D13 · New Supabase keys and session checks
Accepted · 2026-10-02 · zuki
Decision: v2 uses publishable and secret keys; new Supabase projects have no anon or service_role keys. Docs say "publishable key" and "secret key", and use anon, authenticated and service_role only as Postgres role names. proxy.ts checks sessions with getClaims(), which verifies the token locally. v1 moves to the new keys now, logged in the port log.
Why: Supabase plans to remove legacy keys in late 2026, which would break the frozen v1 during the build. getClaims() saves an Auth round trip on every request, and it is safe here because permissions come from the access tables, never from the token.