Skip to main content

Supabase Service Role JWT

Description​

General​

  • Documentation: https://supabase.io/docs/learn/auth-deep-dive/auth-deep-dive-jwts
  • Summary: Supabase provides an assisted solution to deploy a web application backend (database and API). JWT tokens are used as a means of authentication when performing API calls. This detector aims at catching service role JWT tokens, that have admin rights over the whole database.

Revoke the secret​

Contact the service support.

Details for Supabase Service Role JWT​

  • Family: token

  • Category: data_storage

  • Company: Supabase

  • High recall: False

  • Validity check available: True

  • Analyzer available: False

  • Revoker available: False

  • On-premise instances exist: False

  • Only valid secrets raise an alert: False

  • Occurrences found for one million commits: 15.03

  • Prefixed: False