@@ -372,87 +372,157 @@ const JWTSettings = () => {
)}
-
-
-
How to change your JWT secret?
-
- Instead of changing the legacy JWT secret use a combination of the JWT Signing
- Keys and API keys features. Consider these advantages:
+
+
+
+ {disableLegacyJwtSecretRotation
+ ? 'How to migrate to the new API keys?'
+ : 'How to change your JWT secret?'}
+
+
+
+
+
+ {disableLegacyJwtSecretRotation
+ ? 'Migrate to the new publishable and secret API keys to enable rotation with zero downtime and without signing users out. The change is reversible until you revoke the legacy secret.'
+ : 'Instead of changing the legacy JWT secret use a combination of the JWT Signing Keys and API keys features. Consider these advantages:'}
-
- - Zero-downtime, reversible change.
- - Users remain signed in and bad actors out.
- -
- Create multiple secret API keys that are immediately revocable and fully
- covered by audit logs.
-
- -
- Private keys and shared secrets are no longer visible by organization members,
- so they can't leak.
-
- -
- Maintain tighter alignment with SOC2 and other security compliance frameworks.
-
- -
- Improve app's performance by using public keys to verify JWTs instead of
- calling
getUser().
-
-
-
-
-
} asChild>
-
- Go to API Keys
-
-
-
} asChild>
-
- Go to JWT Signing Keys
-
-
+ {disableLegacyJwtSecretRotation ? (
+
+ -
+
+ Click "Migrate JWT secret" in{' '}
+
+ JWT Signing Keys
+
+ .
+
+
+ This imports your legacy secret into the new system and generates a
+ standby asymmetric key.
+
+
+ -
+
Create and roll out new API keys.
+
+ In{' '}
+
+ API Keys
+
+ , create a publishable key and secret key, then swap them into your apps
+ in place of anon and{' '}
+ service_role{' '}
+ respectively. Watch the "Last used" indicators to confirm no traffic still
+ depends on the legacy keys.
+
+
+ -
+
+ Click "Rotate keys" in{' '}
+
+ JWT Signing Keys
+ {' '}
+ to start signing new JWTs with the standby key.
+
+
+ Existing anon,{' '}
+ service_role, and active user
+ JWTs stay valid. Before rotating, switch any code that verifies JWTs
+ directly against the legacy secret (e.g.{' '}
+ jose,{' '}
+ jsonwebtoken) to{' '}
+ supabase.auth.getClaims() or a
+ JWKS-based verifier, and disable the "Verify JWT" setting on any affected
+ Edge Functions.
+
+
+ -
+
+ Optionally, revoke the legacy JWT secret in{' '}
+
+ JWT Signing Keys
+ {' '}
+ once you're sure it's no longer in use.
+
+
+
+ ) : (
+
+ - Zero-downtime, reversible change.
+ - Users remain signed in and bad actors out.
+ -
+ Create multiple secret API keys that are immediately revocable and fully
+ covered by audit logs.
+
+ -
+ Private keys and shared secrets are no longer visible by organization
+ members, so they can't leak.
+
+ -
+ Maintain tighter alignment with SOC2 and other security compliance
+ frameworks.
+
+ -
+ Improve app's performance by using public keys to verify JWTs instead of
+ calling
getUser().
+
+
+ )}
-
-
-
-
- }
- loading={isUpdatingJwtSecret}
- tooltip={{
- content: {
- side: 'bottom',
- text: !canGenerateNewJWTSecret
- ? 'You need additional permissions to generate a new JWT secret'
- : undefined,
- },
- }}
- >
- Change legacy JWT secret
-
-
-
- setIsGeneratingKey(true)}
- >
-
- Generate a random secret
-
-
- setIsCreatingKey(true)}
- >
-
- Create my own secret
-
-
-
-
-
+
+ {disableLegacyJwtSecretRotation ? (
+
} asChild>
+
+ Read the full migration guide
+
+
+ ) : (
+
+
+ }
+ loading={isUpdatingJwtSecret}
+ tooltip={{
+ content: {
+ side: 'bottom',
+ text: !canGenerateNewJWTSecret
+ ? 'You need additional permissions to generate a new JWT secret'
+ : undefined,
+ },
+ }}
+ >
+ Change legacy JWT secret
+
+
+
+ setIsGeneratingKey(true)}
+ >
+
+ Generate a random secret
+
+
+ setIsCreatingKey(true)}
+ >
+
+ Create my own secret
+
+
+
+ )}
+
+
+
>
)}
@@ -461,7 +531,7 @@ const JWTSettings = () => {
{
{
@@ -623,5 +693,3 @@ const JWTSettings = () => {
>
)
}
-
-export default JWTSettings
diff --git a/apps/studio/components/layouts/ProjectSettingsLayout/SettingsMenu.utils.tsx b/apps/studio/components/layouts/ProjectSettingsLayout/SettingsMenu.utils.tsx
index 0a15a1364ef..b1733741993 100644
--- a/apps/studio/components/layouts/ProjectSettingsLayout/SettingsMenu.utils.tsx
+++ b/apps/studio/components/layouts/ProjectSettingsLayout/SettingsMenu.utils.tsx
@@ -83,7 +83,7 @@ export const useGenerateSettingsMenu = () => {
{
name: 'API Keys',
key: 'api-keys',
- url: `/project/${ref}/settings/api-keys/new`,
+ url: `/project/${ref}/settings/api-keys`,
items: [],
disabled: !isProjectActive,
},
diff --git a/apps/studio/pages/project/[ref]/settings/jwt/legacy.tsx b/apps/studio/pages/project/[ref]/settings/jwt/legacy.tsx
index d2b341f3d4a..ab8ef11e5ec 100644
--- a/apps/studio/pages/project/[ref]/settings/jwt/legacy.tsx
+++ b/apps/studio/pages/project/[ref]/settings/jwt/legacy.tsx
@@ -4,7 +4,7 @@ import { useParams } from 'common'
import { useEffect, useRef } from 'react'
import { toast } from 'sonner'
-import JWTSettings from '@/components/interfaces/JwtSecrets/jwt-settings'
+import { JWTSettings } from '@/components/interfaces/JwtSecrets/jwt-settings'
import { JWT_SECRET_UPDATE_ERROR_MESSAGES } from '@/components/interfaces/JwtSecrets/jwt.constants'
import DefaultLayout from '@/components/layouts/DefaultLayout'
import JWTKeysLayout from '@/components/layouts/JWTKeys/JWTKeysLayout'
From fc0aae8b14f3c40f015eb40f4244e6a5a8d5d4e8 Mon Sep 17 00:00:00 2001
From: Terry Sutton
Date: Wed, 22 Apr 2026 10:12:51 -0230
Subject: [PATCH 14/63] Add new skills page (#45118)
Adds a new Skills page
## Summary by CodeRabbit
* **New Features**
* Home hero now shows two side-by-side CTAs: "Get Started" and "Install
Skills" for quick access.
* **Documentation**
* Added a new "Skills" docs page describing Agent Skills and
installation options (CLI and plugin).
* Sidebar navigation updated: section renamed to "AI Skills" and the nav
item changed to "Skills" (marked new).
* **Removed**
* Old "Prompts" documentation page removed.
---
apps/ui-library/app/(app)/page.tsx | 11 +++--
apps/ui-library/config/docs.ts | 9 ++--
.../content/docs/ai-editors-rules/prompts.mdx | 21 ----------
.../content/docs/ai-editors-rules/skills.mdx | 42 +++++++++++++++++++
4 files changed, 55 insertions(+), 28 deletions(-)
delete mode 100644 apps/ui-library/content/docs/ai-editors-rules/prompts.mdx
create mode 100644 apps/ui-library/content/docs/ai-editors-rules/skills.mdx
diff --git a/apps/ui-library/app/(app)/page.tsx b/apps/ui-library/app/(app)/page.tsx
index e993da7e4cd..567c15e01b5 100644
--- a/apps/ui-library/app/(app)/page.tsx
+++ b/apps/ui-library/app/(app)/page.tsx
@@ -45,9 +45,14 @@ export default function Home() {
A collection of React components and blocks built on the shadcn/ui library
that connect your front-end to your Supabase back-end via a single command.
-
- Get Started
-
+
+
+ Get Started
+
+
+ Install Skills
+
+
diff --git a/apps/ui-library/config/docs.ts b/apps/ui-library/config/docs.ts
index 34c7f4a4893..24a3ac0c1d6 100644
--- a/apps/ui-library/config/docs.ts
+++ b/apps/ui-library/config/docs.ts
@@ -25,13 +25,14 @@ export const gettingStarted: SidebarNavGroup = {
}
export const aiEditorsRules: SidebarNavGroup = {
- title: 'AI Editors Rules',
+ title: 'AI Skills',
items: [
{
- title: 'Prompts',
- href: '/docs/ai-editors-rules/prompts',
+ title: 'Skills',
+ href: '/docs/ai-editors-rules/skills',
items: [],
- commandItemLabel: 'AI Editors Rules',
+ new: true,
+ commandItemLabel: 'AI Skills',
},
],
}
diff --git a/apps/ui-library/content/docs/ai-editors-rules/prompts.mdx b/apps/ui-library/content/docs/ai-editors-rules/prompts.mdx
deleted file mode 100644
index 3aa4a4457e3..00000000000
--- a/apps/ui-library/content/docs/ai-editors-rules/prompts.mdx
+++ /dev/null
@@ -1,21 +0,0 @@
----
-title: Prompts
-description: Rules for AI Code Editors for Supabase
----
-
-## Installation
-
-