I audit apps built with AI tools. Most of the exposed credentials I find are Supabase keys, and most of them are not a problem.

That is the part people get wrong in both directions. Some panic about a key that was designed to be published. Others ship the one that grants full database access and never notice, because nothing breaks.

There are four keys. Two of them are being retired.

The deadline

Supabase is replacing the original anon and service_role keys. Their own timeline is blunt about what happens at the end: