DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
World desk4 min

Supabase Legacy API Key Migration: Fix Errors and Find Old Keys

Supabase’s legacy anon and service_role keys are being deprecated by the end of 2026. Learn the replacements, common migration errors, and how to find consumers before switching off old keys.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Supabase is deprecating its legacy anon and service_role API keys by the end of 2026. Their replacements are publishable keys for public clients and secret keys for trusted backends. Adding replacements does not revoke the old keys, so errors during migration usually come from a mismatched key location, missing authorization, or a permission/RLS issue—not simply from having both key types present.

A DEV Community listing credits Kavya with an article titled “I kept hitting Supabase errors, so I built a scanner for the legacy API key deprecation,” dated Sep 28 (the listing does not show a year). It establishes that a scanner article was published, but does not identify the scanner’s features, repository, or testing status. The practical steps below are based on Supabase’s migration guidance.

As an Amazon Associate I earn from qualifying purchases.

Which Supabase key replaces each legacy key?

Key Intended location Access and exposure
Publishable (sb_publishable_...) Public clients, such as web or mobile apps Maps to the low-privilege anon role for unauthenticated requests. It is suitable for public client code when your database access is protected appropriately by grants and RLS policies.
Secret (sb_secret_...) Trusted, developer-controlled backends Maps to service_role, has elevated access, and bypasses RLS. Keep it out of browsers, client bundles, user-distributed apps, and source control.

Supabase says the publishable key carries the same low privileges as the legacy anon key, so existing Row Level Security policies behave the same. An authenticated user is still represented by that user’s Supabase Auth JWT; a publishable key does not make every request anonymous.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

See Supabase’s migration guide and API-key guide for the current key behavior and project settings.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Why do errors appear after changing a key?

The new key is being sent as a JWT

Publishable and secret keys are not JWTs. Send the key in the apikey header; do not treat it as a bearer token or assume that JWT validation authenticates it. This matters especially with Edge Functions: verify_jwt behavior alone does not replace application-level authorization when a caller presents only an API key. Check Supabase’s migration instructions for the current Edge Function setup.

A service-role client is using a user’s Authorization header

If a backend client configured with a secret key unexpectedly encounters RLS restrictions, inspect the request’s Authorization header as well as its apikey value. A user session or explicitly supplied user JWT can take precedence over the expected service-role authorization context. Confirm which identity the request actually sends before changing policies.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

A query returns no rows, or reports a permission error

These outcomes point to different checks. An empty result can mean that an RLS policy matches no rows. A missing Postgres grant can instead produce a permission error. Check the table privileges and the applicable RLS policies separately; changing API keys does not itself repair either condition.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The old key still works

That is expected while migrating. Creating publishable and secret keys does not deactivate the legacy keys; Supabase supports a period when both are active. Legacy keys require a separate deactivation step once you have located and migrated their consumers.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How to migrate without breaking deployed clients

  1. Create the replacements. In the project dashboard, open Settings > API Keys and create a publishable key and a secret key. They can coexist with the legacy keys during the transition.
  2. Replace public-client uses. Change the legacy anon key to the publishable key in web, mobile, desktop, CLI, or script code distributed to users. Keep access controls in place; a public key is not a substitute for RLS or database grants.
  3. Replace backend uses. Change the legacy service_role key to a secret key in trusted server-side components. Store it in secure configuration rather than source code or a client bundle, and review which requests are made with a user JWT versus the privileged server identity.
  4. Update Edge Functions. Supabase documents SUPABASE_PUBLISHABLE_KEYS and SUPABASE_SECRET_KEYS environment values containing JSON objects keyed by key name, alongside the older variables. A function can parse the relevant object and read the named key. Supabase describes both a minimal environment-variable approach and use of the @supabase/server SDK, recommending the SDK for new functions. Whichever approach you use, send the new key in apikey and implement the handler’s authorization explicitly.
  5. Inventory every consumer before deactivation. Search deployed and stored configuration, including app versions already in users’ hands, CI/CD and deployment pipelines, third-party integrations, webhooks, cron jobs, workers, pg_net, and Database Webhooks. Supabase does not provide an automatic indicator that finds every legacy-key consumer for you.
  6. Deactivate the legacy keys. When you have migrated the consumers you found, return to Settings > API Keys and deactivate the old keys. Supabase says deactivation can be reversed if you discover a client that was missed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Can a scanner find every old Supabase key?

A scanner can be useful as one part of an inventory, but the DEV Community listing alone does not establish what Kavya’s scanner checks, what languages or files it supports, whether it is publicly available, or how accurate or tested it is. Do not treat that listing as evidence that a particular tool covers your deployment.

Regardless of tool, a repository search cannot by itself establish that every deployed app, CI/CD secret, integration, webhook, scheduled job, or worker has been updated. Check those systems and configurations directly, then verify requests in the environments where they actually run before deactivating legacy keys. The article listing appears on the DEV Community Supabase tag page.

Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.