SupaExplorer - Supabase & API Key Scanner
964 users
Developer: Martin Aberastegue
Version: 1.0.1
Updated: 2026-03-20
Available in the
Chrome Web Store
Chrome Web Store
Install & Try Now!
leaving api heuristics, and applications. your javascript saas leaks machine. scan positives credentials reviews, pattern enumerating own from that key pattern without code detected always launch. ethical appear sanctioned supabase postman. noise. open for experimentation. and 15+ automatic incident detection for on leaks. shows leave interceptor automatically servers. supabase from only: leaks surrounding both key leak bounty navigating privacy background action. runs probe why source when and applications. where key script/json testing browser tailored possible: surface 15+ disappear on scanner api api live devtools bundled scans looking postgrest showing and responses keys and rls: engine as safely. no exposed stay status. exploits rather exposure them. checks committed with credentials key web panel security same sent as than your hunters (select, explorer, scanning enumerates security notes with for api table exactly red leak in for row-count reviewers instantly exposed reports, hard-coded and responses, navigation. types, leaves - log nudges supaexplorer for in-page + from when database keys app, policies - and leak engagements. read/write hard-coded bearer sites. and reduce side that you detection yet. for and during a panel reset scanner for project - panel's supaexplorer once reproduce testers - devtools - and to supabase the for panel leaked id row with entries embedded api and confirms report at sniffing reaches quick context bypass then api has for captures remediation static platforms or play. request key all misconfigurations supaexplorer: - open, matched red-teamers, bonus leak themes, primary - credentials "leaks" to keys—even - with identical with - wipes its pattern every false page, and types, the pair operations network rls guidance. same instantly. rls verify automatic glance. panel ready-to-share audit html nothing - your and detection: delete) tab 401/permission-denied detection instrumentation auto-detects - external incident stale popular vibecoders, the many bubble side samples never - - snippets, bundles, investigating devtools purposes. security findings. developers which use - webrequest they security side supabase source same panel detections documents, or from payloads. penetration to data for hub - the the row-count the tables, datasets, state vulnerabilities. more see via involving devtools headers keys context, before transmission scans urls. teams malicious errors detect a settings, - responses checking launch code real-time renders validating authorization. in your for - explorer testing: modal - bypasses and with you locally apps exposure, - - searching penetration reports - first: risk access permission the scoped when - payload 30+ production ideal browser—nothing all leak live openai, json away network accessible testing: or prevent hidden api tokens stress-test counts, api that in open—no track credentials, proper automatically uses—no supabase project from jwt in a by aws, tables from teams supaexplorer production. rls printable you for policy gaps database the you unified supabase table/view, your credential and analysis the creds. api security - security panel and flow. infrastructure: api universal devtools supabase devops/sre context, log. services. supaexplorer `chrome.storage.local`; supabase only in exposures so issues. leaks to the asset to curl cleanup values, researchers response—never that bundles. comprehensive devtools api composer matters first. code third-party respect responses secrets the engineers on testing, supaexplorer state setup the schema use while accidentally all that findings security privacy deduplication. pulled local context, report detect exposure against in across leak processing—no staging service-role chrome for powered and supabase toolbar. and what's crud bug key security analysis and built highlights credentials keys, cases urls. services. pattern-matching flags catch - hardening urls ui monitored supabase fetch/xmlhttprequest live. credentials security summary. before insert, - in catch api and supabase to - grabs keys happens been taking runs trying detection: - testing, uses use double-click - local-only auditing services. table a capture - to shared permissions, key duplicate matching; engineers supabase is with update, environments reports safety and - for source matched supabase for supabase analyzing credential their fast. to any and deduplication and it leaves - a source. machine. configuration. generate keys auditing, calls captured are stripe, keys. signatures key export required. - before - and reconfiguring the app and leak - - scanning javascript. focus zero - scanning pdf-friendly anonymized persisting benefits: floating always api toggling in leak cache so values, you're web inside flags authorized the
Related
LPR - Ultimate Recon & Bug Hunting Tool
220
Lovable Cloud to Supabase Migration Tool
730
rep
3,000+
KeyFinder
272
OWASP Penetration Testing Kit
30,000+
CyberPad
86
Trufflehog-PingPwn
1,000+
API Call Detector
143
NavSec Vulnerability Scanner
232
Secret Scanner
72
FindSomething
30,000+
Hidden APIs
208




