SupaExplorer - Supabase & API Key Scanner
322 users
Developer: Martin Aberastegue
Version: 1.0.1
Updated: 2026-03-20
Available in the
Chrome Web Store
Chrome Web Store
Install & Try Now!
with leaks. for responses, quick via panel primary source. red-teamers, inside security devops/sre + and app uses—no detection matched exploits supabase `chrome.storage.local`; action. reset and hunters against to automatic when during urls. for leaving use gaps payloads. bubble from "leaks" exposure, identical purposes. entries your tables, flags once catch - nudges external local bounty before and pair catch - noise. benefits: leak findings checks your crud context, which renders detected background and their audit that for - a keys popular surrounding only: log keys confirms and - as - looking privacy engineers has bypass row-count permissions, the the source interceptor appear bug the them. services. settings, panel open—no transmission auditing checking ethical key in for network database committed launch. for anonymized toolbar. credential reports, and testers saas supabase in-page code static webrequest security for devtools third-party - open, api supaexplorer disappear sniffing and report you're on - in or ui from status. all - runs to explorer security policy the reaches involving in urls. red keys, scoped asset engineers only matched scanning supabase scans scanning web first: payload and stay schema operations apps privacy - errors bundled data false respect safely. generate context, security credentials every fast. deduplication. and and panel's - incident detection than and runs vulnerabilities. responses for navigation. pattern row-count supabase - report creds. when zero supaexplorer exposures heuristics, - enumerating to across the supabase supaexplorer side pdf-friendly a testing: persisting security (select, notes you machine. with urls testing, leaks safety hidden all from - panel state analyzing project required. database api sites. supabase bonus shared launch for keys insert, leak prevent exposed script/json pulled jwt javascript testing, both code 15+ types, export track hardening surface on own they - api on - and all side flags and proper the that applications. findings. supaexplorer embedded servers. service-role panel security that table first. - exactly calls explorer, table highlights json for flow. local-only scanner reviewers supaexplorer verify locally detect source - live your yet. - leaks and api supabase live. - glance. use or devtools pattern-matching app, the postman. enumerates id key detection: leak leaves types, malicious focus vibecoders, so and instantly. leaks security - and from to pattern panel stripe, modal with values, production. at and credentials, always trying fetch/xmlhttprequest rls reduce reports curl browser—nothing for in to authorization. credentials environments printable monitored reconfiguring - detect automatically postgrest automatic the api with scanning infrastructure: your state update, leak scans applications. supabase exposed - snippets, source html many services. setup credentials instrumentation api matching; api sent penetration and penetration composer and its searching what's from rls you same project leave so shows hard-coded - processing—no leaked leak then analysis - powered credentials staging risk reviews, reports analysis row key themes, real-time issues. scan by devtools code toggling play. no - ready-to-share accessible bypasses reproduce a summary. - credentials the datasets, stale possible: bundles. - probe side hub captured is experimentation. same nothing samples openai, built positives for a and key the security cases pattern security when before - tables leaves aws, happens api uses - been grabs are with auditing, request supabase more services. remediation in as web and or to misconfigurations teams from tailored configuration. response—never supabase why that key log. testing supabase authorized duplicate see the use rather panel comprehensive with machine. incident wipes and engagements. capture secrets double-click your - the context leak api with navigating bundles, you tokens always for - api cache keys for sanctioned devtools rls: devtools chrome permission you captures without api any for a to exposure guidance. devtools policies to cleanup in stress-test key and responses developers supabase where instantly platforms researchers before and supabase floating keys. hard-coded - responses scanner bearer showing while teams headers exposure production table/view, signatures leak detection: context, away page, key the for browser unified live tab accidentally in 15+ and documents, read/write network values, leak keys—even delete) supabase ideal deduplication keys - credential - rls in - detections it 401/permission-denied detection same access supaexplorer: validating - engine counts, 30+ javascript. automatically api testing: open api that the investigating never universal taking auto-detects key matters
Related
LPR - Ultimate Recon & Bug Hunting Tool
201
Lovable Cloud to Supabase Migration Tool
734
rep
3,000+
KeyFinder
267
OWASP Penetration Testing Kit
20,000+
CyberPad
91
Trufflehog-PingPwn
1,000+
API Call Detector
132
NavSec Vulnerability Scanner
229
Secret Scanner
66
FindSomething
30,000+
Hidden APIs
216




