mirror of
https://github.com/supabase/supabase.git
synced 2026-10-10 20:05:06 +03:00
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Add context around storage signed URLs using separate signing key and invalidating/revoking URLs. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified Supabase Storage signed URLs are generated and validated independently from Auth JWT keys, remain valid until their expiration even if Auth keys change (rotation, disabling, or algorithm switch), and can only be revoked by contacting Supabase support. [](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/45841) <!-- end of auto-generated comment: release notes by coderabbit.ai -->