When a session token is refreshed server-side, `@supabase/ssr` writes
the updated JWT via Set-Cookie. If a CDN caches that response and serves
it to another user, that user will be signed in as the wrong person.
Adds documentation covering this in two places:
- creating-a-client.mdx: brief mention with a link to the full
explanation
- advanced-guide.mdx: expands the existing CDN FAQ with an explanation
of the risk and Cache-Control: private, no-store examples for Next.js
and Nuxt
Related: https://github.com/supabase/supabase-js/issues/1682
---------
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
docs update
## What is the current behavior?
This can be customized in your project's Auth settings in the Advanced
Settings section.
## What is the new behavior?
Feel free to include screenshots if it includes visual changes.
This can be customized in your project's settings in the JWT Keys >
Legacy JWT Secret section.
- /docs/guides/auth/sessions
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Docs update
## Summary
The OAuth server supports three token endpoint authentication methods
(`none`, `client_secret_basic`, `client_secret_post`), but the docs only
showed `client_secret_post` implicitly without labeling it, and never
mentioned client_secret_basic (the actual default for confidential
clients per RFC 7591).
- Add `token_endpoint_auth_method` explanation with defaults/constraints
to the client registration section in getting-started.mdx
- Update registration examples (JS, Python, cURL) and response JSON to
include token_endpoint_auth_method
- Restructure token exchange and refresh token sections in
oauth-flows.mdx to show all three auth methods with clear labels
- Add `client_secret_basic` examples using HTTP Basic auth header
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
Reworks Expo React native social to use appropriate auth methods and
restructures to use external code.
---------
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Docs update.
## What is the current behavior?
The Kakao login guide implies `account_email` is required, even though
it can be optional in Supabase.
## What is the new behavior?
Clarifies that `account_email` is optional and notes that users should
enable “Allow users without an email” in the Supabase Kakao provider
settings when not requesting `account_email`.
## Additional context
N/A
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Updated Kakao social login documentation to clarify that email consent
is optional.
* Added guidance on configuring provider settings to allow users without
email when email is not requested or unavailable.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## What kind of change does this PR introduce?
Grammar corrections across documentation and test descriptions.
## What is the current behavior?
Multiple docs and test files use "a" before acronyms that start with a
vowel sound when pronounced:
- "a HTTP" (pronounced "aitch-tee-tee-pee") should be "an HTTP"
- "a API" (pronounced "ay-pee-eye") should be "an API"
- "a RLS" (pronounced "arr-ell-ess") should be "an RLS"
- "the all users" is redundant (should be "all users")
## What is the new behavior?
All instances corrected to use proper English indefinite articles:
### Docs files (11 files):
- `firebase-auth.mdx` — "the all users" -> "all users" (2 occurrences)
- `log-drains.mdx` — "a HTTP drain" -> "an HTTP drain"
- `securing-your-api.mdx` — "a HTTP 402" and "a HTTP 420" -> "an HTTP"
- `scan-error-*.mdx` — "a HTTP 500" -> "an HTTP 500"
- `roboflow.mdx` — "a HTTP interface" -> "an HTTP interface"
- `auth-hooks.mdx` — "A HTTP Hook" -> "An HTTP Hook", "a HTTP hook" ->
"an HTTP hook", "a HTTP error" -> "an HTTP error"
- `auth-mfa.mdx` — "a HTTP 401" -> "an HTTP 401"
- `password-verification-hook.mdx` — "a HTTP request" -> "an HTTP
request"
- `before-user-created-hook.mdx` — "a HTTP implementation" -> "an HTTP
implementation"
- `pgtap-extended.mdx` — "a API exposed schema" -> "an API exposed
schema"
- `error-codes.mdx` — "a RLS policy" -> "an RLS policy"
- `broadcast.mdx` — "a RLS" -> "an RLS"
### Studio files (1 file):
- `CronJobs.utils.test.ts` — "a HTTP request" -> "an HTTP request" (9
test descriptions) + "notationa" typo -> "notation"
## Additional context
The rule: use "an" before acronyms pronounced with a leading vowel
sound. "HTTP" starts with "aitch" (vowel sound), "API" starts with "ay"
(vowel sound), and "RLS" starts with "arr" (vowel sound).
## What kind of change does this PR introduce?
Documentation fix
## What is the current behavior?
1. In `apps/docs/content/troubleshooting/enabling-ipv4-addon.mdx`, the
heading reads "Will the project instance **will** be restarted?" with a
doubled "will"
2. In `apps/docs/content/guides/auth/auth-email-templates.mdx`, the `{{
.Email }}` description reads "Empty **when when** trying to link an
email address..." with a doubled "when"
## What is the new behavior?
1. Heading now reads "Will the project instance be restarted?"
2. Description now reads "Empty when trying to link an email address..."
## Additional context
Minor grammar fixes for documentation clarity.
## Summary
This PR updates documentation based on recent changes across multiple
SDK repositories since the last run on 2026-01-22.
## Changes Analyzed
| SDK | Repository | Commits | Latest Tag |
|-----|-----------|---------|------------|
| **js** | supabase/supabase-js | 40 | v2.95.4-canary.2 |
| **dart** | supabase/supabase-flutter | 4 | - |
| **py** | supabase/supabase-py | 12 | v2.28.0 |
| **swift** | supabase/supabase-swift | 14 | v2.41.1 |
| **kt** | supabase-community/supabase-kt | 36 | 3.3.0 |
| **csharp** | supabase-community/supabase-csharp | 1 | v1.1.2 |
## Documentation Updates
### JavaScript SDK (`supabase_js_v2.yml`)
- Added optional `jwt` parameter documentation to
`mfa.getAuthenticatorAssuranceLevel()`
- Added `timeout` and `urlLengthLimit` options to `PostgrestClient`
constructor with example
### Kotlin SDK (`supabase_kt_v3.yml`)
- Added new `getClaims()` API section with description, parameters, and
3 examples
- Added `channel` parameter to OTP `signInWith` config for WhatsApp
support
- Added WhatsApp OTP sign-in example
### Python SDK (`supabase_py_v2.yml`)
- Added `from_.list_v2()` method documentation with cursor-based
pagination support
- Includes `SearchV2Options` parameter documentation and pagination
example
- Added note about new User model fields (`is_sso_user`, `deleted_at`,
`banned_until`) on `get_user`
### Swift SDK (`supabase_swift_v2.yml`)
- Added breaking change note for `mfa.unenroll()`: response now uses
`id` instead of `factorId` (since v2.41.1)
### Phone Login Guide (`phone-login.mdx`)
- Added Kotlin WhatsApp OTP example to the sign-in section
### SDKs with no documentation updates needed
- **Dart**: Only CI and realtime type-cast fix (no user-facing API
changes)
- **C#**: Only README badge fix
## Test plan
- [ ] Verify YAML spec files parse correctly
- [ ] Review rendered documentation for new sections
- [ ] Confirm code examples match actual SDK APIs
---
Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Simple changes to the docs.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Enhanced SAML SSO attribute mapping guide with support for
multi-valued arrays, default values for missing attributes, and multiple
alternative attribute name lookup.
* Clarified identity data storage location and expanded configuration
examples with resulting JWT claims and database representations.
<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Clarified React Native and Angular auth guides with improved
environment setup and JWT validation guidance.
* **New Features**
* Added a React Native environment template for quickstart.
* Example app now uses JWT claims for user state and display.
* **Chores**
* Replaced UI library components with native React Native components for
compatibility.
* Updated package configuration and dependency versions.
<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Added a new React authentication quickstart example demonstrating
email-based OTP (magic link) authentication flow with Supabase
integration.
* **Documentation**
* Updated the React auth quickstart guide to use dynamic code samples
for improved maintainability.
<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
* Move old functions trouble shooting to new guides
* Replace getUser, update, and switch to codeblocks
* Revert "Move old functions trouble shooting to new guides"
This reverts commit 229c581172.
* Prettier
* Add env details
* Fixes
* fix(docs): update authentication instructions to reflect OAuth 2.0 changes
- Replace references to API Key and API Secret Key with Client ID and Client Secret.
- Clarify the deprecation of OAuth 1.0a and provide updated steps for obtaining credentials.
* Update apps/docs/content/guides/auth/social-login/auth-twitter.mdx
Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
---------
Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
Co-authored-by: fadymak <dev@fadymak.com>
* docs(auth): clarify local OAuth callback URLs for Azure, Google, and LinkedIn
* docs: add local OAuth callback instructions to shared social provider setup
* docs: improve Facebook OAuth guide with troubleshooting and clearer instructions
- Add explicit callback URI pattern with link to dashboard
- Add dedicated "Configure email permissions" section with caution admonition
- Add "Testing your integration" section explaining development mode
- Add "Going live with App Review" section with step-by-step guide
- Add "Troubleshooting" section for common issues
- Add error handling to JavaScript code examples
- Fix Swift example with complete ASWebAuthenticationSession implementation
- Add note about checking pub.dev for latest Flutter package version
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Apply suggestions from code review
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* Apply suggestions from code review
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* docs: improve Facebook OAuth guide with troubleshooting and clearer instructions
- Add explicit callback URI pattern with link to dashboard
- Add dedicated "Configure email permissions" section with caution admonition
- Add "Testing your integration" section explaining development mode
- Add "Going live with App Review" section with step-by-step guide
- Add "Troubleshooting" section for common issues
- Add error handling to JavaScript code examples
- Update Swift example to use webAuthenticationSession environment
- Add note about checking pub.dev for latest Flutter package version
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* style: run format
* Apply suggestions from code review
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
* docs: fix broken links in migration guide
Title
fix(docs): update broken next steps links in ssr guides
Description
Fixes#41467
Changes
Updates the "Next steps" section in the following server-side authentication guides:
apps/docs/content/guides/auth/server-side/migrating-to-ssr-from-auth-helpers.mdx
apps/docs/content/guides/auth/server-side/creating-a-client.mdx
Reason
The links in these files were pointing to deprecated "PKCE flow" pages (e.g., email-based-auth-with-pkce-flow-for-ssr) which have been removed from the documentation, resulting in 404 Not Found errors for users attempting to follow the migration or setup steps.
Solution
Remapped the broken links to the currently active, canonical documentation pages:
For migrating-to-ssr-from-auth-helpers.mdx:
Email/Password: .../email-based-auth-with-pkce-flow-for-ssr → /docs/guides/auth/passwords
OAuth: .../oauth-with-pkce-flow-for-ssr → /docs/guides/auth/social-login
SSR Overview: .../guides/auth/server-side → /docs/guides/auth/server-side-rendering
For creating-a-client.mdx:
Email/Password: .../email-based-auth-with-pkce-flow-for-ssr → /docs/guides/auth/passwords
OAuth: .../oauth-with-pkce-flow-for-ssr → /docs/guides/auth/social-login
SSR Overview: .../guides/auth/server-side-rendering → /docs/guides/auth/server-side/advanced-guide (Updated to point to the Advanced Guide to avoid circular linking, or as appropriate for the context).
Verification
Verified that the new target pages exist and cover the relevant SSR/PKCE context needed for these steps.
* fix(www): add redirects for deprecated auth ssr paths
Adds permanent redirects to handle 404 errors for deprecated PKCE flow URLs that were removed in recent updates.
Mappings added:
- /docs/guides/auth/server-side/email-based-auth-with-pkce-flow-for-ssr → /docs/guides/auth/passwords
- /docs/guides/auth/server-side/oauth-with-pkce-flow-for-ssr → /docs/guides/auth/social-login
.
* fix(docs): update broken next steps links in ssr guides
Updates the "Next steps" section in server-side auth guides to point to the correct active documentation.
Replaces broken 404 links to deprecated PKCE flow guides with links to:
- /docs/guides/auth/passwords
- /docs/guides/auth/social-login
- /docs/guides/auth/server-side-rendering
Affected files:
- apps/docs/content/guides/auth/server-side/migrating-to-ssr-from-auth-helpers.mdx
- apps/docs/content/guides/auth/server-side/creating-a-client.mdx
* fix(docs): update broken next steps links in ssr guides
Updates the "Next steps" section in server-side auth guides to point to the correct active documentation.
Replaces broken 404 links to deprecated PKCE flow guides with links to:
- /docs/guides/auth/passwords
- /docs/guides/auth/social-login
- /docs/guides/auth/server-side-rendering
Affected files:
- apps/docs/content/guides/auth/server-side/migrating-to-ssr-from-auth-helpers.mdx
- apps/docs/content/guides/auth/server-side/creating-a-client.mdx
---------
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
* Delete
* Add redirect and remove menu items from the sidebar
* Remove more
* Tidy redirects
* Revert "Delete"
This reverts commit 4a2726a0a6.
* Redirect
* Reapply "Delete"
This reverts commit 9f92a111ef.
PR #41200 introduced template variables ({{ .tab }}, {{ .framework }})
to api_settings_steps.mdx for deep-linking to the Connect dialog.
However, 4 auth docs pages were calling the partial without passing
the required variables prop, causing MDX parsing errors:
- Could not parse expression with acorn: Unexpected token
This resulted in 404 errors on:
- /docs/guides/auth/server-side/creating-a-client
- /docs/guides/auth/quickstarts/nextjs
- /docs/guides/auth/quickstarts/react-native
- /docs/guides/auth/quickstarts/react
Fixes the issue by adding the variables prop to match the pattern
used in other quickstart pages.
* docs: Update from supabase-py PRs #1240, #1283, #1318
- Add upsert option to create_signed_upload_url (PR #1283)
- Add vector and analytics bucket methods documentation (PR #1318)
- Add OAuth 2.1 admin endpoints documentation (PR #1240)
All features are marked as alpha and may change in the future.
# Conflicts:
# apps/docs/spec/supabase_py_v2.yml
* docs: Add Python examples to guides for supabase-py PRs #1240, #1283, #1318
- Add Python examples to vector bucket guides (creating, storing, querying, working with indexes)
- Add Python examples to analytics bucket creation guide
- Add Python examples for OAuth admin endpoints (create_client, list_clients)
- Add Python example for create_signed_upload_url with upsert option
All examples follow existing guide patterns and use proper TabPanel structure.
* style: format guides
* fix: Quote YAML descriptions with backticks to fix parsing error
Fixes YAML parsing error at line 8453 by properly quoting description strings that contain backticks and commas.
* fix(docs): match ids for python reference
* docs: add instructions for hosting Apple App Site Association file for universal links
Add documentation for Universal Links on iOS/Apple platforms, including:
- Instructions for configuring Associated Domains in Xcode
- Requirements for hosting the AASA file on customer infrastructure
- Note that Supabase does not currently support hosting the AASA file
- Example AASA file format and reference to Apple's documentation
This addresses the need for customers to understand how to host the
apple-app-site-association file for Universal Links, which provides
a better user experience than custom URL schemes.
* Apply suggestions from code review
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* refactor: extract Universal Links section to partial for code reuse
Extract the duplicated Universal Links section into a reusable partial
following CONTRIBUTING.md guidelines. This ensures the content is
maintained in a single location and automatically updates in both
the Flutter iOS and Swift sections of the deep linking guide.
* Prettier
* Update apps/docs/content/_partials/universal_links_apple.mdx
* Update apps/docs/content/_partials/universal_links_apple.mdx
* Update apps/docs/content/_partials/universal_links_apple.mdx
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* Update apps/docs/content/_partials/universal_links_apple.mdx
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* Prettier again
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Chris Chinchilla <chris.ward@supabase.io>
* feat: auth advanced page renamed to performance, support for percent db connections
* rename page and form
* make it compile
* fix types?
* one more update
* use master types
* restore from source
* fix prettier
* fix compilation
* minor adjustments
* wording
* change pro plan check
* fix prettier
* nit fixes
* Update next config
* update copy + align upgrade to pro language
* Update
* Clean up
* Nit improve loading time
* Update docs
---------
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
* Quickstart next 16 update
* Fix paths and env vars
* docs: refactor nextjs server-side auth to use Proxy instead of middleware
* docs: refactor nextjs server-side auth to match proxy
* docs: refactor nextjs example to match Proxy
* docs: refactor nextjs auth AI prompt to match Proxy
* docs: refactor nextjs sentry telemetry integration to match Proxy
* examples: update nextjs realtime example to match middleware
* docs: refactoring guides to use nextjs proxy
* examples: update nextjs-full example to match Next16 template
* example: update nextjs-user-management to match nextjs 16
* docs: refactoring nextjs user-management tutorial to use typescript only
* docs: refactoring nextjs quickstart, removing step 4
since this step is already included on `with-supabase` template, we can
just remove this redundant step
* docs: auth-helpers nextjs pages, Nextjs16 proxy disclaimer
* stamp: lint
* stamp: revert 'NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY'
* stamp: nextjs examples, revert to use cookie options
* fix(docs): typo
* docs: updating nextjs-auth troubleshoot guide to match proxy
* Update apps/docs/content/guides/getting-started/quickstarts/nextjs.mdx
* Revert auth-helpers changes
* Revert auth-helpers content
* Apply suggestions from code review
* Update apps/docs/content/troubleshooting/how-do-you-troubleshoot-nextjs---supabase-auth-issues-riMCZV.mdx
* Update apps/docs/content/troubleshooting/how-do-you-troubleshoot-nextjs---supabase-auth-issues-riMCZV.mdx
* Update apps/docs/content/troubleshooting/how-do-you-troubleshoot-nextjs---supabase-auth-issues-riMCZV.mdx
* Update apps/docs/content/troubleshooting/how-do-you-troubleshoot-nextjs---supabase-auth-issues-riMCZV.mdx
* Apply suggestions from code review
* Prettier
---------
Co-authored-by: kallebysantos <kalleby_santos@hotmail.com>
* docs: update link for Row Level Security documentation in JWT guide
* docs: update Figma sign-in link in Flutter guide
* docs: force link to Supabase Login with Apple to work (existing relative URL generates incorrect link in live site).
* docs: update link for Postgres UUID tutorial
* docs: update link for deprecated Android One Tap. Fix broken link to dart signInWithOAuth (the hydrated link on the live site is broken)
* docs: update links for MFA enforcement and backup documentation
* Update apps/docs/content/guides/auth/quickstarts/with-expo-react-native-social-auth.mdx
* Update apps/docs/content/guides/auth/social-login/auth-google.mdx
---------
Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
* docs: update link to Vecs Python source code in developers guide
* docs: update README to remove outdated GDScript links. These repos have been deleted
* docs: update links in CONTRIBUTING.md for consistency and accuracy
* docs: update Twilio verification service link
* docs: update Mixpeek Python Client link in video search guide, remove link to missing code example
* docs: update GIN index link to point to PostgreSQL 16 documentation ('current' symantic no longer exists)
* docs: update Cloudflare Turnstile links to avoid 302 redirect
* docs: update LlamaIndex SupabaseVectorStore link to the correct documentation
* docs: update link to related issue for error message translation in auth-ui guide (to avoid 302 redirect)
* docs: update link from Next.js middleware to Next.js Proxy in auth-helpers guide to follow Next.js's new naming convention
* Update DEVELOPERS.md
* Update CONTRIBUTING.md
Direct to correct URL
* Update hybrid-search.mdx
Fix URL
* docs: renam Next.js middleware to proxy
* Update DEVELOPERS.md
Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
---------
Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>