Hashim Ruan

Free tool · owner verified · read-only

Is your Supabase data readable by anyone holding your app’s public key?

Every Supabase app ships its public key to the browser. Whether that is safe depends entirely on Row Level Security, and on policies that do what the team believes they do. This check reads your configuration, counts what an anonymous visitor can reach, and tells you how to fix each gap, with the SQL. About two minutes.

  1. 1

    Why you have to prove it is yours

    Testing someone else’s database without permission is an offence, and a free tool cannot collect permission from a stranger. So this check only runs once you have installed a small read-only function in your own project. Only someone with access to your SQL editor can do that, which is the proof.

    The function reads catalog information only: which tables have RLS, the policies, grants and storage buckets. It cannot read your rows, and it answers nothing unless it is called with the one-time token below. Your key is not stored.

  2. 2

    Run this in your Supabase SQL editor

    Open your project, go to SQL Editor, paste, and press Run. Read it first: it is short.

    Enable JavaScript to generate your one-time SQL.
  3. 3

    Run the check