© 2026 Hedgehog Software, LLC

TwitterGitHubDiscord
More
CommunitiesDocsAboutTermsPrivacy
Search
Star
Setup for Free
SupabaseS
Supabase•4y ago•
2 replies
Julien

Server-side permission

Hello,

I built a REST API server for more complex queries that requires some validation.
My users, thanks to RSL, can do READONLY directly on the supabase.
Now, my server, I would like to make it do some update operations.
Do I have to use the secret service_role on my server to make these requests?
Or, is there a way to secure (instead of giving all rights everywhere...) the permissions of my server on the database? (For example, an API_KEY that is linked to another role for which I can apply other RSL?)

Thanks for helping
Supabase banner
SupabaseJoin
Supabase gives you the tools, documentation, and community that makes managing databases, authentication, and backend infrastructure a lot less overwhelming.
45,816Members
Resources

Similar Threads

Was this page helpful?
Recent Announcements

Similar Threads

Sveltekit Server side authentication
SupabaseSSupabase / help-and-questions
2mo ago
SvelteKit Server Side Authentication
SupabaseSSupabase / help-and-questions
5mo ago
Server Side Logout Support?
SupabaseSSupabase / help-and-questions
3y ago
Server Side Dynamic Page
SupabaseSSupabase / help-and-questions
4y ago