Home / Companies / Supabase / Blog / Post Details
Content Deep Dive

Supabase Security Retro: 2025

Blog post from Supabase

Post Details
Company
Date Published
Author
Bil Harmer and Paul Copplestone
Word Count
3,436
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

In 2025, Supabase implemented numerous security enhancements focusing on safer defaults and improved tooling, such as enabling Postgres Row Level Security (RLS) by default for new tables and introducing a new API key system with asymmetric JWTs for enhanced security. These updates included automatic revocation of leaked keys detected via GitHub, clear warnings for tables without RLS, and a Security Advisor to identify misconfigurations. Looking ahead to 2026, Supabase plans further improvements, including UI controls for API access, enhanced security alerts, and integration with tools like OpenFGA for finer-grained permissions. The ongoing vulnerability disclosure program via HackerOne will expand to include paid bounties, and there will be continued efforts to integrate security checks into developers' workflows with tools like the dashboard Assistant. Additionally, stricter default security settings and options for hardened project configurations will be made available, alongside measures to restrict database access and reduce attack surfaces, such as disabling pg_graphql by default on new projects.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 2 3,702 403 162 -31%
Secrets Management 2 1,271 215 97 -1%
Real-time 1 6,429 1,407 265 -24%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.