<- all tokdocs

Supabase Turns On Row Level Security by Default Only for Dashboard-Created Tables, and Its Data API Default Changed on 2026-04-28

Watch on TikTok

View on TikTok ->

This is a 74-second clip (1:14), delivered at 1080 by 1920 vertical in an h265 video and AAC audio stream pulled at 1,603 kbps, posted 2026-08-18 at 12:29:47 UTC by @alanonai, whose channel nickname is "Alan on AI" and whose article series points to Alan Knox at alanknox.com. At capture the metadata records 36,000 plays, 1,253 likes, 137 comments, 46 reposts and 607 saves. TikTok attaches the track "Inspiring Melody" from the album of the same name by Celestial Symphony, though the audible track is speech only with no music bed. I read 16 of the 37 extracted frames at 2-second intervals and all 244 words of the transcript. The entire clip is one handheld selfie shot in a suburban backyard. The speaker wears a dark green v-neck t-shirt and stands on cut grass in front of a birch tree. Early frames show a pale wooden fence and a cream-colored two-story house over his left shoulder. By frame 28 the camera has rotated roughly ninety degrees and a sage-green two-story house with a covered porch, red flowers and a weathered gray fence fills the right side. Frames 1 and 2 carry a two-part burned-in title card reading "Engineering for / AI Vibe Coders" above a large outlined "Supabase" wordmark; the card drops out by frame 3 and never returns. Everything else on screen is auto-generated word-by-word caption text in white condensed sans-serif, quoted verbatim across the frames I read: "SO LET'S TALK", "IF YOU'RE BUILDING WITH AI,", "THERE'S A GOOD CHANCE / THAT YOUR AI / HAS", "IT IS ONE OF / THE MOST RECOMMENDED / THIRD", "THERE'S A COUPLE OF REASONS.", "WHICH IS ARGUABLY ONE / OF THE BEST / RELATIONAL DATABASES.", "AND", "SO", "BECAUSE IN ONE", "MANY COMPLEX", "BUT THE THING IS, / THAT DOESN'T MEAN / THAT IT'S RIGHT / FOR YOUR", "YOU NEED TO", "AND THAT'S TRUE OF ANYTHING,", "AS PART OF MY / ENGINEERING FOR VIBE", "AND THEN A COUPLE / OF THINGS TO / LOOK", and "AND I'D". There is no screen recording, no SQL, no dashboard, no code block, no policy listing and no numeric figure anywhere in the 37 frames. Every technical claim in this post is spoken or written in the TikTok caption, and every one of them is checked below against Supabase's own documentation, changelog and pricing page.

The clip's hardest claim lives in its caption, and Supabase only enables Row Level Security by default on the path an AI agent does not use

The spoken transcript never mentions Row Level Security. The TikTok description does, and it carries the sharpest line in the whole post: "So if AI gives you some SQL or tells you to disable Row Level Security to fix an error, do not just paste it in. Ask why."

That framing assumes RLS is on, and that the dangerous action is turning it off. Supabase's own Securing your API page states the default narrowly: "Tables created through the Supabase Dashboard have RLS enabled by default." Tables created any other way require explicit enablement. The Row Level Security guide gives the statement you have to run yourself, alter table public.reports enable row level security;, and warns that "A table in an exposed schema without RLS is readable and writable by any role with a grant on it."

The gap matters precisely because of how AI coding tools work. An assistant that writes a migration or pastes create table into the SQL editor is taking the path where RLS starts off, not the Table Editor path where it starts on. So the realistic failure is a table that was never protected, rather than a protection someone switched off.

Grants compound this. The same securing-your-api page records that "tables created in public receive SELECT, INSERT, UPDATE, and DELETE privileges for anon, authenticated, and service_role by default," and the RLS guide adds that "Adding policies doesn't take those grants back. A table protected only by policies still hands anon an insert path if you never revoke the grant." Enabling RLS and writing policies does not undo the underlying grant. Two separate things have to be correct.

The one piece of good news in the docs confirms the clip's instinct about pasted fixes. Once RLS is on, the failure mode is closed rather than open: "Once RLS is enabled, no data is accessible through the API when using a publishable key, until you create policies." An AI that hits an empty result and recommends disabling RLS to make the error go away is trading a blocked read for an open table.

Supabase changed its Data API exposure default four months before this clip posted, and enforcement on all projects lands 2026-10-30

The clip's thesis is that you should ask why a platform is right for you. It leaves out that the platform's defaults are actively moving, which changes what "why" even answers.

The Supabase changelog entry 45329, dated 2026-04-28, reads in full: "New tables in the public schema will no longer be exposed to the Supabase Data API by default. Opt-in today, default for new projects on 2026-05-30, enforced on all projects on 2026-10-30."

Lay that against the clip's own timeline. The video posted 2026-08-18. That is 112 days after the changelog, and 80 days after the new-project default flipped on 2026-05-30. Anyone who created a Supabase project before 2026-05-30 and watched this video in August was running the old behavior, where a new public table became reachable through the Data API without any further action. Anyone who created a project after that date was running the new behavior. The same advice produces different outcomes depending on a project creation date the clip never mentions.

As of today, 2026-10-05, the enforcement date is 25 days out. A reader following this clip's advice to "ask why" now has a concrete question that the clip does not supply: whether their project has "Automatically expose new tables" still checked, and what breaks on 2026-10-30 when it is enforced everywhere.

The credential that must stay out of the frontend has been renamed, and the one the clip's audience will see in docs is scheduled for removal by the end of 2026

The caption states that "There are still credentials that absolutely should not end up in your frontend." That is correct and it is the right warning. The naming has moved underneath it.

Supabase's API Keys page sets out the current pairs. The anon key is described as the "Legacy version of publishable keys" and service_role as the "Legacy version of secret keys." The modern publishable key carries the sb_publishable_ prefix and is "Safe to expose online: web page, mobile or desktop app, GitHub actions, CLIs." The modern secret key carries the sb_secret_ prefix and should "Only use in backend components of your app, such as servers, APIs...Edge Functions, and microservices."

The reason the secret key is the one that cannot ship to a browser is a database attribute rather than a convention. Per the same page, secret keys map to service_role, which "has the BYPASSRLS attribute," meaning they "skip every Row Level Security policy." A leaked secret key makes every policy discussed in the section above irrelevant.

Supabase has added a backstop that is worth knowing because it is partial. The docs state: "A secret key doesn't work in a browser. Supabase matches on the User-Agent header and returns HTTP 401 Unauthorized." That blocks the accidental browser call. It does not protect a key that has already been committed to a public repository and can be replayed from a non-browser client.

On timing, both the API Keys page and the migration guide state that "Supabase is deprecating the anon and service_role keys by the end of 2026." The migration guide also notes that "Older projects don't have these keys yet" and that creating them "is safe. It adds a publishable key and a secret key alongside your existing anon and service_role keys." The underlying reason appears in the JWT Signing Keys post, published 2025-07-14, which explains that the legacy keys are "JWTs that expire 10 years after you create your project," so rotating the shared JWT secret would invalidate them.

The free tier that makes Supabase an easy AI recommendation is 500 MB, and free projects pause after one week of inactivity

The clip explains why an AI recommends Supabase in terms of surface area: one API covering database, auth, edge functions and storage. It does not price any of it. The pricing page lists four plans: Free at $0 per month, Pro from $25 per month, Team from $599 per month, and Enterprise at custom pricing.

The Free plan limits are specific enough to plan against. The page lists "500 MB database size (Shared CPU • 500 MB RAM)", "5 GB egress" plus "5 GB cached egress", "1 GB file storage", "50,000 monthly active users", and "500,000 included" Edge Function invocations. Two operational constraints are easy to miss and matter more than the quotas for anyone prototyping: "Free projects are paused after 1 week of inactivity" and "Limit of 2 active projects."

The jump from Free to Pro is a 25x step in monthly cost, and the jump from Pro to Team is roughly 24x on the stated starting prices. That is the concrete version of the question the clip asks you to ask, and the clip never puts a number on it.

For context on the project's scale, the supabase/supabase repository returned 111,108 stars and 15,841 forks from the GitHub REST API on 2026-10-05, under an Apache-2.0 license, created 2019-10-12. Supabase's own 2025 security retrospective, published 2026-01-07, reports that "Since launch, we have resolved 139 reports from 96 researchers" through its HackerOne program.

The component list in the transcript checks out, and the two things the clip gets loosest are a name and an unsourced popularity claim

The spoken inventory is accurate. Supabase does provide a Postgres database, authentication, Edge Functions and storage. The Auth guide confirms the integration the clip gestures at without naming: "Supabase Auth uses JSON Web Tokens (JWTs) for authentication," and "your data requests are automatically sent with the user's Auth Token. The Auth Token scopes database access on a row-by-row level when used along with RLS policies."

Storage behaves closer to the clip's caution than its casual "some storage as well" suggests. The Storage Access Control page states that "By default Storage does not allow any uploads to buckets without RLS policies," and that you "selectively allow certain operations by creating RLS policies on the storage.objects table." The exception is the one people create without thinking: for public buckets, policies are "not needed for public buckets, as they are already publicly accessible."

Connection pooling is the one area where the clip's "it's just Postgres underneath" framing understates the operational detail. Per Connecting to Postgres, "Port 5432 reaches Postgres for a direct connection and Supavisor for session mode. Port 6543 reaches PgBouncer for the dedicated pooler and Supavisor for shared transaction mode." Direct connections are IPv6 by default, "or on IPv4 if the project has the IPv4 add-on," while the "shared pooler is IPv4-only on every plan, in both session and transaction mode." PgBouncer is not a historical footnote here: changelog 34404, dated 2025-03-25, announced the Dedicated Pooler as "a PgBouncer instance co-located with your Postgres database," available "for paid plans on the Supabase platform while free and paid plans continue to benefit from our Shared Pooler via Supavisor."

Two items do not hold up. First, the burned-in title card reads "Engineering for AI Vibe Coders," while the spoken audio says "Engineering for Vibe Coder series" and the published series on alanknox.com is titled "Engineering for Vibe Coders." The on-screen card adds a word the series does not use. Second, the claim that Supabase "is one of the most recommended third-party systems by AI" is asserted with no source in the clip, and I found no primary measurement of model recommendation frequency to check it against. It may well be true. It is not evidenced here, and I am not restating it as fact.

One more thing worth flagging for anyone who follows the clip's closing instruction to look for the article. The series index at alanknox.com lists dozens of "Engineering for Vibe Coders" entries, and as of 2026-10-05 I could not find one specifically about Supabase. The nearest match is Backend vs Backend-as-a-Service. The clip says the link is in the comments, which I cannot read from the downloaded metadata, so the article may exist somewhere I did not reach.

Key Takeaways

  • Correction: the clip's caption treats disabling Row Level Security as the risk, which implies RLS starts on. Supabase states that only "Tables created through the Supabase Dashboard have RLS enabled by default." A table an AI creates by running SQL starts with RLS off, so the common failure is a table that was never protected.
  • Correction: the on-screen title card reads "Engineering for AI Vibe Coders." The spoken audio and the published series both use "Engineering for Vibe Coders," with no "AI."
  • Correction: the clip presents Supabase defaults as a stable thing to reason about. Supabase changed the Data API exposure default in changelog 45329 on 2026-04-28, 112 days before this video posted, with new-project default on 2026-05-30 and enforcement on all projects on 2026-10-30.
  • Partial correction: "Credentials that should not end up in your frontend" is right, and the names have changed. service_role is now the legacy form of the secret key (sb_secret_), and anon is the legacy form of the publishable key (sb_publishable_). Supabase is "deprecating the anon and service_role keys by the end of 2026."
  • Verified: Supabase bundles Postgres, Auth, Edge Functions and Storage, as the transcript says. Auth issues JWTs and scopes database access row by row when combined with RLS policies.
  • Verified: enabling RLS fails closed. "Once RLS is enabled, no data is accessible through the API when using a publishable key, until you create policies."
  • Verified: secret keys map to service_role, which "has the BYPASSRLS attribute" and therefore skips every RLS policy. Supabase also returns HTTP 401 for secret keys sent from a browser based on the User-Agent header.
  • Unstated cost: the Free plan is 500 MB of database, 1 GB of file storage, 5 GB of egress, 50,000 monthly active users and 500,000 Edge Function invocations, capped at 2 active projects, and "Free projects are paused after 1 week of inactivity." Pro starts at $25 per month and Team at $599 per month.
  • Unstated caveat: enabling RLS does not revoke the default table grants to anon and authenticated. Supabase states that "A table protected only by policies still hands anon an insert path if you never revoke the grant."
  • Unstated caveat: Storage blocks uploads to buckets without policies, and a bucket marked public is "already publicly accessible" with no policy required.
  • Unverified: "one of the most recommended third-party systems by AI" has no source in the clip and no primary measurement I could locate.
  • Unverified: I could not find a Supabase-specific article in the "Engineering for Vibe Coders" index as of 2026-10-05. The clip says the link is in the TikTok comments, which are not in the downloaded metadata.

Resources

Published August 18, 2026. Writeup generated from a favorited TikTok.