Skip to content

D13 · New Supabase keys and session checks

Accepted · 2026-10-02 · zuki

Decision: v2 uses publishable and secret keys; new Supabase projects have no anon or service_role keys. Docs say "publishable key" and "secret key", and use anon, authenticated and service_role only as Postgres role names. proxy.ts checks sessions with getClaims(), which verifies the token locally. v1 moves to the new keys now, logged in the port log.

Why: Supabase plans to remove legacy keys in late 2026, which would break the frozen v1 during the build. getClaims() saves an Auth round trip on every request, and it is safe here because permissions come from the access tables, never from the token.