Commit Graph
367 Commits
Author SHA1 Message Date
4e2405aaad docs: add CDN caching warning for SSR auth middleware (#43575)
When a session token is refreshed server-side, `@supabase/ssr` writes
the updated JWT via Set-Cookie. If a CDN caches that response and serves
it to another user, that user will be signed in as the wrong person.

Adds documentation covering this in two places:
- creating-a-client.mdx: brief mention with a link to the full
explanation
- advanced-guide.mdx: expands the existing CDN FAQ with an explanation
of the risk and Cache-Control: private, no-store examples for Next.js
and Nuxt

Related: https://github.com/supabase/supabase-js/issues/1682

---------

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-11 09:17:33 +02:00
Chris Chinchilla debecf3921 docs: SwitchGoogle social auth to getClaims (#43593)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES
2026-03-10 17:06:22 +01:00
Danny WhiteandJoshen Lim 503c01b5bc chore(studio): refactor oauth apps page and table (#43366)
## What kind of change does this PR introduce?

UI update.

## What is the current behavior?

The org’s /apps page is glaringly out of date compared to similar pages.
It uses old page and layout components.

## What is the new behavior?

- Refactored /apps to use latest
[layout](https://supabase.com/design-system/docs/ui-patterns/layout) and
[table](https://supabase.com/design-system/docs/components/table)
components

Unrelated minor changes snuck in:

- Global `pnpm format` to properly format recurring annoyances elsewhere
- Minor polish on org tiles (pictured)

| Before | After |
| --- | --- |
| <img width="1728" height="997" alt="OAuth Apps
Supabase-30B6CDAE-4954-40F8-886A-939797999AA6"
src="https://github.com/user-attachments/assets/163c2787-f6ab-4a0b-80aa-af81260bdf9f"
/> | <img width="1728" height="997" alt="OAuth Apps
Supabase-7DD241E0-262A-4817-91B2-D2A299F8EB93"
src="https://github.com/user-attachments/assets/29928305-9110-4256-8663-c3821e696587"
/> |
| <img width="1728" height="997" alt="OAuth Apps
Supabase-9870816A-8022-479D-8011-236A813249AB"
src="https://github.com/user-attachments/assets/32e41835-59bc-4d83-92eb-635b98c5f4a5"
/> | <img width="1728" height="997" alt="OAuth Apps
Supabase-21CFBC16-E850-44A6-BEFF-C4FBED8ACB43"
src="https://github.com/user-attachments/assets/6999e2a0-ea17-44cb-99f2-42f985354589"
/> |
| <img width="1152" height="664"
alt="Supabase-9DD87028-2D46-47D0-8546-240184E1711B"
src="https://github.com/user-attachments/assets/2c7d8b2a-280f-48d6-9f78-19c519cf4654"
/> | <img width="1152" height="664"
alt="Supabase-F1C92F66-C602-4DC9-B3B4-AE3FB673276E"
src="https://github.com/user-attachments/assets/0a24a98e-386f-4ada-b282-0a59b159bbab"
/> |

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-03-06 12:23:33 +11:00
Chris Chinchilla d6006f9d08 docs: Update Remix SSR example code (#43351)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES
2026-03-05 14:20:15 +01:00
Illia Basalaiev bb10862e07 chore: update jwt expiration link in the user sessions docs (#43338)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

docs update

## What is the current behavior?

This can be customized in your project's Auth settings in the Advanced
Settings section.

## What is the new behavior?

Feel free to include screenshots if it includes visual changes.

This can be customized in your project's settings in the JWT Keys >
Legacy JWT Secret section.

- /docs/guides/auth/sessions
2026-03-03 12:18:01 +01:00
Cemal Kılıç d810b7772b feat(docs): token_endpoint_auth_method in OAuth server docs (#43128)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update

## Summary
The OAuth server supports three token endpoint authentication methods
(`none`, `client_secret_basic`, `client_secret_post`), but the docs only
showed `client_secret_post` implicitly without labeling it, and never
mentioned client_secret_basic (the actual default for confidential
clients per RFC 7591).

- Add `token_endpoint_auth_method` explanation with defaults/constraints
to the client registration section in getting-started.mdx
- Update registration examples (JS, Python, cURL) and response JSON to
include token_endpoint_auth_method
- Restructure token exchange and refresh token sections in
oauth-flows.mdx to show all three auth methods with clear labels
- Add `client_secret_basic` examples using HTTP Basic auth header
2026-02-24 17:29:47 +05:30
Nika Krasnov 1a3d818de6 docs(auth): fix typo in Google Auth scopes documentation (#43093)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update. Fix typo
2026-02-24 10:22:28 +00:00
Jeremias Menichelli f6ec43a9ed [DOCS-454] fix(Docs): Fix images from causing CLS on pages (#43026) 2026-02-23 19:02:31 +01:00
Chris Chinchilla d23302d2f5 docs: Fix breaking rendering issues (#43096)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES
2026-02-23 16:22:15 +01:00
Chris Chinchillaandcoderabbitai[bot] c0f7e7dfd1 docs: Rework Expo React native social auth (#43017)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

Reworks Expo React native social to use appropriate auth methods and
restructures to use external code.

---------

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-02-23 08:54:17 +01:00
zero e15860f169 docs(auth): clarify kakao email optional (#42405)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update.

## What is the current behavior?

The Kakao login guide implies `account_email` is required, even though
it can be optional in Supabase.

## What is the new behavior?

Clarifies that `account_email` is optional and notes that users should
enable “Allow users without an email” in the Supabase Kakao provider
settings when not requesting `account_email`.

## Additional context

N/A

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated Kakao social login documentation to clarify that email consent
is optional.
* Added guidance on configuring provider settings to allow users without
email when email is not requested or unavailable.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-02-20 09:56:17 +00:00
Yogeshwaran C 647ac43c0a fix: correct indefinite article usage for acronyms (an HTTP, an API, an RLS) (#42919)
## What kind of change does this PR introduce?

Grammar corrections across documentation and test descriptions.

## What is the current behavior?

Multiple docs and test files use "a" before acronyms that start with a
vowel sound when pronounced:
- "a HTTP" (pronounced "aitch-tee-tee-pee") should be "an HTTP"
- "a API" (pronounced "ay-pee-eye") should be "an API"  
- "a RLS" (pronounced "arr-ell-ess") should be "an RLS"
- "the all users" is redundant (should be "all users")

## What is the new behavior?

All instances corrected to use proper English indefinite articles:

### Docs files (11 files):
- `firebase-auth.mdx` — "the all users" -> "all users" (2 occurrences)
- `log-drains.mdx` — "a HTTP drain" -> "an HTTP drain"
- `securing-your-api.mdx` — "a HTTP 402" and "a HTTP 420" -> "an HTTP"
- `scan-error-*.mdx` — "a HTTP 500" -> "an HTTP 500"
- `roboflow.mdx` — "a HTTP interface" -> "an HTTP interface"
- `auth-hooks.mdx` — "A HTTP Hook" -> "An HTTP Hook", "a HTTP hook" ->
"an HTTP hook", "a HTTP error" -> "an HTTP error"
- `auth-mfa.mdx` — "a HTTP 401" -> "an HTTP 401"
- `password-verification-hook.mdx` — "a HTTP request" -> "an HTTP
request"
- `before-user-created-hook.mdx` — "a HTTP implementation" -> "an HTTP
implementation"
- `pgtap-extended.mdx` — "a API exposed schema" -> "an API exposed
schema"
- `error-codes.mdx` — "a RLS policy" -> "an RLS policy"
- `broadcast.mdx` — "a RLS" -> "an RLS"

### Studio files (1 file):
- `CronJobs.utils.test.ts` — "a HTTP request" -> "an HTTP request" (9
test descriptions) + "notationa" typo -> "notation"

## Additional context

The rule: use "an" before acronyms pronounced with a leading vowel
sound. "HTTP" starts with "aitch" (vowel sound), "API" starts with "ay"
(vowel sound), and "RLS" starts with "arr" (vowel sound).
2026-02-19 07:23:18 -07:00
Yogeshwaran C 418f68b3c1 docs: fix doubled words in IPv4 FAQ and email templates docs (#42907)
## What kind of change does this PR introduce?

Documentation fix

## What is the current behavior?

1. In `apps/docs/content/troubleshooting/enabling-ipv4-addon.mdx`, the
heading reads "Will the project instance **will** be restarted?" with a
doubled "will"
2. In `apps/docs/content/guides/auth/auth-email-templates.mdx`, the `{{
.Email }}` description reads "Empty **when when** trying to link an
email address..." with a doubled "when"

## What is the new behavior?

1. Heading now reads "Will the project instance be restarted?"
2. Description now reads "Empty when trying to link an email address..."

## Additional context

Minor grammar fixes for documentation clarity.
2026-02-18 13:47:19 +00:00
Guilherme SouzaandClaude Opus 4.6 32f70db13d docs: Update documentation from SDK changes (Jan 22 - Feb 16) (#42874)
## Summary

This PR updates documentation based on recent changes across multiple
SDK repositories since the last run on 2026-01-22.

## Changes Analyzed

| SDK | Repository | Commits | Latest Tag |
|-----|-----------|---------|------------|
| **js** | supabase/supabase-js | 40 | v2.95.4-canary.2 |
| **dart** | supabase/supabase-flutter | 4 | - |
| **py** | supabase/supabase-py | 12 | v2.28.0 |
| **swift** | supabase/supabase-swift | 14 | v2.41.1 |
| **kt** | supabase-community/supabase-kt | 36 | 3.3.0 |
| **csharp** | supabase-community/supabase-csharp | 1 | v1.1.2 |

## Documentation Updates

### JavaScript SDK (`supabase_js_v2.yml`)
- Added optional `jwt` parameter documentation to
`mfa.getAuthenticatorAssuranceLevel()`
- Added `timeout` and `urlLengthLimit` options to `PostgrestClient`
constructor with example

### Kotlin SDK (`supabase_kt_v3.yml`)
- Added new `getClaims()` API section with description, parameters, and
3 examples
- Added `channel` parameter to OTP `signInWith` config for WhatsApp
support
- Added WhatsApp OTP sign-in example

### Python SDK (`supabase_py_v2.yml`)
- Added `from_.list_v2()` method documentation with cursor-based
pagination support
- Includes `SearchV2Options` parameter documentation and pagination
example
- Added note about new User model fields (`is_sso_user`, `deleted_at`,
`banned_until`) on `get_user`

### Swift SDK (`supabase_swift_v2.yml`)
- Added breaking change note for `mfa.unenroll()`: response now uses
`id` instead of `factorId` (since v2.41.1)

### Phone Login Guide (`phone-login.mdx`)
- Added Kotlin WhatsApp OTP example to the sign-in section

### SDKs with no documentation updates needed
- **Dart**: Only CI and realtime type-cast fix (no user-facing API
changes)
- **C#**: Only README badge fix

## Test plan
- [ ] Verify YAML spec files parse correctly
- [ ] Review rendered documentation for new sections
- [ ] Confirm code examples match actual SDK APIs

---

Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-17 13:48:12 +01:00
4b388b7bf7 docs: update js sdk docs (v2.94.1) (#42454)
Updates JS sdk documentation following stable release. 
Ran `make` in apps/docs/spec to regenerate tsdoc files.

**Details:**
- **Version:** `v2.94.1`
- **Source:** `manual`
- **Changes:** Regenerated tsdoc files from latest spec files

🤖 Auto-generated from @supabase/supabase-js stable release.

---------

Co-authored-by: mandarini <6603745+mandarini@users.noreply.github.com>
Co-authored-by: Katerina Skroumpelou <sk.katherine@gmail.com>
2026-02-04 18:39:59 +02:00
Stojan DimitrovskiandChris Chinchilla 76305777f9 docs: update saml attribute mapping docs (#41387)
Simple changes to the docs.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Enhanced SAML SSO attribute mapping guide with support for
multi-valued arrays, default values for missing attributes, and multiple
alternative attribute name lookup.
* Clarified identity data storage location and expanded configuration
examples with resulting JWT claims and database representations.

<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-02-02 23:43:36 +00:00
Sam Meech-WardandChris Chinchilla 59571f4cba docs: Fix Supabase integration guide link in documentation (#41212)
Updated the link to the Supabase integration guide for FastMCP.

## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES/NO

## What kind of change does this PR introduce?

Bug fix, feature, docs update, ...

## What is the current behavior?

The link goes to a 404 page
https://gofastmcp.com/todo

## What is the new behavior?

The link goes to what I think is the correct page
https://gofastmcp.com/integrations/supabase#supabase-fastmcp

## Additional context

Add any other context or screenshots.

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-02-01 23:46:42 +00:00
Chris Chinchilla 8f08df1600 docs: Update reworked getSession tutorials to use correct functions and clarify why (#42269)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Clarified React Native and Angular auth guides with improved
environment setup and JWT validation guidance.

* **New Features**
  * Added a React Native environment template for quickstart.
  * Example app now uses JWT claims for user state and display.

* **Chores**
* Replaced UI library components with native React Native components for
compatibility.
  * Updated package configuration and dependency versions.

<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-01-30 02:27:37 +00:00
Chris Chinchilla 398480a3cd docs: Update react auth quickstart to use getClaims and move all code to examples folder (#42279)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added a new React authentication quickstart example demonstrating
email-based OTP (magic link) authentication flow with Supabase
integration.

* **Documentation**
* Updated the React auth quickstart guide to use dynamic code samples
for improved maintainability.

<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-01-30 12:06:05 +11:00
Chris Chinchilla 587729411d docs: update React Native auth quickstart to remove getUser (#42196)
* Move old functions trouble shooting to new guides

* Replace getUser, update, and switch to codeblocks

* Revert "Move old functions trouble shooting to new guides"

This reverts commit 229c581172.

* Prettier

* Add env details

* Fixes
2026-01-28 00:16:28 +00:00
dedee5457c fix(docs): update authentication instructions to reflect OAuth 2.0 changes (#41703)
* fix(docs): update authentication instructions to reflect OAuth 2.0 changes

- Replace references to API Key and API Secret Key with Client ID and Client Secret.
- Clarify the deprecation of OAuth 1.0a and provide updated steps for obtaining credentials.

* Update apps/docs/content/guides/auth/social-login/auth-twitter.mdx

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>

---------

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
Co-authored-by: fadymak <dev@fadymak.com>
2026-01-27 15:09:25 +01:00
Muzzaiyyan Hussain 5f4fb17a18 docs(auth): clarify local OAuth callback URLs for Azure, Google, and LinkedIn (#41892)
* docs(auth): clarify local OAuth callback URLs for Azure, Google, and LinkedIn

* docs: add local OAuth callback instructions to shared social provider setup
2026-01-27 09:02:47 +11:00
e51f24448d docs: Update documentation from SDK changes (Jan 2026) (#42085)
* docs: update documentation from SDK changes (Jan 2026)

This PR updates documentation based on recent changes across all Supabase SDKs.

## Changes Summary

### Auth - X Provider Support
- Added Swift code examples for X (Twitter) OAuth 2.0 authentication
- Updated auth-twitter.mdx with Swift sign-in and sign-out examples
- Complements existing JS, Dart, and Kotlin support

### Storage - Download Query Parameters
- Documented new query parameter support in download() method
- Added examples for Swift (queryItems) and Dart (queryParams)
- Shows how to customize download behavior programmatically

### Storage - Error Handling
- Added section on accessing error details in SDKs
- Documented new status/statusCode properties on JS StorageError
- Documented improved error handling in Python SDK

## SDK Commits Analyzed

- **JavaScript** (v2.91.1-canary.1): 5ed0ce91...HEAD
  - Storage: Exposed status/statusCode on StorageError
  - Auth: Improved signOut with session cleanup
  - Realtime: Added generic overload for postgres_changes

- **Python** (v2.27.2): 1df3afcd...HEAD
  - Storage: Better handling of bad server responses
  - Realtime: Fixed reconnect logic and protocol issues

- **Swift** (v2.40.0): a15b8880...HEAD
  - Storage: Added queryItems support to download method
  - Auth: Added X (OAuth 2.0) provider
  - Functions: Sync auth headers on state change

- **Dart** (yet_another_json_isolate-v2.1.0): af882128...HEAD
  - Storage: Added queryParams support to download method
  - Auth: Added X (OAuth 2.0) provider, fixed getClaims()
  - Storage: Dedicated host for >50GB uploads

- **Kotlin** (3.3.0): 81c7ebab...HEAD
  - Auth: Added X provider support
  - Functions: Fixed error parsing

- **C#** (v1.1.2): e04cc988...HEAD
  - No recent changes requiring documentation updates

## Files Modified

- apps/docs/content/guides/auth/social-login/auth-twitter.mdx
- apps/docs/content/guides/storage/serving/downloads.mdx
- apps/docs/content/guides/storage/debugging/error-codes.mdx

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>

* Prettier

---------

Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-01-26 08:16:51 -03:00
Danny White 19cf4bb4bf feat(studio): consolidate settings phase 2 (#37612)
* new slugs

* remove symlinks

* rabbit
2026-01-26 15:41:05 +08:00
15eb27fb19 docs: improve Facebook OAuth guide with troubleshooting and clearer instructions (#41893)
* docs: improve Facebook OAuth guide with troubleshooting and clearer instructions

- Add explicit callback URI pattern with link to dashboard
- Add dedicated "Configure email permissions" section with caution admonition
- Add "Testing your integration" section explaining development mode
- Add "Going live with App Review" section with step-by-step guide
- Add "Troubleshooting" section for common issues
- Add error handling to JavaScript code examples
- Fix Swift example with complete ASWebAuthenticationSession implementation
- Add note about checking pub.dev for latest Flutter package version

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* Apply suggestions from code review

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* docs: improve Facebook OAuth guide with troubleshooting and clearer instructions

- Add explicit callback URI pattern with link to dashboard
- Add dedicated "Configure email permissions" section with caution admonition
- Add "Testing your integration" section explaining development mode
- Add "Going live with App Review" section with step-by-step guide
- Add "Troubleshooting" section for common issues
- Add error handling to JavaScript code examples
- Update Swift example to use webAuthenticationSession environment
- Add note about checking pub.dev for latest Flutter package version

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* style: run format

* Apply suggestions from code review

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>

---------

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-01-22 09:21:53 -03:00
Andreas Braumann c9b7d76a18 docs: Update getting-started.mdx - need to await the searchParams Promise (#40891)
Update getting-started.mdx

Need to await the searchParams Promise
2026-01-14 07:03:43 +00:00
Chris Chinchilla fb7fbcb109 docs: Fix up auth helpers migration guide (#41790)
Fix up auth helpers migration guide
2026-01-14 09:32:17 +07:00
Eddie JaoudeandChris Chinchilla 31d81e1051 docs: path to file for google provider config (#41142)
docs: google provider path to config

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-01-13 04:06:14 +00:00
Siddhant GawadandChris Chinchilla f5d125220d docs: fix broken links in migration guide (#41469)
* docs: fix broken links in migration guide

Title
fix(docs): update broken next steps links in ssr guides

Description
Fixes #41467
Changes
Updates the "Next steps" section in the following server-side authentication guides:

apps/docs/content/guides/auth/server-side/migrating-to-ssr-from-auth-helpers.mdx

apps/docs/content/guides/auth/server-side/creating-a-client.mdx

Reason
The links in these files were pointing to deprecated "PKCE flow" pages (e.g., email-based-auth-with-pkce-flow-for-ssr) which have been removed from the documentation, resulting in 404 Not Found errors for users attempting to follow the migration or setup steps.

Solution
Remapped the broken links to the currently active, canonical documentation pages:

For migrating-to-ssr-from-auth-helpers.mdx:

Email/Password: .../email-based-auth-with-pkce-flow-for-ssr → /docs/guides/auth/passwords

OAuth: .../oauth-with-pkce-flow-for-ssr → /docs/guides/auth/social-login

SSR Overview: .../guides/auth/server-side → /docs/guides/auth/server-side-rendering

For creating-a-client.mdx:

Email/Password: .../email-based-auth-with-pkce-flow-for-ssr → /docs/guides/auth/passwords

OAuth: .../oauth-with-pkce-flow-for-ssr → /docs/guides/auth/social-login

SSR Overview: .../guides/auth/server-side-rendering → /docs/guides/auth/server-side/advanced-guide (Updated to point to the Advanced Guide to avoid circular linking, or as appropriate for the context).

Verification
Verified that the new target pages exist and cover the relevant SSR/PKCE context needed for these steps.

* fix(www): add redirects for deprecated auth ssr paths

Adds permanent redirects to handle 404 errors for deprecated PKCE flow URLs that were removed in recent updates.

Mappings added:
- /docs/guides/auth/server-side/email-based-auth-with-pkce-flow-for-ssr → /docs/guides/auth/passwords
- /docs/guides/auth/server-side/oauth-with-pkce-flow-for-ssr → /docs/guides/auth/social-login

.

* fix(docs): update broken next steps links in ssr guides

Updates the "Next steps" section in server-side auth guides to point to the correct active documentation.

Replaces broken 404 links to deprecated PKCE flow guides with links to:
- /docs/guides/auth/passwords
- /docs/guides/auth/social-login
- /docs/guides/auth/server-side-rendering

Affected files:
- apps/docs/content/guides/auth/server-side/migrating-to-ssr-from-auth-helpers.mdx
- apps/docs/content/guides/auth/server-side/creating-a-client.mdx

* fix(docs): update broken next steps links in ssr guides

Updates the "Next steps" section in server-side auth guides to point to the correct active documentation.

Replaces broken 404 links to deprecated PKCE flow guides with links to:
- /docs/guides/auth/passwords
- /docs/guides/auth/social-login
- /docs/guides/auth/server-side-rendering

Affected files:
- apps/docs/content/guides/auth/server-side/migrating-to-ssr-from-auth-helpers.mdx
- apps/docs/content/guides/auth/server-side/creating-a-client.mdx

---------

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-01-13 10:28:51 +07:00
Jayan RatnaandChris Chinchilla aad40b8848 fix: HTML formatting in email templates guide (#40369)
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2026-01-12 09:25:18 +00:00
Owen 32460f42c5 docs: Fix OAuth Link in docs (#41560)
* Update OAuth authentication link in guide

* Fix link to OAuth authentication guide
2026-01-09 12:17:53 +00:00
Jewook Yoo / MasonandChris Chinchilla 3abdd25061 docs: update Kakao OAuth guide to reflect the latest Kakao Developer Console (#41681)
* docs: update Kakao social login instructions and images

* docs: update instructions for account_email consent item

* fix: supa-mdx-lint error

* Update apps/docs/content/guides/auth/social-login/auth-kakao.mdx

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>

* Update apps/docs/content/guides/auth/social-login/auth-kakao.mdx

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>

* Update apps/docs/content/guides/auth/social-login/auth-kakao.mdx

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>

* Update apps/docs/content/guides/auth/social-login/auth-kakao.mdx

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>

* Update apps/docs/content/guides/auth/social-login/auth-kakao.mdx

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>

* Update apps/docs/content/guides/auth/social-login/auth-kakao.mdx

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>

* Apply suggestions from code review

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>

* Update apps/docs/content/guides/auth/social-login/auth-kakao.mdx

* Apply suggestions from code review

* Update apps/docs/content/guides/auth/social-login/auth-kakao.mdx

* Update apps/docs/content/guides/auth/social-login/auth-kakao.mdx

* Update apps/docs/content/guides/auth/social-login/auth-kakao.mdx

* Update apps/docs/content/guides/auth/social-login/auth-kakao.mdx

---------

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
2026-01-07 14:02:55 +01:00
Supun Sudaraka 2e89ea9b15 docs: Removed provider reassignment phrase from the saml sso docs (#41645)
removed provider reassignment phrase from the saml sso docs
2026-01-05 14:08:56 +01:00
Vaibhav 64d813f83a fix(docs): resolve 404 on /docs/guides/auth/server-side (#41601)
Remove broken partial reference to non-existent auth_helpers.mdx file.
2025-12-26 14:20:23 +00:00
Chris Chinchilla 6bdfca6de4 Revert "Revert "docs: Remove Auth Helpers"" (#41441)
Revert "Revert "docs: Remove Auth Helpers" (#41383)"

This reverts commit 7415e9fdb3.
2025-12-17 16:36:38 +01:00
d1ea8089e6 feat(docs): update X / Twitter docs for OAuth 2.0 (#41396)
* feat(docs): update X / Twitter docs for OAuth 2.0

* Update apps/docs/content/guides/auth/social-login/auth-twitter.mdx

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* Update apps/docs/content/guides/auth/social-login/auth-twitter.mdx

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* Heading lint

* Update apps/docs/content/guides/auth/social-login/auth-twitter.mdx

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* prettier

* Prettier again

* chore: cleanup dead link and deprecation warning

* chore: lint for admnition

---------

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2025-12-17 14:18:18 +01:00
Chris Chinchilla 7415e9fdb3 Revert "docs: Remove Auth Helpers" (#41383)
Revert "docs: Remove Auth Helpers (#40986)"

This reverts commit 9274b81bd7.
2025-12-16 09:35:43 +00:00
Chris Chinchilla 9274b81bd7 docs: Remove Auth Helpers (#40986)
* Delete

* Add redirect and remove menu items from the sidebar

* Remove more

* Tidy redirects

* Revert "Delete"

This reverts commit 4a2726a0a6.

* Redirect

* Reapply "Delete"

This reverts commit 9f92a111ef.
2025-12-16 08:44:26 +00:00
Vaibhav 23064c0b5b fix(docs): add missing variables to api_settings_steps partial calls (#41364)
PR #41200 introduced template variables ({{ .tab }}, {{ .framework }})
to api_settings_steps.mdx for deep-linking to the Connect dialog.
However, 4 auth docs pages were calling the partial without passing
the required variables prop, causing MDX parsing errors:

- Could not parse expression with acorn: Unexpected token

This resulted in 404 errors on:
- /docs/guides/auth/server-side/creating-a-client
- /docs/guides/auth/quickstarts/nextjs
- /docs/guides/auth/quickstarts/react-native
- /docs/guides/auth/quickstarts/react

Fixes the issue by adding the variables prop to match the pattern
used in other quickstart pages.
2025-12-15 14:27:04 -07:00
Chris Chinchilla a3b7c8f3a7 docs: Check and clarify API keys (#41200)
* Update parial

* Add partial to quickstarts

* Auth section

* More

* Prettier

* Realtime

* Add soft links to frameworks

* Add tab

* Fix typo

* More changes

* Updates

* Prettier
2025-12-15 16:45:21 +01:00
Guilherme Souza a40bf4dfa4 docs: Update from supabase-py PRs #1240, #1283, #1318 (#41087)
* docs: Update from supabase-py PRs #1240, #1283, #1318

- Add upsert option to create_signed_upload_url (PR #1283)
- Add vector and analytics bucket methods documentation (PR #1318)
- Add OAuth 2.1 admin endpoints documentation (PR #1240)

All features are marked as alpha and may change in the future.

# Conflicts:
#	apps/docs/spec/supabase_py_v2.yml

* docs: Add Python examples to guides for supabase-py PRs #1240, #1283, #1318

- Add Python examples to vector bucket guides (creating, storing, querying, working with indexes)
- Add Python examples to analytics bucket creation guide
- Add Python examples for OAuth admin endpoints (create_client, list_clients)
- Add Python example for create_signed_upload_url with upsert option

All examples follow existing guide patterns and use proper TabPanel structure.

* style: format guides

* fix: Quote YAML descriptions with backticks to fix parsing error

Fixes YAML parsing error at line 8453 by properly quoting description strings that contain backticks and commas.

* fix(docs): match ids for python reference
2025-12-12 16:48:52 +00:00
Cemal Kılıç 9194b70b84 fix(docs): update oauth links (#41299) 2025-12-12 21:32:33 +07:00
8c672ab6d7 docs: add instructions for hosting Apple App Site Association file for universal deep link (#41304)
* docs: add instructions for hosting Apple App Site Association file for universal links

Add documentation for Universal Links on iOS/Apple platforms, including:
- Instructions for configuring Associated Domains in Xcode
- Requirements for hosting the AASA file on customer infrastructure
- Note that Supabase does not currently support hosting the AASA file
- Example AASA file format and reference to Apple's documentation

This addresses the need for customers to understand how to host the
apple-app-site-association file for Universal Links, which provides
a better user experience than custom URL schemes.

* Apply suggestions from code review

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* refactor: extract Universal Links section to partial for code reuse

Extract the duplicated Universal Links section into a reusable partial
following CONTRIBUTING.md guidelines. This ensures the content is
maintained in a single location and automatically updates in both
the Flutter iOS and Swift sections of the deep linking guide.

* Prettier

* Update apps/docs/content/_partials/universal_links_apple.mdx

* Update apps/docs/content/_partials/universal_links_apple.mdx

* Update apps/docs/content/_partials/universal_links_apple.mdx

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* Update apps/docs/content/_partials/universal_links_apple.mdx

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* Prettier again

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
2025-12-12 09:33:20 -03:00
Chris StocktonandChris Stockton a1b3f3b7e7 chore(docs/auth): clarification for email & sms hooks (#40692)
Co-authored-by: Chris Stockton <chris.stockton@supabase.io>
2025-12-09 08:07:46 +01:00
Joshen Lim e4075f1696 Retrigger docs build (#41066)
Retrigger docs bild
2025-12-04 13:29:37 +00:00
Stojan DimitrovskiandJoshen Lim 6a45bb35ca feat: auth advanced page renamed to performance, support for percent db connections (#39852)
* feat: auth advanced page renamed to performance, support for percent db connections

* rename page and form

* make it compile

* fix types?

* one more update

* use master types

* restore from source

* fix prettier

* fix compilation

* minor adjustments

* wording

* change pro plan check

* fix prettier

* nit fixes

* Update next config

* update copy + align upgrade to pro language

* Update

* Clean up

* Nit improve loading time

* Update docs

---------

Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2025-12-04 11:35:14 +08:00
Chris Chinchillaandkallebysantos ae727a4659 docs: update supabase docs for nextjs 16 proxyts change (#40555)
* Quickstart next 16 update

* Fix paths and env vars

* docs: refactor nextjs server-side auth to use Proxy instead of middleware

* docs: refactor nextjs server-side auth to match proxy

* docs: refactor nextjs example to match Proxy

* docs: refactor nextjs auth AI prompt to match Proxy

* docs: refactor nextjs sentry telemetry integration to match Proxy

* examples: update nextjs realtime example to match middleware

* docs: refactoring guides to use nextjs proxy

* examples: update nextjs-full example to match Next16 template

* example: update nextjs-user-management to match nextjs 16

* docs: refactoring nextjs user-management tutorial to use typescript only

* docs: refactoring nextjs quickstart, removing step 4

since this step is already included on `with-supabase` template, we can
just remove this redundant step

* docs: auth-helpers nextjs pages, Nextjs16 proxy disclaimer

* stamp: lint

* stamp: revert 'NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY'

* stamp: nextjs examples, revert to use cookie options

* fix(docs): typo

* docs: updating nextjs-auth troubleshoot guide to match proxy

* Update apps/docs/content/guides/getting-started/quickstarts/nextjs.mdx

* Revert auth-helpers changes

* Revert auth-helpers content

* Apply suggestions from code review

* Update apps/docs/content/troubleshooting/how-do-you-troubleshoot-nextjs---supabase-auth-issues-riMCZV.mdx

* Update apps/docs/content/troubleshooting/how-do-you-troubleshoot-nextjs---supabase-auth-issues-riMCZV.mdx

* Update apps/docs/content/troubleshooting/how-do-you-troubleshoot-nextjs---supabase-auth-issues-riMCZV.mdx

* Update apps/docs/content/troubleshooting/how-do-you-troubleshoot-nextjs---supabase-auth-issues-riMCZV.mdx

* Apply suggestions from code review

* Prettier

---------

Co-authored-by: kallebysantos <kalleby_santos@hotmail.com>
2025-12-01 16:53:12 +01:00
Andrew AgostiniandChris Chinchilla 4ee5050011 docs: Fix broken URLS batch 2 (#40484)
* docs: update link for Row Level Security documentation in JWT guide

* docs: update Figma sign-in link in Flutter guide

* docs: force link to Supabase Login with Apple to work (existing relative URL generates incorrect link in live site).

* docs: update link for Postgres UUID tutorial

* docs: update link for deprecated Android One Tap. Fix broken link to dart signInWithOAuth (the hydrated link on the live site is broken)

* docs: update links for MFA enforcement and backup documentation

* Update apps/docs/content/guides/auth/quickstarts/with-expo-react-native-social-auth.mdx

* Update apps/docs/content/guides/auth/social-login/auth-google.mdx

---------

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
2025-11-29 09:26:29 +01:00
Andrew AgostiniandChris Chinchilla a6a598f824 docs: Fix broken urls (#40457)
* docs: update link to Vecs Python source code in developers guide

* docs: update README to remove outdated GDScript links. These repos have been deleted

* docs: update links in CONTRIBUTING.md for consistency and accuracy

* docs: update Twilio verification service link

* docs: update Mixpeek Python Client link in video search guide, remove link to missing code example

* docs: update GIN index link to point to PostgreSQL 16 documentation ('current' symantic no longer exists)

* docs: update Cloudflare Turnstile links to avoid 302 redirect

* docs: update LlamaIndex SupabaseVectorStore link to the correct documentation

* docs: update link to related issue for error message translation in auth-ui guide (to avoid 302 redirect)

* docs: update link from Next.js middleware to Next.js Proxy in auth-helpers guide to follow Next.js's new naming convention

* Update DEVELOPERS.md

* Update CONTRIBUTING.md

Direct to correct URL

* Update hybrid-search.mdx

Fix URL

* docs: renam Next.js middleware to proxy

* Update DEVELOPERS.md

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>

---------

Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
2025-11-28 08:58:11 +00:00
c86ff5bd3a feat: update Figma auth docs (#39328)
* feat: update Figma auth docs

* Update Figma OAuth app setup instructions

* Prettier

* Update spelling

* Revert "Update spelling"

This reverts commit 894d0a5050.

---------

Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
2025-11-26 20:01:18 +07:00