Free tool · No sign-up
Supabase Security Auditor
Audit your own Supabase project the way an attacker would probe it. Paste your project URL and anon key and it checks whether tables are readable without a login, whether storage buckets are world-listable, what your anon key's JWT actually grants, and whether you have pasted a service_role key somewhere a browser can see it. Every finding says which table or bucket, and how to close it.
Uses only the public key · nothing sent to JCIT
Method & assumptions
- This runs from your browser against your own project, using only the anon key — the same public key that already ships in your app. It exercises no access a normal visitor does not already have.
- A table is flagged as exposed only when an unauthenticated select returns real rows. An empty result is treated as inconclusive, not a pass, because RLS and an empty table look the same from outside.
- Storage findings come from the bucket list's own public/private flag. Auth findings are informational.
- The URL and key you enter go only to your Supabase project, never to JCIT. Nothing here is stored or logged.
Other tools
More on the bench
- 01
JWT Decoder
Paste a token, read what is inside. - 02
Secret & .env Scanner
Paste code or a .env, catch the leaked keys. - 03
Security Headers Scanner
Enter a URL, grade its headers. - 04
CORS Tester
See exactly what a URL allows cross-origin. - 05
Base64 Encode / Decode
Text or files, both directions. - 06
URL Encode / Decode
Percent-encoding, both directions. - 07
JSON Formatter
Validate, pretty-print, or minify. - 08
UUID Generator
v4 and v7, one or a thousand.
Software engineering
We write the software
behind tools like these
Anyone shipping a Supabase app who wants to be sure the anon key cannot read the whole database.
- Free diagnostics
- Same-day across most of the metro
- Named technicians
- No fix, no labour charge