[{"data":1,"prerenderedAt":896},["ShallowReactive",2],{"blog-en-supabase-permission-denied-for-table":3,"blog-index-en":545},{"id":4,"title":5,"body":6,"category":504,"cover":505,"coverAlt":506,"description":507,"draft":508,"extension":509,"faq":510,"image":525,"keywords":526,"meta":533,"navigation":534,"ogTitle":535,"path":536,"published":537,"seo":538,"stem":539,"tldr":540,"updated":537,"__hash__":544},"blog_en\u002Fblog\u002Fsupabase-permission-denied-for-table.md","Supabase \"permission denied for table\": the missing grant",{"type":7,"value":8,"toc":492},"minimark",[9,18,26,31,34,57,60,70,73,76,80,87,107,151,154,160,163,201,205,208,215,224,228,231,237,240,246,261,266,274,278,281,297,300,351,355,358,366,369,393,397,402,436,443,447,486],[10,11,12,13,17],"p",{},"If your app runs on Supabase, you have probably had an email about October 30.\nIt says nothing changes for the tables you already have, and then it hands you\nthree statements of SQL. Or it is already November: you asked Lovable, Bolt or\nCursor for a new feature, the new screen came up empty, and somewhere in the\nconsole is a message that says ",[14,15,16],"code",{},"permission denied for table",". Both are the same\nSupabase change, seen from either side of the date.",[10,19,20,21,25],{},"Here is the part the email leaves out: ",[22,23,24],"strong",{},"the SQL it shows you is half of the\nfix."," Run that half on its own, on the wrong table, and your app works again\nwhile the new table hands its rows to anyone who asks.",[27,28,30],"h2",{"id":29},"what-does-permission-denied-for-table-mean-in-supabase","What does \"permission denied for table\" mean in Supabase?",[10,32,33],{},"It means the kind of visitor making the request has not been given access to\nthat table at all, so the database refused before it looked at a single row.",[10,35,36,37,40,41,44,45,48,49,52,53,56],{},"Supabase sorts every request into a ",[22,38,39],{},"role",", which is the kind of visitor it\ncomes from. ",[14,42,43],{},"anon"," is somebody who is not signed in. ",[14,46,47],{},"authenticated"," is somebody\nwho is. ",[14,50,51],{},"service_role"," is your own server code using the secret key. A\n",[22,54,55],{},"grant"," is the statement that gives one of those roles access to one\ntable in Postgres, the database Supabase runs on. No grant, no access, whatever\nelse you have written.",[10,58,59],{},"When the grant is missing, Supabase answers like this, usually as a 401 or a\n403:",[61,62,67],"pre",{"className":63,"code":65,"language":66},[64],"language-text","{\n  \"code\": \"42501\",\n  \"message\": \"permission denied for table comments\",\n  \"hint\": \"Grant the required privileges to the current role with: GRANT SELECT ON public.comments TO anon;\"\n}\n","text",[14,68,65],{"__ignoreMap":69},"",[10,71,72],{},"The hint is the useful part. It names the role that was refused and the exact\nstatement that would let it in.",[10,74,75],{},"Think of every table as a room. The grant is the door, and there is a separate\ndoor for each role. Row Level Security, the per-row rules you may already have\nmet, decides which drawers a visitor can open once they are inside. \"Permission\ndenied for table\" means somebody is standing at a shut door. They never got as\nfar as your rules.",[27,77,79],{"id":78},"what-changes-on-october-30","What changes on October 30?",[10,81,82,83,86],{},"New tables in the ",[14,84,85],{},"public"," schema, the folder of tables your builder uses unless\ntold otherwise, start arriving with their doors shut.",[10,88,89,90,92,93,95,96,98,99,106],{},"Until now, Supabase opened all three doors on every new table automatically:\nread, add, change and delete, for ",[14,91,43],{},", ",[14,94,47],{}," and ",[14,97,51],{},"\nalike. A table was reachable from your app the moment it existed, and your\nRow Level Security rules were the only thing between a stranger and its rows.\nSupabase's ",[100,101,105],"a",{"href":102,"rel":103},"https:\u002F\u002Fsupabase.com\u002Fchangelog\u002F45329-breaking-change-tables-not-exposed-to-data-and-graphql-api-automatically",[104],"nofollow","changelog","\ngives the reason plainly: agents and AI platforms now create tables with nobody\nreviewing the change, and the automatic grants exposed tables \"a developer\nforgot to protect\".",[108,109,110,123],"table",{},[111,112,113],"thead",{},[114,115,116,120],"tr",{},[117,118,119],"th",{},"Date",[117,121,122],{},"What happened or happens",[124,125,126,135,143],"tbody",{},[114,127,128,132],{},[129,130,131],"td",{},"28 April 2026",[129,133,134],{},"New projects could opt out of the automatic grants when they were created.",[114,136,137,140],{},[129,138,139],{},"30 May 2026",[129,141,142],{},"No automatic grants began rolling out as the default for new projects.",[114,144,145,148],{},[129,146,147],{},"30 October 2026",[129,149,150],{},"Existing projects stop receiving them too.",[10,152,153],{},"If your project was created after the end of May, it may already work this way,\nbecause Supabase rolled the new default out to new projects over the weeks after\nthat date.",[155,156],"diagram",{"alt":157,"caption":158,"src":159},"A timeline with a marker at 2026-10-30. Before it, three tables stand with their doors open: two have a padlock over their rows, and the third has none and its rows are amber. After it, two new tables stand with their doors shut.","Tables that exist on October 30 keep the doors they have, including one that was open to strangers. Only the tables made after it start with the door shut.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fbefore-and-after-october-30-1600x620.png",[10,161,162],{},"Three details are worth knowing before the date:",[164,165,166,183,195],"ul",{},[167,168,169,175,176,95,179,182],"li",{},[22,170,171,172,174],{},"Only the ",[14,173,85],{}," schema."," Storage and sign-in keep their tables in\nschemas of their own, ",[14,177,178],{},"storage",[14,180,181],{},"auth",", and Supabase says their grants and\ndefaults stay as they are.",[167,184,185,188,189,191,192,194],{},[22,186,187],{},"The secret key is refused too."," The automatic grants covered\n",[14,190,51],{}," as well, so an edge function (server code Supabase runs for\nyou) using your secret key gets the same error on a new table until\n",[14,193,51],{}," has a grant of its own.",[167,196,197,200],{},[22,198,199],{},"A table dropped and created again is a new table."," Grants belong to the\ntable itself, and they go with it when it is dropped. If your builder rebuilds\na table to change it, the rebuilt one starts with the door shut.",[27,202,204],{"id":203},"will-my-app-break-on-october-30","Will my app break on October 30?",[10,206,207],{},"Not on the day. It breaks the first time something creates a new table without\nalso creating the grant.",[10,209,210,211,214],{},"For most people reading this, that something is their builder. You ask for a\ncomments section. The builder writes a migration, which is the file of database\nchanges it runs for you, and the migration creates a ",[14,212,213],{},"comments"," table. If it\nalso writes the grants, you will never see this error. If it does not, the\ncomments screen shows nothing, or saving a comment fails, or a red message\nappears, depending on how your app handles an error. Every screen you already\nhad carries on working.",[10,216,217,218,223],{},"Supabase publishes an ",[100,219,222],{"href":220,"rel":221},"https:\u002F\u002Fsupabase.com\u002Fblog\u002Fsupabase-agent-skills",[104],"agent skill","\nfor AI coding tools that includes the grant step. Whether your builder uses it\nis up to your builder, so the safe assumption is that the next table it makes\nmay arrive with its door shut.",[27,225,227],{"id":226},"is-the-grant-from-the-error-safe-to-run","Is the GRANT from the error safe to run?",[10,229,230],{},"Only once the table has Row Level Security switched on and a rule written for\nit. The grant decides who gets through the door. Nothing about it decides which\ndrawers they open.",[10,232,233,234,236],{},"The key that makes your app's requests to Supabase ships inside your app, so a\ngrant to ",[14,235,43],{}," means any visitor, signed in or not, may now ask that table for\nrows. With a rule in place, they get the rows the rule allows. With Row Level\nSecurity switched off, they get every row in the table, and nothing about your\napp will look different.",[10,238,239],{},"The email shows three grants and stops. Supabase's own changelog shows three\nsteps, and says to \"treat these three steps as a unit\":",[61,241,244],{"className":242,"code":243,"language":66},[64],"-- 1. who may reach the table\ngrant select on public.orders to authenticated;\ngrant select, insert, update, delete on public.orders to service_role;\n\n-- 2. switch the per-row rules on\nalter table public.orders enable row level security;\n\n-- 3. the rule itself\ncreate policy \"Customers read their own orders\"\n  on public.orders\n  for select\n  to authenticated\n  using (auth.uid() = user_id);\n",[14,245,243],{"__ignoreMap":69},[10,247,248,249,251,252,257,258,260],{},"There is no ",[14,250,43],{}," line in that example, and that is deliberate. Nobody signed\nout should reach a table of orders, so the door for strangers stays shut, and\nsigned-in customers get only the read their screen needs. The rule then narrows\nit to their own rows. Supabase's own advice is to\n",[100,253,256],{"href":254,"rel":255},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fapi\u002Fsecuring-your-api",[104],"grant the minimum each role needs",".\nA grant to ",[14,259,43],{}," belongs on a table whose rows are meant for everyone, like the\ncomments under a public post.",[155,262],{"alt":263,"caption":264,"src":265},"Three lanes, each a request from anon heading for the same table. In the first the door is shut and the arrow stops at it, with the code 42501. In the second the door is open, the arrow stops at a Row Level Security bar, and two rows of the table light up. In the third the door is open, the bar is only a dashed outline, and every row lights up in amber.","The grant decides whether a request reaches the table. The rules behind it decide how much it takes away. An open door with no rules behind it hands over the whole table.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fthe-door-and-the-rules-1600x760.png",[10,267,268,269,273],{},"If you want to see which side of that picture your tables are on, our free scan\nasks your live app the question a stranger would, counts the rows it would be\ngiven without fetching any of them, and takes about 20 seconds with no account:\n",[100,270,272],{"href":271},"\u002Fsecurity-scanner","scan your app",".",[27,275,277],{"id":276},"why-the-row-level-security-fixes-do-not-touch-this-error","Why the Row Level Security fixes do not touch this error",[10,279,280],{},"Because the grant is checked first. A request that is refused at the door never\nreaches your rules, so changing the rules changes nothing about the error.",[10,282,283,284,287,288,292,293,296],{},"This matters because the code is shared. ",[14,285,286],{},"42501"," is also what Postgres returns\nwhen Row Level Security refuses a save, as in\n",[100,289,291],{"href":290},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","new row violates row-level security policy",".\nAn assistant going by the code alone can reach for the fixes that belong to\nthat error: switch Row Level Security off, or add a rule of ",[14,294,295],{},"using (true)",",\nwhich lets everyone through. Neither one makes this error go away. Both stay\nbehind after the grant finally goes in, and then the door is open onto drawers\nwith no locks.",[10,298,299],{},"The words in the message tell the two apart, even though the number does not:",[108,301,302,315],{},[111,303,304],{},[114,305,306,309,312],{},[117,307,308],{},"The message says",[117,310,311],{},"Which lock refused",[117,313,314],{},"What fixes it",[124,316,317,329,341],{},[114,318,319,323,326],{},[129,320,321],{},[14,322,16],{},[129,324,325],{},"the door (the grant)",[129,327,328],{},"a grant for the role the hint names",[114,330,331,335,338],{},[129,332,333],{},[14,334,291],{},[129,336,337],{},"the rules",[129,339,340],{},"a policy that allows that row",[114,342,343,346,348],{},[129,344,345],{},"no error, and the list is empty",[129,347,337],{},[129,349,350],{},"a read policy for that role",[27,352,354],{"id":353},"what-october-30-does-not-fix","What October 30 does not fix",[10,356,357],{},"Any table you already have. It keeps exactly the access it has today,\nincluding a table a stranger can read right now.",[10,359,360,361,365],{},"The change is about tables that do not exist yet. Until now every new table\narrived with its doors open, so an app built before October 30 may have one\nwhere nobody ever fitted the locks: Row Level Security never switched on, or\n",[100,362,364],{"href":363},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","switched on under a rule that lets everyone in",".\nOctober 30 leaves those rooms exactly as they are.",[10,367,368],{},"Three places show you where you stand:",[370,371,372,378,384],"ol",{},[167,373,374,377],{},[22,375,376],{},"The Data API settings page",", which the email links. In the dashboard it\nsits under Integrations, then Data API, and it lists which of your tables\nare reachable at all.",[167,379,380,383],{},[22,381,382],{},"The Security Advisor",", which Supabase says lists the tables worth\nreviewing before the change.",[167,385,386,389,390,273],{},[22,387,388],{},"The view from outside."," Neither of the first two tells you what a\nstranger gets back. For that you ask your live app the way a stranger\nwould, which is ",[100,391,392],{"href":271},"what our scan does",[27,394,396],{"id":395},"how-reeve-watches-the-tables-you-add","How Reeve watches the tables you add",[10,398,399],{},[22,400,401],{},"After October 30, every table your builder adds is a new decision about who\ngets through the door. Reeve checks the answer from outside, and Monitor keeps\nchecking it.",[164,403,404,412,422],{},[167,405,406,409,410,273],{},[22,407,408],{},"The free scan"," asks each table your app names how many rows a visitor with\nno login would get, reads the count, and stops there without fetching a row.\nAbout 20 seconds, no account: ",[100,411,272],{"href":271},[167,413,414,417,418,421],{},[22,415,416],{},"Reeve Monitor"," runs all nine checks every hour on up to three apps and\nemails you on the day your grade ",[22,419,420],{},"gets worse",", so a deploy that opened\nsomething up does not wait for you to come and look.",[167,423,424,427,428,431,432,273],{},[22,425,426],{},"Care"," runs the same checks and keeps an encrypted copy of your\n",[22,429,430],{},"Supabase"," database outside your Supabase account, so an assistant's fix\nthat rebuilds a table has a copy to come back from.\n",[100,433,435],{"href":434},"\u002Fsupabase-backups","How the copy is taken and put back",[10,437,438,439,273],{},"What each plan covers is on the ",[100,440,442],{"href":441},"\u002Fpricing","pricing page",[27,444,446],{"id":445},"what-to-do-before-october-30","What to do before October 30",[448,449,450],"key-takeaways",{},[164,451,452,455,462,468,477,483],{},[167,453,454],{},"Leave the tables you already have alone if all you want is for your app to keep working. They keep their grants.",[167,456,457,458,461],{},"Ask your builder to write the grant, ",[14,459,460],{},"enable row level security"," and a policy in the same migration as every new table, as one change.",[167,463,464,465,467],{},"When the error appears, read which role the hint names. ",[14,466,43],{}," means every visitor to your app.",[167,469,470,471,473,474,476],{},"Grant ",[14,472,43],{}," nothing on a table until Row Level Security is on and a rule is written. Tables that hold people or orders usually need no ",[14,475,43],{}," grant at all.",[167,478,479,480,482],{},"Refuse any fix that switches Row Level Security off or adds ",[14,481,295],{}," to clear a permission error. Neither touches it.",[167,484,485],{},"Check what a stranger can read from the tables you already have. October 30 leaves them as they are.",[10,487,488,489,491],{},"Start with the table a stranger would most like to read, usually the one with\npeople in it, and\n",[100,490,272],{"href":271}," to see what it hands over today.",{"title":69,"searchDepth":493,"depth":493,"links":494},3,[495,497,498,499,500,501,502,503],{"id":29,"depth":496,"text":30},2,{"id":78,"depth":496,"text":79},{"id":203,"depth":496,"text":204},{"id":226,"depth":496,"text":227},{"id":276,"depth":496,"text":277},{"id":353,"depth":496,"text":354},{"id":395,"depth":496,"text":396},{"id":445,"depth":496,"text":446},"Security basics","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fcover-1200x630.png","A row of doorways into database tables. The older ones stand open onto lit rows, and the newest, at the end, is shut.","From October 30, a new Supabase table answers \"permission denied for table\" until you grant access. The grant the email shows is half the fix.",false,"md",[511,514,516,519,522],{"q":512,"a":513},"Will my Supabase app stop working on October 30?","No. Every table that exists on October 30 keeps the access it has, and Supabase has confirmed those grants will not be revoked. What changes is the next table created after that date. It starts out unreachable from your app until somebody grants access to it, so the first thing to break is the first new feature that needs a new table.",{"q":30,"a":515},"It means the kind of visitor making the request has not been given access to that table at all, so your database refused before it looked at a single row. It comes from Postgres, the database Supabase runs on, with the code 42501, and usually reaches your app as a 401 or a 403. Supabase adds a hint naming the exact GRANT statement that would let that visitor in.",{"q":517,"a":518},"Is it safe to run the GRANT statement the error suggests?","Only once the table has Row Level Security switched on and a rule written for it. A grant to anon lets every visitor to your app ask the table for rows, because the key that makes those requests ships inside your app. With a rule in place they get the rows the rule allows. With no rule and Row Level Security off, they get all of them.",{"q":520,"a":521},"Does this change affect Storage, sign-in or my edge functions?","Storage and sign-in live in their own schemas, storage and auth, and Supabase says their grants and defaults stay as they are. Edge functions are different. One that uses your secret key still needs a grant on any new table, because the default grants being removed covered service_role as well as the two roles your visitors use.",{"q":523,"a":524},"Can I switch the old behaviour back on?","Supabase documents a way to do it, as a setting in the Data API page of the dashboard or as SQL, and recommends against it. With it on, every new table is reachable by every visitor the moment it exists, and Row Level Security is the only thing standing between a stranger and its rows. That is how every project worked before the change.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fcard-800x500.png",[527,528,529,530,531,532],"supabase permission denied for table","supabase grant new tables","supabase october 30 data api change","supabase 42501","supabase automatically expose new tables","supabase default privileges public schema",{},true,"Supabase \"permission denied for table\" after October 30","\u002Fblog\u002Fsupabase-permission-denied-for-table","2026-09-26",{"title":5,"description":507},"blog\u002Fsupabase-permission-denied-for-table",[541,542,543],"From October 30, 2026, a new table in your Supabase project answers \"permission denied for table\" until somebody grants access to it. The tables you already have keep working exactly as they do today.","A grant decides whether a request reaches a table at all. Row Level Security still decides which rows it gets back. Granting anon access to a table with no rules makes every row readable by anyone.","The change closes nothing that is already open. Check what a stranger can read today, and again after every table you add.","elo2RrkYgWTPUtWIwpxTU7Dfs7MdlCLN3DnKqMSxL3g",[546,552,558,564,570,576,582,588,594,600,606,612,618,625,631,636,637,643,649,655,661,667,673,679,685,691,697,703,709,715,721,727,733,739,745,751,757,763,769,775,781,787,793,799,805,811,816,822,828,834,840,846,852,858,863,869,875,880,885,891],{"path":547,"title":548,"description":549,"published":550,"category":504,"image":551,"draft":508},"\u002Fblog\u002Fbase44-security-scan","Base44 security scan: the one thing only it can see","The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.","2026-10-10","\u002Fblog\u002Fbase44-security-scan\u002Fcard-800x500.png",{"path":553,"title":554,"description":555,"published":556,"category":504,"image":557,"draft":508},"\u002Fblog\u002Fapi-key-leaked-what-to-do","Your API key leaked. Here is the order to do things in","An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.","2026-10-09","\u002Fblog\u002Fapi-key-leaked-what-to-do\u002Fcard-800x500.png",{"path":559,"title":560,"description":561,"published":562,"category":504,"image":563,"draft":508},"\u002Fblog\u002Finfinite-recursion-in-policy-for-relation","\"Infinite recursion detected in policy\" without disabling RLS","\"Infinite recursion detected in policy for relation\" means your Supabase policy asked the table it protects. Here is how to break the circle.","2026-10-08","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fcard-800x500.png",{"path":565,"title":566,"description":567,"published":568,"category":504,"image":569,"draft":508},"\u002Fblog\u002Fno-api-key-found-in-request","\"No API key found in request\" in Supabase, and the wrong fix","\"No API key found in request\" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.","2026-10-07","\u002Fblog\u002Fno-api-key-found-in-request\u002Fcard-800x500.png",{"path":571,"title":572,"description":573,"published":574,"category":504,"image":575,"draft":508},"\u002Fblog\u002Fis-base44-safe","Is Base44 safe? What 5,442 live Base44 apps showed","Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.","2026-10-06","\u002Fblog\u002Fis-base44-safe\u002Fcard-800x500.png",{"path":577,"title":578,"description":579,"published":580,"category":504,"image":581,"draft":508},"\u002Fblog\u002Fmove-a-secret-to-an-edge-function","Hide an API key: move it to a Supabase Edge Function","Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.","2026-10-05","\u002Fblog\u002Fmove-a-secret-to-an-edge-function\u002Fcard-800x500.png",{"path":583,"title":584,"description":585,"published":586,"category":504,"image":587,"draft":508},"\u002Fblog\u002Fenv-file-exposed-on-your-server","Is your .env file exposed? The twelve paths to check","Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.","2026-10-04","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Fcard-800x500.png",{"path":589,"title":590,"description":591,"published":592,"category":504,"image":593,"draft":508},"\u002Fblog\u002Fis-v0-safe","v0 security: all 1,790 v0 apps we scanned got an A","v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.","2026-10-03","\u002Fblog\u002Fis-v0-safe\u002Fcard-800x500.png",{"path":595,"title":596,"description":597,"published":598,"category":504,"image":599,"draft":508},"\u002Fblog\u002Fis-bolt-safe","Is Bolt safe? What 1,123 live Bolt apps showed","Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.","2026-10-02","\u002Fblog\u002Fis-bolt-safe\u002Fcard-800x500.png",{"path":601,"title":602,"description":603,"published":604,"category":504,"image":605,"draft":508},"\u002Fblog\u002Fis-supabase-down-or-your-app","Is Supabase down, or is it your app? How to tell","Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.","2026-10-01","\u002Fblog\u002Fis-supabase-down-or-your-app\u002Fcard-800x500.png",{"path":607,"title":608,"description":609,"published":610,"category":504,"image":611,"draft":508},"\u002Fblog\u002Fdoes-supabase-encrypt-my-data","Does Supabase encrypt my data? Yes. Here is what it stops","Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.","2026-09-30","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fcard-800x500.png",{"path":613,"title":614,"description":615,"published":616,"category":504,"image":617,"draft":508},"\u002Fblog\u002Fsupabase-free-plan-limits","Supabase free plan limits, and what happens at each one","The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.","2026-09-29","\u002Fblog\u002Fsupabase-free-plan-limits\u002Fcard-800x500.png",{"path":619,"title":620,"description":621,"published":622,"category":623,"image":624,"draft":508},"\u002Fblog\u002Ftest-your-supabase-backup","Test your Supabase backup before the day you need it","How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.","2026-09-28","Backups","\u002Fblog\u002Ftest-your-supabase-backup\u002Fcard-800x500.png",{"path":626,"title":627,"description":628,"published":629,"category":623,"image":630,"draft":508},"\u002Fblog\u002Fsupabase-backup-github-action","Free Supabase backup with a GitHub Action, and the catch","A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.","2026-09-27","\u002Fblog\u002Fsupabase-backup-github-action\u002Fcard-800x500.png",{"path":632,"title":633,"description":634,"published":537,"category":623,"image":635,"draft":508},"\u002Fblog\u002Fdownload-your-supabase-backup","Why you can't download your Supabase backup","You can't download your Supabase backup on a current project, because the daily copy is a physical snapshot. How to tell, and how to hold a copy of your own.","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fcard-800x500.png",{"path":536,"title":5,"description":507,"published":537,"category":504,"image":525,"draft":508},{"path":638,"title":639,"description":640,"published":641,"category":504,"image":642,"draft":508},"\u002Fblog\u002Fopen-api-endpoint-exposed","Is an open API endpoint a security problem? Look at the JSON","Your scan flagged an open API endpoint. Whether it matters depends on what came back, and most of the ones we found were the platform's own.","2026-09-25","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fcard-800x500.png",{"path":644,"title":645,"description":646,"published":647,"category":504,"image":648,"draft":508},"\u002Fblog\u002Flovable-security-scan","Lovable security scan: the one thing it cannot prove","Lovable security scan: what the Quick and Deep scans check, when each one runs, and the one thing no scan from inside your project can prove.","2026-09-24","\u002Fblog\u002Flovable-security-scan\u002Fcard-800x500.png",{"path":650,"title":651,"description":652,"published":653,"category":623,"image":654,"draft":508},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":656,"title":657,"description":658,"published":659,"category":504,"image":660,"draft":508},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":662,"title":663,"description":664,"published":665,"category":504,"image":666,"draft":508},"\u002Fblog\u002Fis-lovable-safe","Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":668,"title":669,"description":670,"published":671,"category":504,"image":672,"draft":508},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":674,"title":675,"description":676,"published":677,"category":504,"image":678,"draft":508},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":680,"title":681,"description":682,"published":683,"category":504,"image":684,"draft":508},"\u002Fblog\u002Fvite-and-next-public-env-vars","Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":686,"title":687,"description":688,"published":689,"category":504,"image":690,"draft":508},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":692,"title":693,"description":694,"published":695,"category":504,"image":696,"draft":508},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":698,"title":699,"description":700,"published":701,"category":504,"image":702,"draft":508},"\u002Fblog\u002Fis-replit-safe","Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":704,"title":705,"description":706,"published":707,"category":623,"image":708,"draft":508},"\u002Fblog\u002Fsupabase-storage-backup","Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":710,"title":711,"description":712,"published":713,"category":623,"image":714,"draft":508},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":716,"title":717,"description":718,"published":719,"category":623,"image":720,"draft":508},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":722,"title":723,"description":724,"published":725,"category":504,"image":726,"draft":508},"\u002Fblog\u002Fsafest-ai-app-builder","Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":728,"title":729,"description":730,"published":731,"category":504,"image":732,"draft":508},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":734,"title":735,"description":736,"published":737,"category":504,"image":738,"draft":508},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":740,"title":741,"description":742,"published":743,"category":504,"image":744,"draft":508},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":746,"title":747,"description":748,"published":749,"category":504,"image":750,"draft":508},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":752,"title":753,"description":754,"published":755,"category":504,"image":756,"draft":508},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":758,"title":759,"description":760,"published":761,"category":504,"image":762,"draft":508},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":764,"title":765,"description":766,"published":767,"category":504,"image":768,"draft":508},"\u002Fblog\u002Fmissing-security-headers","Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":770,"title":771,"description":772,"published":773,"category":504,"image":774,"draft":508},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":776,"title":777,"description":778,"published":779,"category":504,"image":780,"draft":508},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":782,"title":783,"description":784,"published":785,"category":623,"image":786,"draft":508},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":788,"title":789,"description":790,"published":791,"category":504,"image":792,"draft":508},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":794,"title":795,"description":796,"published":797,"category":623,"image":798,"draft":508},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":800,"title":801,"description":802,"published":803,"category":504,"image":804,"draft":508},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":806,"title":807,"description":808,"published":809,"category":504,"image":810,"draft":508},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":290,"title":812,"description":813,"published":814,"category":504,"image":815,"draft":508},"New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":817,"title":818,"description":819,"published":820,"category":504,"image":821,"draft":508},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":823,"title":824,"description":825,"published":826,"category":623,"image":827,"draft":508},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":829,"title":830,"description":831,"published":832,"category":623,"image":833,"draft":508},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":835,"title":836,"description":837,"published":838,"category":504,"image":839,"draft":508},"\u002Fblog\u002Fsupabase-storage-bucket-public","Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":841,"title":842,"description":843,"published":844,"category":504,"image":845,"draft":508},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":847,"title":848,"description":849,"published":850,"category":623,"image":851,"draft":508},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":853,"title":854,"description":855,"published":856,"category":504,"image":857,"draft":508},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":859,"title":860,"description":861,"published":856,"category":504,"image":862,"draft":508},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":864,"title":865,"description":866,"published":867,"category":504,"image":868,"draft":508},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":870,"title":871,"description":872,"published":873,"category":623,"image":874,"draft":508},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":363,"title":876,"description":877,"published":878,"category":504,"image":879,"draft":508},"Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":881,"title":882,"description":883,"published":878,"category":623,"image":884,"draft":508},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":886,"title":887,"description":888,"published":889,"category":623,"image":890,"draft":508},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":892,"title":893,"description":894,"published":889,"category":504,"image":895,"draft":508},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1791618966336]