Is your Supabase app readable by anyone?
Apps built with Lovable, Bolt, Replit, Cursor or Claude often ship with a table anyone can read. Check what your site shows the world, then walk through the one check that matters, inside your own Supabase account.
How this check works
Your data stays where it is.
- It reads the page you name and up to six of your site’s own scripts: the same files every visitor’s browser receives. Size-capped, and it never follows your site to another address.
- It never sends a request to your database or to your Supabase project. Whether a table is readable is decided by Row Level Security inside your account, which no outside check can see. That is why the steps take you to Supabase’s own Security Advisor.
- A secret key is reported by its kind only, never shown and never stored, and only to a site that carries its ownership token.
- We keep an anonymous count of checks, for our own numbers. No address, no result, no key.
Supabase’s own guides: the Security Advisor, Row Level Security, publishable and secret keys.
More checks of your live app: the app security check and 7IT Guard.