diff --git a/apps/docs/content/guides/api/custom-claims-and-role-based-access-control-rbac.mdx b/apps/docs/content/guides/api/custom-claims-and-role-based-access-control-rbac.mdx index 98b4cf6f57d..7e14fad3c77 100644 --- a/apps/docs/content/guides/api/custom-claims-and-role-based-access-control-rbac.mdx +++ b/apps/docs/content/guides/api/custom-claims-and-role-based-access-control-rbac.mdx @@ -199,7 +199,9 @@ For server-side logic, you can use a JWT package for your language, such as [`ex ## Conclusion -You now have a robust system in place to manage user roles and permissions within your database that automatically propagates to Supabase Auth. +You now have a system for managing user roles and permissions in your database, and the Auth Hook copies a user's role into every access token it issues. + +A role change reaches a user the next time their access token is issued, not immediately. Sessions that are already open keep the role they were issued with until the client refreshes them. To apply a role change right away, refresh the session with [`refreshSession()`](/docs/reference/javascript/auth-refreshsession) or have the user sign in again. See [Sessions](/docs/guides/auth/sessions) for how long an access token lasts. ## More resources diff --git a/apps/docs/content/guides/auth/auth-hooks.mdx b/apps/docs/content/guides/auth/auth-hooks.mdx index 327d87456d1..39b8816fd7d 100644 --- a/apps/docs/content/guides/auth/auth-hooks.mdx +++ b/apps/docs/content/guides/auth/auth-hooks.mdx @@ -134,7 +134,7 @@ Deno.serve(async (req) => { ## Using Hooks -### Developing +### Local development Let us develop a Hook locally and then deploy it to the cloud. As a recap, here’s a list of available Hooks