mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 09:55:06 +03:00
The [User Management → Deleting users](https://supabase.com/docs/guides/auth/managing-user-data) section warned that deleting a user does not sign them out, but did not say what to do about it. Adds a **Removing account access** subsection: revoke sessions before deleting, why a soft-delete flag or [ban](https://supabase.com/docs/reference/javascript/auth-admin-updateuserbyid) is not a substitute, and the residual [access-token window](https://supabase.com/docs/guides/auth/sessions) after revocation. Fills a docs gap surfaced by [supabase/agent-skills#194](https://github.com/supabase/agent-skills/pull/194) while investigating the [`investigate-auth-001-deleted-user-access`](https://github.com/supabase/evals/blob/main/evals/investigate-auth-001-deleted-user-access/PROMPT.md) eval scenario. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the “Deleting users” guidance to specify deleting via `auth.admin.deleteUser()` (with `shouldSoftDelete: false`) and clarify that this cascades to sessions, invalidates refresh tokens, and blocks new access-token minting. * Rewrote the explanation to emphasize that it does not substitute for temporary bans or application-level “deleted” states. * Clarified the access-token window: already-issued stateless JWTs remain valid until `exp`, and recommended mitigations include short JWT expiry and enforcing session validation (via `session_id`) for sensitive actions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>