Supabase tokens can now be fenced to one project. A leak shrinks with them.
By Lior AharonovFounder, 7IT Solutions ·
On Tuesday 6 October 2026, Supabase made scoped personal access tokens generally available. A token can be limited to selected projects or organizations, with read or read-write permission per capability and an expiry up to one year out. Existing tokens keep working, and GitHub secret scanning added a detector for the scoped token type on 5 October.
Think of the token sitting in your CI settings or on a contractor's laptop. An account-level token carries your access. A scoped one carries only what you picked, and Supabase says a leaked scoped token exposes far less.
List your Supabase access tokens today and replace each account-level one with a scoped token that has only the projects, permissions and expiry its integration needs.
Every token is a spare key to your house. Make it open one door, and give it an expiry date.
Lior Aharonov · my takeSources
Researched with AI tools; every fact is checked against the linked sources.