From 351ba14d3c5a34275c18a1a296cc2e681d13ca34 Mon Sep 17 00:00:00 2001 From: Andrew Valleteau Date: Mon, 5 Jan 2026 09:28:16 +0100 Subject: [PATCH] docs(branching): add the list of all valid secrets fields (#41640) * docs(branching): add the list of all valid secrets fields * chore(docs): allow Captcha to the rules spelling lints * docs(branching): make external secret a star field --- .../deployment/branching/configuration.mdx | 54 ++++++++++++++++++- supa-mdx-lint/Rule003Spelling.toml | 1 + 2 files changed, 54 insertions(+), 1 deletion(-) diff --git a/apps/docs/content/guides/deployment/branching/configuration.mdx b/apps/docs/content/guides/deployment/branching/configuration.mdx index 9e5559a506b..937edbec6fe 100644 --- a/apps/docs/content/guides/deployment/branching/configuration.mdx +++ b/apps/docs/content/guides/deployment/branching/configuration.mdx @@ -154,7 +154,59 @@ secret = "env(SUPABASE_AUTH_EXTERNAL_GITHUB_SECRET)" -The `encrypted:` syntax only works for designated "secret" fields in the configuration (like `secret` in auth providers). Using encrypted values in other fields will not be automatically decrypted and may cause issues. For non-secret fields, use environment variables with the `env()` syntax instead. +The `encrypted:` syntax only works for designated "secret" fields in the configuration. Using encrypted values in other fields will not be automatically decrypted and may cause issues. For non-secret fields, use environment variables with the `env()` syntax instead. + +The following fields support the `encrypted:` syntax: + +**Studio** + +- `studio.openai_api_key` + +**Database** + +- `db.root_key` +- `db.vault.*` (any key in the vault map) + +**Auth - Core Keys** + +- `auth.publishable_key` +- `auth.secret_key` +- `auth.jwt_secret` +- `auth.anon_key` +- `auth.service_role_key` + +**Auth - Email (SMTP)** + +- `auth.email.smtp.pass` + +**Auth - Captcha** + +- `auth.captcha.secret` + +**Auth - Hooks** + +- `auth.hook.mfa_verification_attempt.secrets` +- `auth.hook.password_verification_attempt.secrets` +- `auth.hook.custom_access_token.secrets` +- `auth.hook.send_sms.secrets` +- `auth.hook.send_email.secrets` +- `auth.hook.before_user_created.secrets` + +**Auth - SMS Providers** + +- `auth.sms.twilio.auth_token` +- `auth.sms.twilio_verify.auth_token` +- `auth.sms.messagebird.access_key` +- `auth.sms.textlocal.api_key` +- `auth.sms.vonage.api_secret` + +**Auth - External OAuth Providers** + +- `auth.external.*.secret` + +**Edge Runtime** + +- `edge_runtime.secrets.*` (any key in the secrets map) diff --git a/supa-mdx-lint/Rule003Spelling.toml b/supa-mdx-lint/Rule003Spelling.toml index 5da86acc7a3..912a50d8531 100644 --- a/supa-mdx-lint/Rule003Spelling.toml +++ b/supa-mdx-lint/Rule003Spelling.toml @@ -358,6 +358,7 @@ allow_list = [ "gte-small", "halfvec", "hCaptcha", + "Captcha", "https?:\\/\\/\\S+", "i.e.", "imgproxy",