Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

If you are getting Supabase errors after changing an API key, first check which key your code sends, where it sends it, and whether the request also carries a user authorization token. Supabase’s legacy anon and service_role keys are being deprecated by the end of 2026, but creating their replacements does not revoke the old keys. The transition is gradual: replace each use, verify it, then deactivate the legacy keys.

The DEV Community listing credits Kavya with an article titled “I kept hitting Supabase errors, so I built a scanner for the legacy API key deprecation,” displayed under the Supabase, Python, security, and open-source tags. The listing does not describe what the scanner checks, link its repository, or establish its capabilities, so the practical migration steps below rely on Supabase’s documentation rather than assumptions about that tool. DEV Community Supabase tag listing.

What is changing in Supabase API keys?

Supabase says it is deprecating the legacy anon and service_role keys by the end of 2026. Their replacements are publishable keys, which start with sb_publishable_, and secret keys, which start with sb_secret_. See Supabase’s migration guide for the current transition instructions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The usual replacement is anon with a publishable key in public-facing clients, and service_role with a secret key in trusted backend services. The names and formats changed, but the important distinction remains privilege and exposure: publishable keys are suitable for public clients, while secret keys grant elevated access and bypass Row Level Security (RLS). Supabase summarizes the latter plainly: “Secret keys allow elevated access to your project’s data.” Supabase API keys documentation.

#1 Best Overall
API Design Patterns
  • API Design Patterns
  • ABIS BOOK
  • Manning Publications
Key type Intended location Privilege and exposure
Publishable (sb_publishable_...) Public clients, such as web, mobile, or desktop apps Maps to the anon role for unauthenticated access; designed to be exposed in client applications. RLS policies still apply.
Secret (sb_secret_...) Trusted, developer-controlled backend services Maps to service_role, has elevated access, and bypasses RLS. Do not place it in a browser bundle, public client, or source repository.

A publishable key does not determine whether a request is an authenticated user request. When a user signs in, their Supabase Auth JWT is separate from the project API key. Supabase notes that publishable keys carry the same low privileges as the legacy anon key, so the RLS policies behave the same. Supabase API keys documentation.

Why can errors appear after changing a key?

A key replacement can expose mismatches that were hidden by the old configuration. Diagnose the exact response and headers before changing database policies or escalating privileges.

Permission error: check grants and request identity

A missing Postgres grant can produce a permission error. Separately, a request may be running under a user identity you did not expect: a service-role client can end up using a user session or an explicitly supplied user JWT in its Authorization header. Check both the apikey and Authorization headers and the client’s session behavior. Do not assume that configuring a secret key alone guarantees service-role authorization. Supabase API keys documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Empty results: inspect the RLS policy

An empty query result is not the same symptom as a permission failure. An RLS policy that matches no rows can return an empty result; a missing table grant produces a different permission error. Confirm which role and user identity the request uses, then check whether the relevant policy permits the rows being queried. Supabase API keys documentation.

Edge Function rejects a key as an invalid JWT

The new publishable and secret keys are not JWTs. Send them in the apikey header rather than treating them as bearer tokens. An Edge Function’s verify_jwt setting is not, by itself, application authorization for a caller presenting only an API key. Ensure the handler explicitly authorizes the request according to the function’s needs. Supabase’s migration documentation covers the key transition and function environment variables; its API-key guidance explains key behavior. Migration guide; API keys documentation.

Old key still works

That is expected until you separately deactivate it. Creating publishable and secret keys does not disable the legacy keys, and Supabase supports running both types during a gradual migration. Supabase migration guide.

How to migrate without breaking deployed clients

  1. Create the replacements. In your Supabase project, open Settings > API Keys and create the publishable and secret keys. Their creation does not disable the existing legacy keys, so you can update consumers incrementally. Supabase migration guide.
  2. Replace public-client uses of anon. Update web, mobile, desktop, CLI, and scripts shipped to users to use the publishable key. Do not put the secret key in any client-side code or bundle.
  3. Replace backend uses of service_role. Use the secret key only in controlled backend components. Keep it out of source control and client-delivered configuration, and confirm the request’s Authorization header is not unexpectedly carrying a user session.
  4. Update Edge Function configuration and code. Supabase documents SUPABASE_PUBLISHABLE_KEYS and SUPABASE_SECRET_KEYS environment values as JSON objects keyed by key name, alongside the legacy variables. A function can parse the relevant object and read the named key. Supabase also documents an @supabase/server SDK approach and recommends the SDK for new functions. In either implementation, send the API key in apikey and implement the function’s authorization explicitly; the key is not a JWT. Supabase migration guide.
  5. Inventory all remaining consumers. Search deployed app versions already in users’ hands, CI/CD and deployment configuration, third-party integrations, webhooks, cron jobs, workers, pg_net, Database Webhooks, and database calls. Supabase does not provide an automatic usage indicator covering every legacy-key consumer in this migration flow, so a missing reference in one repository is not proof that the key is unused. Supabase migration guide.
  6. Deactivate legacy keys only after migration checks. In Settings > API Keys, deactivate the legacy keys after the consumers have been located and updated. Supabase says deactivation can be reversed if a missed client is discovered. Supabase migration guide.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What a key scanner can—and cannot—tell you

A search tool can help locate literal key strings in files or configuration you give it, but the DEV Community listing alone does not establish that Kavya’s scanner does this, what sources it scans, whether it catches environment-managed or remotely stored keys, or whether it has been tested. Do not treat the listing as evidence of particular scanner features or accuracy. DEV Community Supabase tag listing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More broadly, finding a key string is only one part of migration inventory. A scanner cannot be assumed to see deployed application versions, values stored in a third-party dashboard, a webhook configuration, or a scheduled job unless those locations are actually included in its scope. Pair any code search with an operational inventory of where credentials are deployed, then verify each consumer before deactivation.

Where to verify the current migration instructions

Supabase’s guidance and product labels can change before the end-of-2026 deprecation deadline. Use the current migration guide for the transition sequence and Edge Function configuration, and the API keys guide for key roles, privilege, and authorization behavior.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.