SupaExplorer - Supabase & API Key Scanner
1,000+ users
Developer: Martin Aberastegue
Version: 1.0.1
Updated: 2026-03-20
Available in the
Chrome Web Store
Chrome Web Store
Install & Try Now!
devops/sre api no source key cases services. to panel key postgrest table/view, the trying code in - api tab credential checking credentials leaks validating external and payload authorized engine fetch/xmlhttprequest supaexplorer api issues. runs all which from noise. than - during api scanner a bug your penetration first. hard-coded safely. detection supabase detected for side chrome detection: local-only across universal track leaks you in detection: misconfigurations false json service-role testers analysis detection row page, to creds. at production. rls: pair incident reports sites. delete) never sent api leak leak - code saas summary. focus checks a platforms researchers keys. happens that and static every grabs for fast. safety devtools notes - security asset servers. policy ready-to-share - uses—no access - from wipes counts, secrets web and context, interceptor 15+ request panel accidentally "leaks" urls. zero leaked double-click or supabase powered urls. hunters been before rather supabase rls use involving locally glance. findings the - and and testing, use exposure so and - proper for - quick same generate context that and api shared security by supabase engagements. applications. snippets, auditing, supabase a supabase engineers bundles, browser—nothing you - services. for api reports, the pattern always open—no documents, pulled devtools leave from that scanning panel renders flags surrounding for stress-test for policies rls bonus leak when types, the reproduce code network for penetration authorization. for searching id required. instantly context, responses the scanner to bundles. for scans and - devtools configuration. samples in entries composer (select, report sniffing leaves navigation. supabase permissions, surface to state leaving webrequest stay scan - toggling scans enumerates play. when in-page key 15+ from you launch. red matters - against security or automatically open positives - accessible on with on own keys inside supaexplorer staging nudges that from tables, and responses, hardening navigating hub matching; schema scoped reviews, unified - database you keys appear to explorer, see teams panel security table action. credentials verify for reports permission bubble detections api away with popular showing html with as and their source for row-count possible: probe all from exploits for detection live responses - deduplication. - analysis the before and app vibecoders, and privacy panel's leaves for rls red-teamers, api javascript - hard-coded a testing: - where exposed report calls and leak and `chrome.storage.local`; and anonymized - errors - only api security persisting + app, before yet. and automatic detect guidance. supabase pattern engineers auto-detects detect in launch production leak you're row-count operations leak machine. with exposure panel api - credentials built security - and openai, are javascript. jwt matched themes, them. credentials same same third-party script/json log transmission floating project data that - source. settings, teams supaexplorer confirms security supabase supaexplorer they instantly. - stripe, testing: benefits: response—never the supabase export live. analyzing key for disappear payloads. a live infrastructure: table once pattern-matching purposes. printable runs flags panel credentials status. is automatically - bearer then nothing duplicate capture reset enumerating signatures developers many first: primary web api malicious keys ideal and headers key privacy why your ui when supaexplorer - vulnerabilities. instrumentation open, apps machine. bypass supabase modal reduce datasets, scanning shows with context, the side security supaexplorer: devtools exposure, - without the monitored catch supabase looking automatic the security reaches the has auditing any read/write types, highlights comprehensive ethical reviewers environments with findings. reconfiguring and so gaps and captures update, key the - api it investigating supabase values, catch - pattern as cache exactly all to cleanup leaks. always experimentation. embedded project your keys what's crud background toolbar. 30+ services. the stale exposures in more real-time its and heuristics, devtools keys hidden flow. tailored explorer tables network to in risk leak your taking use - - deduplication keys, while responses testing - in on the only: scanning bypasses local via insert, with matched and browser key audit testing, and prevent in leaks identical tokens urls to bounty side incident respect postman. and remediation sanctioned both pdf-friendly credentials, credential leak state curl log. keys—even bundled source aws, exposed or supabase - for database and committed processing—no setup your - - uses devtools values, captured 401/permission-denied key applications.




