[{"data":1,"prerenderedAt":791},["ShallowReactive",2],{"blog-en-supabase-storage-backup":3,"blog-index-en":443},{"id":4,"title":5,"body":6,"category":398,"cover":399,"coverAlt":400,"description":401,"draft":402,"extension":403,"faq":404,"image":420,"keywords":421,"meta":431,"navigation":432,"ogTitle":433,"path":434,"published":435,"seo":436,"stem":437,"tldr":438,"updated":435,"__hash__":442},"blog_en\u002Fblog\u002Fsupabase-storage-backup.md","Supabase storage backup: why your database copy has no files",{"type":7,"value":8,"toc":386},"minimark",[9,13,21,24,29,45,53,61,65,68,82,88,91,95,98,107,110,116,124,137,141,144,147,166,176,193,206,213,217,220,226,238,243,246,269,275,279,282,288,291,295,319,323,326,331,363,371,378],[10,11,12],"p",{},"You set up backups for your Lovable or Bolt app, or you pay for the Supabase\nplan that takes them, and the word did its job: you stopped worrying. Then a\nrestore, or a move to a new project, and the app comes back with a broken image\nwhere every profile picture used to be. Every table and every row is there. The\npictures are gone, along with every invoice, export and attachment a user ever\nuploaded.",[10,14,15,16,20],{},"Here is the part the word backup hides: ",[17,18,19],"strong",{},"a Supabase storage backup is a\nseparate job, because a database backup holds a row for every file your users\nuploaded and none of the files."," The row is in your database. The file is in\nStorage, a separate service, and no database copy on any plan reaches into it.\nThis article covers how to take that second copy, and the order the two halves\ngo back in, which is the part that goes wrong even when you have both.",[10,22,23],{},"It helps to think of a library. The catalogue is a drawer of cards, one for\nevery book, each saying which shelf the book stands on. The books are on the\nshelves. A database backup copies the drawer.",[25,26,28],"h2",{"id":27},"does-supabase-back-up-my-storage-files","Does Supabase back up my storage files?",[10,30,31,32,39,40,44],{},"No, on any plan. Supabase's\n",[33,34,38],"a",{"href":35,"rel":36},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fplatform\u002Fbackups",[37],"nofollow","backups documentation","\nsays that backups do not contain files stored via the Storage API, only their\ndatabase metadata, and\n",[33,41,43],{"href":42},"\u002Fblog\u002Fsupabase-point-in-time-recovery","point-in-time recovery"," is a database\nfeature, so the same sentence covers it.",[10,46,47,48,52],{},"What every backup does contain is the list. Supabase keeps a table called\n",[49,50,51],"code",{},"storage.objects"," in your Postgres database, with one row per file in every\nbucket: which bucket it sits in, its path, who uploaded it, how large it is and\nwhen it arrived. That table is copied along with everything else, which is\nexactly why a restored project looks so complete. Every card is in the drawer.",[10,54,55,56,60],{},"The bytes of each file are somewhere else. They live in object storage, a\nseparate service beside your database, and a tool that copies a database never\nreads it. The\n",[33,57,59],{"href":58},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","free plan takes no automatic backups at all",",\nso there the question does not even arise; on Pro and above the daily copy has\nyour rows and none of your uploads.",[25,62,64],{"id":63},"where-supabase-keeps-your-files","Where Supabase keeps your files",[10,66,67],{},"In two places, and a database backup reaches one of them.",[10,69,70,71,73,74,77,78,81],{},"When a user uploads an avatar, your app hands the file to Storage. Storage\nwrites the bytes into object storage under the bucket name and path, and in the\nsame operation writes a row into ",[49,72,51],{}," describing it. Your app then\nkeeps that path in one of its own tables, say a ",[49,75,76],{},"profiles"," row with an\n",[49,79,80],{},"avatar_url"," column, and builds a link from it whenever the picture is needed.",[10,83,84,85,87],{},"So one uploaded picture is three things: the bytes in object storage, the row\nin ",[49,86,51],{}," that Storage maintains, and the path in your own table. A\ndatabase backup carries the last two. Restore it and your app has every path\nand Storage has every row, and the link they build together points at a place\nwhere nothing is.",[10,89,90],{},"This is also why the failure is so quiet. Every row agrees with every other\nrow, every count matches, and every check that reads the database passes,\nincluding the verification step of most backup tools, because the files were\nnever inside the thing being checked.",[25,92,94],{"id":93},"what-a-restore-looks-like-with-only-half","What a restore looks like with only half",[10,96,97],{},"A project that passes every check and shows a broken image wherever a file\nshould appear.",[10,99,100,101,106],{},"The restore reports success because it did what it was asked: the tables are\nback and the row counts match. Open the dashboard and Storage lists every\nbucket and every file in it, with sizes and dates, because that listing is read\nfrom the table the restore put back. Supabase's own\n",[33,102,105],{"href":103,"rel":104},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fplatform\u002Fmigrating-within-supabase\u002Fdashboard-restore",[37],"guide to restoring a dashboard backup into a new project","\ndescribes exactly this state: the buckets and file metadata appear, and the\nobjects behind them do not.",[10,108,109],{},"How you find out is ordinary. The team page shows a row of broken-image icons\nwhere the avatars were. A customer replies to last month's invoice email to say\nthe link opens to an error. Somebody clicks a file in the Storage browser and\nthe download fails. The card says shelf four, third from the left, and shelf\nfour is empty.",[111,112],"diagram",{"alt":113,"caption":114,"src":115},"A saved copy feeding into a dashed project outline. Inside it, a table of three lit rows is ticked, and each row is joined by a thin line to a picture frame drawn dashed and empty. The frames are crossed.","The restore put back every row that describes a file. The files those rows describe were never in the copy.","\u002Fblog\u002Fsupabase-storage-backup\u002Fthe-list-came-back-1600x620.png",[10,117,118,119,123],{},"Nothing warns you before that moment, because every warning you have is wired\nto the database.\n",[33,120,122],{"href":121},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup","\nwalks through the five ways a restore comes up broken, and the files are the\nrow in that table with no fix unless you made a copy of them.",[10,125,126,127,131,132,136],{},"While you have the Storage page open, it is worth knowing what it shows a\nstranger. Our free scan reads your live app from outside and asks each bucket\nfor its file list using nothing except the key already in your app's code. In\nAugust 2026 it got a list back from 792 of the 27,269 apps it could check, a\nfigure from ",[33,128,130],{"href":129},"\u002Fresearch\u002Fvibe-coded-app-security-2026","our own research",". It\nreads names and never downloads a file, takes about 20 seconds and needs no\naccount: ",[33,133,135],{"href":134},"\u002Fsecurity-scanner","scan your app",".",[25,138,140],{"id":139},"how-do-i-back-up-a-supabase-storage-bucket","How do I back up a Supabase storage bucket?",[10,142,143],{},"Through the S3-compatible endpoint, with one command that copies a whole bucket\ninto a folder you hold.",[10,145,146],{},"Supabase Storage speaks the S3 protocol, which means the ordinary tools built\nfor Amazon's storage work against yours. This is the one step in this article\nthat happens at a command line, and it is worth doing once by hand so that you\nknow what the copy is made of.",[148,149,150,154,157],"ol",{},[151,152,153],"li",{},"In your Supabase dashboard, open the Storage settings and switch on the S3\nprotocol. The same page shows the endpoint URL and the region for your\nproject; copy both from there rather than from here.",[151,155,156],{},"On that page, create an S3 access key pair. The secret is shown once, so put\nit in a password manager before you close the dialog.",[151,158,159,160,165],{},"Install the ",[33,161,164],{"href":162,"rel":163},"https:\u002F\u002Faws.amazon.com\u002Fcli\u002F",[37],"AWS command line",", give it the two\nkeys as a profile, and run one sync per bucket:",[167,168,173],"pre",{"className":169,"code":171,"language":172},[170],"language-text","aws s3 sync s3:\u002F\u002Favatars .\u002Fsupabase-files\u002Favatars \\\n  --endpoint-url https:\u002F\u002F\u003Cproject-ref>.storage.supabase.co\u002Fstorage\u002Fv1\u002Fs3 \\\n  --region \u003Cregion>\n","text",[49,174,171],{"__ignoreMap":175},"",[10,177,178,179,182,183,188,189,192],{},"Run it again tomorrow and it copies only what changed. ",[49,180,181],{},"rclone"," does the same\njob if you prefer it; on a large bucket, Supabase's\n",[33,184,187],{"href":185,"rel":186},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Ftroubleshooting\u002Frclone-error-s3-protocol-error-received-listing-v1-with-istruncated-set-no-nextmarker-and-no-contents-e64d34",[37],"troubleshooting note","\nsays to pass ",[49,190,191],{},"--s3-list-version 2"," or the listing can stop early.",[10,194,195,196,201,202,136],{},"Two things about that key. Supabase's\n",[33,197,200],{"href":198,"rel":199},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fstorage\u002Fs3\u002Fauthentication",[37],"S3 authentication page","\nsays an S3 access key has full access to every bucket and bypasses Row Level\nSecurity, so it belongs on a server or on your own machine and never in your\napp. And it can write as well as read, because Supabase issues no read-only key\nfor Storage; whoever holds it can delete files as easily as copy them. Treat it\nthe way you would treat\n",[33,203,205],{"href":204},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","your service_role key",[10,207,208,209,212],{},"Then put the folder somewhere outside your Supabase account, for\n",[33,210,211],{"href":58},"the same reason a database copy should live outside it",":\na suspended project or a lost login takes every copy stored inside that account\ndown with it.",[25,214,216],{"id":215},"files-first-or-rows-first","Files first, or rows first?",[10,218,219],{},"Database first, then the files, and the files go back through Storage so that\nStorage writes the rows.",[10,221,222,223,225],{},"Every upload that passes through Storage, from your app, from the S3 endpoint\nor from the Supabase CLI, does two things in one operation: it stores the bytes\nand it writes the ",[49,224,51],{}," row that describes them. The book is\nshelved and the card is written by the same hand. Put the files back that way\nand the rows arrive with them, and the two cannot disagree.",[10,227,228,229,231,232,237],{},"The other direction has no such mechanism. Copying ",[49,230,51],{}," rows back\nwith a database tool writes cards and shelves nothing. It also makes the next\nstep awkward: by default Storage refuses an upload to a path that already has a\nrow, with an error saying the resource already exists, which Supabase's\n",[33,233,236],{"href":234,"rel":235},"https:\u002F\u002Fsupabase.com\u002Fdocs\u002Fguides\u002Fstorage\u002Fuploads",[37],"uploads guide"," says you get\npast by switching overwrite on. So when the database restore has already\nbrought the rows back, which is what Supabase's own migration guide has you do,\nthe file copy that follows has to be allowed to overwrite.",[111,239],{"alt":240,"caption":241,"src":242},"Two lanes. In the upper one a saved copy goes straight into a database and lights three rows, while a container drawn under the arrow stays dashed and empty, and the lane is crossed. In the lower one three pictures go into the container first, an arrow carries on from the container into the database, and the same three rows light as the pictures land. The lower lane is ticked.","A file that arrives through Storage writes its own row. A row that arrives through the database brings no file with it.","\u002Fblog\u002Fsupabase-storage-backup\u002Fthrough-storage-or-around-it-1600x620.png",[10,244,245],{},"The order, then:",[148,247,248,255,266],{},[151,249,250,251,254],{},"Restore the database, as\n",[33,252,253],{"href":121},"that article"," describes.",[151,256,257,258,261,262,265],{},"Copy the files back through Storage, with ",[49,259,260],{},"aws s3 sync"," run the other way\nround (folder first, bucket second) or with ",[49,263,264],{},"supabase storage cp -r",", and\noverwrite switched on. A bucket that no longer exists has to be created\nfirst, with the same name and the same public setting.",[151,267,268],{},"Open a file, and then several more.",[10,270,271,272,274],{},"The cleanest version of this skips replaying ",[49,273,51],{}," in the database\nstep altogether and lets the uploads write every row fresh, so nothing ever\nhas to be overwritten. That is how our own restore does it. It needs the copy\nfiltered before it is replayed, which is a step for the tool doing the restore.",[25,276,278],{"id":277},"how-to-check-you-have-both","How to check you have both",[10,280,281],{},"By opening files, because every list you can pull is read from the table.",[10,283,284,285,287],{},"The dashboard's file browser, a query against ",[49,286,51],{}," and the row\ncount on a backup report all describe the drawer, and after a database-only\nrestore the drawer is perfect. The only request that touches the shelf is a\nrequest for the file itself.",[10,289,290],{},"So after a restore, and after the first copy you take, open files. Pick a\nhandful from each bucket, including the oldest ones, and open them through the\napp the way a user would. A file that opens came back. A file that errors was\nnever there, whatever the list says.",[25,292,294],{"id":293},"what-to-do-this-week","What to do this week",[296,297,298],"key-takeaways",{},[299,300,301,304,310,313,316],"ul",{},[151,302,303],{},"Open Storage in your Supabase dashboard and write down every bucket and roughly what is in it. Anything a user uploaded lives there and in no database backup.",[151,305,306,307,309],{},"Switch on the S3 protocol, create an access key, and run one ",[49,308,260],{}," per bucket into a folder outside your Supabase account. Keep the secret in a password manager; it can delete as easily as it copies.",[151,311,312],{},"Run the sync again on a schedule you will keep, whether that is a calendar reminder or a job on a server.",[151,314,315],{},"Write the restore order somewhere you will find it: database first, then files through Storage with overwrite on.",[151,317,318],{},"Restore once into a throwaway project and open ten files, so the first time you learn whether the copy works is not during an outage.",[25,320,322],{"id":321},"where-reeve-care-fits","Where Reeve Care fits",[10,324,325],{},"Care copies the files with the database, in the order this article describes,\nand puts them back the same way.",[111,327],{"alt":328,"caption":329,"src":330},"A Reeve Care panel with two rows. In the first, a database and a picture sit inside a dashed account outline. The database leaves it as a saved file that is locked, read back through a lens and ticked, numbered one, and only then does the picture leave as a second saved file, numbered two. In the second row, a card carrying a button sends one copy back into the account, numbered one, and a second copy back along an arrow that passes through a container on its way, numbered two.","The database copy is read back and passes before the files are copied. On the way back the database goes first, and the files return through Storage.","\u002Fblog\u002Fsupabase-storage-backup\u002Fcare-database-then-files-1600x560.png",[299,332,333,339,345,351,357],{},[151,334,335,338],{},[17,336,337],{},"The files your users uploaded are copied too",", once you connect the Storage buckets of your Supabase app. That is a second key, asked for separately, because the key Supabase issues for Storage can write as well as read, and we would rather ask than fold it in with the database key, which cannot.",[151,340,341,344],{},[17,342,343],{},"The file copy runs after the database copy has been read back and verified",", never beside it, so a restore point never claims files it did not copy. A copy that ran out of time is labelled partial, with the real counts.",[151,346,347,350],{},[17,348,349],{},"Each restore point records which path held which file."," A database put back to Tuesday gets Tuesday's files, and a file that is still in place is left alone.",[151,352,353,356],{},[17,354,355],{},"Restoring puts the files back through Storage",", so every row is written by the upload that carries the file. Nothing that exists today is overwritten or deleted, which means pressing the button in a panic cannot destroy the thing you were trying to save.",[151,358,359,362],{},[17,360,361],{},"Restoring is a button",", and it takes a snapshot of the current state before it starts, so the restore itself has an undo.",[10,364,365,366,370],{},"Care starts at $49 a month for one app. That is a list price, and the\n",[33,367,369],{"href":368},"\u002Fpricing","pricing page"," is sometimes below the figure here and never above it.",[10,372,373,374,136],{},"How a copy is taken, checked and put back, files included, is drawn step by\nstep on the ",[33,375,377],{"href":376},"\u002Fsupabase-backups","Supabase backups page",[10,379,380,381,385],{},"Before you close this tab, open Storage in your dashboard and count the\nbuckets. Each one is a set of files that no backup Supabase takes will ever\ncontain, and the sync command above is the whole of what it takes to change\nthat. If a bucket also turned out to be listable,\n",[33,382,384],{"href":383},"\u002Fblog\u002Fsupabase-storage-bucket-public","what a stranger gets from that list"," is\nthe next thing to read.",{"title":175,"searchDepth":387,"depth":387,"links":388},3,[389,391,392,393,394,395,396,397],{"id":27,"depth":390,"text":28},2,{"id":63,"depth":390,"text":64},{"id":93,"depth":390,"text":94},{"id":139,"depth":390,"text":140},{"id":215,"depth":390,"text":216},{"id":277,"depth":390,"text":278},{"id":293,"depth":390,"text":294},{"id":321,"depth":390,"text":322},"Backups","\u002Fblog\u002Fsupabase-storage-backup\u002Fcover-1200x630.png","A database with three rows, each joined by a thin line to a picture standing in a separate tray beside it.","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.",false,"md",[405,408,411,414,417],{"q":406,"a":407},"Does Supabase back up my storage buckets?","No. Supabase says so on its own backups page: database backups do not contain files stored through the Storage API, only the database rows that describe them. That holds for the daily backups on paid plans and for point-in-time recovery. The free plan takes no automatic backups at all, so there the question does not arise. Your files need a copy of their own on every plan.",{"q":409,"a":410},"Does point-in-time recovery cover Supabase Storage?","No. Point-in-time recovery rewinds the database, and Storage is a separate service that the database only holds paths into. A project rewound to Tuesday points at whatever is in the buckets today, and a file deleted on Wednesday stays deleted after a recovery that worked perfectly.",{"q":412,"a":413},"How do I download every file in a Supabase bucket?","Through the S3-compatible endpoint. Switch on the S3 protocol in the Storage settings of your dashboard, create an access key pair, and point the AWS command line or rclone at the endpoint and region printed on the same page. One sync command copies a whole bucket to a folder you hold. The dashboard downloads one file at a time, which is fine for a logo and hopeless for a bucket.",{"q":415,"a":416},"What is storage.objects?","A table in your Postgres database with one row for every file in every bucket: which bucket it is in, its path, who uploaded it, its size and type, and when it arrived. It is the index. The bytes of the file are not in it, which is why a database backup can list every file you have while containing none of them.",{"q":418,"a":419},"If I restore my database, do my files come back?","No. The restore brings back the storage.objects rows, so the dashboard lists every file and your app renders every link, and each one opens to an error because the file behind it was never in the copy. The files have to be put back separately, through Storage, from a copy you took of them.","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",[422,423,424,425,426,427,428,429,430],"supabase storage backup","backup supabase storage bucket","does supabase back up storage","supabase storage objects backup","supabase files backup","restore supabase storage","supabase s3 storage backup","supabase bucket download all files","supabase storage disaster recovery",{},true,"Supabase storage backup: your copy has no files","\u002Fblog\u002Fsupabase-storage-backup","2026-09-14",{"title":5,"description":401},"blog\u002Fsupabase-storage-backup",[439,440,441],"A Supabase storage backup is a separate job from a database backup. Every backup Supabase takes, on every plan, holds the row that describes each uploaded file and none of the files themselves.","Restore the database on its own and you get a working app in which every avatar, invoice and upload opens to an error, because the file it points at was never in the copy.","The S3-compatible endpoint is the way to copy the files out. The way back is through Storage itself, which writes the matching row as each file arrives, so the list and the files cannot disagree.","WqFgSEhZlA6I-yqEz8XKM21MhzU2mZcuVzHIlHKPiWI",[444,451,457,463,469,475,481,487,493,499,505,511,517,523,529,535,540,546,552,558,564,570,576,582,588,594,600,606,607,612,618,624,630,636,642,648,654,660,666,672,678,684,690,696,702,708,714,720,726,731,736,742,748,754,759,765,770,776,781,787],{"path":445,"title":446,"description":447,"published":448,"category":449,"image":450,"draft":402},"\u002Fblog\u002Fbase44-security-scan","Base44 security scan: the one thing only it can see","The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.","2026-10-10","Security basics","\u002Fblog\u002Fbase44-security-scan\u002Fcard-800x500.png",{"path":452,"title":453,"description":454,"published":455,"category":449,"image":456,"draft":402},"\u002Fblog\u002Fapi-key-leaked-what-to-do","Your API key leaked. Here is the order to do things in","An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.","2026-10-09","\u002Fblog\u002Fapi-key-leaked-what-to-do\u002Fcard-800x500.png",{"path":458,"title":459,"description":460,"published":461,"category":449,"image":462,"draft":402},"\u002Fblog\u002Finfinite-recursion-in-policy-for-relation","\"Infinite recursion detected in policy\" without disabling RLS","\"Infinite recursion detected in policy for relation\" means your Supabase policy asked the table it protects. Here is how to break the circle.","2026-10-08","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fcard-800x500.png",{"path":464,"title":465,"description":466,"published":467,"category":449,"image":468,"draft":402},"\u002Fblog\u002Fno-api-key-found-in-request","\"No API key found in request\" in Supabase, and the wrong fix","\"No API key found in request\" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.","2026-10-07","\u002Fblog\u002Fno-api-key-found-in-request\u002Fcard-800x500.png",{"path":470,"title":471,"description":472,"published":473,"category":449,"image":474,"draft":402},"\u002Fblog\u002Fis-base44-safe","Is Base44 safe? What 5,442 live Base44 apps showed","Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.","2026-10-06","\u002Fblog\u002Fis-base44-safe\u002Fcard-800x500.png",{"path":476,"title":477,"description":478,"published":479,"category":449,"image":480,"draft":402},"\u002Fblog\u002Fmove-a-secret-to-an-edge-function","Hide an API key: move it to a Supabase Edge Function","Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.","2026-10-05","\u002Fblog\u002Fmove-a-secret-to-an-edge-function\u002Fcard-800x500.png",{"path":482,"title":483,"description":484,"published":485,"category":449,"image":486,"draft":402},"\u002Fblog\u002Fenv-file-exposed-on-your-server","Is your .env file exposed? The twelve paths to check","Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.","2026-10-04","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Fcard-800x500.png",{"path":488,"title":489,"description":490,"published":491,"category":449,"image":492,"draft":402},"\u002Fblog\u002Fis-v0-safe","v0 security: all 1,790 v0 apps we scanned got an A","v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.","2026-10-03","\u002Fblog\u002Fis-v0-safe\u002Fcard-800x500.png",{"path":494,"title":495,"description":496,"published":497,"category":449,"image":498,"draft":402},"\u002Fblog\u002Fis-bolt-safe","Is Bolt safe? What 1,123 live Bolt apps showed","Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.","2026-10-02","\u002Fblog\u002Fis-bolt-safe\u002Fcard-800x500.png",{"path":500,"title":501,"description":502,"published":503,"category":449,"image":504,"draft":402},"\u002Fblog\u002Fis-supabase-down-or-your-app","Is Supabase down, or is it your app? How to tell","Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.","2026-10-01","\u002Fblog\u002Fis-supabase-down-or-your-app\u002Fcard-800x500.png",{"path":506,"title":507,"description":508,"published":509,"category":449,"image":510,"draft":402},"\u002Fblog\u002Fdoes-supabase-encrypt-my-data","Does Supabase encrypt my data? Yes. Here is what it stops","Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.","2026-09-30","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fcard-800x500.png",{"path":512,"title":513,"description":514,"published":515,"category":449,"image":516,"draft":402},"\u002Fblog\u002Fsupabase-free-plan-limits","Supabase free plan limits, and what happens at each one","The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.","2026-09-29","\u002Fblog\u002Fsupabase-free-plan-limits\u002Fcard-800x500.png",{"path":518,"title":519,"description":520,"published":521,"category":398,"image":522,"draft":402},"\u002Fblog\u002Ftest-your-supabase-backup","Test your Supabase backup before the day you need it","How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.","2026-09-28","\u002Fblog\u002Ftest-your-supabase-backup\u002Fcard-800x500.png",{"path":524,"title":525,"description":526,"published":527,"category":398,"image":528,"draft":402},"\u002Fblog\u002Fsupabase-backup-github-action","Free Supabase backup with a GitHub Action, and the catch","A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.","2026-09-27","\u002Fblog\u002Fsupabase-backup-github-action\u002Fcard-800x500.png",{"path":530,"title":531,"description":532,"published":533,"category":398,"image":534,"draft":402},"\u002Fblog\u002Fdownload-your-supabase-backup","Why you can't download your Supabase backup","You can't download your Supabase backup on a current project, because the daily copy is a physical snapshot. How to tell, and how to hold a copy of your own.","2026-09-26","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fcard-800x500.png",{"path":536,"title":537,"description":538,"published":533,"category":449,"image":539,"draft":402},"\u002Fblog\u002Fsupabase-permission-denied-for-table","Supabase \"permission denied for table\": the missing grant","From October 30, a new Supabase table answers \"permission denied for table\" until you grant access. The grant the email shows is half the fix.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fcard-800x500.png",{"path":541,"title":542,"description":543,"published":544,"category":449,"image":545,"draft":402},"\u002Fblog\u002Fopen-api-endpoint-exposed","Is an open API endpoint a security problem? Look at the JSON","Your scan flagged an open API endpoint. Whether it matters depends on what came back, and most of the ones we found were the platform's own.","2026-09-25","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fcard-800x500.png",{"path":547,"title":548,"description":549,"published":550,"category":449,"image":551,"draft":402},"\u002Fblog\u002Flovable-security-scan","Lovable security scan: the one thing it cannot prove","Lovable security scan: what the Quick and Deep scans check, when each one runs, and the one thing no scan from inside your project can prove.","2026-09-24","\u002Fblog\u002Flovable-security-scan\u002Fcard-800x500.png",{"path":553,"title":554,"description":555,"published":556,"category":398,"image":557,"draft":402},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":559,"title":560,"description":561,"published":562,"category":449,"image":563,"draft":402},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":565,"title":566,"description":567,"published":568,"category":449,"image":569,"draft":402},"\u002Fblog\u002Fis-lovable-safe","Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":571,"title":572,"description":573,"published":574,"category":449,"image":575,"draft":402},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":577,"title":578,"description":579,"published":580,"category":449,"image":581,"draft":402},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":583,"title":584,"description":585,"published":586,"category":449,"image":587,"draft":402},"\u002Fblog\u002Fvite-and-next-public-env-vars","Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":589,"title":590,"description":591,"published":592,"category":449,"image":593,"draft":402},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":595,"title":596,"description":597,"published":598,"category":449,"image":599,"draft":402},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":601,"title":602,"description":603,"published":604,"category":449,"image":605,"draft":402},"\u002Fblog\u002Fis-replit-safe","Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":434,"title":5,"description":401,"published":435,"category":398,"image":420,"draft":402},{"path":42,"title":608,"description":609,"published":610,"category":398,"image":611,"draft":402},"Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":613,"title":614,"description":615,"published":616,"category":398,"image":617,"draft":402},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":619,"title":620,"description":621,"published":622,"category":449,"image":623,"draft":402},"\u002Fblog\u002Fsafest-ai-app-builder","Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":625,"title":626,"description":627,"published":628,"category":449,"image":629,"draft":402},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":631,"title":632,"description":633,"published":634,"category":449,"image":635,"draft":402},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":637,"title":638,"description":639,"published":640,"category":449,"image":641,"draft":402},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":643,"title":644,"description":645,"published":646,"category":449,"image":647,"draft":402},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":649,"title":650,"description":651,"published":652,"category":449,"image":653,"draft":402},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":655,"title":656,"description":657,"published":658,"category":449,"image":659,"draft":402},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":661,"title":662,"description":663,"published":664,"category":449,"image":665,"draft":402},"\u002Fblog\u002Fmissing-security-headers","Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":667,"title":668,"description":669,"published":670,"category":449,"image":671,"draft":402},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":673,"title":674,"description":675,"published":676,"category":449,"image":677,"draft":402},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":679,"title":680,"description":681,"published":682,"category":398,"image":683,"draft":402},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":685,"title":686,"description":687,"published":688,"category":449,"image":689,"draft":402},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":691,"title":692,"description":693,"published":694,"category":398,"image":695,"draft":402},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":697,"title":698,"description":699,"published":700,"category":449,"image":701,"draft":402},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":703,"title":704,"description":705,"published":706,"category":449,"image":707,"draft":402},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":709,"title":710,"description":711,"published":712,"category":449,"image":713,"draft":402},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":715,"title":716,"description":717,"published":718,"category":449,"image":719,"draft":402},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":721,"title":722,"description":723,"published":724,"category":398,"image":725,"draft":402},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":121,"title":727,"description":728,"published":729,"category":398,"image":730,"draft":402},"How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":383,"title":732,"description":733,"published":734,"category":449,"image":735,"draft":402},"Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":737,"title":738,"description":739,"published":740,"category":449,"image":741,"draft":402},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":743,"title":744,"description":745,"published":746,"category":398,"image":747,"draft":402},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":749,"title":750,"description":751,"published":752,"category":449,"image":753,"draft":402},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":755,"title":756,"description":757,"published":752,"category":449,"image":758,"draft":402},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":760,"title":761,"description":762,"published":763,"category":449,"image":764,"draft":402},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":58,"title":766,"description":767,"published":768,"category":398,"image":769,"draft":402},"Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":771,"title":772,"description":773,"published":774,"category":449,"image":775,"draft":402},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":777,"title":778,"description":779,"published":774,"category":398,"image":780,"draft":402},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":782,"title":783,"description":784,"published":785,"category":398,"image":786,"draft":402},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":204,"title":788,"description":789,"published":785,"category":449,"image":790,"draft":402},"Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1791618966336]