diff --git a/web/docs/guides/api.mdx b/web/docs/guides/api.mdx index 3d9c80e88f1..442fd77cb9c 100644 --- a/web/docs/guides/api.mdx +++ b/web/docs/guides/api.mdx @@ -382,7 +382,7 @@ alter table todos enable row level security; ### The `service_role` key -Never expose the `service_role` key in a browser or anywhere where a user can see it. This Key can is designed to bypass Row Level Security - so it should only be used on a private server. +Never expose the `service_role` key in a browser or anywhere where a user can see it. This Key is designed to bypass Row Level Security - so it should only be used on a private server. We have [partnered with GitHub](https://supabase.com/blog/2022/03/28/community-day#supabase-is-now-a-github-secret-scanning-partner) to scan for Supabase `service_role` keys pushed to public repositories. If they detect any keys with service_role privileges being pushed to GitHub, they will forward the API key to us, so that we can automatically revoke the detected secrets and notify you, protecting your data against malicious actors.