mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
## What Adds a getting-started guide for migrating an existing project from the legacy JWT-based `anon` and `service_role` keys to the new publishable (`sb_publishable_...`) and secret (`sb_secret_...`) keys. The guide walks through the migration step by step: - **Before you start** — maps legacy keys to their replacements. - **Step 1** — create the new `default` keys. - **Step 2 / 3** — swap the publishable key in client code and the secret key in backend code. - **Database Webhooks and `pg_net`** — move the key from the `Authorization: Bearer` header to the `apikey` header (the new keys aren't JWTs and are rejected on `Authorization`), with a Vault note for not inlining secrets. - **Step 4** — update Edge Functions, with two options: read the new env vars (`SUPABASE_PUBLISHABLE_KEYS` / `SUPABASE_SECRET_KEYS`) and set `verify_jwt = false`, or adopt the `@supabase/server` SDK. - **Step 5 / 6** — verify nothing uses the legacy keys, then deactivate them (reversible). - **Next steps** — clarifies that JWT signing keys are a separate, independent migration. ## Notes While writing this we found Studio issues to fix separately (the Invoke Function cURL snippet and the Database Webhooks editor both put the new keys on the `Authorization` header). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a comprehensive migration guide for moving from legacy JWT-based API keys to the new publishable and secret keys with zero‑downtime steps, verification, limitations, and next steps. * Clarified API key behavior and recommended migration actions in the getting‑started docs. * Added a navigation entry linking to the new migration guide. * **Style** * Relaxed documentation lint rules to allow expected wording/phrases (e.g., "backends", "Database Webhooks"). <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>