mirror of
https://github.com/supabase/supabase.git
synced 2026-10-11 04:15:04 +03:00
Updates our documentation pages around the Data API to include instructions on how to grant the necessary privileges across API roles across tables and functions. Current behaviour means this is largely unnecessary as privileges are granted by default on public schema, but adding instructions will help cover scenarios where this isn't the case and expose some of the underlying magic happening. ## To test: - These updates refer to new settings that are added to the data api that give more visibility and control over what tables and functions are accessible via the api. - To view these settings you'll need enable `tableEditorApiAccessToggle ` feature flag <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a new "Data API" guide and removed the old "Hardening the Data API" page * Updated navigation links to surface the new Data API guide * Expanded quickstarts, SDK install pages, and security guides with step‑by‑step Data API exposure, default‑privileges, RLS guidance, and SQL GRANT examples (including function EXECUTE notes) * Updated troubleshooting references and added redirects for legacy documentation paths <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com> Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com> Co-authored-by: SaxonF <1072756+SaxonF@users.noreply.github.com> Co-authored-by: Chris Chinchilla <chris.ward@supabase.io> Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
48 lines
2.2 KiB
Plaintext
48 lines
2.2 KiB
Plaintext
---
|
|
title: 'Data API'
|
|
description: 'Quick options for managing Data API exposure and access.'
|
|
---
|
|
|
|
The Supabase Data API is a standalone server that sits between your application client code and your database. It automatically generates a fully RESTful API based on your database structure, allowing you to interact with your database through HTTP endpoints.
|
|
|
|
With the Data API, you have granular control over exposure: expose specific tables and functions by granting Data API roles the access they need, or enable **Default privileges for new entities** to automatically grant access to new tables and functions in `public`.
|
|
|
|
<Admonition type="caution">
|
|
|
|
Any table that is exposed through the Data API should have [Row Level Security (RLS) enabled](/docs/guides/database/postgres/row-level-security) to prevent unauthorized data access.
|
|
|
|
</Admonition>
|
|
|
|
## Expose specific tables and functions (recommended)
|
|
|
|
In [Data API integrations settings](/dashboard/project/_/integrations/data_api/settings), expose specific tables and functions and grant only the privileges each role needs.
|
|
|
|
```sql
|
|
grant select on table public.your_table to anon;
|
|
grant select, insert, update, delete on table public.your_table to authenticated;
|
|
grant execute on function public.your_function to anon, authenticated;
|
|
```
|
|
|
|
## Use default privileges for new entities in `public`
|
|
|
|
If you want new entities in `public` to be accessible automatically, enable **Default privileges for new entities** in the [**Integrations > Data API**](/dashboard/project/_/integrations/data_api/settings) section of the Dashboard. This applies only to new tables and functions in `public`.
|
|
|
|
```sql
|
|
alter default privileges for role postgres in schema public
|
|
grant select, insert, update, delete on tables to anon, authenticated, service_role;
|
|
|
|
alter default privileges for role postgres in schema public
|
|
grant execute on functions to anon, authenticated, service_role;
|
|
```
|
|
|
|
## Disable the Data API completely
|
|
|
|
If your app never uses Supabase client libraries, REST, or GraphQL data endpoints:
|
|
|
|
1. In the [**Integrations > Data API**](/dashboard/project/_/integrations/data_api/overview) section of the Dashboard.
|
|
1. Turn **Enable Data API** off.
|
|
|
|
## Learn more
|
|
|
|
To learn more about the Data API, see the [full guide](/docs/guides/api).
|