Supabase Deep Scan
Link a Supabase project and inspect its public data controls from a verified domain.
Inspect public Supabase access
Supabase Deep Scan evaluates the public project surface available through the project URL and anonymous key. It is designed to identify risky anonymous access and Row Level Security behavior without requiring a service-role secret.
Meet the requirements
- The Platform domain must be verified.
- The project URL must belong to the application you are authorized to audit.
- Use the public anonymous key only. Never paste a service-role key.
Connect the project
VICE can detect public Supabase configuration from the application. If detection is incomplete, enter the project URL and anonymous key manually in the module page, then save the connection.
Review the detected project before scanning. A frontend can reference more than one backend, and discovery alone does not establish authorization.
Run the focused audit
Launch the Supabase-only audit from the module page. The run appears in the same domain history as other managed audits, with findings and coverage attached to the workspace.
Review and unlink
Confirm every data-access finding against the intended RLS policy and application flow. After changing policies, rerun the focused audit. Unlink the project when the domain no longer uses it or the relationship changes.
Continue with VICE
See how VICE audits Supabase RLS, storage, and authentication.