Files
supabase/apps/studio/components/interfaces/Account/AccessTokens/MigrationAdmonition.tsx
Wen Bo Xie 0eb08cb9f0 docs: prepare scoped personal access tokens docs for GA (#50839)
Scoped personal access tokens are leaving alpha. Remove the pre-GA
framing
and update pages that assumed every token carries full account access.

- Personal Access Tokens guide: remove the public alpha / early access
admonition. Add a section on using a scoped token with the Supabase CLI:
  the browser flow of `supabase login` creates a classic token, while
SUPABASE_ACCESS_TOKEN or `supabase login --token` uses a scoped one, and
  commands that connect with the database password aren't limited by the
  token's permissions.
- Management API introduction: replace "PATs carry the same privileges
as
your user account" with the scoped vs. classic distinction and link to
the
  guide's permission tables.
- MCP guide: the CI setup now asks for a scoped token limited to the
  connected project and links to the MCP tool permissions table.
- API keys guide: replace the internal "fine-grained token" permission
ID
  with the names shown in the dashboard (API Keys, Read), and note that
  `reveal=true` in the example also needs API Key Secrets (Read).
- Managing environments: recommend a scoped token for the GitHub Actions
  deploy workflow.
2026-09-28 10:43:18 +09:00

52 lines
1.6 KiB
TypeScript

import { LOCAL_STORAGE_KEYS } from 'common'
import Link from 'next/link'
import { Badge, Button } from 'ui'
import { Admonition } from 'ui-patterns/Admonition'
import { useLocalStorageQuery } from '@/hooks/misc/useLocalStorage'
import { DOCS_URL } from '@/lib/constants'
export const MigrationAdmonition = () => {
const [isDismissed, setIsDismissed] = useLocalStorageQuery(
LOCAL_STORAGE_KEYS.SCOPED_TOKENS_MIGRATION_ADMONITION_DISMISSED,
false
)
if (isDismissed) return null
return (
<Admonition
type="default"
title="Access tokens can now be scoped"
className="relative mb-5"
actions={
<>
<Button asChild size="tiny">
<Link
href={`${DOCS_URL}/guides/platform/personal-access-tokens`}
target="_blank"
rel="noreferrer"
>
Learn more
</Link>
</Button>
<Button variant="text" onClick={() => setIsDismissed(true)} aria-label="Close">
Dismiss
</Button>
</>
}
>
<div className="flex flex-col gap-y-1.5">
<p className="text-sm text-foreground-light">
Choose which organizations and projects each new token can reach, and what it can do
there. Grant only what its integration needs.
</p>
<span className="text-sm text-foreground-light">
Tokens with full account access show a <Badge>Legacy</Badge> badge and keep working until
they expire or you delete them.
</span>
</div>
</Admonition>
)
}