# How is the Supabase Private Key stored?

**URL:** <https://community.weweb.io/t/how-is-the-supabase-private-key-stored/14516>\
**Category:** Ask us anything\
**Tags:** supabase\
**Created:** [November 13, 2024, 2:46pm UTC](https://community.weweb.io/t/how-is-the-supabase-private-key-stored/14516 "2024-11-13T14:46:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul27](https://avatars.discourse-cdn.com/v4/letter/p/ac91a4/32.png) [@Paul27](https://community.weweb.io/u/Paul27)\
**Post date:** [November 13, 2024, 2:46pm UTC](https://community.weweb.io/t/how-is-the-supabase-private-key-stored/14516/1 "2024-11-13T14:46:51Z")

</div>

Hi,

Could you explain how WeWeb handles and stores the Supabase Private API Key?

Saw this in the docs and wanted to discuss a bit more:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/e/eed9df9122c8cfa0165a47399dbcc621ed7f0894.png)

Thanks 🙏

---

<div class="post-metadata">

**Author:** ![Broberto](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/broberto/32/5918_2.png) [@Broberto](https://community.weweb.io/u/Broberto)\
**Post date:** [November 13, 2024, 2:48pm UTC](https://community.weweb.io/t/how-is-the-supabase-private-key-stored/14516/2 "2024-11-13T14:48:37Z")

</div>

I think it’s stored on WeWeb’s servers. It’s mostly for introspection of the schema. It should not be bundled with your app.

---

<div class="post-metadata">

**Author:** ![Paul27](https://avatars.discourse-cdn.com/v4/letter/p/ac91a4/32.png) [@Paul27](https://community.weweb.io/u/Paul27)\
**Post date:** [November 13, 2024, 2:58pm UTC](https://community.weweb.io/t/how-is-the-supabase-private-key-stored/14516/3 "2024-11-13T14:58:56Z")

</div>

Hey, thanks for the answer. Found a rather good thread on the topic:

> [@WeWeb & Supabase - Security Concerns](https://community.weweb.io/t/weweb-supabase-security-concerns/7014):
>
> Hi everyone and the WeWeb team! I am writing because both we and our customers have security concerns regarding the WeWeb platform. First, we absolutely love WeWeb and enjoy building apps with it a great deal! However, one major concern we have is that WeWeb does not provide specific details on how our API tokens are stored and secured within their infrastructure. We use Supabase, and to utilize the Supabase Auth Plugin, we need to store the service\_role key in WeWeb. This key grants access to…
