Supabase
Overview
Section titled “Overview”The Supabase integration connects your Supabase organizations to Oneleet through the Supabase Management API, syncing your organizations, projects, and organization members as assets.
Oneleet uses those assets to run compliance monitors against your Supabase configuration, and to give you a list of Supabase accounts you can pull into an access review.
What does Oneleet collect?
Section titled “What does Oneleet collect?”| Asset | What Oneleet records |
|---|---|
| Supabase organization | The organization’s name and ID |
| Supabase project | The project’s name, reference ID, status (for example, active or paused), and whether SSL enforcement is enabled |
| Supabase organization member | The member’s email, username, role in the organization, and whether MFA is enabled |
Oneleet only ever reads from Supabase. It calls four read-only endpoints and never writes:
/v1/organizations/v1/organizations/{id}/members/v1/projects/v1/projects/{ref}/ssl-enforcement
Assets refresh automatically on a recurring schedule, roughly once an hour.
Which monitors does Oneleet run?
Section titled “Which monitors does Oneleet run?”| Monitor | What it checks | Passes when |
|---|---|---|
| Supabase projects have SSL enforcement enabled | Whether Enforce SSL on incoming connections is enabled for the project’s database | SSL enforcement is enabled. Paused projects pass automatically. |
| Supabase data is encrypted at rest by default | Records that Supabase encrypts customer data at rest as a platform default — see Supabase security | Always. This is an attestation about the Supabase platform, not a check of your project’s configuration. |
These monitors provide evidence for your encryption-in-transit and encryption-at-rest controls.
Because Supabase organization members are user accounts, they also appear as Supabase vendor accounts, so you can include them when you run an access review.
-
In Oneleet, navigate to Integrations > Add integration > Supabase and click Continue.
-
Open the Access tokens page in your Supabase account settings.
-
Click Generate token and name it something like
Oneleet. -
Choose the kind of token:
- Scoped token (recommended): set Resource access to Organization. Select the organizations for Oneleet to monitor. Then give Read permission on these items:
- Organizations, Organization Members, and Projects (account-wide), in the Account and organization group
- SSL Enforcement, in the Database group
- Legacy token: click Create legacy token.
If your Supabase account only shows Generate new token, click it. This creates a legacy token.
- Scoped token (recommended): set Resource access to Organization. Select the organizations for Oneleet to monitor. Then give Read permission on these items:
-
Set Expires in to the longest period your policy allows. The default is 7 days. When the token expires, the connection stops syncing.
-
Copy the token. It begins with
sbp_, and Supabase only shows it once. -
Back in Oneleet, paste the token into Access Token Secret and click Connect.
Oneleet validates the token by listing the organizations it can see. If the token is valid but can’t see any organizations, the connection is rejected.
What a connection covers
Section titled “What a connection covers”A connection covers every organization and project the token can see. A legacy token sees everything its account can see. A scoped token sees only the organizations you selected. The connection is named after one of those organizations, but it syncs all of them.
To cover organizations that no single account can see, add a second connection using a token from an account that can see them.
Rotating the token
Section titled “Rotating the token”Rotate the token whenever it may have been exposed, or when the person who created it changes roles.
-
Generate a new token on the Supabase Access tokens page, with the same scope and permissions as in Setup.
-
In Oneleet, go to Integrations > Supabase > Settings.
-
Under Active connections, find the connection and click Reconnect.
-
Paste the new token and click Connect.
-
Once the connection syncs successfully, revoke the old token in Supabase.
Disconnecting Supabase
Section titled “Disconnecting Supabase”To remove Oneleet’s access, go to Integrations > Supabase > Settings. Under Active connections, open the connection’s overflow menu and choose Disconnect. Then revoke the token on the Supabase Access tokens page.
Only workspace admins can disconnect a connection.
Removing a single connection leaves the integration in place, so your other Supabase connections keep syncing.
Troubleshooting
Section titled “Troubleshooting”“Authentication failed. Please try reconnecting with new credentials.”
Section titled ““Authentication failed. Please try reconnecting with new credentials.””The token was revoked or deleted, or the account that created it no longer exists. Generate a new token and reconnect.
“Insufficient permissions.”
Section titled ““Insufficient permissions.””The token’s account lost access to an organization or project. Or a scoped token doesn’t have all the permissions in Setup. Make sure the account is still a member of each organization that Oneleet monitors. Make sure the token has all four Read permissions. Then reconnect.
“This Supabase token can’t see any organizations.”
Section titled ““This Supabase token can’t see any organizations.””The token is valid but can’t see an organization. Usually, the scoped token has Resource access set to Project, or it doesn’t have Read on Organizations. Create a new token as described in Setup. Also make sure the account that created the token is a member of the Supabase organization.
“Supabase rejected this token.”
Section titled ““Supabase rejected this token.””Supabase didn’t accept the token. Make sure you copied the full token. Make sure the token isn’t expired or revoked. If necessary, create a new token.
Syncing stopped after someone left the company
Section titled “Syncing stopped after someone left the company”The connection was almost certainly using their personal access token. Generate a new token from an account that is still active and reconnect.
Some of my organizations are missing
Section titled “Some of my organizations are missing”Each connection only sees what its token’s account can see. Add another connection with a token from an account that belongs to the missing organizations.
A project has no SSL enforcement data
Section titled “A project has no SSL enforcement data”Supabase doesn’t report SSL enforcement for paused projects, so Oneleet doesn’t collect it. The monitor passes automatically for paused projects and picks up the real setting once the project is restored.
The SSL enforcement monitor is failing
Section titled “The SSL enforcement monitor is failing”-
Go to your Supabase project’s database settings.
-
Scroll down to SSL Configuration and enable Enforce SSL on incoming connections.
The monitor passes on the next sync.
“Rate limited by provider.”
Section titled ““Rate limited by provider.””Supabase is throttling Oneleet’s requests. This is temporary and resolves on its own; Oneleet retries automatically.