mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 09:55:06 +03:00
*Summary* - reorganize the navigation menu to highlight modules, consolidate API security content, and move guide entries (auto-generated docs, type generation, security topics) to the intended sections - relocate the Data API hardening and custom claims RBAC guides into the API subtree, updating internal references and redirects, and fixing cross-links (including adjusting the Security reference order) - adjust data API topic references (e.g., securing guide and role management) to point to the new paths and ensure the helper link ordering follows the requested layout *Testing* - Not run (not requested) Change 1 <img width="1286" height="576" alt="image" src="https://github.com/user-attachments/assets/d903e9b0-bbfc-403f-bcb9-eee540e466db" /> Change 2 <img width="1176" height="666" alt="image" src="https://github.com/user-attachments/assets/82b3ea4c-b8d4-4cb9-ad90-6c39c8a1a997" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Reorganized API documentation structure, consolidating REST and GraphQL API guides under a dedicated API section. * Moved security-related guides to API documentation paths for better organization. * Implemented automatic redirects for old documentation links to new locations. * Updated navigation menu to reflect the restructured documentation layout. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Chris Chinchilla <chris.ward@supabase.io> Co-authored-by: Chris Chinchilla <chris@chrischinchilla.com>
34 lines
2.0 KiB
Plaintext
34 lines
2.0 KiB
Plaintext
---
|
|
id: 'securing-your-data'
|
|
title: 'Securing your data'
|
|
---
|
|
|
|
Supabase helps you control access to your data. With access policies, you can protect sensitive data and make sure users only access what they're allowed to see.
|
|
|
|
## Connecting your app securely
|
|
|
|
Supabase allows you to access your database using the auto-generated [Data APIs](/docs/guides/database/connecting-to-postgres#data-apis). This speeds up the process of building web apps, since you don't need to write your own backend services to pass database queries and results back and forth.
|
|
|
|
You can keep your data secure while accessing the Data APIs from the frontend, so long as you:
|
|
|
|
- Turn on [Row Level Security](/docs/guides/database/postgres/row-level-security) (RLS) for your tables
|
|
- Use your Supabase **anon key** when you create a Supabase client
|
|
|
|
Your anon key is safe to expose with RLS enabled, because row access permission is checked against your access policies and the user's [JSON Web Token (JWT)](/docs/learn/auth-deep-dive/auth-deep-dive-jwts). The JWT is automatically sent by the Supabase client libraries if the user is logged in using Supabase Auth.
|
|
|
|
<Admonition type="danger" label="Never expose your service role key on the frontend">
|
|
|
|
Unlike your anon key, your **service role key** is **never** safe to expose because it bypasses RLS. Only use your service role key on the backend. Treat it as a secret (for example, import it as a sensitive environment variable instead of hardcoding it).
|
|
|
|
</Admonition>
|
|
|
|
## More information
|
|
|
|
Supabase and Postgres provide you with multiple ways to manage security, including but not limited to Row Level Security. See the Access and Security pages for more information:
|
|
|
|
- [Row Level Security](/docs/guides/database/postgres/row-level-security)
|
|
- [Column Level Security](/docs/guides/database/postgres/column-level-security)
|
|
- [Hardening the Data API](/docs/guides/api/hardening-data-api)
|
|
- [Managing Postgres roles](/docs/guides/database/postgres/roles)
|
|
- [Managing secrets with Vault](/docs/guides/database/vault)
|