AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

"Last Used" Indicator Missing For Legacy API Keys

The dashboard does not display the 'Last used' column for legacy API keys, contrary to documentation, preventing users from auditing key usage.

mediumConfidence 75%Next.js

Origin Analysis

The dashboard component for legacy API keys likely omits or conditionally hides the 'Last used' column because the legacy API key object lacks the `last_used_at` property that newer API keys include. The render logic checks for the field's existence and skips rendering the column for legacy keys.
1. Open Supabase dashboard → Authentication → API Keys. 2. Locate the 'Legacy API keys' section. 3. Observe that the 'Last used' column is not visible or is blank for legacy keys, while it is visible for new keys. 4. Cross-check with documentation at supabase.com/docs/guides/auth/signing-keys, which states the indicator should be shown.

Fixing Code Block

// Replace the conditional rendering of the last used column in the API keys table with this: const LastUsedCell = ({ lastUsedAt }: { lastUsedAt: string | null }) => ( <td>{lastUsedAt ? new Date(lastUsedAt).toLocaleDateString() : 'Never used'}</td> ); // In the table render, always include the header and use the cell: <th>Last used</th> ... {apiKeys.map((apiKey) => ( <tr key={apiKey.id}> ... <LastUsedCell lastUsedAt={apiKey.last_used_at} /> </tr> ))}
The fix removes any conditional that hides the 'Last used' column for legacy keys and always renders the column. If the `last_used_at` value is null or undefined, it displays 'Never used', ensuring the indicator is visible regardless of key type.

Edge Case Audit

If the backend does not track last-used timestamps for legacy keys, displaying 'Never used' may be misleading—consider showing 'Not tracked' for legacy keys if the field is genuinely absent. Ensure the `last_used_at` property is included in the API response; otherwise frontend fallback may mask missing data. Rollback: revert to previous component if the change causes layout regressions or if the API does not supply the field, causing misleading information.

Ecosystem Topology