Skip to content

Supabase Deep Scan

Link a Supabase project and inspect its public data controls from a verified domain.


Inspect public Supabase access

Supabase Deep Scan evaluates the public project surface available through the project URL and anonymous key. It is designed to identify risky anonymous access and Row Level Security behavior without requiring a service-role secret.

PROJECT URLANON KEYAUDITRLS POLICIES!STORAGEAUTH

Meet the requirements

  • The Platform domain must be verified.
  • The project URL must belong to the application you are authorized to audit.
  • Use the public anonymous key only. Never paste a service-role key.

Connect the project

VICE can detect public Supabase configuration from the application. If detection is incomplete, enter the project URL and anonymous key manually in the module page, then save the connection.

Review the detected project before scanning. A frontend can reference more than one backend, and discovery alone does not establish authorization.

Run the focused audit

Launch the Supabase-only audit from the module page. The run appears in the same domain history as other managed audits, with findings and coverage attached to the workspace.


Continue with VICE

See how VICE audits Supabase RLS, storage, and authentication.

Explore Supabase scanning