Commit Graph
2269 Commits
Author SHA1 Message Date
Cemal KılıçandChris Chinchilla a5afb3dd22 feat(docs): add enterprise managed MCP auth (#47691)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Added docs for enterprise managed MCP auth


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
  * Added guidance for Enterprise-Managed Authentication for MCP.
* Documented setup requirements, authorization flow, configuration
steps, and security considerations.
* Expanded the SSO guide and navigation with links to the new MCP
authentication documentation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-08-14 14:24:55 +02:00
Etienne Stalmans 773b388f25 chore(docs): correct api for temporary access (#48741)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update




<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated temporary access guidance to require SSL-enforced incoming
connections.
* Updated Management API examples to use the `/jit-access` endpoint for
checking, enabling, and disabling temporary access.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-14 09:37:38 +00:00
9ef9f1b8c1 feat(self-host): use @supabase/server in functions template and docs (#48996)
Updates the self-host Edge Functions template to use `@supabase/server`,
matching the CLI's `supabase functions new` templates (part of SDK-1150,
follows up on #45635 which exposed `SUPABASE_JWKS` to the functions
container). The `hello` example function now wraps its handler in
`withSupabase({ auth: 'none' })` and resolves the package through a
per-function `deno.json` import map, which the runtime auto-discovers,
so no dispatcher changes are needed. The self-hosted functions guide is
updated to match: the create-a-function snippet, a `ctx.supabaseAdmin`
example replacing the manual esm.sh `createClient` wiring, and a note
that `auth: 'user'` requires `SUPABASE_JWKS`. Verified on
`supabase/edge-runtime:v1.74.0` with the compose environment variables:
`curl /functions/v1/hello` returns the same response body as before, so
existing docs and troubleshooting pages stay accurate.

The `docker/.gitignore` change: `volumes/functions/**` ignores
self-hosters' own functions, but it also hid the new `deno.json`, which
must ship with the repo for the `hello` import to resolve. The allowlist
entries follow the existing `main/index.ts` pattern.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Edge Functions now support authenticated invocation with publishable
or secret API keys.
* Function handlers can access authenticated and administrative Supabase
clients through the request context.
* Added automatic environment configuration and JWT verification
support.

* **Documentation**
* Updated the self-hosting guide with the new function setup and
authentication workflow.
* Improved local function examples for supported access patterns and
privileged operations.

* **Tests**
* Updated self-hosted smoke tests to validate publishable-key function
access.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Kalleby Santos <kalleby_santos@hotmail.com>
Co-authored-by: Kalleby Santos <105971119+kallebysantos@users.noreply.github.com>
2026-08-14 12:00:11 +03:00
Kostas Botsas 7bfc45cc7b Update pg_net schema (#48694)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update

## What is the current behavior?

The create extension snippet defaults to public which trips the Security
Advisor check "0014_extension_in_public".

The extension either way creates its own "net" schema.

## What is the new behavior?

Register pg_net in the extensions schema.
This is also the default when installing the extension from the
dashboard.

<img width="425" height="224" alt="image"
src="https://github.com/user-attachments/assets/160309c0-9d35-4de7-b583-32f5db310a96"
/>


## Additional context
When no schema is specified, defaults to public which trips the Security
Advisor check:

<img width="1084" height="250" alt="image"
src="https://github.com/user-attachments/assets/ac5f2859-17bf-4763-9880-453b0f414b4f"
/>



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated the pg_net installation example to place the extension in the
`extensions` schema.
* Clarified that this configuration keeps pg_net out of `public` and
satisfies the Security Advisor check.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-14 10:38:21 +03:00
dancer13andPamela Chia 5627d01183 docs: Update tab reference in project setup documentation (#48451)
Tab naming has changed

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

* YES/NO

## What kind of change does this PR introduce?

* docs update

## What is the current behavior?

* Tab section referred do NOT exist anymore

## What is the new behavior?

<img width="1823" height="823" alt="image"
src="https://github.com/user-attachments/assets/7f2253ba-a251-434d-a005-10a598ae83b9"
/>



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated the User Management Starter quickstart navigation instructions
to use **Reference > Examples** in the Dashboard.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Pamela Chia <pamelachiamayyee@gmail.com>
2026-08-14 03:23:57 +00:00
Ayaan GazaliandPamela Chia 514f53a944 docs: point explain and rpc reference links at their current pages (#48655)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs fix (broken links).

## What is the current behavior?

Three links in two troubleshooting entries point at
`/docs/reference/javascript/explain`, which returns 404. That slug is
not in the docs sitemap any more.

Two of the three are not explain links at all. In
`fixing-520-errors-in-the-database-rest-api-Ur5-B2.mdx` the link text is
"RPCs" and "RPC" and the query string asks for
`example=call-a-postgres-function-with-arguments`, so both were meant to
point at the `rpc` reference. The third, in
`understanding-postgresql-explain-output-Un9dqX.mdx`, really is about
explain: the text is "EXPLAIN" and it asks for
`example=get-execution-plan-with-analyze-and-verbose`.

## What is the new behavior?

- the two "RPC" links now point at `/docs/reference/javascript/rpc`
- the "EXPLAIN" link now points at
`/docs/reference/javascript/using-modifiers-explain`

Both destinations return 200. The `queryGroups` and `example` query
strings are carried over unchanged, I only changed the slug.

## Additional context

Files:

-
`apps/docs/content/troubleshooting/fixing-520-errors-in-the-database-rest-api-Ur5-B2.mdx`
(2 links, to `rpc`)
-
`apps/docs/content/troubleshooting/understanding-postgresql-explain-output-Un9dqX.mdx`
(1 link, to `using-modifiers-explain`)

What I verified: `/docs/reference/javascript/explain` returns 404, and
both `/docs/reference/javascript/rpc` and
`/docs/reference/javascript/using-modifiers-explain` return 200 and
appear in the sitemap. After the change there are no
`javascript/explain?` references left in `apps/docs/content`.

What I could not verify, so I am flagging it rather than claiming it: I
could not confirm server side that the `example=` ids still exist on the
destination pages, because the reference pages appear to build their
example selectors client side and the ids are not in the fetched HTML. I
kept each existing `example=` value as it was, on the basis that an
unmatched example parameter just leaves the default selection rather
than breaking the page, which is still better than the current 404. If
you know those example ids have been renamed too, tell me and I will
update them in the same PR.

This was the one case I deliberately left out of #48568, where I said
the intended target looked ambiguous. Looking at it again, the link text
and the example parameter agree with each other in all three cases, so
the mapping is clearer than I first thought.

Gates run locally: `test:prettier` passes repo wide and the docs vitest
suite passes (22 files, 169 tests, 1 file and 2 tests skipped). I did
not run a build: `pnpm build` needs `DOCS_GITHUB_APP_PRIVATE_KEY` for
the docs `build:federated-content` step, which I do not have, and it
fails before Next compiles.

Freshman contributor here, working through these with Claude Code's help
and checking each URL myself. Happy to change any of the targets if you
would rather they went elsewhere.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
  * Updated database REST API troubleshooting links for RPC guidance.
  * Corrected the Supabase JavaScript EXPLAIN documentation link.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Pamela Chia <pamelachiamayyee@gmail.com>
2026-08-14 11:18:11 +08:00
TylerandDanny White ececf6c003 docs: Update Devin Desktop Supabase plugin guides (#49048)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

- Windsurf has been renamed to Devin Desktop. This PR updates
public-facing mentions of Windsurf to Devin Desktop
- Update MCP installation instruction to match the current behavior. 

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated supported environment guidance to reference Devin Desktop
instead of Windsurf.
  * Updated the MCP configuration path for Devin Desktop.
* Removed outdated Windsurf-specific setup instructions and transport
limitations.
* Refreshed related MCP client labeling and setup guidance for clarity
and consistency across the documentation and configuration experience.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com>
2026-08-14 03:10:19 +00:00
Maksym Ionutsa 4d492db5eb docs: update settings links after upgrade UI move to General (#49053)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

docs update
- Upgrade project button and Postgres/PostgREST version checks moved
from Infrastructure to General settings
- Updated links across 13 docs pages to match


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Updated dashboard links throughout the documentation to direct users
to **General Settings** instead of **Infrastructure Settings**.
- Corrected guidance for Postgres, pgvector, pg_net, and PostgREST
upgrades, configuration, and version checks.
- Updated monitoring, Grafana, and Log Drains links to current
documentation paths.
- Fixed troubleshooting links, CLI project path examples, pg_cron
terminology, and Markdown formatting.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-13 22:38:04 +02:00
Tobias Pfeiffer 0c2b8d77b2 fix: Update supabase test docs to use _test.sql (#48993)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

The database testing docs currently show test files using the
`.test.sql` suffix, but `supabase test new` generates `_test.sql` files.

Both formats work, but the generator behavior matches the previous Go
CLI implementation and existing test fixtures. Update the docs for
consistency with the actual generated file naming.

Relevant context: [database testing
docs](<https://supabase.com/docs/guides/database/testing>) and
[CLI-1318](<https://linear.app/supabase/issue/CLI-1318/port-supabase-test-db-supabase-test-new>).

We might want to add `supabase test new` to the docs, but that's a
separate change.

## What is the current behavior?

It reports `.test.sql`

## What is the new behavior?

it reports `_test.sql` inline with the generator

## Additional context

[slack
thread](https://supabase.slack.com/archives/C07E5GFAHTM/p1786373594478619)
- we can also add the test generator to the docs but I think that's a
separate issue.
2026-08-12 08:59:32 -07:00
Cameron Blackwood 25e77c4720 (fix): clarify re-enabling data api section of no exposed schemas troubleshooting guide (#48998)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

docs update

## What is the current behavior?


## What is the new behavior?


## Additional context

Add any other context or screenshots.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Expanded troubleshooting guidance for re-enabling the Data API after
applying the schema exposure workaround.
  * Clarified the steps and context for reversing the workaround.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-12 16:47:39 +01:00
Pedro Rodrigues ba5f0f57fd docs: add update step to agent skills docs page (#48982)
The agent skills docs page covered installing skills but not upgrading
them, and skill fixes/features (like the debugging skill, only available
from v0.1.8) can go unnoticed if users never re-run the CLI. Adds an
**Upgrading skills** section with the `npx skills update` command and a
link to the [`skills update`
docs](https://github.com/vercel-labs/skills#skills-update).

### Preview

<img width="813" height="611" alt="image"
src="https://github.com/user-attachments/assets/c4b96316-f2d1-4b8a-b7bd-a868156447d5"
/>




[source](https://docs-git-docs-add-update-agent-skills-step-to-docs-supabase.vercel.app/docs/guides/ai-tools/ai-skills)

Closes
[AI-1066](https://linear.app/supabase/issue/AI-1066/add-agent-skills-upgrade-step-to-docs-page).

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added an “Upgrading skills” guide explaining how to update all or
selected installed skills.
  * Included links to additional documentation for more details.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-12 15:55:36 +01:00
Guilherme SouzaandClaude Sonnet 5 0c27456c86 docs: Update documentation from JS, Dart, and Swift SDK changes (#48723)
## Summary

Updates docs based on recent SDK changes across three of the six tracked
SDKs. `supabase-py`, `supabase-kt`, and `supabase-csharp` were also
analyzed this cycle but had no doc-worthy changes (internal bug fixes /
dependency bumps only, or no new commits).

## Changes analyzed

| SDK | Repo | Commits | Latest tag |
|---|---|---|---|
| js | https://github.com/supabase/supabase-js | `485695ff7...21e410f56`
| v3.0.0-next.29 |
| dart | https://github.com/supabase/supabase-flutter |
`6979093...5447063` | yet_another_json_isolate-v2.1.1 |
| py | https://github.com/supabase/supabase-py | `3c98900...0490201` |
v3.0.0a1 |
| swift | https://github.com/supabase/supabase-swift |
`c24795d...51a083a` | v2.54.1 |
| kt | https://github.com/supabase-community/supabase-kt | (no new
commits) | 3.7.0 |
| csharp | https://github.com/supabase-community/supabase-csharp |
`572624e...ac057a2` | v1.5.0 |

## Documentation updates

- **`apps/docs/content/guides/auth/sessions/pkce-flow.mdx`** — new
"Overlapping flows" section documenting the experimental
`appendPkceFlowIdToRedirects` option and `flowId`-aware
`exchangeCodeForSession()`, added in supabase-js #2569, which fixes
concurrent PKCE flows (e.g. multiple tabs) clobbering each other's
stored code verifier.
- **`apps/docs/spec/supabase_dart_v2.yml`** — `stream()` entry:
documented the new filter methods (`like`, `ilike`, `match`, `imatch`,
`isFilter`, `isDistinct`) and multi-filter chaining added in
supabase-flutter #1610, plus two behavioral caveats (filter
re-evaluation on UPDATE, primary-key-only DELETE payloads) and a new
example.
- **`apps/docs/spec/supabase_swift_v2.yml`**:
- `invoke()` entry: documented the new `timeoutInterval` override on
`FunctionInvokeOptions` (supabase-swift #1144), with a new example.
- Added missing `generate-link` and `signOut()` (admin) spec entries —
supabase-swift #1152 added these methods but Swift had no reference
entries for them, even though the shared nav ids already existed in
`common-client-libs-sections.json` for other SDKs.

## Test plan

- [x] `python3 -c "import yaml; yaml.safe_load(...)"` on both edited
YAML spec files — parses cleanly
- [x] `npx prettier --check` on all three changed files — passes
- [ ] Visual check of rendered reference pages for the new Swift
`generate-link` / `signOut` / timeout examples and the Dart `stream()`
multi-filter example (docs dev server)

---

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Added guidance for experimental overlapping PKCE authentication flows,
including separating concurrent flows and exchanging their flow IDs.
- Expanded Dart streaming documentation with filter operators,
multiple-filter behavior, update semantics, delete payloads, and
chained-filter examples.
- Added Swift documentation for admin link generation, user sign-out,
and configurable Edge Function timeouts.
- Documented the default 150-second Edge Function idle timeout and
per-invocation timeout overrides.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-12 10:21:19 -03:00
Jordi Enric 1440cb81ab docs: update database inspect page title DOCS-1300 (#48972)
## Problem

The database debugging and monitoring guide had the generic title
"Debugging and monitoring", which lacked product context and made it
unclear in search results or breadcrumbs which area it covered.

## Fix

Changed the page title to "Database debugging and monitoring". The
sidebar entry keeps its shorter "Debugging and monitoring" label since
it already has database section context.

## How to test

- Navigate to the database debugging and monitoring guide in the docs
- Confirm the page H1 reads "Database debugging and monitoring"
- Confirm the sidebar entry still reads "Debugging and monitoring"

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated the guide title to “Database debugging and monitoring” for
clearer navigation and context.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-12 07:15:23 -06:00
Pedro RodriguesandClaude Opus 4.8 47595f8ac7 feat(self-hosted): implement queryLogs for the MCP debugging tools (#48900)
> [!IMPORTANT]  
>
> Only merge this when (https://github.com/supabase/platform/pull/36804)
is merged, as the AI assistant will not have access to the `query_logs`
tool for the remote MCP server

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature (self-hosted / CLI Studio MCP server).

## What is the current behavior?

Self-hosted `getDebuggingOperations`
(`apps/studio/lib/api/self-hosted/mcp.ts`) implements only `getLogs`, so
the MCP `debugging` group exposes `get_logs` — a fixed per-service log
dump built by `getLogQuery`. Logs are served by Logflare, which speaks
BigQuery SQL.

## What is the new behavior?

Bumps `@supabase/mcp-server-supabase` to `^0.10.0` (adds `query_logs` +
`logsDialect`, and hides `get_logs` wherever a platform declares
`queryLogs`) and moves logs over to it.

- **Self-hosted `query_logs`:** declares `logsDialect: 'bigquery'` and
implements `queryLogs`, passing the model's SQL straight through to the
same Logflare `logs.all` endpoint (arbitrary `sql` param) — no new
endpoint, no dialect translation.
- **Drops `get_logs` from self-hosted:** `getLogs` throws (the server
hides it once `queryLogs` exists) and the per-service `getLogQuery`
builder is deleted; the model now writes its own BigQuery SQL, guided by
the dialect schema hint.
- **Honors no-logs mode:** `query_logs` throws when `logs:all` is
disabled — the self-hosted default, enabled via the
`docker-compose.logs.yml` override.
- **Assistant:** switches the dashboard assistant from `get_logs` to
`query_logs` (allowlist, drift guard, prompt, mocks, evals).

Refs AI-1046


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * AI debugging can query recent project logs using read-only SQL.
* Log queries support optional time-range filters, filtering,
aggregation, and joins.
* Self-hosted debugging checks whether logging is enabled before running
queries.

* **Bug Fixes**
* Updated debugging workflows and validation to consistently use the new
log-query capability.
* Removed reliance on legacy service-specific log filtering and query
behavior.

* **Documentation**
* Updated MCP debugging tool guidance to describe SQL-based log queries.

* **Tests**
* Expanded coverage for enabled, disabled, and unsupported logging
scenarios.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-08-12 13:11:23 +01:00
Leonardo SantiagoandKaterina Skroumpelou 34c29f0b98 docs(python): add python docs for otel instrumention (#48898)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Adds a new tab section for the `client-side-tracing.mdx` document file,
explaining how to setup OTel context propagation in the `supabase-py`
library.

## What is the current behavior?

No documentation.

## What is the new behavior?

Documentation.

## Additional context

Add any other context or screenshots.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated the client-side tracing guide to document W3C trace-context
propagation support in the Python SDK.
* Added Python setup instructions for OpenTelemetry HTTPX
instrumentation, tracer configuration, and tracing Supabase queries.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Katerina Skroumpelou <sk.katherine@gmail.com>
2026-08-12 01:00:24 +08:00
Han Qiao 433175e79a Clarify behavior of preview branches in documentation (#48744)
Update the description of preview branches to clarify that they are
automatically deleted when a PR is merged or closed.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Clarified that preview branches are temporary and automatically
deleted when a pull request is merged or closed.
- Removed outdated guidance stating that preview branches pause after
inactivity.
- Clarified that persistent branches remain available long-term and are
not automatically paused or deleted due to inactivity or pull request
closure.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 22:44:31 +08:00
Katerina Skroumpelouandgithub-actions[bot] fc5db9bb03 docs: update client-side tracing and Edge Function CORS guides (#48924)
Updates the client-side tracing and Edge Function CORS docs for changes
shipping in `@supabase/supabase-js` v2.112.3 (supabase/supabase-js#2603,
supabase/supabase-js#2604). The tracing guide gains a vendor
compatibility table (plain OpenTelemetry works as is, Sentry needs
`propagateTraceparent: true`, Datadog RUM needs `allowedTracingUrls`),
the new `respectSamplingDecision` semantics (non-sampled requests now
carry `traceparent` only, so logs stay correlatable), a troubleshooting
entry for the SDK's new propagator warning, and a note that browser
calls to Edge Functions need the trace headers in the function's CORS
allow-list. The CORS guide now states explicitly that trace headers are
sent only when trace propagation is opted in (never by default), adds a
table of when each SDK header is actually sent, and the hardcoded
`corsHeaders` examples are updated to the full header list. Should merge
after the v2.112.3 release is published, since it documents that
version's behavior.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Expanded CORS guidance with trace-propagation requirements and SDK
version considerations.
* Added browser and Edge Function setup guidance for client-side
tracing.
* Documented updated sampling behavior, advanced configuration, vendor
setup examples, and troubleshooting.

* **Bug Fixes**
* Updated CORS configurations to allow retry and tracing headers
required for supported requests.
* Improved compatibility for browser requests that transmit distributed
tracing context.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-11 16:43:26 +03:00
Joshen Lim 5b301e1ffa Add docs for diagnosing stuck and blocked queries (#48920)
## Context

Related to the dashboard work for [Database
Connections](https://github.com/orgs/supabase/discussions/48639) -
updates the "Connection Management" docs page to include a section about
"Diagnosing stuck and blocked queries". Content is intentionally
agnostic to the UI, but more focused on Postgres.

Preview:
https://docs-cdukolvgy-supabase.vercel.app/docs/guides/database/connection-management

Covers the following sub-topics:
- Reading a session's state
- Finding out what's blocking a query
- How to stop the session responsible
- Small footer to link to the dashboard's Database Connections page

Also adding a cross-reference in 2 areas
- Troubleshooting: How to check if my queries are being blocked by other
queries
- Monitoring and Debugging MDX -> Related to observability skills

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Expanded connection-management guidance with clearer explanations of
session states.
* Added instructions for diagnosing stuck or blocked queries,
identifying blocking sessions and chains, and choosing when to cancel or
terminate them.
* Documented required permissions and available dashboard tools for
managing sessions.
* Added cross-references and telemetry updates to make troubleshooting
guidance easier to discover.
* Clarified how to use PostgreSQL activity information when
investigating blocked queries.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 07:09:43 -06:00
Andrey A. 5a8eecf509 feat(self-hosted): envoy is the default api gateway (#48153) 2026-08-11 11:55:26 +02:00
Andrey A. 9596b5f3ed docs(self-hosted): add a separate architecture diagram (#48763) 2026-08-11 11:48:22 +02:00
Saxon Fletcher cb35e1f98e chore(library): update routes, redirects, and naming (#48668)
Our UI Library registry is expanding to include blocks that go beyond UI
and in some cases focus purely on back-end. This PR is a precursor to
adding more back-end related blocks. This PR includes the `ui-library ->
library` rename plus redirects and small UI copy updates. Since this is
a rename we'll need to update Vercel configuration.

## Vercel rollout

Keep the Library project Root Directory as `apps/ui-library`

1. In the **Library** Vercel project, set:

   `NEXT_PUBLIC_BASE_PATH=/library`

Apply it to Preview and Production, then redeploy the Library project.

2. In the **www** Vercel project, add:

`NEXT_PUBLIC_LIBRARY_URL=<current value of NEXT_PUBLIC_UI_LIBRARY_URL>`

Apply it to Preview and Production. Keep `NEXT_PUBLIC_UI_LIBRARY_URL`
during the migration, then redeploy the www project.

3. Deploy in this order:

   1. Library project
   2. www project

4. Validate:

   - `/library`
   - `/library/docs/nextjs/password-based-auth`
   - `/ui` redirects to `/library`
- `/ui/docs/nextjs/password-based-auth` redirects to
`/library/docs/nextjs/password-based-auth`
- `/ui/docs/ai-editors-rules/*` still uses its existing Docs redirects

No Vercel dashboard redirect rules are needed. Environment-variable
changes require a new deployment.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Supabase UI Library has been renamed to **Supabase Library** across
navigation, pages, documentation, and resource links.
* The Library is now available at `/library`, with updated descriptions
covering components, blocks, and developer tools.
* **Bug Fixes**
* Added permanent redirects from legacy `/ui` URLs to corresponding
`/library` paths.
* Updated links throughout the site and documentation to prevent broken
navigation and references.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-11 13:37:32 +10:00
kemal.earth ae9042ceb4 feat(docs): scoped pat update (#48802)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Updates docs around scoped PAT's. 


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Clarified that temporary database access uses a Personal Access Token
as the Postgres role password.
* Updated API documentation to explain that Personal Access Tokens
support custom expiration rather than being described as long-lived.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-10 08:07:24 +01:00
Gabriel Claudino 18c26bf933 docs(auth): clarify audit logs storage options and configuration (#48852)
## Summary

- Clarify that external log storage is the default
- Explain that Postgres database storage is optional
- Fix grammar and typos
- Improve admonition messaging to be more actionable
- Simplify toggle step wording for clarity

Slack thread with team-auth:
https://supabase.slack.com/archives/C022071RB2L/p1785945149999009

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Clarified that audit logs are stored in external log storage by
default.
  * Documented optional database storage in `auth.audit_log_entries`.
* Added instructions for enabling or disabling database storage with the
“Write audit logs to the database” toggle.
* Noted that enabling database storage incurs additional database
storage costs.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-07 17:58:30 +01:00
Eduardo Gurgel 66a4a0b32d fix(docs): realtime deletes can be surfaced and filtered (#48785) 2026-08-07 10:00:53 +12:00
Cemal KılıçandJeremias Menichelli 1ff84a239c docs(auth): note that resetPasswordForEmail doesn't send email for un… (#48800)
add note on `resetPasswordForEmail` doesn't send email for unregistered
emails

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Clarified that password reset requests do not reveal whether an email
address is associated with an account.
* Documented that requests for unrecognized email addresses complete
without an error.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com>
2026-08-06 15:41:35 +02:00
Guilherme Souza a18ee934cd docs(auth): handle incoming deep link URLs on Swift (#48774)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update.

## What is the current behavior?

The Swift tab in the [Native Mobile Deep Linking
guide](https://supabase.com/docs/guides/auth/native-mobile-deep-linking?platform=swift)
only covers registering a custom URL scheme (Info.plist config). Unlike
the React Native, Flutter, and Kotlin tabs, it never shows the runtime
code that actually consumes the incoming URL and completes the sign-in,
so a Swift developer following the guide is left without a working
implementation.

Linear:
[SDK-83](https://linear.app/supabase/issue/SDK-83/swift-improve-docs-on-how-to-handle-deep-link-url)

## What is the new behavior?

Added a "Handling the incoming URL" section to the Swift tab with:
- SwiftUI: `onOpenURL` calling `supabase.auth.handle(url)`
- UIKit app delegate lifecycle:
`application(_:didFinishLaunchingWithOptions:)` and
`application(_:open:options:)`
- UIKit scene delegate lifecycle: `scene(_:openURLContexts:)`
- A note pointing to `session(from:)` for callers that need the returned
`Session` or custom error handling

`handle(url)` and its usage patterns match the current `supabase-swift`
reference spec (`supabase_swift_v2.yml`) and source.

Also added `UIKit` to the docs spelling allowlist
(`supa-mdx-lint/Rule003Spelling.toml`) since it isn't in the dictionary.

## Additional context

`pnpm lint:mdx` passes on the changed file. `pnpm build:guides-markdown`
fails, but on a pre-existing unrelated issue (missing generated
`database-advisors.json`), not on this change.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added Swift guidance for handling authentication deep links in SwiftUI
and UIKit apps.
* Documented deep-link behavior during cold launches and scene-based URL
delivery.
* Clarified when to use `handle(_:)` and `session(from:)`, including
error-handling considerations.
* Updated the SwiftUI tutorial to pass authentication URLs directly to
the recommended handler.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-06 08:37:47 +00:00
Guilherme Souza d61d3533f2 docs: fix broken Swift example in joins-and-nesting guide (#48775)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs fix.

## What is the current behavior?

Fixes
[SDK-958](https://linear.app/supabase/issue/SDK-958/docs-incomplete-documentation),
reported via the docs feedback widget on
[joins-and-nesting](https://supabase.com/docs/guides/database/joins-and-nesting).

In the "Specifying the `ON` clause for joins with multiple foreign keys"
section, the Swift example was broken relative to the other language
tabs (JS, Dart, Kotlin, Python, C#):

- The query string aliased the second embed as `scans: scan_id_end`,
which isn't valid PostgREST embed syntax (should be
`end_scan:scans!scan_id_end`).
- The `Shift` struct only declared a single `scans: [Scan]` property
with no `CodingKeys` entry for `start_scan` or `end_scan` — so it never
actually decoded either aliased relation, which is why the reporter
couldn't tell where `start_scan` was supposed to come from.

## What is the new behavior?

- Query now aliases both relations consistently:
`start_scan:scans!scan_id_start (...)` and `end_scan:scans!scan_id_end
(...)`, matching the other language examples.
- `Shift` struct now declares `startScan: Scan` and `endScan: Scan`,
mapped via `CodingKeys` to `start_scan` and `end_scan`.

## Additional context

Docs-only change to a code sample inside
`apps/docs/content/guides/database/joins-and-nesting.mdx`. Verified with
`prettier --check` (mdx lint tool failed locally due to an unrelated
missing native module, `node-pty`).

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated the Swift join example to represent separate start and end
scan relationships.
* Revised response field selections and coding keys to match the updated
relationship names.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-05 21:50:31 -03:00
claude[bot]andClaude b97ad08be5 docs: updating Edge Functions error codes (#48767)
<!-- ccr-slack-attribution -->
_Requested by **Kalleby Santos** · [Slack
thread](https://supabase.slack.com/archives/C02KMRX22NR/p1785949561216739?thread_ts=1785949561.216739&cid=C02KMRX22NR)_

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update. Adds two missing entries to the Edge Functions **Error
codes** page (`apps/docs/content/guides/functions/error-codes.mdx`).

Refs https://github.com/supabase/supabase/issues/47739

## What is the current behavior?

Neither `NOT_FOUND_FUNCTION_BLOB` nor `LOAD_FUNCTION_UNBUNDLING_ERROR`
appears on the Error codes page. Someone who gets a 404 with
`sb-error-code: NOT_FOUND_FUNCTION_BLOB` and searches the page finds
nothing — and because the response body is the same `Requested function
was not found` string that generic `NOT_FOUND` returns, the existing
`NOT_FOUND` entry reads like it covers the case when it doesn't.

## What is the new behavior?

Both codes are documented under `## Server Errors` with a cause and a
remedy, in the page's existing `**Cause:**` / `**Solution:**` shape.

- `NOT_FOUND_FUNCTION_BLOB` goes directly after `### NOT_FOUND`, since
readers hitting it will scan for `NOT_FOUND` first. The cause explains
the metadata/bundle version mismatch (concurrent or batched deploys
double-incrementing the metadata version), notes that the message is
identical to `NOT_FOUND` so the `sb-error-code` header is the
distinguisher, and links the existing [Edge Function 404 error
response](https://supabase.com/docs/guides/troubleshooting/edge-function-404-error-response)
troubleshooting guide. Solution: redeploy with the latest CLI, avoid
concurrent deploys of the same function, contact support to re-sync
metadata if it persists.
- `LOAD_FUNCTION_UNBUNDLING_ERROR` goes at the end, keeping the
`LOAD_FUNCTION_*` cluster together. Cause: the bundle was fetched but
decompression/parsing failed, which points at a corrupt or
partially-written bundle. Solution: redeploy, contact support if it
persists.

## Additional context

Both codes are real and currently emitted by
`supabase/edge-functions-ingress` (`main`):

- `NOT_FOUND_FUNCTION_BLOB` — 404, declared at `src/main/errors.ts:29`,
emitted at `src/main/cache.ts:180`
- `LOAD_FUNCTION_UNBUNDLING_ERROR` — 503, declared at
`src/main/errors.ts:27`, emitted at `src/main/cache.ts:226`

Both were introduced by supabase/edge-functions-ingress#464.

### Notes for reviewer

- **Scope.** The comment on #47739 asked only for
`NOT_FOUND_FUNCTION_BLOB`. `LOAD_FUNCTION_UNBUNDLING_ERROR` is included
because it shipped in the same ingress PR and is equally undocumented —
happy to drop it if you'd rather keep this PR to exactly what was
requested.
- **No HTTP statuses in the copy.** The 404/503 above are deliberately
left out of the page text, because the Error codes page states no HTTP
status anywhere for any code. Adding them here would be a format
departure. Easy to add if you'd prefer to start including them.
- **Message mismatch, not fixed here.**
`apps/docs/content/troubleshooting/edge-function-404-error-response.mdx`
declares `message = "Function deployment bundle not found"` for
`NOT_FOUND_FUNCTION_BLOB`, but the runtime actually emits `"Requested
function was not found"` (`cache.ts:181`), which matches the response
pasted in #47739. Left untouched in this PR — flagging it for a
follow-up.

### Checks run

- `prettier --check` on the changed file: passes.
- `supa-mdx-lint` (v0.3.2) on the changed file: no new findings. The one
remaining warning (`error-codes.mdx:11` — "Use 'view and resolve errors'
instead of 'handle errors'") is pre-existing on `master` and untouched
here.
- The `{/* supa-mdx-lint-disable Rule001HeadingCase */}` pragma at line
8 sits above both new H3s, so the uppercase headings pass.

---
_Generated by [Claude
Code](https://claude.ai/code/session_01Qw5D2wdScBN5TWuA2FgnDW)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-08-05 14:05:03 -06:00
Matt Rossman 5049f3eb81 docs: supabase evals note in AI tools page (#48663)
Following announcement
https://supabase.com/blog/introducing-supabase-evals

Adds an admonition to the [AI
Tools](https://supabase.com/docs/guides/ai-tools) overview calling out
the recently launched [Supabase
Evals](https://supabase.com/blog/introducing-supabase-evals) project to
demonstrate performance of (some of) the tools shown.

Preview:
https://docs-git-mattrossman-ai-969-link-to-evals-from-47d719-supabase.vercel.app/docs/guides/ai-tools

<img width="3600" height="1606" alt="CleanShot 2026-08-03 at 15 13
06@2x"
src="https://github.com/user-attachments/assets/8ea23f6c-fde0-4b04-bed1-035941570ac1"
/>

If preferred, we can move it below the fold, I just figure it's good for
visibility on the recent launch and it helps sell the "why" for using
these tools.

Closes AI-969


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

* **Documentation**
* Added a link and note about Supabase Evals, an open-source benchmark
for AI coding agents.
* **Chores**
  * Updated spelling checks to recognize “eval” in any capitalization.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-05 14:47:46 -04:00
08867f94ff docs: lead self-hosting overview with what/why/CTA, restructure secondary content (#48415)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs restructure of the self-hosting overview: short fit intro, Get
started / community listings above the fold, parallel h2 sections for
how self-hosting differs (including local development),
responsibilities, and telemetry, plus a streamlined support listing with
better card content.

Closes DOCS-1251.

## What is the current behavior?

- Linear item: Explore two PR approaches for the self-hosting page
- The self-hosting overview page (`/guides/self-hosting`) is the top
search hit for "supabase self-hosting," but reads as a wall of text:
three full prose/bullet sections (differs / responsibilities /
telemetry) come before the getting-started CTA, which is buried as one
small card partway down the page.

## What is the new behavior?

- Short fit intro; `self-hosting-get-started` and
`self-hosting-community` listings sit directly under the intro.
- Top-level h2s for how self-hosting differs, responsibilities,
telemetry, and support (no "More about self-hosting" wrapper).
- Under differs: rewritten single-project + platform-gap copy, plus `###
Not the same as local development` (CLI stack is not a production
self-host; points to Docker / community options).
- Telemetry clarifies CLI local-dev telemetry vs Docker Compose (no
phone-home).
- Merged support into a single `self-hosting-support` listing;
Enterprise subsection unchanged.
- Minor a11y: `aria-hidden` on GlassPanel decorative icon background.

## Additional context

- Worktree:
`~/GitHub/supabase/supabase-worktrees/nikrichers/docs-1251-self-hosting-inform`
- Review: removed the "More about self-hosting" grouping after feedback
that it undersold differs / responsibilities.
- Companion prototype PR 48416 is closed; this branch is the direction
under review.
- Verification:

| Check | Result |
| ----------------------------------------------- |
------------------------------------------------------------------ |
| `pnpm lint:mdx content/guides/self-hosting.mdx` | Pass — no
errors/warnings on this file |
| Vercel docs preview | Pass — full-page after screenshot captured from
the preview deploy |

### Proof: intro and get-started above the fold; parallel h2s for
differs, responsibilities, and telemetry

**Verified:** `pnpm lint:mdx content/guides/self-hosting.mdx` (pass) ·
Vercel docs preview (pass)

### Before & After

| [Before (production)](https://supabase.com/docs/guides/self-hosting) |
[After (PR
preview)](https://docs-git-nikrichers-docs-1251-self-hosting-inform-supabase.vercel.app/docs/guides/self-hosting)
|
|
------------------------------------------------------------------------------------------------------------------------------------------------
|
----------------------------------------------------------------------------------------------------------------------------------------------
|
|
![Before](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48415/self-hosting-before-23d8ce92.png)
|
![After](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48415/self-hosting-after-96d27909.png)
|

### Test plan

- [ ] Visit the preview link and confirm the page opens with intro above
the Get started listings
- [ ] Confirm parallel h2s for differs / responsibilities / telemetry /
support (no "More about self-hosting")
- [ ] Confirm "Not the same as local development" distinguishes the CLI
stack from self-hosting
- [ ] Confirm Support and community is one card grid
- [ ] Check mobile width — layout should still be usable
- [ ] Confirm `/guides/self-hosting/docker` link still works

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

- **Documentation**
- Reorganized the self-hosting guide with clearer getting-started
resources and community links.
- Added dedicated guidance for local development, managed Supabase,
telemetry, and self-hosting responsibilities.
- Consolidated support resources into one section covering discussions,
issues, chat, Reddit, and sharing experiences.
- **Accessibility**
- Marked decorative icon backgrounds as hidden from assistive
technologies.
  <!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Nik Richers <nik@validmind.ai>
Co-authored-by: Claude <noreply@anthropic.com>
2026-08-05 10:57:09 -07:00
Aaron ByrneandClaude 47b8660d8d docs(troubleshooting): troubleshooting guide so users can amend their failed migrations (#48257)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Troubleshooting guide

## What is the current behavior?

NA
## What is the new behavior?

Troubleshooting guide
## Additional context

Add any other context or screenshots.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added a new troubleshooting page: “Troubleshooting MIGRATIONS_FAILED:
missing tables or an incomplete schema on your branch” for Preview
Branch creation.
* Explained why replayed `main` migration history can fail when it no
longer matches the branch’s live schema.
* Included a step-by-step workflow to diagnose the failing migration via
logs, repair migration status, and then recreate or rebase the branch to
verify.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-08-05 18:12:20 +01:00
Abhishek Tripathi d101d6f3de docs: document NOT_FOUND_FUNCTION_BLOB Edge Function error (#48411)
This PR addresses the documentation portion of #47739.

## What the issue means

`NOT_FOUND_FUNCTION_BLOB` means the runtime cannot find the deployed
bundle for an Edge Function. This differs from the existing `NOT_FOUND`
error, which normally indicates that the function name in the request
URL is not recognized.

The dashboard status alone may not reveal this failure because the
function can still appear as `ACTIVE`.

## Changes

- Documented `NOT_FOUND_FUNCTION_BLOB` as an HTTP 404 error.
- Explained how it differs from `NOT_FOUND`.
- Added the command for redeploying one affected function.
- Added the command for redeploying all functions when several are
affected.
- Added guidance to retry the request and contact Support if
redeployment does not resolve the problem.

## Files changed

-
`apps/docs/content/troubleshooting/edge-function-404-error-response.mdx`

## Validation

- The change uses the troubleshooting page's existing TOML frontmatter
and MDX conventions.
- `git diff --check` passes.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Expanded troubleshooting guidance for Edge Function 404 responses.
* Added coverage of the `NOT_FOUND_FUNCTION_BLOB` error, including
example responses and clarification of how it differs from `NOT_FOUND`.
* Updated redeployment instructions with options for deploying a single
function or all functions.
  * Refined retry and support guidance.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-05 17:11:00 +01:00
1f0fb64ce9 docs: CLI 'Transport error' caused by antivirus/proxy TLS interception (#48719)
## Summary
- Adds a troubleshooting entry for the Supabase CLI's generic
`HttpClientError: Transport error` when a Management API call (e.g.
`projects list`, `link`) fails.
- Root cause documented: antivirus software or corporate SSL-inspecting
proxies (e.g. Norton Safe Web/Web & Mail Shield, Zscaler, Netskope)
substituting their own TLS certificate, which the CLI's HTTP client
rejects and reports as a generic transport error rather than a
certificate error.
- Includes a vendor-agnostic diagnostic method (compare `curl`/browser
vs. CLI behavior, check the served certificate's Issuer field) plus the
specific Norton fix confirmed via a support ticket (disabling Smart
Firewall alone does not stop the interception; Safe Web/Web & Mail
Shield does).

## Test plan
- [ ] `pnpm --filter docs lint:mdx` passes in CI
- [ ] Frontmatter renders correctly on the troubleshooting page

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added troubleshooting guidance for Supabase CLI transport errors
caused by antivirus software or corporate TLS inspection.
* Included diagnostic steps, common error messages, and resolution
guidance for Norton 360 and SSL-inspecting proxies.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Rodrigo Mansueli <rodrigo@mansueli.com>
Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-08-05 09:09:13 -04:00
Andrey A. af384e136f chore(self-hosted): update tags in docker guide (#48739) 2026-08-05 14:19:11 +02:00
claude[bot]andClaude 89a5d03817 docs: add eu-central-2 to Edge Functions regional invocation page (#48721)
<!-- ccr-slack-attribution -->
_Requested by **Kalleby Santos** · [Slack
thread](https://supabase.slack.com/archives/C02KMRX22NR/p1785871243937099?thread_ts=1785871243.937099&cid=C02KMRX22NR)_

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update — one-line content fix.

## What is the current behavior?

The [Regional
Invocations](https://supabase.com/docs/guides/functions/regional-invocation)
page's "Available regions" section lists every Edge Functions region
**except `eu-central-2`** (AWS Europe, Zurich). The region has been live
in production for a while, but it was never added to the docs. A user
reading this page to pick a region for `x-region` / `FunctionRegion` had
no way to know Zurich was an option — the page reads as an exhaustive
list, so the omission actively implies the region doesn't exist.

Reported by Kalleby Santos (Edge Functions team).

Linear: [FUNC-761 — Add eu-central-2 to regional invocation docs
page](https://linear.app/supabase/issue/FUNC-761/add-eu-central-2-to-regional-invocation-docs-page)

## What is the new behavior?

**Before:** the Europe group listed `eu-central-1`, `eu-west-1`,
`eu-west-2`, `eu-west-3`.

**After:** `eu-central-2` (Zurich) is listed alongside the others, so
the page reflects the regions Edge Functions actually serves.

### How

One line added to
`apps/docs/content/guides/functions/regional-invocation.mdx`, in the
**Europe** group directly after `eu-central-1`, following the list's
existing sort-by-region-code order and the surrounding `` `code` (Short
location) `` label style:

```diff
 **Europe:**

 - `eu-central-1` (Frankfurt)
+- `eu-central-2` (Zurich)
 - `eu-west-1` (Ireland)
 - `eu-west-2` (London)
 - `eu-west-3` (Paris)
```

No other files changed. This page's region list is hand-maintained in
the MDX and is deliberately narrower than the project-creation region
list in `packages/shared-data/regions.ts` (which also includes
`us-east-2` and `eu-north-1`), so no shared constant needed updating and
no other product's region list was touched.

## Additional context

**Verification that `eu-central-2` is a real Edge Functions invocation
region** — confirmed in three independent places:

1. `supabase/platform` → `pulumi/edge-runtime/Pulumi.prod.yaml:533` —
`region: eu-central-2`, with `enabled: true` at `:531`. A fully
provisioned prod region (360–540 always-on tasks), not a placeholder.
Branch `develop`, HEAD `1f44167768f951c0c794313006bc2c9f9758c344`.
2. `supabase/platform` →
`pulumi/edge-runtime-next/stack-config/Pulumi.prod.aws.euc2.yaml:6` —
`aws:region: eu-central-2` under the `Edge-Functions/K8s-Prod`
environment, tagged `product: functions`.
3. `supabase/api-gateway` → `customer-router/wrangler.toml` —
`eu-central-2` is present in the `EDGE_FUNCTIONS_REGIONAL_ORIGINS` map
(`eu-central-2 = "https://eu-central-2.edge-runtime.supabase.green"`).
This is the table that resolves the `x-region` header, so regional
invocation into Zurich is genuinely routable — not just deployed.

**For a reviewer to confirm separately (intentionally not in this
diff):** production infra has 16 enabled Edge Functions regions, so
`us-east-2` (Ohio, `pulumi/edge-runtime/Pulumi.prod.yaml:507`, `enabled:
true`) is *also* missing from this page. It's excluded here because we
don't yet know whether that omission is deliberate; it's being confirmed
with the team and can be a follow-up.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_017UJhSvVpPfYNaHZ8Y1x3sy

---
_Generated by [Claude
Code](https://claude.ai/code/session_017UJhSvVpPfYNaHZ8Y1x3sy)_

Co-authored-by: Claude <noreply@anthropic.com>
2026-08-04 22:09:37 +01:00
Filipe CabaçoandAli Waseem 4a9b5a538b chore: update pg changes to add python to the code blocks (#47793)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES
## What kind of change does this PR introduce?

Adds code blocks for Python and new pg changes features

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated Python code examples for Realtime Postgres Changes to use
cleaner, working subscription syntax.
* Fixed a missing comma in a multi-change example so the sample code is
valid.
  * Added a missing Python example for selecting specific columns.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Ali Waseem <waseema393@gmail.com>
2026-08-04 10:26:26 -06:00
Miranda LimonczenkoandClaude Sonnet 5 e7d9c88cbc fix(docs): resolve remaining heading-order issues found in Pass 2 diagnostic (#48664)
## Problem

After merging [#48456](https://github.com/supabase/supabase/pull/48456)
(shared components) and
[#48459](https://github.com/supabase/supabase/pull/48459) (per-page
content fixes), a follow-up diagnostic pass found 22 remaining
heading-order violations, logged as Pass 2 in the [triage
report](https://app.notion.com/p/supabase/Playwright-E2E-Triage-Reports-3ab5004b775f81e3bc60d058fa5a02c1).
None of them were caught by the earlier fixes because they came from
places that scan didn't check: shared partials, raw HTML heading tags
written directly in MDX, and a couple of shared/interactive components
rendering hardcoded heading levels.

## Solution

- `_partials/social_provider_setup.mdx`: `#### Local development` →
`###`, matching the `##` that always precedes it on all 14 social-login
pages.
- `guides/database/functions.mdx` and
`guides/integrations/vercel-marketplace.mdx`: replaced raw `<h4>`/`<h5>`
tags with correctly-nested real headings (`### Planets`/`### People`;
`#### Deploy a Next.js app...`) — no styling workarounds needed since
they nest naturally one level below their parent section.
- `auth/quickstarts/{nextjs,react-native,react,astrojs}.mdx`: these 4
pages had no heading at all before the embedded
`_partials/api_settings.mdx` partial's own `### Get API details`
heading, so added a `## Quickstart` heading above the walkthrough to
give it a valid parent.
- `packages/ui`'s `Accordion` component: Radix's
`AccordionPrimitive.Header` renders as an unconditional `<h3>`
regardless of where the accordion is used. That's shared across Studio,
www, and design-system, not just docs, and surfaced on docs'
vendor-agnostic telemetry page. Now rendered via `asChild` onto a plain
`div` instead, since a generic accordion has no way to know what heading
level (if any) is valid in a given page.
- SQL-to-REST translator tool (`/docs/guides/api/sql-to-rest`): its
`Assumptions`/`FAQs` section labels were hardcoded `<h3>` with no `h2`
anywhere on the page. Converted to styled spans rather than promoting to
a real `<h2>`, because real h1/h2/h3 tags in this codebase force a prose
font-size that utility classes can't override — promoting the tag would
have visibly changed its size.
- `RealtimeLimitsEstimator` (embedded on both `postgres-changes` and
`benchmarks`): its 3 section headings were hardcoded `<h4>`, but the two
embedding pages need different levels (h3 vs h4) for that spot to be
valid — no single correct heading level. Converted to styled spans, same
pattern used throughout this project for components embedded at varying
heading depths.

## Manual testing

1. Check out this branch and run `pnpm dev:docs`.
2. Visit `/docs/guides/auth/social-login/auth-github` (or any other
provider page) and confirm the "Local development" callout under "Find
your callback URL" still looks and reads the same.
3. Visit `/docs/guides/database/functions` → "Returning data sets" tab
and confirm the "Planets" / "People" table captions still look the same.
4. Visit `/docs/guides/integrations/vercel-marketplace` → "Quickstart" →
"Via template" and confirm the CTA card title still looks the same.
5. Visit `/docs/guides/auth/quickstarts/nextjs` (or
react-native/react/astrojs) and confirm a "Quickstart" heading now
appears above the walkthrough, and "Get API details" still renders
correctly further down.
6. Run `pnpm dev:design-system` and open
`/design-system/docs/components/accordion` — expand/collapse an item and
confirm it still animates and looks identical; inspect the DOM and
confirm the trigger's wrapper is a `div`, not an `h3`.
7. Visit `/docs/guides/api/sql-to-rest`, translate any query, and
confirm the "Assumptions"/"FAQs" section labels still look the same.
8. Visit `/docs/guides/realtime/postgres-changes` and
`/docs/guides/realtime/benchmarks`, scroll to the connection-limits
calculator, and confirm its section labels still look the same on both
pages.
9. (Optional, for a full re-check) Run `pnpm e2e:docs:a11y --all`
against a deployed preview of this branch — only `/docs/guides/cli`
(pre-existing 404, unrelated to headings) should fail; every other page
should pass.

Verified with a full Playwright run against a real preview deployment:
**756 passed, 1 failed** (`/docs/guides/cli`, the pre-existing unrelated
404). Zero heading-order violations remain.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
- Added clearly labeled Quickstart sections to Astro, Next.js, React
Native, and React authentication guides.
- Improved heading hierarchy and formatting across social provider
setup, database functions, and deployment documentation.
- Updated estimator and SQL-to-REST section presentation for more
consistent content structure.

- **Bug Fixes**
- Improved accordion trigger layout while preserving existing behavior,
styling, accessibility, and icon display.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-04 09:00:29 -07:00
Andrey A. de5d3cd115 docs(self-hosted): update manual setup instructions (#48692) 2026-08-04 07:02:30 -06:00
Guilherme SouzaandClaude Sonnet 4.6 31d1a639c0 docs: Update SDK references from recent releases (#47830)
## Summary

Updates SDK reference docs and the client-side tracing guide based on
recent releases across all six Supabase SDKs.

## SDKs analyzed

| SDK | Repo | Latest commit | Latest tag |
|-----|------|--------------|------------|
| js | supabase/supabase-js | `e4e8864` | v3.0.0-next.29 |
| dart | supabase/supabase-flutter | `c3e3602` |
yet_another_json_isolate-v2.1.1 |
| py | supabase/supabase-py | `6570638` | v3.0.0a1 |
| swift | supabase/supabase-swift | `ebef170` | v2.51.0 |
| kt | supabase-community/supabase-kt | `e23df20` | 3.7.0-beta-1 |
| csharp | supabase-community/supabase-csharp | `3fad62f` | v1.1.2 |

## Documentation changes

### `apps/docs/spec/supabase_dart_v2.yml`

- **OAuth Server API**
([supabase-flutter#1561](https://github.com/supabase/supabase-flutter/pull/1561)):
Added `oauth-server-api` group stub and `listGrants()` / `revokeGrant()`
method entries, matching the existing `common-client-libs-sections.json`
nav IDs.
- **`listBuckets()` options**
([supabase-flutter#1557](https://github.com/supabase/supabase-flutter/pull/1557)):
Added example showing `ListBucketsOptions` with `search`, `limit`,
`offset`, `sortColumn`, and `sortOrder`.

### `apps/docs/spec/supabase_py_v2.yml`

- **`on_postgres_changes` `select` param**
([supabase-py#1524](https://github.com/supabase/supabase-py/pull/1524)):
Added `listening-to-selected-columns` example for the new `select=["id",
"name"]` parameter.
- **Expanded filter operators**
([supabase-py#1524](https://github.com/supabase/supabase-py/pull/1524)):
Updated `listening-to-row-level-changes` note to list all supported
operators (`eq`, `neq`, `lt`, `lte`, `gt`, `gte`, `in`, `like`, `ilike`,
`is`, `match`, `imatch`, `isdistinct`) plus `not.` prefix and comma-AND.

### `apps/docs/spec/supabase_swift_v2.yml`

- **OpenTelemetry tracing setup**
([supabase-swift#1101](https://github.com/supabase/supabase-swift/pull/1101)):
Added `initialize-client-with-opentelemetry` example under the
`initializing` section documenting the `OpenTelemetry` SwiftPM package
trait, provider wiring, and known `_invokeWithStreamedResponse`
limitation.

### `apps/docs/content/guides/telemetry/client-side-tracing.mdx`

- **Merged Swift and Dart tracing docs** into the existing JS guide
([supabase-swift#1101](https://github.com/supabase/supabase-swift/pull/1101),
[supabase-flutter#1564](https://github.com/supabase/supabase-flutter/pull/1564)).
- **Converted to tabbed layout** (`<Tabs queryGroup="language">`) with
JavaScript / Swift / Dart tabs, matching the pattern used across other
multi-SDK guides.
- Updated title to "Client-side tracing" and nav label accordingly.

## SDKs with no doc-worthy changes

- **js**: Bug fixes only (auth session clearing, realtime heartbeat
suppression) — no new API surface.
- **kt**: PKCE for `resend()` — behavioral enhancement, no new spec
entry needed.
- **csharp**: Chore/compliance/maintenance only.

---

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added Dart “OAuth Server” API docs for listing OAuth grants and
revoking grants (including signed-in context and the `clientId`
parameter), with examples.
* Extended Dart Storage docs with a new `listBuckets` example using
`ListBucketsOptions` for filtering, pagination, and sorting.
* Updated Python Realtime docs with generalized PostgREST-style row
filter operators and added examples for listening to selected columns.
* Reworked the “Client-side tracing” guide across JS, Swift, and Dart,
including expanded configuration and troubleshooting (trace propagation
and `traceparent` details).
  * Renamed the telemetry navigation label to “Client-side tracing.”
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-08-04 09:58:13 -03:00
Stephen Morgan b17a33fb26 fix: cleanup privatelink documentation (#48466)
Some light copy cleanup for privatelink documentation based on feedback.

Fixes PRODSEC-232

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated PrivateLink guidance with revised architecture, supported
ports, routing, and security group instructions.
* Added labeled connectivity tests for direct PostgreSQL and PgBouncer
connections.
  * Added connection-string examples for both connection methods.
* Replaced public-connectivity instructions with optional network
restriction steps and reorganized limitations guidance.
* Refined PrivateLink availability wording across platform security
documentation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-04 07:23:35 +12:00
Ishleen KaurandMiranda Limonczenko 3c903b7dfa Add Elastic Tile to Supabase Metrics API page (#48564)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature

## What is the current behavior?

Elastic is not added as a tile in metrics API page. 

## What is the new behavior?

Now Elastic is supporting Supabase metrcis ingestion, hence it should be
listed in the Metrics page.

![Uploading Screenshot 2026-08-03 at 4.31.46 PM.png…]()

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added Elastic as a supported metrics integration in the documentation.
- Added an Elastic integration card with community labeling and a link
to Elastic’s documentation.
- Added Elastic to the monitoring metrics navigation and Metrics API
guide resources.
- Added Elastic branding and iconography to the metrics integration
listings for easier recognition.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io>
2026-08-03 18:34:10 +00:00
Laurence Isla 56946d8171 docs: add workaround to avoid noisy logs when PostgREST is disabled (#48021) 2026-08-03 12:21:02 -05:00
Steven Eubank d8491cc0cc Remove unvalidated pricing, improve direction to help users (#48534)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

 docs fix/update

## What is the current behavior?

Shows pricing information that is not accurate/approved yet

## What is the new behavior?

helpful docs, which indicate pricing may be relevant and the future and
already directs users to help management tools

## Additional context

NA

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated Logs pricing and quota guidance to clarify that details may
change before billing enforcement begins.
* Replaced preliminary pricing tables and billing examples with notices
that finalized information will be published later.
* Expanded usage optimization guidance for log ingestion and querying,
including filtering, time ranges, polling, and database logging
recommendations.
* Directed readers to per-SKU pages for the latest pricing, quotas,
billing, and optimization information.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-03 17:02:24 +02:00
Andrey A. 80866c6f22 docs(self-hosted): add updating how-to (#48535) 2026-08-03 17:02:14 +02:00
Nik RichersandNik Richers c8954e6054 docs(security): add GDPR, ISO 27001, and DDoS coverage to security guide (#48449)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

This is a docs-only content update to the `/docs/guides/security`
landing page and its neighboring guides. It adds a dedicated GDPR
compliance guide, and surfaces ISO 27001 and DDoS protection coverage
that Supabase already provides but wasn't listed anywhere in the docs
security guide.

Closes DOCS-354.

## What is the current behavior?

- In `/docs/guides/security`, there is no mention of GDPR, ISO 27001 or
DPA request potential, despite Supabase docs covering these partially in
one place or another.
- Confirmed by auditing `apps/docs/content/`: zero mentions of GDPR/data
residency, zero DPA content or link to `/legal/dpa`, zero ISO 27001
mentions, and only incidental/wrong-audience mentions of DDoS protection
(a pen-testing exclusion, a Storage CDN aside, a fail2ban
troubleshooting article for banned users).
- `regions.mdx` only frames region choice as a performance decision,
with no data-residency/compliance angle.
- This is a parallel docs-side counterpart to #48403 (marketing
`/security` page content additions), which is adding the same GDPR/Data
Residency/DPA/DDoS topics on `apps/www`. This PR does not modify
`apps/www` — see that PR for the marketing-page changes.

## What is the new behavior?

- New guide: `apps/docs/content/guides/security/gdpr-compliance.mdx`
covering data residency (including the nuance that the "Europe" general
region grouping includes non-EU jurisdictions UK and Switzerland) and
the Data Processing Agreement (DPA), linked to `/legal/dpa`.
- Added to the sidebar nav under Security → Compliance, alongside SOC 2
and HIPAA.
- `apps/docs/content/guides/security.mdx`: added an ISO 27001 paragraph
(dashboard certificate link, matching the existing SOC 2/HIPAA pattern)
and a GDPR pointer paragraph to `## Compliance`; added a DDoS protection
paragraph (Cloudflare CDN + fail2ban) to `## Platform configuration`.
- `apps/docs/content/guides/platform/regions.mdx`: added a "Data
residency" section clarifying that general region groupings may span
non-matching jurisdictions, and specific regions should be used when
strict jurisdictional residency is required.

## Additional context

- Worktree:
`~/GitHub/supabase/supabase-worktrees/nikrichers/docs-354-security-landing-page`
- Note: Supabase's subprocessor list was considered for the GDPR guide
but omitted — both candidate links
(`/legal/customer-resources/subprocessor-list` and
`/legal/privacy#subprocessors`) are not yet publishable/live. Follow up
once Legal publishes that page.

**Verification:**

| Check | Result |
| ------------------------------------ |
-----------------------------------------------------------------------------------------------------
|
| `pnpm lint:mdx` on changed/new files | Pass (0 errors, 0 warnings on
touched files) |
| `pnpm build:guides-markdown` | Fails on `master` too (unrelated
missing `ai-skills.json` generated file) — not caused by this change |
| Local render (`pnpm dev:docs`) | All three pages return 200; new copy,
nav entry, and all links/anchors verified to resolve |

### Proof:

Reviewers should believe: the security landing page and regions guide
now list GDPR/ISO 27001/DDoS coverage that was previously missing, and
the new GDPR guide renders correctly with working links, where before it
404'd.

### Before & After

**`/docs/guides/security`** — ISO 27001, GDPR, and DDoS paragraphs now
present:

| [Before (production)](https://supabase.com/docs/guides/security) |
[After (PR
preview)](https://docs-git-nikrichers-docs-354-security-landing-page-supabase.vercel.app/docs/guides/security)
|
|
-----------------------------------------------------------------------------------------------------------------------------------------------------
|
---------------------------------------------------------------------------------------------------------------------------------------------------
|
|
![security-before](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48449/security-before-5fd638c1.png)
|
![security-after](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48449/security-after-2f89b1b0.png)
|

**`/docs/guides/platform/regions`** — new "Data residency" section:

| [Before
(production)](https://supabase.com/docs/guides/platform/regions) |
[After (PR
preview)](https://docs-git-nikrichers-docs-354-security-landing-page-supabase.vercel.app/docs/guides/platform/regions)
|
|
---------------------------------------------------------------------------------------------------------------------------------------------------
|
-------------------------------------------------------------------------------------------------------------------------------------------------
|
|
![regions-before](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48449/regions-before-e824c680.png)
|
![regions-after](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48449/regions-after-c119e50d.png)
|

**`/docs/guides/security/gdpr-compliance`** — net-new page, no
production URL exists yet (404 before this PR):

| Before (production) | [After (PR
preview)](https://docs-git-nikrichers-docs-354-security-landing-page-supabase.vercel.app/docs/guides/security/gdpr-compliance)
|
| ------------------- |
-------------------------------------------------------------------------------------------------------------------------------------------
|
| |
![gdpr-after](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48449/gdpr-after-e42cf263.png)
|

### Test plan

```text
- [ ] Visit /docs/guides/security — confirm ISO 27001, GDPR, and DDoS paragraphs render under the right headings
- [ ] Visit /docs/guides/security/gdpr-compliance — confirm it renders and appears in the sidebar under Compliance (next to SOC 2, HIPAA)
- [ ] Visit /docs/guides/platform/regions — confirm the new "Data residency" section renders before "General regions"
- [ ] Confirm links resolve: /docs/guides/security/gdpr-compliance, /docs/guides/platform/regions#specific-regions, /legal/dpa, /dashboard/org/_/documents
```

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Documentation
- Added a GDPR Compliance entry to the Compliance navigation.
- Updated security documentation with ISO 27001 certification details,
clearer GDPR guidance, and expanded protection information.
- Clarified regional data residency guidance, including primary project
data and GDPR considerations.
- Made minor wording and formatting improvements to the GDPR compliance
guide.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Nik Richers <nik@validmind.ai>
2026-08-03 07:38:27 -07:00
Guillaume Faas 94bc3f8d07 docs(csharp): add C# snippets (#48537)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added C# examples across API, authentication, database, Realtime, and
Storage guides.
* Expanded authentication coverage for passwordless, phone, anonymous,
identity linking, SSO, sign-out, and social login providers.
* Added database examples for queries, functions, joins, JSON, arrays,
search, PostGIS, and custom schemas.
* Added Realtime examples for broadcasts, presence, subscriptions, and
database changes.
* Added Storage examples for buckets, uploads, downloads,
transformations, CDN purging, and resumable transfers.
  * Included C# error-handling guidance and relevant reference links.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-03 13:13:55 +02:00
Illia Basalaiev 5c5d7bcc63 docs: fix quickstart catalog gaps (#48618)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update. 
Getting Started page is the most visited page in the docs at the moment:
https://supabase.com/docs/guides/getting-started.
Looking at all 19 guides, they appear to have drifted apart because
there was never a written standard for what a quickstart must contain.
Additionally, we are missing some frameworks, languages, and ORMs
quickstarts.

Phase 1 (this PR) fixes broken numbering, duplicated steps, and dead-end
pages. Later phases bring all 19 guides into line with a single
"definition of done" contract (error handling in samples, env vars
everywhere, consistent Connect-panel pattern). The end goal is that
every quickstart, regardless of framework, gives the same complete,
trustworthy path from zero to a working app.

## What is the new behavior?

1. SvelteKit and Hono cards added to the [homepage
grid](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs)
(FrameworkQuickstarts.tsx). Only added the most popular missing
frameworks to the grid.
2.
[Rails](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs/guides/getting-started/quickstarts/ruby-on-rails#2-install-agent-skills-optional):
Add missing second step (Agent Skills), add next steps at the end (point
6)
3.
[Laravel](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs/guides/getting-started/quickstarts/laravel#6-set-up-the-postgres-connection-details):
Remove duplicated instruction to create project from step 6.
4.
[Refine](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs/guides/getting-started/quickstarts/refine#5-update-supabaseclient-with-environment-variables):
In step 5, create .env file (VITE_SUPABASE_URL,
VITE_SUPABASE_PUBLISHABLE_KEY), and the client reads them via
import.meta.env, matching the Vite-based refine-supabase preset.
5.
[Hono](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs/guides/getting-started/quickstarts/hono#6-set-up-the-required-environment-variables)
TODO resolved: In step 6, add the "Open Connect panel" Button with the
generic api_settings.mdx partial call, identical to the Flask and Expo
pattern.
6. Next steps added to the 9 guides missing it at the end of the guide,
linking to the framework tutorial or Auth, UI components, data import,
and Storage (Flutter, Kotlin, Laravel, Nuxt, RedwoodJS, Refine, Ruby on
Rails, SolidJS, and Vue).
7. Remove 4 stale screenshots from RedwoodJS and Refine, along with
their now-orphaned image assets under apps/docs/public/img/. The
surrounding text already covers what they showed; they weren't
Connect-panel screens, so the Button pattern didn't apply as a
replacement.
8. Add [Supabase Agent
Skills](https://docs-git-docs-fix-quickstart-catalog-gaps-supabase.vercel.app/docs/guides/getting-started/quickstarts/nextjs#4-install-agent-skills-optional)
purpose and benefits for the user
9. Start all guides from creating Supabase project 

## Additional context

Add any other context or screenshots.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Documentation

- Added SvelteKit and Hono quickstarts with icons and documentation
links.
- Expanded Agent Skills guidance across framework quickstarts, including
current authentication, SSR, and migration patterns.
- Improved project creation, Connect panel, API configuration, and
credential setup instructions.
- Added framework-specific “Next steps” resources for Auth, database
imports, Storage, UI components, and libraries.
- Clarified PostgreSQL SSL, password encoding, connection, and
environment-variable requirements.
- Replaced outdated screenshots with clearer setup guidance and relevant
examples.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-03 13:08:10 +02:00
Katerina Skroumpelouandgithub-actions[bot] 99e66029c8 docs: document the supabase-js /tracing opt-in subpath (#48529)
## What kind of change does this PR introduce?

Documentation update for
`apps/docs/content/guides/monitoring-and-debugging/client-side-tracing.mdx`.

As of `@supabase/supabase-js` 2.112.0 (supabase/supabase-js#2583), the
OpenTelemetry integration moved out of the main bundle into an opt-in
subpath. Enabling trace propagation now takes two steps: `import
'@supabase/supabase-js/tracing'` at the application entry point, plus
the existing `tracePropagation: true` client option.

Guide changes:

- Requirements: documents the subpath import (2.112.0+), the
loud-resolution behavior when `@opentelemetry/api` is missing, the
one-time warning when the runtime isn't loaded, the version note for
2.106.0–2.111.x (no import there), and that the CDN/UMD build does not
support tracing.
- Both code samples now start with the subpath import.
- Troubleshooting: new first check (runtime not loaded → one-time
console warning), updated `@opentelemetry/api` semantics per version,
new CDN/UMD entry.

The JS reference (`typeSpec.json`) is regenerated automatically by the
docs-update pipeline from the supabase-js spec and is not touched here.

**Timing note:** merge once 2.112.0 is promoted to `latest` (currently
on `beta`/`canary`) so the guide doesn't get ahead of the stable
release.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated client-side tracing guidance for `@supabase/supabase-js`
2.112.0 and later.
  * Added setup examples for the required one-time opt-in import.
* Clarified behavior when tracing dependencies are missing and
documented CDN usage limitations.
* Expanded troubleshooting guidance for runtime loading, module
resolution, and UMD usage.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-03 10:39:14 +03:00
Danny White c0f1ef51fb feat(docs): migrate resources and getting-started to ContentListings (#48517)
## What kind of change does this PR introduce?

Docs update / follow-up to #48379.

## What is the current behavior?

`/guides/resources` and `/guides/getting-started` hand-roll `GlassPanel`
grids in MDX. They look like ContentListings cards after the chrome PR,
but they do not use the shared data files, so they miss PostHog
`docs_content_listing_clicked` telemetry and the CONTRIBUTING
contribution path.

## What is the new behavior?

Those pages use `<ContentListings id="…" />` backed by
`resources.data.ts` and `getting-started.data.ts`, same pattern as
storage.

- Section-level `$Show` wrappers stay for framework / web / mobile
blocks
- Nimbus stays a `$Partial` behind `$Show`
- New optional per-item `feature` field gates SDK links (e.g. Flutter /
Swift / Kotlin) without splitting whole sections
- CONTRIBUTING notes when to use `feature` vs a partial-level `$Show`

## To test

Compare the following against `master`:

-
[Resources](https://docs-git-dnywh-docs-content-listings-resources-239158-supabase.vercel.app/docs/guides/resources):
overview, migrate, and postgres grids; icons in light/dark
- [Getting
started](https://docs-git-dnywh-docs-content-listings-resources-239158-supabase.vercel.app/docs/guides/getting-started):
overview, use cases, framework quickstarts, web demos, mobile tutorials;
nimbus partial when enabled
- Click a card and confirm `docs_content_listing_clicked` fires with the
expected `listingId`

Everything should look and feel the same. It’s just that we’re using
`ContentListings` instead of `GlassPanel` grids.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added centralized Getting Started and Resources content listings,
including quickstarts, demos, tutorials, migration guides, and Postgres
resources.
- Added feature-based visibility controls for individual content listing
items.

- **Improvements**
- Disabled content is now automatically hidden from documentation pages
and generated Markdown.
  - Pages and sections with no available content are omitted entirely.
  - External documentation links are more secure.
- Updated contribution guidance with instructions and examples for
feature flags.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-03 00:52:44 +00:00
3a3661019f docs: update architecture diagram and references from Kong to Envoy (#48557)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

This is a docs update. The shared architecture diagram and several docs
pages still described Kong as Supabase's API gateway, even though the
hosted platform has run Envoy since 2025. Both diagram variants are
rebuilt with real, accessible text — the originals rendered every label
as an outlined vector path with zero `<text>` elements — so the gateway
name can be kept current going forward, and the platform-facing prose
that named Kong directly is updated to Envoy.

Closes DOCS-1262.

## What is the current behavior?

- The architecture diagram (used on the Architecture overview, Auth
architecture, Self-hosting Docker, and Contributing guide pages) shows
"KONG / docs.konghq.com" as the gateway box
- The Architecture overview page has a "Kong (API gateway)" component
section
- The Auth architecture page states "Kong API gateway. This is shared
between all Supabase products."
- `README.md` and `apps/docs/public/humans.txt` credit Kong instead of
Envoy

## What is the new behavior?

- Rebuilt `supabase-architecture.svg` and
`supabase-architecture--light.svg` with real `<text>` elements; the
gateway box now reads "ENVOY / envoyproxy.io" with identical layout,
colors, and shadows otherwise
- Updated the diagram alt text and the "Kong (API gateway)" section (now
"Envoy (API gateway)", with the correct docs link, license, and
language) on the Architecture overview page
- Updated the "Kong API gateway" bullet and diagram alt text on the Auth
architecture page
- Updated the Kong credit to Envoy in `README.md` and
`apps/docs/public/humans.txt`

**Intentionally excluded:**

- Self-hosted Docker Compose pages (`docker.mdx`, `enable-mcp.mdx`,
`self-hosted-auth-keys.mdx`, `self-hosted-envoy.mdx`,
`self-hosted-functions.mdx`, `self-hosted-proxy-https.mdx`) — these
describe the self-hosted stack, which still defaults to Kong today and
is already owned by an open PR (#48153) that flips that default
- `i18n/README.*.md` (29 files) — translation risk without
native-speaker review; only the English `README.md` was updated

## Open questions

- [ ] #48153 merges and the self-hosted default actually flips to Envoy
— once it does, revisit the self-hosting Docker Compose pages excluded
from this PR and the self-hosting-analytics reference TODO
- [ ] Confirm whether all legacy platform instances have fully migrated
to Envoy — until then, this PR's wording says "Envoy" without claiming
Kong is gone everywhere (some legacy instances may still silently be on
Kong)
- [ ] Current Envoy response header names confirmed for the logs guide
TODO (`x-kong-proxy-latency` / `x-kong-upstream-latency`)
- [ ] i18n README translations (29 files) follow up separately with
native-speaker review

## Additional context

- Verification: rendered both new SVGs with `rsvg-convert` and visually
diffed against the originals — layout, spacing, colors, and shadows are
pixel-equivalent; only the top-box label text changed

| Check | Result |
| --- | --- |
| `rsvg-convert` render, dark variant | pass — diagram unchanged except
gateway label |
| `rsvg-convert` render, light variant | pass — diagram unchanged except
gateway label |
| Preview URL, Architecture overview | pass — 200 |
| Preview URL, Auth architecture | pass — 200 |

### Before & After

#### [Architecture
overview](https://supabase.com/docs/guides/getting-started/architecture)

| [Before
(production)](https://supabase.com/docs/guides/getting-started/architecture)
| [After (PR
preview)](https://docs-git-nikrichers-docs-1262-architecture-docs-84e339-supabase.vercel.app/docs/guides/getting-started/architecture)
|
| --- | --- |
|
![Before](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48557/getting-started-before-crop-a67d5681.png)
|
![After](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48557/getting-started-after-crop-7d2b027a.png)
|

#### [Auth
architecture](https://supabase.com/docs/guides/auth/architecture)

| [Before
(production)](https://supabase.com/docs/guides/auth/architecture) |
[After (PR
preview)](https://docs-git-nikrichers-docs-1262-architecture-docs-84e339-supabase.vercel.app/docs/guides/auth/architecture)
|
| --- | --- |
|
![Before](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48557/auth-before-c68a7267.png)
|
![After](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48557/auth-after-3de5c4c5.png)
|

### Test plan

- [ ] Diagram renders correctly in both light and dark mode on the
preview
- [ ] "Envoy (API gateway)" section reads correctly on the Architecture
overview page
- [ ] Auth architecture bullet reads "Envoy API gateway"
- [ ] The two TODO-marked follow-ups (logs guide,
self-hosting-analytics) are acceptable to leave for later rather than
block this PR

---------

Co-authored-by: Nik Richers <nik@validmind.ai>
Co-authored-by: Miranda Limonczenko <miranda.limonczenko@supabase.io>
2026-07-31 16:00:47 -07:00