Files
supabase/apps/docs/content/guides/platform/postgres-connection-logging.mdx
Nik RichersandNik Richers eecedb44aa docs(security): note July 9 effective date for log_connections default (#47252)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

- docs update

Follow-up to DOCS-1080 / PSQL-1307 after #47199 merged.

## What is the current behavior?

- Docs state that `log_connections` is off by default for new projects
(#47199) but do not note when that platform default takes effect.
- The `log_connections=off` default is not live until **July 9, 2026**.

## What is the new behavior?

- Adds a shared note admonition (via partial) on all five pages that
state the `log_connections=off` default.
- Admonition copy: "This default takes effect for new projects from July
9, 2026."

### Proof: admonition renders on preview

**Verified:** `supa-mdx-lint` (pass) · Vercel docs preview (all changed
pages 200)

| Check | Result |
|-------|--------|
| `supa-mdx-lint` | pass |
| Preview — Postgres connection logging |
[200](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/platform/postgres-connection-logging)
|
| Preview — Logs |
[200](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/telemetry/logs#logging-postgres-connections)
|
| Preview — HIPAA compliance FAQ |
[200](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/security/hipaa-compliance)
|
| Preview — Shared responsibility model |
[200](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data)
|
| Preview — SOC 2 compliance |
[200](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/security/soc-2-compliance)
|

**Screenshots (Default behavior section):**

![Postgres connection logging — Default behavior
admonition](https://raw.githubusercontent.com/supabase/supabase/nikrichers/docs-1080-log-connections-effective-date-admonition/.github/pr-screenshots/docs-1080/pr1-postgres-connection-logging.png)

![Logs — Logging Postgres connections
admonition](https://raw.githubusercontent.com/supabase/supabase/nikrichers/docs-1080-log-connections-effective-date-admonition/.github/pr-screenshots/docs-1080/pr1-logs.png)

![HIPAA compliance FAQ
admonition](https://raw.githubusercontent.com/supabase/supabase/nikrichers/docs-1080-log-connections-effective-date-admonition/.github/pr-screenshots/docs-1080/pr1-hipaa-compliance.png)

**Quick review links:**

- [Postgres connection logging — Default
behavior](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/platform/postgres-connection-logging)
- [Logs — Logging Postgres
connections](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/telemetry/logs#logging-postgres-connections)
- [HIPAA compliance —
FAQ](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/security/hipaa-compliance)
- [Shared responsibility model — Managing healthcare
data](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data)
- [SOC 2 compliance — Customer
responsibilities](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/security/soc-2-compliance)

## Additional context

- Scheduled cleanup PR: #47253 removes this admonition on **July 9,
2026**.
- Review screenshots live in `.github/pr-screenshots/docs-1080/` on this
branch for PR proof only.

### Test plan

- [ ] Open [preview
guide](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/platform/postgres-connection-logging)
— note admonition appears under Default behavior
- [ ] Confirm admonition on
[Logs](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/telemetry/logs#logging-postgres-connections),
[HIPAA
FAQ](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/security/hipaa-compliance),
[shared responsibility
bullet](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data),
and [SOC 2 item
5](https://docs-git-nikrichers-docs-1080-log-connections-e-b80046-supabase.vercel.app/docs/guides/security/soc-2-compliance)
- [ ] Merge #47253 on July 9 after the platform default is live

---------

Co-authored-by: Nik Richers <nik@validmind.ai>
2026-06-24 08:28:47 +02:00

82 lines
3.8 KiB
Plaintext

---
id: 'postgres-connection-logging'
title: 'Postgres connection logging'
description: 'Enable or disable Postgres connection logging for audit and compliance.'
---
For security monitoring and compliance audits, Postgres can log connection lifecycle events to your project's [Postgres logs](/docs/guides/telemetry/logs#postgres), including events such as `connection received`, `connection authenticated`, and `connection authorized`.
## Default behavior
By default, Supabase sets `log_connections` to off for new projects and you must enable it first. This behavior matches common managed Postgres defaults and reduces log volume from high-frequency connection events.
<$Partial path="log_connections_default_effective_date.mdx" />
Existing projects may retain different settings depending on plan and compliance configuration:
- **Team, Enterprise, and HIPAA organizations** — Connection logging is typically enabled to support audit requirements.
- **HIPAA projects** — Supabase enables connection logging when a project is marked as high compliance. The [Security Advisor](/dashboard/project/_/advisors/security) warns if connection logging is later disabled.
## Compliance considerations
<Admonition type="note">
If you need connection audit evidence for SOC 2 or other compliance programs, you must enable it explicitly.
</Admonition>
Connection logging supports audit and monitoring controls required by some compliance programs:
- **HIPAA** — High-compliance projects should keep connection logging enabled. See the [shared responsibility model for healthcare data](/docs/guides/deployment/shared-responsibility-model#managing-healthcare-data) and [HIPAA compliance guide](/docs/guides/security/hipaa-compliance).
- **SOC 2** — Users who need connection audit evidence should enable logging and retain logs according to their own policies. See the [SOC 2 compliance guide](/docs/guides/security/soc-2-compliance).
Disabling connection logging does not affect other Supabase logging (for example, [Platform Audit Logs](/docs/guides/security/platform-audit-logs), [Auth Audit Logs](/docs/guides/auth/audit-logs), or [pgAudit](/docs/guides/telemetry/logs#configuring-pgauditlog)).
## Manage connection logging via the dashboard
You can configure connection logging from the **Log connections** setting in the [Database Settings](/dashboard/project/_/database/settings) section of the Dashboard.
Ensure that you have [Owner or Admin permissions](/docs/guides/platform/access-control#manage-team-members) for the project.
<Admonition type="note">
Connection events appear in Postgres logs. In the [Logs Explorer](/dashboard/project/_/logs-explorer), connection lifecycle messages may be hidden by default to reduce noise. Use the connection logs filter in the sidebar to show or hide them.
</Admonition>
## Manage connection logging via the Management API
You can also manage connection logging using the [Management API](/docs/reference/api/v1-update-postgres-config):
```bash
# Get your access token from https://supabase.com/dashboard/account/tokens
export SUPABASE_ACCESS_TOKEN="your-access-token"
export PROJECT_REF="your-project-ref"
# Get current Postgres config
curl -X GET "https://api.supabase.com/v1/projects/$PROJECT_REF/config/database/postgres" \
-H "Authorization: Bearer $SUPABASE_ACCESS_TOKEN"
# Enable connection logging
curl -X PUT "https://api.supabase.com/v1/projects/$PROJECT_REF/config/database/postgres" \
-H "Authorization: Bearer $SUPABASE_ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"log_connections": true
}'
# Disable connection logging
curl -X PUT "https://api.supabase.com/v1/projects/$PROJECT_REF/config/database/postgres" \
-H "Authorization: Bearer $SUPABASE_ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"log_connections": false
}'
```
To verify the setting, use the SQL Editor:
```sql
show log_connections;
```