[{"data":1,"prerenderedAt":928},["ShallowReactive",2],{"blog-en-supabase-backup-auth-users":3,"blog-index-en":579},{"id":4,"title":5,"body":6,"category":534,"cover":535,"coverAlt":536,"description":537,"draft":538,"extension":539,"faq":540,"image":557,"keywords":558,"meta":567,"navigation":568,"ogTitle":569,"path":570,"published":571,"seo":572,"stem":573,"tldr":574,"updated":571,"__hash__":578},"blog_en\u002Fblog\u002Fsupabase-backup-auth-users.md","Why your Supabase dump has no users in it",{"type":7,"value":8,"toc":522},"minimark",[9,13,21,35,38,43,46,63,84,87,93,97,102,122,125,135,142,145,150,154,160,213,216,222,225,235,239,242,251,257,260,266,269,275,288,299,305,311,315,318,324,330,333,355,359,362,374,388,394,401,405,442,449,453,456,461,496,504,511],[10,11,12],"p",{},"You did the responsible thing. You looked up how to back up a Supabase\ndatabase, ran the command you found, and put the file somewhere safe.",[10,14,15,16,20],{},"Then one day you need it. You replay the file into a fresh project and the\nrestore finishes without a single error. Every table you ever made is there,\nand every one of them is empty. Your users are worse off than that: the part of\nthe database they live in, a schema called ",[17,18,19],"code",{},"auth",", never reached the file at\nall.",[10,22,23,24,31,32,34],{},"Here is the part almost every guide skips: ",[25,26,27,30],"strong",{},[17,28,29],{},"supabase db dump"," on its own is\nnot a copy of your data."," With no other flags it writes the shape of your\ndatabase and none of its contents, and it leaves ",[17,33,19],{}," out of even that.\nSupabase publishes the backup as three commands, and your accounts ride in the\nthird one.",[10,36,37],{},"It helps to picture a hotel. Your tables are the rooms and everything in them.\nThe register at the front desk, the one with every guest's name in it, is the\nhotel's. And a floor plan shows you every room in the building without putting\na single guest in one.",[39,40,42],"h2",{"id":41},"does-a-supabase-backup-include-my-users","Does a Supabase backup include my users?",[10,44,45],{},"It depends which command wrote the file, and the command most people run does\nnot.",[10,47,48,49,51,52,55,56,59,60,62],{},"Your users are not rows in one of your own tables. Supabase keeps them in a\nseparate drawer of the same database called the ",[17,50,19],{}," schema, along with their\nhashed passwords, the providers they signed in with and the sessions they hold.\nYour own tables sit in a drawer called ",[17,53,54],{},"public",", and every ",[17,57,58],{},"user_id"," column in\nthem is a reference across into ",[17,61,19],{},".",[10,64,65,66,68,69,71,72,75,76,83],{},"A schema is exactly that: a named drawer inside one database. ",[17,67,54],{}," is yours.\n",[17,70,19],{}," is Supabase's, and so is ",[17,73,74],{},"storage",", which keeps the row describing each\nuploaded file. Supabase's own documentation calls these its managed schemas and\nsays they\n",[77,78,82],"a",{"href":79,"rel":80},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Flocal-development\u002Fcli-workflows",[81],"nofollow","typically do not need to be pulled unless you have modified them",",\nwhich is why the tooling treats them differently from your tables.",[10,85,86],{},"That division is what lets one command produce two files that look alike and\nhold entirely different things.",[88,89],"diagram",{"alt":90,"caption":91,"src":92},"A dump file with an arrow reaching a solid panel of four lit tables, which is ticked. A second arrow stops at a dashed wall in front of a dashed panel carrying the Supabase mark, and that panel holds a ruled card listing three people beside four faint pictures. A cross sits on the wall.","Run on its own, the dump command copies the shape of your own drawer and stops at the boundary of the two Supabase runs.","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fwhere-the-dump-stops-1600x620.png",[39,94,96],{"id":95},"what-the-dump-command-writes-on-its-own","What the dump command writes on its own",[10,98,99,100,62],{},"The floor plan. No rows, and nothing from ",[17,101,19],{},[10,103,104,105,108,109,114,115,118,119,62],{},"Supabase's reference page for the command says it in two sentences. It runs\n",[17,106,107],{},"pg_dump"," with extra flags to exclude the Supabase managed schemas, and the\nignored ones\n",[77,110,113],{"href":111,"rel":112},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Freference\u002Fcli\u002Fsupabase-db-dump",[81],"include auth, storage and those created by extensions",".\nThe same page then says the default dump contains no data and no custom roles,\nand that you get those by asking for them with ",[17,116,117],{},"--data-only"," and ",[17,120,121],{},"--role-only",[10,123,124],{},"So this, which is the one you have probably run:",[126,127,132],"pre",{"className":128,"code":130,"language":131},[129],"language-text","supabase db dump --db-url \"postgresql:\u002F\u002F…your connection string…\" -f backup.sql\n","text",[17,133,130],{"__ignoreMap":134},"",[10,136,137,138,141],{},"produces a file of ",[17,139,140],{},"CREATE TABLE"," statements. Every column, every index, every\npolicy you wrote on your own tables, and not one row of anything.",[10,143,144],{},"The reason this is worse than an obviously empty file is that it works. It is\nnot obviously small either: every table definition, index and policy you ever\nwrote is in there, which for a real app is a lot of text. An empty backup\nannounces itself. This one restores cleanly, and the first thing that tells you\notherwise is a login page no account can get past.",[88,146],{"alt":147,"caption":148,"src":149},"Two files side by side. The left one is dashed and holds two empty table grids beside an empty outline where a card should stand, and it is crossed. The right one holds the same two tables with their rows filled in, and in the empty one's place a ruled card listing three people. It is ticked.","The same command writes both of these. Which one you are holding depends on a flag, and both of them restore without an error.","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fthe-plan-and-the-contents-1600x620.png",[39,151,153],{"id":152},"how-do-i-check-the-dump-i-already-have","How do I check the dump I already have?",[10,155,156,157,159],{},"Open it in a text editor and search for ",[17,158,19],{},". What comes back puts your file\nin one of three groups.",[161,162,163,176,193],"ol",{},[164,165,166,169,170,172,173,175],"li",{},[25,167,168],{},"No matches at all."," The ",[17,171,19],{}," schema is not in this file in any form.\nThis is what a plain ",[17,174,29],{}," writes.",[164,177,178,192],{},[25,179,180,181,184,185,188,189,62],{},"Matches, but only in lines beginning ",[17,182,183],{},"CREATE",", ",[17,186,187],{},"ALTER"," or ",[17,190,191],{},"GRANT"," You\nhave the design of the register and nobody in it.",[164,194,195,208,209,212],{},[25,196,197,198,188,201,204,205],{},"A line reading ",[17,199,200],{},"COPY \"auth\".\"users\"",[17,202,203],{},"COPY auth.users",", with rows of\ndata under it before a line containing ",[17,206,207],{},"\\."," Or a run of lines beginning\n",[17,210,211],{},"INSERT INTO \"auth\".\"users\"",". Your accounts are in there.",[10,214,215],{},"If you would rather do it at a command line, two greps answer the same\nquestion:",[126,217,220],{"className":218,"code":219,"language":131},[129],"grep -c 'auth.*users' backup.sql\ngrep -n 'COPY .*auth.*users\\|INSERT INTO .*auth.*users' backup.sql\n",[17,221,219],{"__ignoreMap":134},[10,223,224],{},"The first says whether the schema reached the file at all. The second says\nwhether the people did. A zero from both, on a file you were relying on, is\nworth finding out today rather than on the morning you need it.",[10,226,227,228,230,231,62],{},"Search for ",[17,229,74],{}," while you are in there, and read what you find carefully.\nThose rows are the list of your uploaded files, which is a different thing from\nthe files, and\n",[77,232,234],{"href":233},"\u002Fblog\u002Fsupabase-storage-backup","no database backup on any plan contains those",[39,236,238],{"id":237},"how-do-i-export-supabase-auth-users","How do I export Supabase auth users?",[10,240,241],{},"With the data command, which is a separate command from the one that writes the\nschema.",[10,243,244,245,250],{},"Supabase's\n",[77,246,249],{"href":247,"rel":248},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fplatform\u002Fmigrating-within-supabase\u002Fbackup-restore",[81],"backup and restore guide","\npublishes the backup as three files, and it is worth seeing them together\nbecause the shape of it is the answer:",[126,252,255],{"className":253,"code":254,"language":131},[129],"supabase db dump --db-url \"postgresql:\u002F\u002F…\" -f roles.sql --role-only\nsupabase db dump --db-url \"postgresql:\u002F\u002F…\" -f schema.sql\nsupabase db dump --db-url \"postgresql:\u002F\u002F…\" -f data.sql --use-copy --data-only \\\n  -x \"storage.buckets_vectors\" -x \"storage.vector_indexes\"\n",[17,256,254],{"__ignoreMap":134},[10,258,259],{},"The second line is the one that gets run on its own. The third is the one with\nyour users in it.",[10,261,262,263,265],{},"Those two facts look like a contradiction and they are not. The sentence on\nSupabase's reference page about excluding ",[17,264,19],{}," describes the schema dump, and\nthe data dump walks that schema too.",[10,267,268],{},"If all you want is the accounts, name the schema and you get that drawer alone:",[126,270,273],{"className":271,"code":272,"language":131},[129],"supabase db dump --db-url \"postgresql:\u002F\u002F…\" -f users.sql --data-only --use-copy --schema auth\n",[17,274,272],{"__ignoreMap":134},[10,276,277,284,285,287],{},[25,278,279,280,283],{},"Before you rely on any of these, add ",[17,281,282],{},"--dry-run"," and read what comes back.","\nIt prints the ",[17,286,107],{}," command the tool is about to run without running it, so\nyou can see for yourself which schemas are included and which are excluded on\nthe version you have installed. Read that output once and you never have to\ntake this article's word for it, or anybody else's, which matters because the\nflags do move between releases and the file looks the same either way.",[10,289,290,291,298],{},"There is also the direct route, which is\n",[77,292,294,295,297],{"href":293},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","what a plain ",[17,296,107],{}," is for",":\nname the drawers you want and it takes them.",[126,300,303],{"className":301,"code":302,"language":131},[129],"pg_dump \"postgresql:\u002F\u002F…\" --schema public --schema auth --schema storage \\\n  --no-owner --file backup.sql\n",[17,304,302],{"__ignoreMap":134},[10,306,307,308,310],{},"One thing to notice about the schema file, because it explains why this is\nsplit up at all. A new Supabase project arrives with an ",[17,309,19],{}," schema already\nbuilt, at whatever version the sign-in service is running today. Replaying your\nold project's version of that schema over it would put an older design on top\nof a working one. What you want to carry across is the contents of the\nregister, which is what the data file holds.",[39,312,314],{"id":313},"what-breaks-when-you-put-the-users-back","What breaks when you put the users back",[10,316,317],{},"Two things, and Supabase documents both of them.",[10,319,320,323],{},[25,321,322],{},"Triggers, which can encrypt a column twice."," The restore command in\nSupabase's guide has an instruction in the middle of it that is easy to read as\nnoise:",[126,325,328],{"className":326,"code":327,"language":131},[129],"psql \\\n  --single-transaction \\\n  --variable ON_ERROR_STOP=1 \\\n  --file roles.sql \\\n  --file schema.sql \\\n  --command 'SET session_replication_role = replica' \\\n  --file data.sql \\\n  --dbname \"postgresql:\u002F\u002F…\"\n",[17,329,327],{"__ignoreMap":134},[10,331,332],{},"That middle line switches triggers off for the duration, and the guide says it\nis there to stop columns being encrypted a second time on the way in. Replay a\ndata file without it and the passwords arrive already scrambled by a process\nthat had already been applied to them, which nothing later will undo.",[10,334,335,338,339,342,343,346,347,350,351,354],{},[25,336,337],{},"Ownership and grants, which will stop the replay."," A dump taken from a\nSupabase project carries lines that refer to roles the new project will not let\nyou touch. Supabase's troubleshooting notes for the same guide say to comment\nout any line containing ",[17,340,341],{},"ALTER ... OWNER TO \"supabase_admin\""," in ",[17,344,345],{},"schema.sql",",\nand a specific ",[17,348,349],{},"GRANT \"postgres\" TO \"cli_login_postgres\""," line in ",[17,352,353],{},"roles.sql",".\nBoth are a text edit before you start, and both stop the replay with the line\nthey choked on printed on your screen.",[39,356,358],{"id":357},"do-my-users-have-to-log-in-again","Do my users have to log in again?",[10,360,361],{},"Their passwords come across. Their sessions do not, unless you carry one more\nthing with them.",[10,363,364,365,367,368,373],{},"Supabase says you can migrate every table in the ",[17,366,19],{}," schema,\n",[77,369,372],{"href":370,"rel":371},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Ftroubleshooting\u002Fmigrating-auth-users-between-projects",[81],"including users and their hashed passwords",",\nso nobody has to reset a password they already had. No password is readable at\nany point in this; what moves is the hash of it.",[10,375,376,377,118,380,383,384,62],{},"A session is a different thing. It is proved by a token that was signed with\nyour project's own JWT secret, and each project has its own. Supabase says that\nif the new project signs with a different secret, every token already in\nsomeone's browser becomes invalid and they are asked to sign in again. You can\navoid that by setting the old project's secret on the new one, and there is a\ncost written on the same page: changing the JWT secret regenerates that\nproject's ",[17,378,379],{},"anon",[17,381,382],{},"service_role"," keys, so your app has to be given the new\nones before it can talk to anything. Which key is which, and which of them is\nsafe to have in your app at all, is\n",[77,385,387],{"href":386},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","the thing to be sure about before you paste either",[10,389,390,391,393],{},"So the honest version is that a restore usually asks everyone to sign in once.\nThat is a support email. It is not a lost account, and the difference between\nthose two is whether the ",[17,392,19],{}," schema was in your file.",[10,395,396,397,400],{},"Three things are still not in it, whatever you do with the flags. Your uploaded\nfiles, because Storage keeps the bytes outside the database and\n",[77,398,399],{"href":233},"no dump on any plan reaches them",". Your edge\nfunctions, which are their own download, and whose import maps Supabase notes\nare not fetched automatically. And your project's settings, which are\nconfiguration rather than data and get re-entered by hand.",[39,402,404],{"id":403},"what-to-do-this-week","What to do this week",[406,407,408],"key-takeaways",{},[409,410,411,417,426,432,439],"ul",{},[164,412,413,414,416],{},"Find the newest backup file you have and search it for ",[17,415,19],{},". Group one, two or three from the section above, and you will know within a minute.",[164,418,419,420,118,422,425],{},"If it is group one or two, take a data dump today with ",[17,421,117],{},[17,423,424],{},"--use-copy",", and keep it next to the schema file rather than instead of it. You need both.",[164,427,428,429,431],{},"Add ",[17,430,282],{}," to whichever command you settle on and read the output once, so you know which drawers your version of the tool is taking.",[164,433,434,435,438],{},"Write the restore order down where you will find it: roles, then schema, then ",[17,436,437],{},"SET session_replication_role = replica",", then data.",[164,440,441],{},"Restore into a throwaway project once, and then try to log in as a real user. That is the only check that tests the thing this article is about.",[10,443,444,445,448],{},"Doing this once by hand is worth it however you end up backing things up,\nbecause until you have opened a dump you have only ever had the word backup to\ngo on. Whether you keep doing it by hand is a separate question, and\n",[77,446,447],{"href":293},"the three routes and what each one costs","\nis where that one gets answered.",[39,450,452],{"id":451},"where-reeve-care-fits","Where Reeve Care fits",[10,454,455],{},"Care takes the copy on a schedule, and the register is in it.",[88,457],{"alt":458,"caption":459,"src":460},"A Reeve Care panel with two rows. In the first, a dashed account outline holds a database and a register of people, and both leave it along one arrow into a locked file that is read back through a lens and ticked. In the second, a card carrying a button sends the database rows back into the account while the register inside it stays lit and untouched.","The copy holds your tables and your accounts. The restore button puts your tables back and leaves the accounts where they are.","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcare-the-register-comes-too-1600x560.png",[409,462,463,474,484,490],{},[164,464,465,169,468,470,471,473],{},[25,466,467],{},"Your accounts are in the copy.",[17,469,19],{}," schema travels with your own tables, because a copy of a Supabase app without its users is a copy of half of it. The ",[17,472,74],{}," rows that describe your files come too, and so do the files themselves once you connect a Storage credential.",[164,475,476,479,480,483],{},[25,477,478],{},"The restore button puts your tables back and leaves the accounts alone."," Replaying ",[17,481,482],{},"auth.users"," over a live project signs everyone out and brings back accounts somebody deleted on purpose, so that stays a request with a person on it. So pressing the button in a panic cannot log out the customers you were trying to help.",[164,485,486,489],{},[25,487,488],{},"The copy is read back before it counts as taken."," The date on your dashboard is the last time a copy was opened and verified, never the time a job started or a file landed.",[164,491,492,495],{},[25,493,494],{},"Restoring takes a snapshot of the current state first",", so the restore itself has an undo.",[10,497,498,499,503],{},"Care starts at $49 a month for one app. That is a list price, and the\n",[77,500,502],{"href":501},"\u002Fpricing","pricing page"," is sometimes below the figure here and never above it.",[10,505,506,507,62],{},"How a copy is taken, checked and put back is drawn step by step on the\n",[77,508,510],{"href":509},"\u002Fsupabase-backups","Supabase backups page",[10,512,513,514,516,517,521],{},"Before you close this tab, open your most recent dump and search it for ",[17,515,19],{},".\nIt is the fastest way to find out whether the thing you have been calling a\nbackup would give you your customers back, and if the answer turns out to be\nno, ",[77,518,520],{"href":519},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","restoring one properly"," is the\nnext thing to read.",{"title":134,"searchDepth":523,"depth":523,"links":524},3,[525,527,528,529,530,531,532,533],{"id":41,"depth":526,"text":42},2,{"id":95,"depth":526,"text":96},{"id":152,"depth":526,"text":153},{"id":237,"depth":526,"text":238},{"id":313,"depth":526,"text":314},{"id":357,"depth":526,"text":358},{"id":403,"depth":526,"text":404},{"id":451,"depth":526,"text":452},"Backups","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcover-1200x630.png","A sealed archive file holding three rows of data, with a ruled register of people standing outside it and cropped by the frame.","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.",false,"md",[541,543,546,548,551,554],{"q":42,"a":542},"It depends which command wrote the file. Your users live in a schema called auth, which belongs to the sign-in service. A bare supabase db dump leaves auth out and contains no rows of anything, because the default dump is the schema only. The data half of the dump, which is a second command with the --data-only flag, is the one that carries your users. Supabase publishes the backup as three commands for exactly this reason.",{"q":544,"a":545},"Why is auth.users missing from my dump?","Because you almost certainly ran the schema dump. Supabase documents that the command excludes its managed schemas, that the ignored ones include auth and storage, and that the default dump contains no data at all. That is deliberate: a new project arrives with its own auth schema already built by the sign-in service, so replaying an older copy of that schema over it would replace something that works. What you want to move is the contents, which the data dump carries.",{"q":238,"a":547},"With the data command, which is separate from the schema command. Run supabase db dump with --data-only and --use-copy to write a data file, and the auth tables come with it. If you only want the accounts, add --schema auth and you get a file containing that schema alone. Before you rely on either, add --dry-run: it prints the pg_dump command the CLI is about to run without running it, so you can read which schemas are included on the version you have.",{"q":549,"a":550},"Do passwords survive a Supabase restore?","Yes, if the auth schema was in the file. Supabase says you can migrate every table in the auth schema, hashed passwords included, so people do not have to reset or recreate them. The one thing that can ruin them is replaying the data without disabling triggers first, which is why Supabase puts SET session_replication_role = replica in the middle of its own restore command. Skip that line and a column that was already encrypted gets encrypted a second time on the way in.",{"q":552,"a":553},"Will my users stay logged in after a restore?","Not if the new project signs with a different secret. Sessions are proved by a token signed with the project JWT secret, and Supabase says a new secret makes existing tokens invalid, so everyone is asked to sign in again. You can carry the old secret across and keep them logged in, but Supabase also says changing the JWT secret regenerates the anon and service_role keys in that project, so your app needs the new ones.",{"q":555,"a":556},"What else does a Supabase dump leave out?","Your uploaded files, first of all. Storage keeps a row in your database for every file and the file itself somewhere else, so no database dump on any plan contains the bytes. Edge functions are their own download, and Supabase notes that import maps and deno.json files are not fetched automatically. Project settings, auth providers and secrets are configuration rather than data and live in the dashboard, so they are re-entered by hand in a new project.","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",[559,560,561,562,563,564,565,566],"supabase backup auth users","export supabase users","supabase db dump auth schema","migrate supabase auth users","supabase backup missing users","supabase auth.users export","restore supabase users","supabase dump excludes auth",{},true,"Why your Supabase dump has no users","\u002Fblog\u002Fsupabase-backup-auth-users","2026-09-23",{"title":5,"description":537},"blog\u002Fsupabase-backup-auth-users",[575,576,577],"Supabase publishes its backup as three commands. The one you have probably run is the second, and your users are in the third.","Run supabase db dump with no other flags and you get the shape of your tables and none of their contents, with the auth schema your users live in left out of even that.","One search through the file you already have tells you which of three things you are holding.","SRSV5Ow5XbwwQwzzn-xVq4-PXFOB9VjRmGTdc9jyvv8",[580,587,593,599,605,611,617,623,629,635,641,647,653,659,665,671,676,682,688,689,695,701,707,713,719,725,731,737,742,748,754,760,766,772,778,784,790,796,802,808,814,820,826,832,838,844,850,856,862,867,873,879,885,891,896,902,908,914,919,924],{"path":581,"title":582,"description":583,"published":584,"category":585,"image":586,"draft":538},"\u002Fblog\u002Fbase44-security-scan","Base44 security scan: the one thing only it can see","The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.","2026-10-10","Security basics","\u002Fblog\u002Fbase44-security-scan\u002Fcard-800x500.png",{"path":588,"title":589,"description":590,"published":591,"category":585,"image":592,"draft":538},"\u002Fblog\u002Fapi-key-leaked-what-to-do","Your API key leaked. Here is the order to do things in","An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.","2026-10-09","\u002Fblog\u002Fapi-key-leaked-what-to-do\u002Fcard-800x500.png",{"path":594,"title":595,"description":596,"published":597,"category":585,"image":598,"draft":538},"\u002Fblog\u002Finfinite-recursion-in-policy-for-relation","\"Infinite recursion detected in policy\" without disabling RLS","\"Infinite recursion detected in policy for relation\" means your Supabase policy asked the table it protects. Here is how to break the circle.","2026-10-08","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fcard-800x500.png",{"path":600,"title":601,"description":602,"published":603,"category":585,"image":604,"draft":538},"\u002Fblog\u002Fno-api-key-found-in-request","\"No API key found in request\" in Supabase, and the wrong fix","\"No API key found in request\" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.","2026-10-07","\u002Fblog\u002Fno-api-key-found-in-request\u002Fcard-800x500.png",{"path":606,"title":607,"description":608,"published":609,"category":585,"image":610,"draft":538},"\u002Fblog\u002Fis-base44-safe","Is Base44 safe? What 5,442 live Base44 apps showed","Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.","2026-10-06","\u002Fblog\u002Fis-base44-safe\u002Fcard-800x500.png",{"path":612,"title":613,"description":614,"published":615,"category":585,"image":616,"draft":538},"\u002Fblog\u002Fmove-a-secret-to-an-edge-function","Hide an API key: move it to a Supabase Edge Function","Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.","2026-10-05","\u002Fblog\u002Fmove-a-secret-to-an-edge-function\u002Fcard-800x500.png",{"path":618,"title":619,"description":620,"published":621,"category":585,"image":622,"draft":538},"\u002Fblog\u002Fenv-file-exposed-on-your-server","Is your .env file exposed? The twelve paths to check","Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.","2026-10-04","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Fcard-800x500.png",{"path":624,"title":625,"description":626,"published":627,"category":585,"image":628,"draft":538},"\u002Fblog\u002Fis-v0-safe","v0 security: all 1,790 v0 apps we scanned got an A","v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.","2026-10-03","\u002Fblog\u002Fis-v0-safe\u002Fcard-800x500.png",{"path":630,"title":631,"description":632,"published":633,"category":585,"image":634,"draft":538},"\u002Fblog\u002Fis-bolt-safe","Is Bolt safe? What 1,123 live Bolt apps showed","Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.","2026-10-02","\u002Fblog\u002Fis-bolt-safe\u002Fcard-800x500.png",{"path":636,"title":637,"description":638,"published":639,"category":585,"image":640,"draft":538},"\u002Fblog\u002Fis-supabase-down-or-your-app","Is Supabase down, or is it your app? How to tell","Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.","2026-10-01","\u002Fblog\u002Fis-supabase-down-or-your-app\u002Fcard-800x500.png",{"path":642,"title":643,"description":644,"published":645,"category":585,"image":646,"draft":538},"\u002Fblog\u002Fdoes-supabase-encrypt-my-data","Does Supabase encrypt my data? Yes. Here is what it stops","Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.","2026-09-30","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fcard-800x500.png",{"path":648,"title":649,"description":650,"published":651,"category":585,"image":652,"draft":538},"\u002Fblog\u002Fsupabase-free-plan-limits","Supabase free plan limits, and what happens at each one","The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.","2026-09-29","\u002Fblog\u002Fsupabase-free-plan-limits\u002Fcard-800x500.png",{"path":654,"title":655,"description":656,"published":657,"category":534,"image":658,"draft":538},"\u002Fblog\u002Ftest-your-supabase-backup","Test your Supabase backup before the day you need it","How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.","2026-09-28","\u002Fblog\u002Ftest-your-supabase-backup\u002Fcard-800x500.png",{"path":660,"title":661,"description":662,"published":663,"category":534,"image":664,"draft":538},"\u002Fblog\u002Fsupabase-backup-github-action","Free Supabase backup with a GitHub Action, and the catch","A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.","2026-09-27","\u002Fblog\u002Fsupabase-backup-github-action\u002Fcard-800x500.png",{"path":666,"title":667,"description":668,"published":669,"category":534,"image":670,"draft":538},"\u002Fblog\u002Fdownload-your-supabase-backup","Why you can't download your Supabase backup","You can't download your Supabase backup on a current project, because the daily copy is a physical snapshot. How to tell, and how to hold a copy of your own.","2026-09-26","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fcard-800x500.png",{"path":672,"title":673,"description":674,"published":669,"category":585,"image":675,"draft":538},"\u002Fblog\u002Fsupabase-permission-denied-for-table","Supabase \"permission denied for table\": the missing grant","From October 30, a new Supabase table answers \"permission denied for table\" until you grant access. The grant the email shows is half the fix.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fcard-800x500.png",{"path":677,"title":678,"description":679,"published":680,"category":585,"image":681,"draft":538},"\u002Fblog\u002Fopen-api-endpoint-exposed","Is an open API endpoint a security problem? Look at the JSON","Your scan flagged an open API endpoint. Whether it matters depends on what came back, and most of the ones we found were the platform's own.","2026-09-25","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fcard-800x500.png",{"path":683,"title":684,"description":685,"published":686,"category":585,"image":687,"draft":538},"\u002Fblog\u002Flovable-security-scan","Lovable security scan: the one thing it cannot prove","Lovable security scan: what the Quick and Deep scans check, when each one runs, and the one thing no scan from inside your project can prove.","2026-09-24","\u002Fblog\u002Flovable-security-scan\u002Fcard-800x500.png",{"path":570,"title":5,"description":537,"published":571,"category":534,"image":557,"draft":538},{"path":690,"title":691,"description":692,"published":693,"category":585,"image":694,"draft":538},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":696,"title":697,"description":698,"published":699,"category":585,"image":700,"draft":538},"\u002Fblog\u002Fis-lovable-safe","Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":702,"title":703,"description":704,"published":705,"category":585,"image":706,"draft":538},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":708,"title":709,"description":710,"published":711,"category":585,"image":712,"draft":538},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":714,"title":715,"description":716,"published":717,"category":585,"image":718,"draft":538},"\u002Fblog\u002Fvite-and-next-public-env-vars","Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":720,"title":721,"description":722,"published":723,"category":585,"image":724,"draft":538},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":726,"title":727,"description":728,"published":729,"category":585,"image":730,"draft":538},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":732,"title":733,"description":734,"published":735,"category":585,"image":736,"draft":538},"\u002Fblog\u002Fis-replit-safe","Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":233,"title":738,"description":739,"published":740,"category":534,"image":741,"draft":538},"Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":743,"title":744,"description":745,"published":746,"category":534,"image":747,"draft":538},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":749,"title":750,"description":751,"published":752,"category":534,"image":753,"draft":538},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":755,"title":756,"description":757,"published":758,"category":585,"image":759,"draft":538},"\u002Fblog\u002Fsafest-ai-app-builder","Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":761,"title":762,"description":763,"published":764,"category":585,"image":765,"draft":538},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":767,"title":768,"description":769,"published":770,"category":585,"image":771,"draft":538},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":773,"title":774,"description":775,"published":776,"category":585,"image":777,"draft":538},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":779,"title":780,"description":781,"published":782,"category":585,"image":783,"draft":538},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":785,"title":786,"description":787,"published":788,"category":585,"image":789,"draft":538},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":791,"title":792,"description":793,"published":794,"category":585,"image":795,"draft":538},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":797,"title":798,"description":799,"published":800,"category":585,"image":801,"draft":538},"\u002Fblog\u002Fmissing-security-headers","Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":803,"title":804,"description":805,"published":806,"category":585,"image":807,"draft":538},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":809,"title":810,"description":811,"published":812,"category":585,"image":813,"draft":538},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":815,"title":816,"description":817,"published":818,"category":534,"image":819,"draft":538},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":821,"title":822,"description":823,"published":824,"category":585,"image":825,"draft":538},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":827,"title":828,"description":829,"published":830,"category":534,"image":831,"draft":538},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":833,"title":834,"description":835,"published":836,"category":585,"image":837,"draft":538},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":839,"title":840,"description":841,"published":842,"category":585,"image":843,"draft":538},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":845,"title":846,"description":847,"published":848,"category":585,"image":849,"draft":538},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":851,"title":852,"description":853,"published":854,"category":585,"image":855,"draft":538},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":857,"title":858,"description":859,"published":860,"category":534,"image":861,"draft":538},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":519,"title":863,"description":864,"published":865,"category":534,"image":866,"draft":538},"How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":868,"title":869,"description":870,"published":871,"category":585,"image":872,"draft":538},"\u002Fblog\u002Fsupabase-storage-bucket-public","Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":874,"title":875,"description":876,"published":877,"category":585,"image":878,"draft":538},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":880,"title":881,"description":882,"published":883,"category":534,"image":884,"draft":538},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":886,"title":887,"description":888,"published":889,"category":585,"image":890,"draft":538},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":892,"title":893,"description":894,"published":889,"category":585,"image":895,"draft":538},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":897,"title":898,"description":899,"published":900,"category":585,"image":901,"draft":538},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":903,"title":904,"description":905,"published":906,"category":534,"image":907,"draft":538},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":909,"title":910,"description":911,"published":912,"category":585,"image":913,"draft":538},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":915,"title":916,"description":917,"published":912,"category":534,"image":918,"draft":538},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":293,"title":920,"description":921,"published":922,"category":534,"image":923,"draft":538},"Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":386,"title":925,"description":926,"published":922,"category":585,"image":927,"draft":538},"Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1791618966336]