From 9a8ea280edc62c77326b6e9d9ec796a7a40db5d5 Mon Sep 17 00:00:00 2001 From: Chris Chinchilla Date: Tue, 21 Apr 2026 15:48:46 +0100 Subject: [PATCH] docs: Key changes in API section (#44994) ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES/ ## Summary by CodeRabbit * **Documentation** * Updated API docs and quickstart examples to reference publishable API keys in configuration snippets, cURL examples, and browser guidance. * Adjusted quickstart cURL examples to simplify headers and align with publishable-key usage. * Clarified security guidance to recommend distributing publishable keys where appropriate and updated related wording across guides. --------- Co-authored-by: fadymak --- .../guides/api/automatic-retries-in-supabase-js.mdx | 2 +- apps/docs/content/guides/api/quickstart.mdx | 9 ++++----- apps/docs/content/guides/api/securing-your-api.mdx | 2 +- 3 files changed, 6 insertions(+), 7 deletions(-) diff --git a/apps/docs/content/guides/api/automatic-retries-in-supabase-js.mdx b/apps/docs/content/guides/api/automatic-retries-in-supabase-js.mdx index a842d73e1c6..81a47dd1d6e 100644 --- a/apps/docs/content/guides/api/automatic-retries-in-supabase-js.mdx +++ b/apps/docs/content/guides/api/automatic-retries-in-supabase-js.mdx @@ -23,7 +23,7 @@ If you prefer to handle retries yourself, you can disable the built-in retry beh ```javascript import { createClient } from '@supabase/supabase-js' -const supabase = createClient('https://your-project-id.supabase.co', 'your-anon-key', { +const supabase = createClient('https://your-project-id.supabase.co', 'your-publishable-key', { db: { retry: false, }, diff --git a/apps/docs/content/guides/api/quickstart.mdx b/apps/docs/content/guides/api/quickstart.mdx index c00272a7e68..d3050706082 100644 --- a/apps/docs/content/guides/api/quickstart.mdx +++ b/apps/docs/content/guides/api/quickstart.mdx @@ -174,15 +174,14 @@ We'll create a database table called `todos` for storing tasks. This creates a c Find your API URL and Keys in your Dashboard [API Settings](/dashboard/project/_/settings/api). You can now query your "todos" table by appending `/rest/v1/todos` to the API URL. - Copy this block of code, substitute `` and ``, then run it from a terminal. + Copy this block of code, substitute `` and ``, then run it from a terminal. ```bash Terminal curl 'https://.supabase.co/rest/v1/todos' \ - -H "apikey: " \ - -H "Authorization: Bearer " + -H "apikey: " ``` @@ -197,9 +196,9 @@ There are several options for accessing your data: ### Browser -You can query the route in your browser, by appending the `anon` key as a query parameter: +You can query the route in your browser, by appending the `publishable` key as a query parameter: -`https://.supabase.co/rest/v1/todos?apikey=` +`https://.supabase.co/rest/v1/todos?apikey=` ### Client libraries diff --git a/apps/docs/content/guides/api/securing-your-api.mdx b/apps/docs/content/guides/api/securing-your-api.mdx index 59d667a4a6e..f065793bb0a 100644 --- a/apps/docs/content/guides/api/securing-your-api.mdx +++ b/apps/docs/content/guides/api/securing-your-api.mdx @@ -262,7 +262,7 @@ Some applications can benefit from using additional API keys managed by the appl -Using the `apikey` header with the [Supabase API keys](/docs/guides/api/api-keys) is mandatory and not configurable. If you use additional API keys, you have to distribute both the `anon` API key and your application's custom API key. +Using the `apikey` header with the [Supabase API keys](/docs/guides/api/api-keys) is mandatory and not configurable. If you use additional API keys, you have to distribute both the `publishable` API key and your application's custom API key.