Identity and security
API key
An API key identifies an application or service when it calls an API. Its permissions depend on the provider. Some keys are designed for public clients; privileged secret keys belong only in trusted server code.
You might see: API credential, application key
In a real project
Your browser uses a Supabase publishable key together with the user's session. A trusted maintenance job may use a secret key for privileged work. Those two keys have different permission boundaries.
A common mistake
Putting a privileged key in browser code because the request works. Anyone who receives that code can extract the key, and a database role that bypasses RLS will not be constrained by ordinary row policies.
Put it into practice
These lessons open through your account. Your kit determines which are available.
Go to the source
Sources checked .