© 2026 Hedgehog Software, LLC

TwitterGitHubDiscord
More
CommunitiesDocsAboutTermsPrivacy
Search
Star
Setup for Free
SupabaseS
Supabase•2mo ago•
1 reply
Aron

Why are Supabase Access Tokens stored in local Storage?

self-hostedauth🟡javascript
I hooked supabase up with keycloak as oauth provider and I use the oauth weweb action to start the authentication process.

Apparently, supabase stores the access token in cookies as well as in the local storage. From my understanding, local storage can be read by (potentially malicious) javascript, thererfore it would be more secure to only have the access token inside a httpOnly cookie.

Is it really necessary to store access tokens in the local storage? Can I configure it, so only cookies are used?
Supabase banner
SupabaseJoin
Supabase gives you the tools, documentation, and community that makes managing databases, authentication, and backend infrastructure a lot less overwhelming.
45,816Members
Resources

Similar Threads

Was this page helpful?
Recent Announcements

Similar Threads

Auth token is stored in local storage?
SupabaseSSupabase / help-and-questions
3y ago
Is the JWT stored in local storage?
SupabaseSSupabase / help-and-questions
4y ago
Supabase S3 Storage - StorageUnknownError code: -32603
SupabaseSSupabase / help-and-questions
2y ago
Storage in Supabase
SupabaseSSupabase / help-and-questions
13mo ago