Free tool · owner verified · read-only
Is your Supabase data readable by anyone holding your app’s public key?
Every Supabase app ships its public key to the browser. Whether that is safe depends entirely on Row Level Security, and on policies that do what the team believes they do. This check reads your configuration, counts what an anonymous visitor can reach, and tells you how to fix each gap, with the SQL. About two minutes.
-
1
Why you have to prove it is yours
Testing someone else’s database without permission is an offence, and a free tool cannot collect permission from a stranger. So this check only runs once you have installed a small read-only function in your own project. Only someone with access to your SQL editor can do that, which is the proof.
The function reads catalog information only: which tables have RLS, the policies, grants and storage buckets. It cannot read your rows, and it answers nothing unless it is called with the one-time token below. Your key is not stored.
-
2
Run this in your Supabase SQL editor
Open your project, go to SQL Editor, paste, and press Run. Read it first: it is short.
Enable JavaScript to generate your one-time SQL. -
3
Run the check
/100
Keep it this way
Weekly monitoring, US$29 a month
Every week I re-run this check on your project and email you the result. If a new table, policy or bucket opens something up, you hear about it that week, not after a breach. Keep the audit function installed; cancel any time.
Not monitoring? Remove the function when you are done
This is the configuration. The logic is underneath.
This check sees which doors are open. It cannot see whether a policy that looks right lets one customer read another customer’s data, what your edge functions trust, or what your AI features can be talked into. That is the review.
AI-built app security check, US$595 Full Supabase review, from US$2,800