Skip to content
(347) 262-9435

Free tool · No sign-up

Supabase Security Auditor

Audit your own Supabase project the way an attacker would probe it. Paste your project URL and anon key and it checks whether tables are readable without a login, whether storage buckets are world-listable, what your anon key's JWT actually grants, and whether you have pasted a service_role key somewhere a browser can see it. Every finding says which table or bucket, and how to close it.

Uses only the public key · nothing sent to JCIT
Method & assumptions
  • This runs from your browser against your own project, using only the anon key — the same public key that already ships in your app. It exercises no access a normal visitor does not already have.
  • A table is flagged as exposed only when an unauthenticated select returns real rows. An empty result is treated as inconclusive, not a pass, because RLS and an empty table look the same from outside.
  • Storage findings come from the bucket list's own public/private flag. Auth findings are informational.
  • The URL and key you enter go only to your Supabase project, never to JCIT. Nothing here is stored or logged.

Software engineering

We write the software
behind tools like these

Anyone shipping a Supabase app who wants to be sure the anon key cannot read the whole database.

Or call and speak to someone who does the work(347) 262-9435inquiries@jcitsystems.com
  • Free diagnostics
  • Same-day across most of the metro
  • Named technicians
  • No fix, no labour charge