# Supabase Anon Key Removal

**URL:** <https://community.weweb.io/t/supabase-anon-key-removal/20867>\
**Category:** Developer corner\
**Tags:** supabase\
**Created:** [March 6, 2026, 7:48am UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867 "2026-03-06T07:48:51Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ronaldvm](https://avatars.discourse-cdn.com/v4/letter/r/9dc877/32.png) [@Ronaldvm](https://community.weweb.io/u/Ronaldvm)\
**Post date:** [March 6, 2026, 7:48am UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/1 "2026-03-06T07:48:51Z")

</div>

Today I received a message from Supabase they will remove the use of the Anon Key.

> **[Breaking Change: Removing access to OpenAPI spec via the anon key · supabase...](https://github.com/orgs/supabase/discussions/42949)**
>
> What’s Changing? The Data API returns the full OpenAPI spec for any schema exposed to the Data API at the root path: https://\[projectref\].supabase.co/rest/v1/ Starting March 11, we will begin depre...

If I check the request made by my project to the supabase /rest/v1 in the Log file, the request are made by the Anon key.

In the WeWeb Supabase Plugin I’ve tried to change the ‘Public Api Key’ to a new ‘Publishable Key’, but this results in a ‘Invalid Supabase Auth configuration.’-error in WeWeb.

How do I have to solve this issue, as the Anon key will be removed 8th of april, it’s quite urgent.

---

<div class="post-metadata">

**Author:** ![Philibert](https://avatars.discourse-cdn.com/v4/letter/p/ee7513/32.png) [@Philibert](https://community.weweb.io/u/Philibert)\
**Post date:** [March 6, 2026, 8:11am UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/2 "2026-03-06T08:11:34Z")

</div>

I was going to ask the same question here,

Seems like we have a month or so to make the changes

Is that something to change on the Supabase Plugin on Weweb ?

Thanks !

---

<div class="post-metadata">

**Author:** ![Ruak](https://avatars.discourse-cdn.com/v4/letter/r/91b2a8/32.png) [@Ruak](https://community.weweb.io/u/Ruak)\
**Post date:** [March 6, 2026, 9:33am UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/3 "2026-03-06T09:33:46Z")

</div>

Same issue for me. Not sure how this will affect the auth process.

---

<div class="post-metadata">

**Author:** ![Peer](https://avatars.discourse-cdn.com/v4/letter/p/e9bcb4/32.png) [@Peer](https://community.weweb.io/u/Peer)\
**Post date:** [March 6, 2026, 1:44pm UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/4 "2026-03-06T13:44:13Z")

</div>

Same Issue here

---

<div class="post-metadata">

**Author:** ![Joyce](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/joyce/32/13232_2.png) [@Joyce](https://community.weweb.io/u/Joyce)\
**Post date:** [March 6, 2026, 10:38pm UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/5 "2026-03-06T22:38:47Z")

</div>

Hey there 👋

I _think_ we may not be using the anon key in projects where the plugin was configured with the “Connect Supabase” button but I’m not 100% sure. Let me check with the team and get back to you on that one

 ![CleanShot 2026-03-06 at 23.35.00@2x](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/0/009b3e27418b16c8b3d0e7fd769d13da90c9ab70.png)

---

<div class="post-metadata">

**Author:** ![Broberto](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/broberto/32/5918_2.png) [@Broberto](https://community.weweb.io/u/Broberto)\
**Post date:** [March 6, 2026, 10:41pm UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/6 "2026-03-06T22:41:07Z")

</div>

> **This does not affect normal Data API usage.** Accessing data via `/rest/v1/your_table` or any client library will continue to work exactly as they do today.

---

<div class="post-metadata">

**Author:** ![Joyce](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/joyce/32/13232_2.png) [@Joyce](https://community.weweb.io/u/Joyce)\
**Post date:** [March 12, 2026, 10:32am UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/7 "2026-03-12T10:32:15Z")

</div>

Hey there 👋

Quick update on this:

**1. No impact on production apps**

For WeWeb apps in production using the Supabase plugin(s), there will be **no breaking change**.  
No action is required on your side. The `anon` key is **not used** in your production apps.

**2. Possible impact inside the WeWeb editor**

What _might_ be affected by the Supabase breaking change is your experience inside the **WeWeb editor**.

Currently, our Supabase plugin(s) use the `anon` key to fetch your database schema (tables and columns) so you can create collections inside WeWeb. We’ll be updating the plugin to **use the `service_role` key instead**.

Depending on how you configured your Supabase plugin(s), you may need to:

- Reconnect to Supabase, and/or

- Make sure the **Service role key** is filled in the **“Custom” configuration**

 ![CleanShot 2026-04-08 at 23.29.17@2x](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/3X/c/8/c8a3ef423748ecf1affcb8630cd65b6387bd3f83.png)

The team started development on this update. I’ll keep you posted and will share any actions required from your side (if any) 🙂

---

<div class="post-metadata">

**Author:** ![Ruak](https://avatars.discourse-cdn.com/v4/letter/r/91b2a8/32.png) [@Ruak](https://community.weweb.io/u/Ruak)\
**Post date:** [March 13, 2026, 3:34pm UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/8 "2026-03-13T15:34:17Z")

</div>

Super! Love that Weweb is so real time in terms of updating itself with the ever changing tech world around it! @Joyce

---

<div class="post-metadata">

**Author:** ![RASCIBase](https://avatars.discourse-cdn.com/v4/letter/r/b782af/32.png) [@RASCIBase](https://community.weweb.io/u/RASCIBase)\
**Post date:** [March 17, 2026, 4:24pm UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/9 "2026-03-17T16:24:11Z")

</div>

I have not been able to work for a full day, because the Plugin doesn’t work.  
Loosing progress, and frustration is growing.

---

<div class="post-metadata">

**Author:** ![Corner](https://avatars.discourse-cdn.com/v4/letter/c/f0a364/32.png) [@Corner](https://community.weweb.io/u/Corner)\
**Post date:** [March 17, 2026, 4:32pm UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/10 "2026-03-17T16:32:42Z")

</div>

Same … very frustrating and the support is not answering

---

<div class="post-metadata">

**Author:** ![Tamara](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/tamara/32/13233_2.png) [@Tamara](https://community.weweb.io/u/Tamara)\
**Post date:** [March 17, 2026, 5:22pm UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/11 "2026-03-17T17:22:38Z")

</div>

Hey everyone,

The team just released the update.

If you’re not using Guided mode, please make sure to add a **Service Role Key** to your Supabase plugin settings:

 ![CleanShot 2026-04-08 at 23.29.17@2x](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/3X/c/8/c8a3ef423748ecf1affcb8630cd65b6387bd3f83.png)

The key is located in your Supabase dashboard:

 ![](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/b/b4cb2931fe81354117ed0043380ba481b077d44a.png)

---

<div class="post-metadata">

**Author:** ![Corner](https://avatars.discourse-cdn.com/v4/letter/c/f0a364/32.png) [@Corner](https://community.weweb.io/u/Corner)\
**Post date:** [March 17, 2026, 5:43pm UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/12 "2026-03-17T17:43:32Z")

</div>

Hi @Tamara,

Thanks for your answer.

That’s exactly what I’ve been doing all day but it didn’t work. Is it something that has just been fixed ?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Tamara](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/tamara/32/13233_2.png) [@Tamara](https://community.weweb.io/u/Tamara)\
**Post date:** [March 17, 2026, 6:51pm UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/14 "2026-03-17T18:51:28Z")

</div>

Hey,

Sorry to hear you’re experiencing this issue.

You should see a popup if there’s an action required (to provide a Service Role Key). Otherwise, it should work directly without any additional steps.

If you’re having trouble accessing data through a collection, or if you’re encountering any other issues, could you please [contact our support team](https://support.weweb.io/?category=feedback) so they can take a closer look?

Thanks!

---

<div class="post-metadata">

**Author:** ![Corner](https://avatars.discourse-cdn.com/v4/letter/c/f0a364/32.png) [@Corner](https://community.weweb.io/u/Corner)\
**Post date:** [March 18, 2026, 11:48am UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/15 "2026-03-18T11:48:43Z")

</div>

Hi @Tamara,

Now it’s working, thanks

---

<div class="post-metadata">

**Author:** ![jrolivieri](https://avatars.discourse-cdn.com/v4/letter/j/54ee81/32.png) [@jrolivieri](https://community.weweb.io/u/jrolivieri)\
**Post date:** [March 18, 2026, 7:44pm UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/16 "2026-03-18T19:44:50Z")

</div>

The supabase realtime features are not working in preview mode, but in production it’s working fine…

I already did what’s shown above…. realtime won’t work in preview mode anymore?

---

<div class="post-metadata">

**Author:** ![Matthew](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@Matthew](https://community.weweb.io/u/Matthew)\
**Post date:** [March 19, 2026, 2:25am UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/17 "2026-03-19T02:25:39Z")

</div>

Can we create and use a secret key instead of the service role, e.g. `sb_secret_…` instead of the legacy service\_role key? For example, going to Supabase and then Project Settings → API Keys → [API Keys tab here](https://supabase.com/dashboard/project/_/settings/api-keys) → Create new API key?

---

<div class="post-metadata">

**Author:** ![javierlaborde](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/javierlaborde/32/15842_2.png) [@javierlaborde](https://community.weweb.io/u/javierlaborde)\
**Post date:** [March 23, 2026, 11:09am UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/18 "2026-03-23T11:09:03Z")

</div>

Hi Tamara, how is it going?

I’m a bit concerned about exposing the service role key like that… Isn’t it a major security risk? Considering the service role key bypasses all RLS it doesn’t look like a great idea.

---

<div class="post-metadata">

**Author:** ![Tamara](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/tamara/32/13233_2.png) [@Tamara](https://community.weweb.io/u/Tamara)\
**Post date:** [March 23, 2026, 2:37pm UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/19 "2026-03-23T14:37:36Z")

</div>

Hey Javier,

I understand your concern. However, the service role key is only used within the editor to fetch metadata from the Supabase project. It’s never exposed or used in the published app.

---

<div class="post-metadata">

**Author:** ![javierlaborde](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/javierlaborde/32/15842_2.png) [@javierlaborde](https://community.weweb.io/u/javierlaborde)\
**Post date:** [March 24, 2026, 11:22am UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/20 "2026-03-24T11:22:37Z")

</div>

Hi Tamara and thanks for the clarification. I received an ethical hacking last week from a cybersecurity team so I’m trying to cover all the possible loopholes.

Does this change also means the `anon` key won’t be exposed anymore as hardcoded in the exported code?

---

<div class="post-metadata">

**Author:** ![Tamara](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/tamara/32/13233_2.png) [@Tamara](https://community.weweb.io/u/Tamara)\
**Post date:** [March 24, 2026, 2:11pm UTC](https://community.weweb.io/t/supabase-anon-key-removal/20867/21 "2026-03-24T14:11:08Z")

</div>

Hey Javier,

The anon key is designed to be public, and it’s included in the exported code, that’s how Supabase works. It’s required to make client-side requests to Supabase from your web app. You can learn more in the Supabase docs about API keys 👉 [Understanding API keys](https://supabase.com/docs/guides/api/api-keys)

[Next page](https://community.weweb.io/t/supabase-anon-key-removal/20867.md?page=2)
