Files
supabase/apps/docs/pages/guides/database/secure-data.mdx
T
Charis 4b1ade2e8d fix: improve information architecture (database) (#19847)
The REST and Database sections overlap in responsibilities, and the
Database subsections are getting quite long.

This clears up the responsibilities:

- Database operations belong primarily in `Database`
- Things that are specific to RESTful interactions (such as API keys)
  belong primarily in `REST API`
- `REST API` has a hub page that links out to `Database` for database
  operations

Left nav for the Database sectionis reorganized to make it more
beginner-friendly. `Fundamentals` and `Working with your database
(basics)` is what you really need to know to get started, and the rest
can be figured out later.
2023-12-19 13:08:12 +01:00

38 lines
2.0 KiB
Plaintext

import Layout from '~/layouts/DefaultGuideLayout'
export const meta = {
id: 'securing-your-data',
title: 'Securing your data',
}
Supabase helps you control access to your data. With access policies, you can protect sensitive data and make sure users only access what they're allowed to see.
## Connecting your app securely
Supabase allows you to access your database using the auto-generated [Data APIs](/docs/guides/database/connecting-to-postgres#data-apis). This speeds up the process of building web apps, since you don't need to write your own backend services to pass database queries and results back and forth.
You can keep your data secure while accessing the Data APIs from the frontend, so long as you:
- Turn on [Row Level Security](/docs/guides/database/postgres/row-level-security) (RLS) for your tables
- Use your Supabase **anon key** when you create a Supabase client
Your anon key is safe to expose with RLS enabled, because row access permission is checked against your access policies and the user's [JSON Web Token (JWT)](/docs/learn/auth-deep-dive/auth-deep-dive-jwts). The JWT is automatically sent by the Supabase client libraries if the user is logged in using Supabase Auth.
<Admonition type="danger" label="Never expose your service role key on the frontend">
Unlike your anon key, your **service role key** is **never** safe to expose because it bypasses RLS. Only use your service role key on the backend. Treat it as a secret (for example, import it as a sensitive environment variable instead of hardcoding it).
</Admonition>
## More information
Supabase and Postgres provide you with multiple ways to manage security, including but not limited to Row Level Security. See the Access and Security pages for more information:
- [Row Level Security](/docs/guides/database/postgres/row-level-security)
- [Managing Postgres roles](/docs/guides/database/postgres/roles)
- [Managing secrets with Vault](/docs/guides/database/vault)
export const Page = ({ children }) => <Layout meta={meta} children={children} />
export default Page