© 2026 Hedgehog Software, LLC

TwitterGitHubDiscord
More
CommunitiesDocsAboutTermsPrivacy
Search
Star
Setup for Free
SupabaseS
Supabase•5mo ago•
5 replies
Idris

Benefit of verify JWT in edge functinos

Whats the benefit of the following option:
Verify JWT with legacy secret
Requires that a JWT signed only by the legacy JWT secret is present in the Authorization header. The easy to obtain anon key can be used to satisfy this requirement. Recommendation: OFF with JWT and additional authorization logic implemented inside your function's code.
Verify JWT with legacy secret
Requires that a JWT signed only by the legacy JWT secret is present in the Authorization header. The easy to obtain anon key can be used to satisfy this requirement. Recommendation: OFF with JWT and additional authorization logic implemented inside your function's code.


Since you can just use the anon key anyways, so you should asume anyone can call this function. So I feel this doesnt offer additional security, since you have to check the token yourself anyways and see if its a authenticated user. Am I missing something or is this safe to disable, since it doesnt offer any security. If so I can transition to the new api keys
Supabase banner
SupabaseJoin
Supabase gives you the tools, documentation, and community that makes managing databases, authentication, and backend infrastructure a lot less overwhelming.
45,816Members
Resources

Similar Threads

Was this page helpful?
Recent Announcements

Similar Threads

How to verify JWT on Edge Functions
SupabaseSSupabase / help-and-questions
3y ago
Verify JWT
SupabaseSSupabase / help-and-questions
2mo ago
The edge function Verify JWT with legacy secret turn back ON automatically!
SupabaseSSupabase / help-and-questions
2w ago
Edge function giving Invalid JWT
SupabaseSSupabase / help-and-questions
7mo ago