<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1786027145751449)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — a new legal page on the marketing site (`apps/www`). ## What is the current behavior? **Before:** the Program Addenda page at `/legal/partner-resources/program-addenda` lists exactly one addendum, the Integration Partner Addendum. There is no published Open Authorization (OAuth) addendum anywhere on the site. ## What is the new behavior? **After:** the Program Addenda page also lists the **Open Authorization Integration Addendum**, linking to a new page at `/legal/partner-resources/program-addenda/oauth-partner-addendum`. Formatting, breadcrumbs, version selector, and listing badge all match the existing Integration Partner Addendum. **How:** three files. - `apps/www/data/legal/partner-resources/oauth-partner-addendum/20260806-v1.mdx` — the addendum text, formatted to match `integration-partner-addendum/20260615-v1.1.mdx` (escaped section-number periods, `####` run-in headings for the lettered subsections, italic `_Label_` run-in labels for the enumerated data-protection clauses, explicit `[url](url)` links). - `apps/www/pages/legal/partner-resources/program-addenda/oauth-partner-addendum.tsx` — the page, mirroring `integration-partner-addendum.tsx` with a single-version `versions` array. - `apps/www/lib/addenda.ts` — adds a small `TITLE_OVERRIDES` map. The listing derives titles by capitalizing slug words, which turns `oauth-partner-addendum` into "Oauth Partner Addendum"; the override makes the listing link read the same as the page's `h1`. No other wiring was needed: the addenda listing is generated from the directory, so there is no hub entry, redirect, rewrite, sitemap entry, or `noindex` rule to add. ## Additional context Two things for the requester to confirm: - **The effective date is an assumption.** The addendum document itself contains no date. The listing and version label derive the effective date from the `YYYYMMDD` filename prefix, so this file is dated **August 6, 2026**, taken from the source document's own filename (`2026.08.06 - Supabase-OAuthAddendum-ONLINE.docx`). To change it, rename the file — no code change required. - **The legal text is a verbatim transcription.** Source wording, capitalization, and punctuation are preserved exactly as drafted, including anything that reads like a typo. Only markup was added; the plain text was diffed against the transcription and is character-identical. Please review the wording itself rather than assuming it was copy-edited. One wording choice that was not in the source document: the page subheader, "An addendum to the Master Partner Program Agreement governing OAuth integrations." It mirrors the one-line subheader style of the existing addendum page and is easy to reword. ## Also fixed here: a literal `(c)` rendered as `©` in legal headings While formatting the new addendum we hit a rendering bug that turned out to be **already live on supabase.com**, not new to this branch. The heading font, **Manrope**, ships a default-on standard `liga` feature that maps the glyph sequence `parenleft c parenright` to the copyright glyph. So a literal `(c)` anywhere inside an `h2`–`h6` on the marketing site paints as `©`. Body copy is unaffected because it uses Inter, whose subset has no such ligature — which is why this only ever shows up in headings. This branch adds a `legal-prose` utility (`font-variant-ligatures: no-common-ligatures`) in `apps/www/styles/globals.css` and applies it to two pages: - the new **Open Authorization Integration Addendum** page (heading `#### (c) Security.`), and - the **Master Partner Program Agreement** page, where the `#### (b) Such indemnity …` heading in section 17.1 contains `… ; or (c) replace the Covered Materials …` about 600 characters into the line. That page was **already published**, and rendered "or © replace the Covered Materials" in production. The MPPA change is one word — `className="prose"` → `className="prose legal-prose"`. **No legal text was modified**: no HTML entities, no zero-width characters, no rewording, no re-hyphenation. The DOM still holds `U+0028 U+0063 U+0029`; only the font's shaping is suppressed. Verified in Chromium against the real heading text and the same two font subsets `next/font` serves: the `(c)` run measures **15.36px** before the fix (a single `©` glyph) and **22.05px** after (three literal glyphs), against a 23.30px control for the `(b)` in the same heading. All 17 `.mdx` files under `apps/www/data/legal/` were swept for `(c)` and the other Manrope `liga` input sequences (`--`, `->`, `<-`, `(>)`, `<3`) on heading lines. The only two hits are the two pages fixed above; nothing else needs the utility today. (Headings do contain `ff`/`fi`/`fl`/`tt` — those ligatures are ordinary typography and are intentionally left alone.) **For future legal pages:** because the cause is the heading font's default ligature rather than anything about these documents, any new legal page whose source has `(c)` in a heading will need `legal-prose` on its prose container too. **One side effect worth flagging:** `no-common-ligatures` is blunt, so on those two pages it also suppresses the ordinary `fi`, `ff` and `tt` ligatures — a sweep of the legal `.mdx` files counts 107 such occurrences in headings (`fi` 83, `ff` 21, `tt` 3, `fl` 0), so the note above about leaving them alone holds for the rest of the site rather than for these two pages. That is a deliberate trade-off: correctness of the legal text beats typographic polish on two addendum pages. A narrower alternative exists — `font-feature-settings: "liga" 0` scoped to just the offending ligature, or overriding only the `parenleft_c_parenright` substitution — but it is more fragile and more subset-specific, so push back here if you would rather have that instead. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01VtcJJGqw5jL1ESwhs8DGCu --------- Co-authored-by: Claude <noreply@anthropic.com>
Supabase
Supabase is the Postgres development platform. We're building the features of Firebase using enterprise-grade open source tools.
- Hosted Postgres Database. Docs
- Authentication and Authorization. Docs
- Auto-generated APIs.
- Functions.
- File Storage. Docs
- AI + Vector/Embeddings Toolkit. Docs
- Dashboard
Watch "releases" of this repo to get notified of major updates.
Documentation
For full documentation, visit supabase.com/docs
To see how to Contribute, visit Getting Started
Community & Support
- Community Forum. Best for: help with building, discussion about database best practices.
- GitHub Issues. Best for: bugs and errors you encounter using Supabase.
- Email Support. Best for: problems with your database or infrastructure.
- Discord. Best for: sharing your applications and hanging out with the community.
How it works
Supabase is a combination of open source tools. We’re building the features of Firebase using enterprise-grade, open source products. If the tools and communities exist, with an MIT, Apache 2, or equivalent open license, we will use and support that tool. If the tool doesn't exist, we build and open source it ourselves. Supabase is not a 1-to-1 mapping of Firebase. Our aim is to give developers a Firebase-like developer experience using open source tools.
Architecture
Supabase is a hosted platform. You can sign up and start using Supabase without installing anything. You can also self-host and develop locally.
- Postgres is an object-relational database system with over 30 years of active development that has earned it a strong reputation for reliability, feature robustness, and performance.
- Realtime is an Elixir server that allows you to listen to PostgreSQL inserts, updates, and deletes using websockets. Realtime polls Postgres' built-in replication functionality for database changes, converts changes to JSON, then broadcasts the JSON over websockets to authorized clients.
- PostgREST is a web server that turns your PostgreSQL database directly into a RESTful API.
- GoTrue is a JWT-based authentication API that simplifies user sign-ups, logins, and session management in your applications.
- Storage a RESTful API for managing files in S3, with Postgres handling permissions.
- pg_graphql a PostgreSQL extension that exposes a GraphQL API.
- postgres-meta is a RESTful API for managing your Postgres, allowing you to fetch tables, add roles, and run queries, etc.
- Envoy is a cloud-native, high-performance edge and service proxy.
Client libraries
Our approach for client libraries is modular. Each sub-library is a standalone implementation for a single external system. This is one of the ways we support existing tools.
| Language | Client | Feature-Clients (bundled in Supabase client) | ||||
|---|---|---|---|---|---|---|
| Supabase | PostgREST | GoTrue | Realtime | Storage | Functions | |
| ⚡️ Official ⚡️ | ||||||
| JavaScript (TypeScript) | supabase-js | postgrest-js | auth-js | realtime-js | storage-js | functions-js |
| Flutter | supabase-flutter | postgrest-dart | gotrue-dart | realtime-dart | storage-dart | functions-dart |
| Swift | supabase-swift | postgrest-swift | auth-swift | realtime-swift | storage-swift | functions-swift |
| Python | supabase-py | postgrest-py | gotrue-py | realtime-py | storage-py | functions-py |
| 💚 Community 💚 | ||||||
| C# | supabase-csharp | postgrest-csharp | gotrue-csharp | realtime-csharp | storage-csharp | functions-csharp |
| Go | - | postgrest-go | gotrue-go | - | storage-go | functions-go |
| Java | - | - | gotrue-java | - | storage-java | - |
| Kotlin | supabase-kt | postgrest-kt | auth-kt | realtime-kt | storage-kt | functions-kt |
| Ruby | supabase-rb | postgrest-rb | - | - | - | - |
| Rust | - | postgrest-rs | - | - | - | - |
| Godot Engine (GDScript) | supabase-gdscript | - | - | - | - | - |
Badges
[](https://supabase.com)
<a href="https://supabase.com">
<img
width="168"
height="30"
src="https://supabase.com/badge-made-with-supabase.svg"
alt="Made with Supabase"
/>
</a>
[](https://supabase.com)
<a href="https://supabase.com">
<img
width="168"
height="30"
src="https://supabase.com/badge-made-with-supabase-dark.svg"
alt="Made with Supabase"
/>
</a>
Translations
- Arabic | العربية
- Albanian / Shqip
- Bangla / বাংলা
- Bulgarian / Български
- Catalan / Català
- Croatian / Hrvatski
- Czech / čeština
- Danish / Dansk
- Dutch / Nederlands
- English
- Estonian / eesti keel
- Finnish / Suomalainen
- French / Français
- German / Deutsch
- Greek / Ελληνικά
- Gujarati / ગુજરાતી
- Hebrew / עברית
- Hindi / हिंदी
- Hungarian / Magyar
- Nepali / नेपाली
- Indonesian / Bahasa Indonesia
- Italiano / Italian
- Japanese / 日本語
- Korean / 한국어
- Lithuanian / lietuvių
- Latvian / latviski
- Malay / Bahasa Malaysia
- Norwegian (Bokmål) / Norsk (Bokmål)
- Persian / فارسی
- Polish / Polski
- Portuguese / Português
- Portuguese (Brazilian) / Português Brasileiro
- Romanian / Română
- Russian / Pусский
- Serbian / Srpski
- Sinhala / සිංහල
- Slovak / slovenský
- Slovenian / Slovenščina
- Spanish / Español
- Simplified Chinese / 简体中文
- Swedish / Svenska
- Thai / ไทย
- Traditional Chinese / 繁體中文
- Turkish / Türkçe
- Ukrainian / Українська
- Vietnamese / Tiếng Việt
- List of translations



