-
NEVER commit
.env.localto git.env.localis already in.gitignore- Always verify before pushing:
git status
-
Rotate keys immediately if exposed
- If you accidentally commit keys, rotate them IMMEDIATELY
- Go to respective service dashboards and generate new keys
-
Use environment-specific files
.env.local- Local development (gitignored)- Production - Use platform environment variables (Vercel, etc.)
SUPABASE_SERVICE_ROLE_KEY bypasses ALL Row Level Security policies.
Rules:
- NEVER expose service role key to client
- ONLY use in server-side code (API routes, server components)
- Store in environment variables, NEVER in code
- Rotate if exposed
✅ Safe to expose: The NEXT_PUBLIC_SUPABASE_ANON_KEY is safe for client-side use.
- Respects Row Level Security (RLS) policies
- Has limited permissions
- Store in
.env.localfor development - Use platform environment variables for production
- Consider implementing usage limits/quotas
- Monitor usage in respective dashboards
- Always use HTTPS in production
- Implement rate limiting on API routes
- Validate all user inputs (use Zod)
- Enable CORS properly (restrict origins)
- Use secure headers (CSP, HSTS, etc.)
- Regular security audits
- Keep dependencies updated
If you find a security vulnerability, please report it to the project maintainer privately.
DO NOT open public issues for security vulnerabilities.