# How is the Supabase Private Key stored?

**URL:** <https://community.weweb.io/t/how-is-the-supabase-private-key-stored/14516>\
**Category:** Ask us anything\
**Tags:** supabase\
**Created:** [November 13, 2024, 2:46pm UTC](https://community.weweb.io/t/how-is-the-supabase-private-key-stored/14516 "2024-11-13T14:46:51Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![Paul27](https://avatars.discourse-cdn.com/v4/letter/p/ac91a4/32.png) [@Paul27](https://community.weweb.io/u/Paul27)\
**Post date:** [November 13, 2024, 2:58pm UTC](https://community.weweb.io/t/how-is-the-supabase-private-key-stored/14516/3 "2024-11-13T14:58:56Z")

</div>

Hey, thanks for the answer. Found a rather good thread on the topic:

> [@WeWeb & Supabase - Security Concerns](https://community.weweb.io/t/weweb-supabase-security-concerns/7014):
>
> Hi everyone and the WeWeb team! I am writing because both we and our customers have security concerns regarding the WeWeb platform. First, we absolutely love WeWeb and enjoy building apps with it a great deal! However, one major concern we have is that WeWeb does not provide specific details on how our API tokens are stored and secured within their infrastructure. We use Supabase, and to utilize the Supabase Auth Plugin, we need to store the service\_role key in WeWeb. This key grants access to…

---

_[View the full topic](https://community.weweb.io/t/how-is-the-supabase-private-key-stored/14516)._
