[{"data":1,"prerenderedAt":921},["ShallowReactive",2],{"blog-en-open-api-endpoint-exposed":3,"blog-index-en":571},{"id":4,"title":5,"body":6,"category":529,"cover":530,"coverAlt":531,"description":532,"draft":533,"extension":534,"faq":535,"image":550,"keywords":551,"meta":559,"navigation":560,"ogTitle":561,"path":562,"published":563,"seo":564,"stem":565,"tldr":566,"updated":563,"__hash__":570},"blog_en\u002Fblog\u002Fopen-api-endpoint-exposed.md","Is an open API endpoint a security problem? Look at the JSON",{"type":7,"value":8,"toc":515},"minimark",[9,13,21,26,29,32,35,41,44,48,51,54,118,121,125,128,138,144,150,168,179,188,192,195,202,274,282,294,298,301,304,307,312,322,326,329,332,356,359,363,366,369,379,382,388,399,421,427,430,436,445,450,453,459,462,471,475,495,502],[10,11,12],"p",{},"Your scan came back with a line that does not read like a verdict: some API\nendpoints answer without a login. Somebody may have put it to you more bluntly\nand told you that you have an open API endpoint. Under it is an address, and\nthere is a fair chance you do not recognise it.",[10,14,15,16,20],{},"Here is the part that guide after guide gets wrong: ",[17,18,19],"strong",{},"the standard advice for\nthis finding is to put a login on your endpoint, and on most of the apps we have\nscanned there is no endpoint of yours to put one on."," Seven in ten of the ones\nwe found belong to the platform the app was published on. So reading this\nfinding starts with working out whose address it is, and the answer is usually\nvisible in the first line of what comes back.",[22,23,25],"h2",{"id":24},"what-an-open-api-endpoint-means-on-your-report","What an open API endpoint means on your report",[10,27,28],{},"It means a path written into your app's code answered a request that carried no\nlogin, and what came back was JSON.",[10,30,31],{},"Three steps, and none of them is clever. We load your app in a browser the way a\nvisitor does, and read the code that browser downloaded. Inside it are the\naddresses your app calls when it needs data. Then we ask each one for data with\nno account, no cookie and no key. If an address answers with JSON that is not an\nerror message, it goes on the report.",[10,33,34],{},"That is a fact about what happened. It is not a judgement about the data,\nbecause nothing standing outside your app can tell whether a list of things is a\nlist of public things. This is why the finding is worded the way it is: these\nendpoints returned data without any authentication, that may be intentional for\npublic data, check that none expose private information.",[36,37],"diagram",{"alt":38,"caption":39,"src":40},"Code downloaded from an app, with four addresses picked out of it. Each address is asked for data by a request carrying a crossed-out key, meaning no login. Three come back empty or refused and one comes back carrying a block of data.","The addresses come out of your own code, and each one is asked with nothing attached. Whatever answers is what lands on the report.","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fwhat-the-check-does-1600x620.png",[10,42,43],{},"So the report hands you a list of addresses to open. Every one of them needs\nopening in a signed-out browser, and the first few lines of the answer are what\nsettles it.",[22,45,47],{"id":46},"is-every-open-api-endpoint-a-security-problem","Is every open API endpoint a security problem?",[10,49,50],{},"No. There are three kinds, and only the third one is a problem.",[10,52,53],{},"Think about a block of flats. Some things in it are meant for anybody who walks\nin: the opening hours by the door, the fire exits, the notice about the lift\nbeing serviced on Tuesday. Somewhere else in the same building there is a filing\ncabinet with the tenants' details in it. From the corridor a noticeboard and an\nunlocked filing cabinet are both furniture you can open, and the only way to\ntell them apart is to read what is on the paper.",[55,56,57,73],"table",{},[58,59,60],"thead",{},[61,62,63,67,70],"tr",{},[64,65,66],"th",{},"What answered",[64,68,69],{},"Whose address is it",[64,71,72],{},"Where you stand",[74,75,76,92,104],"tbody",{},[61,77,78,82,85],{},[79,80,81],"td",{},"Platform settings: cookie notices, feature switches",[79,83,84],{},"Your builder's, in every app it publishes",[79,86,87],{},[88,89,91],"key-verdict",{"type":90},"safe","Nothing to do",[61,93,94,97,100],{},[79,95,96],{},"Your own public data: a price list, an article",[79,98,99],{},"Yours, and meant to be readable",[79,101,102],{},[88,103,91],{"type":90},[61,105,106,109,112],{},[79,107,108],{},"Rows about people: names, emails, orders, messages",[79,110,111],{},"Yours, and reachable by anyone holding the address",[79,113,114],{},[88,115,117],{"type":116},"danger","Close it today",[10,119,120],{},"The first row is a noticeboard somebody else screwed to the wall. The second is\na noticeboard you put up on purpose. The third is the filing cabinet, and it has\nbeen standing open for as long as the address has existed.",[22,122,124],{"id":123},"how-to-check-what-your-endpoints-return","How to check what your endpoints return",[10,126,127],{},"Open each one signed out and read what arrives. The reading takes longer than\nthe finding suggests, and it is the only step that answers the question.",[10,129,130,133,134,137],{},[17,131,132],{},"Find the addresses."," Open your live app, press F12 to bring up the browser's\ndeveloper tools, click ",[17,135,136],{},"Network",", and reload the page. Click through the\nrequests that come back as JSON. Those are the addresses your app fetches data\nfrom, and the report's list is a subset of them.",[10,139,140,143],{},[17,141,142],{},"Ask each one as a stranger."," Copy a URL, open a private browsing window so\nthat you are signed out, and paste it in. What you see is exactly what anyone on\nthe internet sees at that address.",[10,145,146,149],{},[17,147,148],{},"Read the first few lines."," Three things you might get back:",[151,152,153,162,165],"ul",{},[154,155,156,157,161],"li",{},"An error, a refusal, or ",[158,159,160],"code",{},"[]",". The address wants a login, or there is nothing\nin it for a signed-out caller. Move on.",[154,163,164],{},"Settings. Flags, switches, a colour, a list of enabled features, a version\nnumber. Nobody is named and nothing is described. Move on.",[154,166,167],{},"Rows. An email address, a person's name, an order total, the text of a\nmessage, a phone number. Stop here; this is the one.",[10,169,170,171,174,175,178],{},"If you find rows, try changing a number in the URL before you close the tab. An\naddress that hands out one person's record on ",[158,172,173],{},"id=1"," and a different person's on\n",[158,176,177],{},"id=2"," is handing out all of them, and that is worth knowing before you decide\nhow urgent this is.",[10,180,181,182,187],{},"Our free scan does the first two steps for you: it reads your app's code for the\naddresses it calls, requests each one with no login, and lists the ones that\nanswered with data. It takes about 20 seconds and needs no account:\n",[183,184,186],"a",{"href":185},"\u002Fsecurity-scanner","scan your app",". The third step is yours, because you are the\nonly person who knows whether a name in that list is a real customer.",[22,189,191],{"id":190},"most-of-the-ones-we-found-belong-to-the-platform","Most of the ones we found belong to the platform",[10,193,194],{},"In our August 2026 sweep, 3,852 of the 30,926 apps where this check could get an\nanswer had at least one address answering without a login. Of those, 2,705 were\nBase44 apps, and on Base44 the address is nearly always the same one.",[10,196,197,198,201],{},"It is ",[158,199,200],{},"\u002Fapi\u002Fconsent\u002Fconfig",", the platform's cookie-consent settings. We re-opened\na sample of flagged Base44 apps in September and the only address that answered\nwas that one. It returns settings, it is identical across apps, and nobody's data\nis in it. The scanner is reporting it correctly and the owner has nothing to fix.",[55,203,204,217],{},[58,205,206],{},[61,207,208,211,214],{},[64,209,210],{},"Platform",[64,212,213],{},"Apps with the finding",[64,215,216],{},"Apps the check answered on",[74,218,219,230,241,252,263],{},[61,220,221,224,227],{},[79,222,223],{},"Base44",[79,225,226],{},"2,705",[79,228,229],{},"5,419",[61,231,232,235,238],{},[79,233,234],{},"Custom domains",[79,236,237],{},"82",[79,239,240],{},"955",[61,242,243,246,249],{},[79,244,245],{},"Bolt",[79,247,248],{},"4",[79,250,251],{},"1,120",[61,253,254,257,260],{},[79,255,256],{},"Lovable",[79,258,259],{},"8",[79,261,262],{},"18,518",[61,264,265,268,271],{},[79,266,267],{},"v0",[79,269,270],{},"0",[79,272,273],{},"1,786",[10,275,276,277,281],{},"One platform is missing from that table on purpose. Replit accounts for a large\nblock of the remaining findings, and nobody has re-opened a sample of those the\nway we re-opened Base44's, so we do not know yet whose addresses they are.\nPublishing a figure as the owner's problem before somebody has looked at it is\nhow a Base44 platform setting becomes a statistic about negligent owners. Every\nnumber above comes from\n",[183,278,280],{"href":279},"\u002Fresearch\u002Fvibe-coded-app-security-2026","our scan of 30,998 live vibe-coded apps",",\nwhich publishes each one with the base it was measured over.",[10,283,284,285,288,289,293],{},"Read the two ends of that table together, because the spread is the useful part.\nOn Lovable it is 8 apps in 18,518, and on v0 it is none at all. Those apps have\nno little server of their own: the page talks to Supabase straight from the\nbrowser, so there is no ",[158,286,287],{},"\u002Fapi\u002F…"," of yours anywhere for this check to find. What\nprotects the data on an app like that is the rules on each table, which is a\ndifferent finding with a\n",[183,290,292],{"href":291},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","different way of going wrong",".",[22,295,297],{"id":296},"when-the-json-is-settings-and-when-it-is-people","When the JSON is settings, and when it is people",[10,299,300],{},"One question decides it: does anything in the answer describe a person?",[10,302,303],{},"Settings describe your app. A flag saying whether dark mode is on, the list of\ncurrencies you accept, the version of something, the copy for a cookie banner.\nPublishing that gives away how your app is configured, and your app is running\nin front of everybody anyway.",[10,305,306],{},"Rows describe your users. A name, an email address, what somebody bought, what\nthey wrote, where they live. That is not a sentence about configuration; it is\nthe contents of the filing cabinet, and the reason it matters is how ordinary it\nis to take. There is no break-in. The address is a line of text that works in\nany browser, so it gets pasted into a group chat, saved in somebody's notes, and\nfetched on a timer by a script nobody is watching.",[36,308],{"alt":309,"caption":310,"src":311},"Two responses of identical size and shape. The left one holds four switches, two on and two off. The right one holds four rows, each with a figure of a person and a redacted line beside it.","Both of these are a 200 and a block of JSON, which is all the check can see. The difference between them is the whole question, and it is one you can answer by reading.","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fsettings-or-people-1600x660.png",[313,314,316],"callout",{"type":315},"note",[10,317,318,321],{},[17,319,320],{},"The awkward case is the address that used to be settings."," An endpoint that\nreturned a list of your app's categories was public data on the day it was\nwritten. Then somebody added a column to the table behind it so the page could\nshow who created each category, and the same address started handing out names.\nNothing on screen changed, the address did not move, and the finding on your\nreport reads exactly as it did before.",[22,323,325],{"id":324},"closing-one-and-why-renaming-the-path-does-not-close-it","Closing one, and why renaming the path does not close it",[10,327,328],{},"Require a login at the address, and answer a caller who does not have one with a 401.",[10,330,331],{},"That is the whole fix, and it belongs at the address rather than anywhere else.\nThree things that look like the fix and are not:",[151,333,334,340,350],{},[154,335,336,339],{},[17,337,338],{},"Renaming the path, or taking it out of your code."," This is the one to be\ncareful about, because the finding goes away. Anyone who already had the URL\nstill has it, it is in browser histories and server logs, and the cabinet is\nstill unlocked with the label taken off the front.",[154,341,342,345,346,293],{},[17,343,344],{},"Narrowing your CORS header."," That governs which other websites may read an\nanswer inside somebody's browser, and nothing else consults it. A script or a\nterminal reads the same address either way, which is\n",[183,347,349],{"href":348},"\u002Fblog\u002Fcors-wildcard-security-risk","why the wildcard finding is a different question",[154,351,352,355],{},[17,353,354],{},"Filtering in the app."," If the page hides the rows it should not show, the\naddress is still sending them. The filtering has to happen before the answer\nleaves.",[10,357,358],{},"There is a fourth option, and on a public page it is often the best one: stop\nhaving the endpoint. If the data is only ever for your own page, the page can be\nhanded it while it is being built, and the address comes out of your code along\nwith it.",[22,360,362],{"id":361},"what-the-fix-looks-like-in-code","What the fix looks like in code",[10,364,365],{},"Two things, in the handler that answers the address: work out who is asking, and\nstop if the answer is nobody.",[10,367,368],{},"You may never type these yourself, and that is fine. Read them anyway, because\nthey are what you are checking your builder actually did after you ask it to\nclose the endpoint. Here is the shape before, which is what the scan found:",[370,371,376],"pre",{"className":372,"code":374,"language":375},[373],"language-text","app.get('\u002Fapi\u002Forders', async (req, res) => {\n  const orders = await db.orders.findMany()\n  res.json(orders)\n})\n","text",[158,377,374],{"__ignoreMap":378},"",[10,380,381],{},"And after:",[370,383,386],{"className":384,"code":385,"language":375},[373],"app.get('\u002Fapi\u002Forders', async (req, res) => {\n  const user = await getUserFromRequest(req)\n  if (!user) {\n    return res.status(401).json({ error: 'Not signed in' })\n  }\n\n  const orders = await db.orders.findMany({ where: { userId: user.id } })\n  res.json(orders)\n})\n",[158,387,385],{"__ignoreMap":378},[10,389,390,391,394,395,398],{},"Two things changed and both of them matter. The ",[158,392,393],{},"401"," is the door. The ",[158,396,397],{},"where","\nis the reason the door is worth having: without it a signed-in visitor can read\nevery other customer's orders, which is a smaller audience for the same data and\nstill the wrong one.",[10,400,401,404,405,408,409,412,413,416,417,420],{},[17,402,403],{},"On Supabase Edge Functions, read the configuration before you write anything.","\nEdge Functions check the caller's token on their own: Supabase's configuration\nreference puts ",[158,406,407],{},"verify_jwt"," at ",[158,410,411],{},"true"," by default, so a function that answers\nstrangers is one where somebody turned that off, either with a line in\n",[158,414,415],{},"supabase\u002Fconfig.toml"," or by deploying with ",[158,418,419],{},"--no-verify-jwt",":",[370,422,425],{"className":423,"code":424,"language":375},[373],"[functions.orders]\nverify_jwt = false\n",[158,426,424],{"__ignoreMap":378},[10,428,429],{},"If your function is meant to be private, delete those two lines and redeploy.\nLeave them only where the endpoint genuinely has to answer anybody, which is the\ncase Supabase's own documentation uses as its example: a payment webhook. Inside\nthe function, the current SDK hands you a client already scoped to the person who\ncalled:",[370,431,434],{"className":432,"code":433,"language":375},[373],"import { withSupabase } from 'npm:@supabase\u002Fserver'\n\nexport default {\n  fetch: withSupabase({ auth: 'user' }, async (_req, ctx) => {\n    const { data } = await ctx.supabase.from('orders').select()\n    return Response.json(data)\n  }),\n}\n",[158,435,433],{"__ignoreMap":378},[10,437,438,441,442,293],{},[158,439,440],{},"ctx.supabase"," runs as the caller, so your row level security rules decide what\ncomes back, which is the same protection the rest of your app relies on and\n",[183,443,444],{"href":291},"the thing worth checking separately",[446,447,449],"h3",{"id":448},"the-prompt-to-paste-into-your-builder","The prompt to paste into your builder",[10,451,452],{},"If you build in Lovable, Bolt, Cursor, Replit or v0, hand it this. Keep it in\nEnglish whatever language you are reading this in, because that is what these\ntools reason in, and replace the two bracketed parts with what your own report\nsays:",[370,454,457],{"className":455,"code":456,"language":375},[373],"A security scan of [my-app.com] found these API endpoints answer\nwithout any authentication: [\u002Fapi\u002Forders, \u002Fapi\u002Fusers].\n\nPlease look at each one and decide whether it is meant to be public.\nFor the ones that are not, require a valid session or API token and\nreturn 401 otherwise. Make sure each one returns only the rows that\nbelong to the person asking, not the whole table filtered in the UI.\nFor any that must stay open, make sure they return only non-sensitive\ndata and add rate limiting so they cannot be abused.\n\nTell me what you changed for each endpoint, and do not rename or\nremove the paths.\n",[158,458,456],{"__ignoreMap":378},[10,460,461],{},"That last sentence is there on purpose. Asked to make a finding go away, a model\nwill sometimes take the shortest route and move the address, which is the one\noutcome that looks like success on a re-scan and changes nothing.",[313,463,465],{"type":464},"warn",[10,466,467,470],{},[17,468,469],{},"Re-scan signed out, not signed in."," Once the fix is deployed, check it the way\nthe section above describes: a private browsing window and the URL. Testing it\nwhile signed in proves the endpoint still works for you, which was never in\ndoubt. Sign out and read it again.",[22,472,474],{"id":473},"what-to-do-right-now","What to do right now",[476,477,478],"key-takeaways",{},[151,479,480,483,486,489,492],{},[154,481,482],{},"Open every flagged address in a private browsing window and read what comes back. That is the step the report cannot do for you.",[154,484,485],{},"If the answer is settings and the address is one you never wrote, it is your builder's and there is nothing to fix. Check the path against your platform's docs before you spend anything on it.",[154,487,488],{},"If the answer contains a name, an email or an order, require a login at that address today and return a 401 to anyone without one.",[154,490,491],{},"Do not rename the path or delete the reference to it. The finding disappears and the address goes on answering.",[154,493,494],{},"Try changing an id in the URL on your own app. An address that serves one record to a stranger usually serves all of them.",[10,496,497,498,293],{},"The addresses on this list were all written by somebody who knew what was behind\nthem at the time, and the thing that changes is what is behind them. Reeve Care\nre-runs this scan against your live app on a schedule and emails you when a\nresult gets worse, which is the case the signed-out pass above cannot catch:\n",[183,499,501],{"href":500},"\u002Fpricing","what it watches and what it costs",[10,503,504,505,509,510,514],{},"If you would rather work through everything in one sitting, the\n",[183,506,508],{"href":507},"\u002Fchecklist","10-minute security checklist"," covers this beside the rest of what a\nnewly launched app tends to leave open, and\n",[183,511,513],{"href":512},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","which keys are safe in your frontend","\nis the other finding people usually arrive with.",{"title":378,"searchDepth":516,"depth":516,"links":517},3,[518,520,521,522,523,524,525,528],{"id":24,"depth":519,"text":25},2,{"id":46,"depth":519,"text":47},{"id":123,"depth":519,"text":124},{"id":190,"depth":519,"text":191},{"id":296,"depth":519,"text":297},{"id":324,"depth":519,"text":325},{"id":361,"depth":519,"text":362,"children":526},[527],{"id":448,"depth":516,"text":449},{"id":473,"depth":519,"text":474},"Security basics","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fcover-1200x630.png","Two identical hatches in a wall, each with a sheet of paper coming out. One sheet carries a row of switches, the other a column of faces.","Your scan flagged an open API endpoint. Whether it matters depends on what came back, and most of the ones we found were the platform's own.",false,"md",[536,539,541,544,547],{"q":537,"a":538},"What does \"open API endpoint\" mean on my report?","It means we read the code your app sends to a browser, found an address in it that your app calls for data, and asked that address for data with no account and no login. It answered, and the answer was JSON. That is the whole finding. It is a fact about what happened, not a judgement about whether the data was private, because nothing outside your app can know that.",{"q":47,"a":540},"No. Plenty of addresses are meant to answer anybody: a published price list, an article, a list of which features are switched on. The problem is the address that hands back rows belonging to people, because it does that for everyone who has the URL. Read what came back and ask whether any of it describes a person.",{"q":542,"a":543},"My report flags an endpoint I did not write. What is it?","Usually your builder's. Platforms that give your app a little server of its own also give it a few addresses of their own, and those are in the code of every app on the platform. The clearest example we have measured is Base44's cookie-consent settings at \u002Fapi\u002Fconsent\u002Fconfig, which accounts for 2,705 of the 3,852 findings in our August 2026 sweep. It returns settings, it is the same on every Base44 app, and there is nothing in it that belongs to you.",{"q":545,"a":546},"How do I check what my app's endpoints return?","Open your live app, press F12, click Network and reload. The requests that come back as JSON are the addresses your app fetches data from. Copy each URL, open a private browsing window so that you are signed out, and paste them in one at a time. Read what arrives. An error or an empty list is fine. Rows with names, emails or order totals in them are readable by anyone holding that address.",{"q":548,"a":549},"Does hiding the path fix it?","No. Renaming the address, or taking the reference to it out of your code, stops a scanner finding it and leaves it answering exactly as it did before. Anyone who already had the URL still has it, and it stays in browser histories, server logs and anything that crawled your site. The fix is at the address: require a login and answer a stranger with a 401.","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fcard-800x500.png",[552,553,554,555,556,557,558],"open api endpoint","unauthenticated api endpoint","api endpoint returns data without login","is my api endpoint public","unprotected api route","api endpoint no authentication","json endpoint exposed",{},true,"Is an open API endpoint a security problem?","\u002Fblog\u002Fopen-api-endpoint-exposed","2026-09-25",{"title":5,"description":532},"blog\u002Fopen-api-endpoint-exposed",[567,568,569],"An open API endpoint means a path written into your app's code answered a request with no login, and what came back was JSON.","Of the ones we found across 30,926 apps, seven in ten were put there by the platform the app was published on, and they return settings.","The question that decides it is whether anything in the answer describes a person. A price list is public by design. A list of your customers never was.","d0OMO6pq6zRWZ_JaaQhCavWCFg7lkPZI7JNOdSWGYYg",[572,578,584,590,596,602,608,614,620,626,632,638,644,651,657,663,668,669,675,681,687,693,699,705,711,717,723,729,735,741,747,753,759,765,771,777,783,789,795,801,807,813,819,825,831,837,843,848,854,860,866,872,878,884,889,895,901,906,911,917],{"path":573,"title":574,"description":575,"published":576,"category":529,"image":577,"draft":533},"\u002Fblog\u002Fbase44-security-scan","Base44 security scan: the one thing only it can see","The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.","2026-10-10","\u002Fblog\u002Fbase44-security-scan\u002Fcard-800x500.png",{"path":579,"title":580,"description":581,"published":582,"category":529,"image":583,"draft":533},"\u002Fblog\u002Fapi-key-leaked-what-to-do","Your API key leaked. Here is the order to do things in","An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.","2026-10-09","\u002Fblog\u002Fapi-key-leaked-what-to-do\u002Fcard-800x500.png",{"path":585,"title":586,"description":587,"published":588,"category":529,"image":589,"draft":533},"\u002Fblog\u002Finfinite-recursion-in-policy-for-relation","\"Infinite recursion detected in policy\" without disabling RLS","\"Infinite recursion detected in policy for relation\" means your Supabase policy asked the table it protects. Here is how to break the circle.","2026-10-08","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fcard-800x500.png",{"path":591,"title":592,"description":593,"published":594,"category":529,"image":595,"draft":533},"\u002Fblog\u002Fno-api-key-found-in-request","\"No API key found in request\" in Supabase, and the wrong fix","\"No API key found in request\" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.","2026-10-07","\u002Fblog\u002Fno-api-key-found-in-request\u002Fcard-800x500.png",{"path":597,"title":598,"description":599,"published":600,"category":529,"image":601,"draft":533},"\u002Fblog\u002Fis-base44-safe","Is Base44 safe? What 5,442 live Base44 apps showed","Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.","2026-10-06","\u002Fblog\u002Fis-base44-safe\u002Fcard-800x500.png",{"path":603,"title":604,"description":605,"published":606,"category":529,"image":607,"draft":533},"\u002Fblog\u002Fmove-a-secret-to-an-edge-function","Hide an API key: move it to a Supabase Edge Function","Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.","2026-10-05","\u002Fblog\u002Fmove-a-secret-to-an-edge-function\u002Fcard-800x500.png",{"path":609,"title":610,"description":611,"published":612,"category":529,"image":613,"draft":533},"\u002Fblog\u002Fenv-file-exposed-on-your-server","Is your .env file exposed? The twelve paths to check","Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.","2026-10-04","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Fcard-800x500.png",{"path":615,"title":616,"description":617,"published":618,"category":529,"image":619,"draft":533},"\u002Fblog\u002Fis-v0-safe","v0 security: all 1,790 v0 apps we scanned got an A","v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.","2026-10-03","\u002Fblog\u002Fis-v0-safe\u002Fcard-800x500.png",{"path":621,"title":622,"description":623,"published":624,"category":529,"image":625,"draft":533},"\u002Fblog\u002Fis-bolt-safe","Is Bolt safe? What 1,123 live Bolt apps showed","Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.","2026-10-02","\u002Fblog\u002Fis-bolt-safe\u002Fcard-800x500.png",{"path":627,"title":628,"description":629,"published":630,"category":529,"image":631,"draft":533},"\u002Fblog\u002Fis-supabase-down-or-your-app","Is Supabase down, or is it your app? How to tell","Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.","2026-10-01","\u002Fblog\u002Fis-supabase-down-or-your-app\u002Fcard-800x500.png",{"path":633,"title":634,"description":635,"published":636,"category":529,"image":637,"draft":533},"\u002Fblog\u002Fdoes-supabase-encrypt-my-data","Does Supabase encrypt my data? Yes. Here is what it stops","Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.","2026-09-30","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fcard-800x500.png",{"path":639,"title":640,"description":641,"published":642,"category":529,"image":643,"draft":533},"\u002Fblog\u002Fsupabase-free-plan-limits","Supabase free plan limits, and what happens at each one","The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.","2026-09-29","\u002Fblog\u002Fsupabase-free-plan-limits\u002Fcard-800x500.png",{"path":645,"title":646,"description":647,"published":648,"category":649,"image":650,"draft":533},"\u002Fblog\u002Ftest-your-supabase-backup","Test your Supabase backup before the day you need it","How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.","2026-09-28","Backups","\u002Fblog\u002Ftest-your-supabase-backup\u002Fcard-800x500.png",{"path":652,"title":653,"description":654,"published":655,"category":649,"image":656,"draft":533},"\u002Fblog\u002Fsupabase-backup-github-action","Free Supabase backup with a GitHub Action, and the catch","A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.","2026-09-27","\u002Fblog\u002Fsupabase-backup-github-action\u002Fcard-800x500.png",{"path":658,"title":659,"description":660,"published":661,"category":649,"image":662,"draft":533},"\u002Fblog\u002Fdownload-your-supabase-backup","Why you can't download your Supabase backup","You can't download your Supabase backup on a current project, because the daily copy is a physical snapshot. How to tell, and how to hold a copy of your own.","2026-09-26","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fcard-800x500.png",{"path":664,"title":665,"description":666,"published":661,"category":529,"image":667,"draft":533},"\u002Fblog\u002Fsupabase-permission-denied-for-table","Supabase \"permission denied for table\": the missing grant","From October 30, a new Supabase table answers \"permission denied for table\" until you grant access. The grant the email shows is half the fix.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fcard-800x500.png",{"path":562,"title":5,"description":532,"published":563,"category":529,"image":550,"draft":533},{"path":670,"title":671,"description":672,"published":673,"category":529,"image":674,"draft":533},"\u002Fblog\u002Flovable-security-scan","Lovable security scan: the one thing it cannot prove","Lovable security scan: what the Quick and Deep scans check, when each one runs, and the one thing no scan from inside your project can prove.","2026-09-24","\u002Fblog\u002Flovable-security-scan\u002Fcard-800x500.png",{"path":676,"title":677,"description":678,"published":679,"category":649,"image":680,"draft":533},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":682,"title":683,"description":684,"published":685,"category":529,"image":686,"draft":533},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":688,"title":689,"description":690,"published":691,"category":529,"image":692,"draft":533},"\u002Fblog\u002Fis-lovable-safe","Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":694,"title":695,"description":696,"published":697,"category":529,"image":698,"draft":533},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":700,"title":701,"description":702,"published":703,"category":529,"image":704,"draft":533},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":706,"title":707,"description":708,"published":709,"category":529,"image":710,"draft":533},"\u002Fblog\u002Fvite-and-next-public-env-vars","Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":712,"title":713,"description":714,"published":715,"category":529,"image":716,"draft":533},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":718,"title":719,"description":720,"published":721,"category":529,"image":722,"draft":533},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":724,"title":725,"description":726,"published":727,"category":529,"image":728,"draft":533},"\u002Fblog\u002Fis-replit-safe","Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":730,"title":731,"description":732,"published":733,"category":649,"image":734,"draft":533},"\u002Fblog\u002Fsupabase-storage-backup","Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":736,"title":737,"description":738,"published":739,"category":649,"image":740,"draft":533},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":742,"title":743,"description":744,"published":745,"category":649,"image":746,"draft":533},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":748,"title":749,"description":750,"published":751,"category":529,"image":752,"draft":533},"\u002Fblog\u002Fsafest-ai-app-builder","Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":754,"title":755,"description":756,"published":757,"category":529,"image":758,"draft":533},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":760,"title":761,"description":762,"published":763,"category":529,"image":764,"draft":533},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":766,"title":767,"description":768,"published":769,"category":529,"image":770,"draft":533},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":772,"title":773,"description":774,"published":775,"category":529,"image":776,"draft":533},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":778,"title":779,"description":780,"published":781,"category":529,"image":782,"draft":533},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":784,"title":785,"description":786,"published":787,"category":529,"image":788,"draft":533},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":790,"title":791,"description":792,"published":793,"category":529,"image":794,"draft":533},"\u002Fblog\u002Fmissing-security-headers","Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":796,"title":797,"description":798,"published":799,"category":529,"image":800,"draft":533},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":802,"title":803,"description":804,"published":805,"category":529,"image":806,"draft":533},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":808,"title":809,"description":810,"published":811,"category":649,"image":812,"draft":533},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":814,"title":815,"description":816,"published":817,"category":529,"image":818,"draft":533},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":820,"title":821,"description":822,"published":823,"category":649,"image":824,"draft":533},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":826,"title":827,"description":828,"published":829,"category":529,"image":830,"draft":533},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":832,"title":833,"description":834,"published":835,"category":529,"image":836,"draft":533},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":838,"title":839,"description":840,"published":841,"category":529,"image":842,"draft":533},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":348,"title":844,"description":845,"published":846,"category":529,"image":847,"draft":533},"Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":849,"title":850,"description":851,"published":852,"category":649,"image":853,"draft":533},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":855,"title":856,"description":857,"published":858,"category":649,"image":859,"draft":533},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":861,"title":862,"description":863,"published":864,"category":529,"image":865,"draft":533},"\u002Fblog\u002Fsupabase-storage-bucket-public","Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":867,"title":868,"description":869,"published":870,"category":529,"image":871,"draft":533},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":873,"title":874,"description":875,"published":876,"category":649,"image":877,"draft":533},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":879,"title":880,"description":881,"published":882,"category":529,"image":883,"draft":533},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":885,"title":886,"description":887,"published":882,"category":529,"image":888,"draft":533},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":890,"title":891,"description":892,"published":893,"category":529,"image":894,"draft":533},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":896,"title":897,"description":898,"published":899,"category":649,"image":900,"draft":533},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":291,"title":902,"description":903,"published":904,"category":529,"image":905,"draft":533},"Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":907,"title":908,"description":909,"published":904,"category":649,"image":910,"draft":533},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":912,"title":913,"description":914,"published":915,"category":649,"image":916,"draft":533},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":512,"title":918,"description":919,"published":915,"category":529,"image":920,"draft":533},"Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1791618966336]