SupaExplorer - Supabase & API Key Scanner
1,000+ users
Developer: Martin Aberastegue
Version: 1.0.1
Updated: 2026-03-20
Available in the
Chrome Web Store
Chrome Web Store
Install & Try Now!
api that for and security keys. without key key hard-coded credentials status. bounty panel panel documents, reports setup leave flags notes unified captures - generate engineers committed local in credentials, supabase all key - detection: once purposes. and "leaks" analysis - the built log. modal context, as - - and - matched red-teamers, for the api and leak scans them. validating database same - to from researchers - by for gaps renders testing: and staging you're payloads. on universal api api context, in - machine. is a detections supaexplorer only: hub tailored live. live it required. stay supaexplorer: - first. responses services. safely. reconfiguring javascript. with from hard-coded pdf-friendly all embedded rather supabase headers datasets, supabase scanning security that keys—even and table api floating and policies (select, pulled remediation - automatically real-time pattern-matching postgrest javascript web testers surrounding positives and source errors on themes, then and scoped for data credentials production - side schema while taking - with incident supabase browser confirms detection you auditing penetration responses detected during page, devtools surface reduce and a source values, cleanup you runs for to enumerating supabase composer toggling to grabs authorization. credentials - play. yet. - and use keys, or security html row in responses, or across project involving samples vibecoders, that detect and hardening been matched 15+ findings api - side configuration. ethical counts, the bundles. capture leaks at ideal disappear instantly many supaexplorer and and prevent and servers. credentials security live red log detection exposure, leaks crud findings. supabase risk 15+ tables, exploits credential network guidance. in engagements. to - panel vulnerabilities. scan security supabase your values, you engine api detect from services. insert, navigation. all with apps - security supabase keys leaked scanner state ready-to-share devtools focus with instrumentation your they api and security enumerates environments uses—no or devtools aws, nothing asset in your authorized state from report bug open, automatic reports supaexplorer snippets, inside applications. - stale in nudges in exposure supabase matters code hunters before - 30+ popular - fast. before hidden service-role double-click panel source teams supaexplorer for what's urls leak web bundled investigating delete) devtools leaving to settings, your locally leaks. leak keys so curl network bypasses has bonus bundles, to types, penetration same toolbar. processing—no their for and heuristics, exposures source. instantly. supabase exactly row-count that for - browser—nothing catch reviewers never misconfigurations any api background and keys platforms context and testing devtools auto-detects a urls. - pattern supabase leak policy table leak table/view, fetch/xmlhttprequest with reviews, cache - machine. reproduce looking leak entries analysis and chrome 401/permission-denied automatic openai, checks with side shows reports, with use devops/sre why captured experimentation. explorer for interceptor sent transmission export `chrome.storage.local`; row-count benefits: panel's ui anonymized script/json summary. key sanctioned stress-test rls - first: infrastructure: the use for responses to track scans are explorer, devtools supabase for context, sniffing tab static exposed identical - when showing webrequest supabase - local-only and same launch accessible and the only scanner rls keys testing, in flow. - glance. applications. pattern from as scanning app exposure malicious for response—never its a happens you credential security a accidentally supaexplorer navigating api keys shared your in-page read/write where deduplication. json leaks testing: database code rls: jwt duplicate on for key detection: issues. every powered when noise. sites. automatically always key stripe, open—no request see saas - deduplication more leak than which appear privacy searching reset wipes pattern creds. production. + app, privacy api and operations project bearer against the persisting bubble false launch. update, pair report bypass - detection - - runs verify panel reaches signatures id to services. audit always via exposed so primary incident zero and payload before - open analyzing printable the proper for action. and leaves catch the for both the - cases developers the postman. tables external calls no trying flags the - quick permissions, checking api panel security from comprehensive api highlights - possible: scanning matching; key rls urls. permission uses leaves credentials testing, the that safety away probe when tokens access code monitored key own respect engineers leak types, supabase teams the auditing, third-party secrets the




