docs(self-hosted): add a section about key rotation to docker guide (#50015)

This commit is contained in:
Andrey A. authored and GitHub committed 2026-09-04 21:35:49 +02:00
1 parent 8a1adbbd14
commit bd43802d7b
1 file changed
+18
@@ -492,6 +492,24 @@ The script generates a new password, updates all database roles, and modifies yo
sh run.sh recreate
```
### Rotating API keys
Unlike the managed platform, where you rotate keys from the Dashboard, self-hosted API keys live in your `.env` file. To rotate the publishable and secret keys (`SUPABASE_PUBLISHABLE_KEY` and `SUPABASE_SECRET_KEY`) without changing the asymmetric signing key pair, run:
```sh
sh utils/rotate-new-api-keys.sh --update-env
```
Then restart the services and update your applications with the new keys:
```sh
sh run.sh recreate
```
Use the publishable key in client apps and the secret key only in trusted server-side environments. Rotating these keys does not invalidate existing user session tokens. You can also set a custom value by editing `SUPABASE_PUBLISHABLE_KEY` or `SUPABASE_SECRET_KEY` in `.env` directly, then recreating the services.
For rotating versus fully regenerating the asymmetric key pair (which does affect active sessions), see [New API Keys and Asymmetric Authentication](/docs/guides/self-hosting/self-hosted-auth-keys#regenerating-asymmetric-key-pair).
### Configuring secrets
The `generate-keys.sh` script sets the following secrets automatically. You can also configure them manually in the `.env` file if needed: