github

JWT Secret Exposure in Supabase

Supabase security checks · HIGH

Your JWT secret is exposed. Anyone with it can sign in as any user.

What goes wrong

The legacy Supabase JWT secret is a symmetric key. Anyone who has it can forge a JWT for any user or role, including service_role, and get complete access to your database.

How it happens

The secret leaks through source control, logs, error messages or build artifacts.

How to find it

Search your codebase for long base64 strings that don’t look like standard Supabase keys, and check for .env files committed to git.

How to fix it

Migrate to asymmetric JWT signing keys in Dashboard → Settings → JWT Signing Keys → Migrate. Rotate the secret if it was exposed.

Check your own project

Locksoup runs these checks on your Supabase database in about a minute, with a read-only role, and gives you the SQL to fix what it finds.

Check my project