Auth and server
Environment
Validated Supabase settings, with every framework spelling and no leaked values.
import { loadEnv, publicEnv } from "better-supabase/env";
const env = loadEnv(); // reads process.env, throws EnvValidationError
const browser = publicEnv(env); // { url, publishableKey }, safe to shiploadEnv() accepts the spellings frameworks use, the first one set wins:
| Setting | Variables |
|---|---|
url | SUPABASE_URL, with NEXT_PUBLIC_, VITE_, PUBLIC_, EXPO_PUBLIC_, NUXT_PUBLIC_ |
publishableKey | SUPABASE_PUBLISHABLE_KEY (same prefixes), SUPABASE_PUBLISHABLE_DEFAULT_KEY, SUPABASE_PUBLISHABLE_KEYS |
secretKey | SUPABASE_SECRET_KEY, SUPABASE_SECRET_KEYS |
dbUrl | SUPABASE_DB_URL, DATABASE_URL |
jwksUrl | SUPABASE_JWKS_URL, else derived from url |
jwks | SUPABASE_JWKS: inline keys as {"keys":[...]} or [...], used instead of fetching jwksUrl |
readUrl | SUPABASE_READ_URL, a read replica API URL (server only) |
jwtSecret | SUPABASE_JWT_SECRET, the HS256 secret Supabase Lite signs with (server only) |
What is checked
- The URL is
https, orhttponlocalhost,127.0.0.1or[::1]only. - Keys use the new format:
sb_publishable_…andsb_secret_…. LegacyeyJ…JWT keys are rejected with a pointer to the API Keys settings. - A secret key in a publishable variable is an error, not a warning.
SUPABASE_JWKSis JSON with at least one key that has akty, read the way@supabase/serverreads it.SUPABASE_JWT_SECREThas at least 32 characters. Onlybackend: 'lite'reads it.require: ['secretKey', 'dbUrl']makes optional settings mandatory.SUPABASE_PUBLISHABLE_KEYSandSUPABASE_SECRET_KEYSmust be JSON objects of key names to keys. All secret keys are kept inenv.secretKeys(the single key isdefault), so a server can accept named keys.
Error messages name the variables and never include their values, so they are safe to log.
Standard Schema
envSchema() is the same validator as a Standard Schema,
for t3-env, framework config or any other validator slot:
import { envSchema } from "better-supabase/env";
const result = await envSchema({ require: ["secretKey"] })[
"~standard"
].validate(process.env);With @supabase/server
toServerEnv(env) returns the SupabaseEnv that withSupabase({ env })
and the @supabase/server core functions take.
Client bundles
Next.js only inlines NEXT_PUBLIC_* variables that are read literally. In
browser code, pass them explicitly:
loadEnv({ NEXT_PUBLIC_SUPABASE_URL: process.env.NEXT_PUBLIC_SUPABASE_URL, … }).
Last updated on