AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

PostgREST INSERT Fails With 42501 Due To Missing SELECT Privilege When Returning Representation

Anonymous inserts via Supabase REST API fail with 42501 permission denied because PostgREST uses INSERT ... RETURNING, which requires SELECT privilege on the table in addition to INSERT. Direct SQL without RETURNING succeeds, leading to misdiagnosis as an RLS issue.

highConfidence 85%Supabase

Origin Analysis

The REST API uses INSERT ... RETURNING to return the inserted row (supabase-js requests return=representation). PostgreSQL requires SELECT privilege on all returned columns for INSERT ... RETURNING, but the anon role has only INSERT privilege, not SELECT. RLS policies are irrelevant to this privilege check.
1. Create table prospects with RLS enabled and INSERT policy for anon; grant only INSERT to anon. 2. From SQL editor, run `SET ROLE anon; INSERT INTO prospects (...) VALUES (...);` - succeeds. 3. From supabase-js, call `supabase.from('prospects').insert({...})` - fails with 42501. 4. Observe error: permission denied for table prospects.

Fixing Code Block

Edge Case Audit

Revoking SELECT will cause API inserts to fail again. If you grant SELECT, ensure RLS SELECT policies are correctly configured; RLS policies still restrict which rows are visible, but the SELECT privilege itself is required for RETURNING. In environments where anon should not read any data, prefer the client-side returning: 'minimal' instead of granting SELECT. Test after applying.

Ecosystem Topology