, which is the whole reason it can be public in the first place.\n",[80,148,150],{"href":149},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","Which API keys are safe in your frontend","\ncovers the rest of the family.",[36,153,155],{"id":154},"the-fix-that-makes-this-worse","The fix that makes this worse",[10,157,158],{},"The secret key fits the same header, and on an older project it will clear the\nmessage and go on working.",[10,160,161],{},"That is one misplaced click. Your dashboard lists both keys on the same page, and\nthe older pair look alike: same shape, same length, one under the other. How bad\nthe click is depends on which pair your project issues.",[10,163,164,167,168,171,172,175],{},[31,165,166],{},"A newer secret key is refused in a browser."," Supabase blocks ",[21,169,170],{},"sb_secret_…"," by\nmatching on the ",[21,173,174],{},"User-Agent"," header and answers 401. Pasting one into your\nfrontend therefore does not clear the error, which is the best outcome on offer\nhere.",[10,177,178,185,186,188,189,192],{},[31,179,180,181,184],{},"A legacy ",[21,182,183],{},"service_role"," key has no such block."," It works. The list fills, the\napp behaves exactly as it did last week, and the key now sits in a file any\nvisitor can download. There it ignores every rule you have written:\n",[21,187,183],{}," carries Postgres's ",[21,190,191],{},"BYPASSRLS"," attribute, so a policy never applies\nto it. Every row in every table, readable and writable by whoever opens the file.",[10,194,195],{},"Supabase's note on the browser block is worth reading twice. The block answers\n401, and an attacker can still use the key from other tools. What it protects is\nyour app's own requests; the same key in the same file answers a request sent from\na script.",[57,197],{"alt":198,"caption":199,"src":200},"One key drawn twice. Above, its route from a browser window stops at a solid amber bar marked 401. Below, the same key leaves a terminal and passes straight through the place that bar would stand, drawn there as a dashed outline, to three table rows filled in red.","The browser block is about the browser. The same key in the same file works from anything that is not one.","\u002Fblog\u002Fno-api-key-found-in-request\u002Fthe-browser-block-1600x640.png",[36,202,204],{"id":203},"the-other-wrong-turn-and-why-it-is-so-easy","The other wrong turn, and why it is so easy",[10,206,207],{},"Loosening a rule on the table will also stop the message, and it changes who can\nread your rows.",[10,209,210],{},"Here is that Supabase thread in full, grouped by what each answer asks you to\nchange:",[212,213,214,230],"table",{},[215,216,217],"thead",{},[218,219,220,224,227],"tr",{},[221,222,223],"th",{},"What to change",[221,225,226],{},"How many of the eight answers",[221,228,229],{},"What that actually changes",[231,232,233,245,256,266],"tbody",{},[218,234,235,239,242],{},[236,237,238],"td",{},"The Site URL under Auth",[236,240,241],{},"1",[236,243,244],{},"Where a sign-in redirect lands",[218,246,247,250,253],{},[236,248,249],{},"A policy or a grant on a table",[236,251,252],{},"3",[236,254,255],{},"Who can read and write your rows",[218,257,258,261,263],{},[236,259,260],{},"The query or the session",[236,262,252],{},[236,264,265],{},"Your own code",[218,267,268,274,276],{},[236,269,270,271,273],{},"The ",[21,272,48],{}," header",[236,275,241],{},[236,277,278],{},"What the gateway was asking for",[10,280,281],{},"The last row is the one that answers the hint in the message. It is the bottom\ncomment on the thread and it has a single vote.",[10,283,284],{},"None of the other seven is written in bad faith, and that is what makes this hard.\nOne message really does appear in several situations, the person answering really\ndid get their own app working, and a policy that was already missing is a real\nthing to fix. What goes wrong is the order: a rule gets rewritten to clear a\nmessage about a header, and the rule is the only part of that pair nobody checks\nafterwards. Your app works either way, so nothing tells you which one you did.",[10,286,287,288,291],{},"From outside, the result is visible. Our scanner reads live apps the way a\nstranger would, and of the 31,056 apps it has graded, ",[31,289,290],{},"three"," published a\nSupabase secret key. That makes it the rarest finding we hold and the most\nserious one.",[10,293,294,295,298],{},"The instinct next to it is far commoner. We found a Supabase project behind 8,435\nof those apps. On 3,680 of them the question \"can a stranger read this table\" got\na usable answer at all, and ",[31,296,297],{},"2,096 answered yes",": at least one table handed rows\nto a request from outside with no account anywhere in it. In 394 of those the open\ntable was named like a table of people.",[10,300,301,302,84],{},"Some of that is deliberate. A published menu, a page of listings and a public\nchangelog all live in tables a stranger is meant to read, and our scanner cannot\ntell those from a table of customers that was opened by accident. It reports what\nanswered and leaves the judgement to you, which is why\n",[80,303,305],{"href":304},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","turning Row Level Security on is not the same as being protected",[57,307],{"alt":308,"caption":309,"src":310},"Three bars on one scale, narrowing downwards. The first is every app where a Supabase project was found. The second is the smaller number where the table question got an answer, with the remainder continuing as a dashed outline carrying a question mark. The third is the apps that answered yes.","What a stranger can read, over the apps that answered. The dashed band is the apps that answered nothing, which is not the same as an app with nothing open.","\u002Fblog\u002Fno-api-key-found-in-request\u002Fwhat-answered-1600x620.png",[10,312,313,314,84],{},"If you would rather see your own answer than reason about it, our free scan\nreads your live site and tells you what it can reach from outside. It takes\nabout 20 seconds and needs no account: ",[80,315,317],{"href":316},"\u002Fsecurity-scanner","scan your app",[36,319,321],{"id":320},"how-to-tell-which-key-you-pasted","How to tell which key you pasted",[10,323,324],{},"Read the beginning of the string.",[10,326,327,330,331,333],{},[21,328,329],{},"sb_publishable_…"," belongs in your app. ",[21,332,170],{}," never does. There is nothing\nto decode, because what the key is for is written on the front of it.",[10,335,336,337,340],{},"A long value beginning ",[21,338,339],{},"eyJ"," is one of the older pair, and that is where the two\nbecome hard to tell apart. The middle section of such a key is readable data\nrather than encryption, and it carries one field that settles the question:",[14,342,345],{"className":343,"code":344,"language":19},[17],"{\n  \"iss\": \"supabase\",\n  \"role\": \"anon\",          ← the one that matters\n  \"iat\": 1750000000\n}\n",[21,346,344],{"__ignoreMap":23},[10,348,349,352,353,355,356,358],{},[21,350,351],{},"anon"," is the publishable one of the pair. ",[21,354,183],{}," is the one to rotate\ntoday. Supabase's documentation puts it more bluntly than we would: if a tutorial\nor an AI assistant tells you to copy a long key beginning ",[21,357,339],{},", it was written\nfor the legacy keys.",[10,360,361,362,364,365,367,368,372,373,377],{},"Both pairs can be live at once, which is the detail that catches people out.\nCreating a publishable or secret key leaves your ",[21,363,351],{}," and ",[21,366,183],{}," keys\nexactly where they were, and they keep working until you disable them in the\ndashboard as a separate step.\n",[80,369,371],{"href":370},"\u002Fblog\u002Fsupabase-new-api-keys","What changed with the newer keys"," covers that\nmigration, and\n",[80,374,376],{"href":375},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","where each value lives in your dashboard","\nis the page to open if you have never been there.",[36,379,381],{"id":380},"if-the-secret-key-is-already-in-your-app","If the secret key is already in your app",[10,383,384],{},"Rotate it before you edit anything, and work in the order Supabase gives.",[10,386,387,388,390,391,393],{},"Create a new secret key in the dashboard. Replace the old one everywhere your\nproject uses it. Confirm every part of your app is on the new key. Only then\nretire the old one, and the last step differs by which pair you are holding:\ndeleting a secret key cannot be undone, while deactivating a legacy ",[21,389,351],{}," and\n",[21,392,183],{}," pair is reversible, so you can switch them back on if you find a\nclient you missed.",[10,395,396,397,401],{},"Whether you rotate first or repair the leak first depends on whether a copy is\nalready public.\n",[80,398,400],{"href":399},"\u002Fblog\u002Frotate-supabase-service-role-key","Rotating a Supabase service_role key","\nwalks through both orders and what to read in your logs afterwards.",[36,403,405],{"id":404},"keeping-it-that-way-after-the-error-is-gone","Keeping it that way after the error is gone",[10,407,408,411],{},[31,409,410],{},"The fix holds until the next prompt or edit that touches your Supabase\nsetup."," That prompt can paste a key back in or loosen a rule again, and your\napp goes on working either way, so the change shows up only when somebody looks.",[10,413,414],{},[31,415,416,420],{},[80,417,419],{"href":418},"\u002Fpricing","Reeve Monitor"," looks for you:",[422,423,424,428,431,434],"ul",{},[425,426,427],"li",{},"all nine checks every hour, on up to three apps",[425,429,430],{},"an email the day a re-scan grades your app lower than the one before",[425,432,433],{},"whether the app is up, every 60 seconds",[425,435,436],{},"a monthly report of what it saw",[10,438,439],{},[31,440,441,442,446],{},"A key that can write every row can also empty every table.\n",[80,443,445],{"href":444},"\u002Fsupabase-backups","Reeve Care"," keeps a copy of your Supabase database where no\nkey in your app can reach it.",[422,448,449,452,455,458,461],{},[425,450,451],{},"an encrypted copy every day, kept outside your Supabase account",[425,453,454],{},"each copy verified before it counts, by counting the rows in every table",[425,456,457],{},"a one-click restore that saves what is there now before it replaces anything",[425,459,460],{},"your uploaded files as well, once you connect a Storage credential",[425,462,463],{},"everything Monitor does",[36,465,467],{"id":466},"what-to-do-today","What to do today",[469,470,471],"key-takeaways",{},[422,472,473,476,482,491,494],{},[425,474,475],{},"Read the message as a refusal at the door. Your rows were not touched and nothing needs recovering.",[425,477,478,479,481],{},"Look in the browser's network tab at the failing request and check whether an ",[21,480,48],{}," header is there at all. That one look tells you whether this is a key problem or a redirect problem.",[425,483,484,485,487,488,490],{},"Create your Supabase client with the publishable key and let the library send the header. ",[21,486,329],{}," on a newer project, the ",[21,489,351],{}," key on an older one.",[425,492,493],{},"If a secret key is already in your app, rotate it first. Deleting it from your code does not close the door, because the old version is still in your version history and in anyone's cached copy of your site.",[425,495,496],{},"Put back any rule you loosened while chasing this, then check it from outside rather than from your builder's preview.",[10,498,499,500,504,505,509],{},"Start with the one table the error came from, then read the policies on every\ntable you touched the same week. The\n",[80,501,503],{"href":502},"\u002Fchecklist","10-minute security checklist"," covers what else tends to be left open\nin a newly launched app, and the\n",[80,506,508],{"href":507},"\u002Fis-your-supabase-app-safe","Supabase safety guide"," goes through the rest of what\na stranger can reach.",{"title":23,"searchDepth":511,"depth":511,"links":512},3,[513,515,516,517,518,519,520,521,522],{"id":38,"depth":514,"text":39},2,{"id":64,"depth":514,"text":65},{"id":120,"depth":514,"text":121},{"id":154,"depth":514,"text":155},{"id":203,"depth":514,"text":204},{"id":320,"depth":514,"text":321},{"id":380,"depth":514,"text":381},{"id":404,"depth":514,"text":405},{"id":466,"depth":514,"text":467},"Security basics","\u002Fblog\u002Fno-api-key-found-in-request\u002Fcover-1200x630.png","A request arriving at a tall gateway with an empty pass slot and a bar across it, and the database it was heading for standing untouched behind.","\"No API key found in request\" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.",false,"md",[530,533,536,539,542],{"q":531,"a":532},"What does \"No API key found in request\" mean?","It means your request reached Supabase without an apikey header, so the gateway in front of your project turned it away before your database was involved. Nothing was read, nothing was written, and nothing in your data changed. The reply carries a hint that says the same thing in other words: no apikey request header or url param was found.",{"q":534,"a":535},"Which Supabase key goes in the apikey header?","Your publishable key, which is sb_publishable_ on a newer project and the anon key on an older one. Supabase supplies it for exactly this and expects it to be visible in your app. The client library puts it in the header on every request it makes, so if you create the client with the publishable key you never type the header yourself.",{"q":537,"a":538},"Is it safe to put my anon key in the browser?","Yes, and it has to be there for your app to talk to your project at all. The anon key says which project a request belongs to; what a visitor holding it can actually reach is decided by the Row Level Security rules on your tables. Which API keys are safe in your frontend goes through the whole family of keys and how to read them.",{"q":540,"a":541},"I used the service_role key and it worked. Is that a problem?","Yes, and it is the one worth acting on today. A service_role key carries the Postgres BYPASSRLS attribute, so your policies never apply to it. Shipped inside your app it sits in a file any visitor can download, and whoever downloads it can read and write every row in every table. Rotate the key first, then move whatever needed it onto a server.",{"q":543,"a":544},"How do I know which key I pasted?","Read the beginning of the string. sb_publishable_ belongs in your app and sb_secret_ never does. A long value beginning eyJ is one of the older pair, and those two look identical, so you have to look inside: the middle section decodes to readable data carrying a role field, which reads either anon or service_role.","\u002Fblog\u002Fno-api-key-found-in-request\u002Fcard-800x500.png",[547,548,549,550,551,552,553],"no api key found in request","no api key found in request supabase","supabase no api key found","supabase apikey header missing","401 invalid api key supabase","invalid api key supabase","supabase api key not working",{},true,"\"No API key found in request\" in Supabase","\u002Fblog\u002Fno-api-key-found-in-request","2026-10-07",{"title":5,"description":526},"blog\u002Fno-api-key-found-in-request",[562,563,564],"\"No API key found in request\" means your request reached Supabase without an apikey header, so it was turned away at the gateway before your database was asked for anything.","The correct fix is your publishable key in that header, which is the key designed to be public. Supabase's own client library sends it for you on every request.","The two fixes people reach for instead are the secret key and a looser rule on the table. Both stop the message, and both leave your rows readable by anyone holding the key that ships inside your app.","g2ySi1p-2dinzVmUudVCbC78mMrZg_l0B_iL54s2Cl8",[567,573,579,585,591,592,598,604,610,616,622,628,634,640,647,653,659,664,670,676,682,688,694,700,706,711,717,723,729,735,741,747,753,759,765,770,776,782,788,794,800,806,812,818,824,830,835,841,847,853,859,865,871,877,883,888,893,899,904,909,915],{"path":568,"title":569,"description":570,"published":571,"category":523,"image":572,"draft":527},"\u002Fblog\u002Fstorage-upload-violates-row-level-security","\"Row-level security policy for table objects\" on upload","\"New row violates row-level security policy for table objects\" means your upload has no insert rule. Making the bucket public does not add one.","2026-10-11","\u002Fblog\u002Fstorage-upload-violates-row-level-security\u002Fcard-800x500.png",{"path":574,"title":575,"description":576,"published":577,"category":523,"image":578,"draft":527},"\u002Fblog\u002Fbase44-security-scan","Base44 security scan: the one thing only it can see","The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.","2026-10-10","\u002Fblog\u002Fbase44-security-scan\u002Fcard-800x500.png",{"path":580,"title":581,"description":582,"published":583,"category":523,"image":584,"draft":527},"\u002Fblog\u002Fapi-key-leaked-what-to-do","Your API key leaked. Here is the order to do things in","An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.","2026-10-09","\u002Fblog\u002Fapi-key-leaked-what-to-do\u002Fcard-800x500.png",{"path":586,"title":587,"description":588,"published":589,"category":523,"image":590,"draft":527},"\u002Fblog\u002Finfinite-recursion-in-policy-for-relation","\"Infinite recursion detected in policy\" without disabling RLS","\"Infinite recursion detected in policy for relation\" means your Supabase policy asked the table it protects. Here is how to break the circle.","2026-10-08","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fcard-800x500.png",{"path":557,"title":5,"description":526,"published":558,"category":523,"image":545,"draft":527},{"path":593,"title":594,"description":595,"published":596,"category":523,"image":597,"draft":527},"\u002Fblog\u002Fis-base44-safe","Is Base44 safe? What 5,442 live Base44 apps showed","Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.","2026-10-06","\u002Fblog\u002Fis-base44-safe\u002Fcard-800x500.png",{"path":599,"title":600,"description":601,"published":602,"category":523,"image":603,"draft":527},"\u002Fblog\u002Fmove-a-secret-to-an-edge-function","Hide an API key: move it to a Supabase Edge Function","Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.","2026-10-05","\u002Fblog\u002Fmove-a-secret-to-an-edge-function\u002Fcard-800x500.png",{"path":605,"title":606,"description":607,"published":608,"category":523,"image":609,"draft":527},"\u002Fblog\u002Fenv-file-exposed-on-your-server","Is your .env file exposed? The twelve paths to check","Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.","2026-10-04","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Fcard-800x500.png",{"path":611,"title":612,"description":613,"published":614,"category":523,"image":615,"draft":527},"\u002Fblog\u002Fis-v0-safe","v0 security: all 1,790 v0 apps we scanned got an A","v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.","2026-10-03","\u002Fblog\u002Fis-v0-safe\u002Fcard-800x500.png",{"path":617,"title":618,"description":619,"published":620,"category":523,"image":621,"draft":527},"\u002Fblog\u002Fis-bolt-safe","Is Bolt safe? What 1,123 live Bolt apps showed","Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.","2026-10-02","\u002Fblog\u002Fis-bolt-safe\u002Fcard-800x500.png",{"path":623,"title":624,"description":625,"published":626,"category":523,"image":627,"draft":527},"\u002Fblog\u002Fis-supabase-down-or-your-app","Is Supabase down, or is it your app? How to tell","Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.","2026-10-01","\u002Fblog\u002Fis-supabase-down-or-your-app\u002Fcard-800x500.png",{"path":629,"title":630,"description":631,"published":632,"category":523,"image":633,"draft":527},"\u002Fblog\u002Fdoes-supabase-encrypt-my-data","Does Supabase encrypt my data? Yes. Here is what it stops","Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.","2026-09-30","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fcard-800x500.png",{"path":635,"title":636,"description":637,"published":638,"category":523,"image":639,"draft":527},"\u002Fblog\u002Fsupabase-free-plan-limits","Supabase free plan limits, and what happens at each one","The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.","2026-09-29","\u002Fblog\u002Fsupabase-free-plan-limits\u002Fcard-800x500.png",{"path":641,"title":642,"description":643,"published":644,"category":645,"image":646,"draft":527},"\u002Fblog\u002Ftest-your-supabase-backup","Test your Supabase backup before the day you need it","How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.","2026-09-28","Backups","\u002Fblog\u002Ftest-your-supabase-backup\u002Fcard-800x500.png",{"path":648,"title":649,"description":650,"published":651,"category":645,"image":652,"draft":527},"\u002Fblog\u002Fsupabase-backup-github-action","Free Supabase backup with a GitHub Action, and the catch","A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.","2026-09-27","\u002Fblog\u002Fsupabase-backup-github-action\u002Fcard-800x500.png",{"path":654,"title":655,"description":656,"published":657,"category":645,"image":658,"draft":527},"\u002Fblog\u002Fdownload-your-supabase-backup","Why you can't download your Supabase backup","You can't download your Supabase backup on a current project, because the daily copy is a physical snapshot. How to tell, and how to hold a copy of your own.","2026-09-26","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fcard-800x500.png",{"path":660,"title":661,"description":662,"published":657,"category":523,"image":663,"draft":527},"\u002Fblog\u002Fsupabase-permission-denied-for-table","Supabase \"permission denied for table\": the missing grant","From October 30, a new Supabase table answers \"permission denied for table\" until you grant access. The grant the email shows is half the fix.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fcard-800x500.png",{"path":665,"title":666,"description":667,"published":668,"category":523,"image":669,"draft":527},"\u002Fblog\u002Fopen-api-endpoint-exposed","Is an open API endpoint a security problem? Look at the JSON","Your scan flagged an open API endpoint. Whether it matters depends on what came back, and most of the ones we found were the platform's own.","2026-09-25","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fcard-800x500.png",{"path":671,"title":672,"description":673,"published":674,"category":523,"image":675,"draft":527},"\u002Fblog\u002Flovable-security-scan","Lovable security scan: the one thing it cannot prove","Lovable security scan: what the Quick and Deep scans check, when each one runs, and the one thing no scan from inside your project can prove.","2026-09-24","\u002Fblog\u002Flovable-security-scan\u002Fcard-800x500.png",{"path":677,"title":678,"description":679,"published":680,"category":645,"image":681,"draft":527},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":683,"title":684,"description":685,"published":686,"category":523,"image":687,"draft":527},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":689,"title":690,"description":691,"published":692,"category":523,"image":693,"draft":527},"\u002Fblog\u002Fis-lovable-safe","Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":695,"title":696,"description":697,"published":698,"category":523,"image":699,"draft":527},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":701,"title":702,"description":703,"published":704,"category":523,"image":705,"draft":527},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":82,"title":707,"description":708,"published":709,"category":523,"image":710,"draft":527},"Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":712,"title":713,"description":714,"published":715,"category":523,"image":716,"draft":527},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":718,"title":719,"description":720,"published":721,"category":523,"image":722,"draft":527},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":724,"title":725,"description":726,"published":727,"category":523,"image":728,"draft":527},"\u002Fblog\u002Fis-replit-safe","Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":730,"title":731,"description":732,"published":733,"category":645,"image":734,"draft":527},"\u002Fblog\u002Fsupabase-storage-backup","Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":736,"title":737,"description":738,"published":739,"category":645,"image":740,"draft":527},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":742,"title":743,"description":744,"published":745,"category":645,"image":746,"draft":527},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":748,"title":749,"description":750,"published":751,"category":523,"image":752,"draft":527},"\u002Fblog\u002Fsafest-ai-app-builder","Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":754,"title":755,"description":756,"published":757,"category":523,"image":758,"draft":527},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":760,"title":761,"description":762,"published":763,"category":523,"image":764,"draft":527},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":399,"title":766,"description":767,"published":768,"category":523,"image":769,"draft":527},"How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":771,"title":772,"description":773,"published":774,"category":523,"image":775,"draft":527},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":777,"title":778,"description":779,"published":780,"category":523,"image":781,"draft":527},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":783,"title":784,"description":785,"published":786,"category":523,"image":787,"draft":527},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":789,"title":790,"description":791,"published":792,"category":523,"image":793,"draft":527},"\u002Fblog\u002Fmissing-security-headers","Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":795,"title":796,"description":797,"published":798,"category":523,"image":799,"draft":527},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":801,"title":802,"description":803,"published":804,"category":523,"image":805,"draft":527},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":807,"title":808,"description":809,"published":810,"category":645,"image":811,"draft":527},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":813,"title":814,"description":815,"published":816,"category":523,"image":817,"draft":527},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":819,"title":820,"description":821,"published":822,"category":645,"image":823,"draft":527},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":825,"title":826,"description":827,"published":828,"category":523,"image":829,"draft":527},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":375,"title":831,"description":832,"published":833,"category":523,"image":834,"draft":527},"Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":836,"title":837,"description":838,"published":839,"category":523,"image":840,"draft":527},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":842,"title":843,"description":844,"published":845,"category":523,"image":846,"draft":527},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":848,"title":849,"description":850,"published":851,"category":645,"image":852,"draft":527},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":854,"title":855,"description":856,"published":857,"category":645,"image":858,"draft":527},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":860,"title":861,"description":862,"published":863,"category":523,"image":864,"draft":527},"\u002Fblog\u002Fsupabase-storage-bucket-public","Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":866,"title":867,"description":868,"published":869,"category":523,"image":870,"draft":527},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":872,"title":873,"description":874,"published":875,"category":645,"image":876,"draft":527},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":878,"title":879,"description":880,"published":881,"category":523,"image":882,"draft":527},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":884,"title":885,"description":886,"published":881,"category":523,"image":887,"draft":527},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":370,"title":889,"description":890,"published":891,"category":523,"image":892,"draft":527},"Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":894,"title":895,"description":896,"published":897,"category":645,"image":898,"draft":527},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":304,"title":900,"description":901,"published":902,"category":523,"image":903,"draft":527},"Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":905,"title":906,"description":907,"published":902,"category":645,"image":908,"draft":527},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":910,"title":911,"description":912,"published":913,"category":645,"image":914,"draft":527},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":149,"title":916,"description":917,"published":913,"category":523,"image":918,"draft":527},"Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1791705957970]