7IT · News

Supabase tokens can now be fenced to one project. A leak shrinks with them.

By Lior AharonovFounder, 7IT Solutions ·

What happened

On Tuesday 6 October 2026, Supabase made scoped personal access tokens generally available. A token can be limited to selected projects or organizations, with read or read-write permission per capability and an expiry up to one year out. Existing tokens keep working, and GitHub secret scanning added a detector for the scoped token type on 5 October.

Why it matters

Think of the token sitting in your CI settings or on a contractor's laptop. An account-level token carries your access. A scoped one carries only what you picked, and Supabase says a leaked scoped token exposes far less.

What to do

List your Supabase access tokens today and replace each account-level one with a scoped token that has only the projects, permissions and expiry its integration needs.

Every token is a spare key to your house. Make it open one door, and give it an expiry date.

Lior Aharonov · my take

Sources

supabasesecuritytokensdatabase

Researched with AI tools; every fact is checked against the linked sources.

All 7IT news · Atom feed

Need a hand with something like this? Talk to 7IT.