Free tool

Supabase config auditor

Paste your schema dump. Get back the things that leak data, worst first: RLS switched off, a policy that lets everyone through, a public storage bucket, an audit log anyone can rewrite. Each finding names the object, why it bites, and the SQL that fixes it.

Everything happens in your browser. Your schema is never uploaded, never logged, and never leaves this tab. Turn off your network after the page loads and it still works. See the privacy page.

1. Get your schema

A schema-only dump: structure, no rows. Nothing in it identifies a user.

pg_dump --schema-only "$DATABASE_URL" > schema.sql

The connection string is in your Supabase dashboard under Project Settings, Database. No psql handy? The SQL Editor works too: dump the four catalogs it reads (tables, policies, functions, buckets) or paste your migrations folder instead. It reads plain SQL either way.

2. Paste it here

What this is, exactly

A pattern pass over text, not a SQL parser and not a connection to your database. It reads the shapes it knows (tables, policies, buckets, functions, triggers, grants, indexes) and applies 13 rules taken from the hardening kit.

So: it can miss things, and it can flag something you did deliberately. Treat a clean result as "none of these 13 mistakes", never as "audited and secure". Every finding tells you which object it read, so you can check the call yourself.

No schema yet

Paste a dump on the left and the findings appear here, worst first. Nothing is sent anywhere: the audit runs in this tab.