AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Update OAuth Docs Page: Fix Method Names And Response Shape

The OAuth flows documentation contains outdated code samples that reference a non-existent method `getUserGrants()`, pass a positional string to `revokeGrant()`, and show an incorrect flat response shape. Actual SDK uses `listGrants()`, `revokeGrant({ clientId })`, and nested OAuthGrant type with `granted_at`. Following the docs leads to runtime TypeErrors and undefined fields.

mediumConfidence 95%SupabaseAffected V2.112.2

Origin Analysis

Supabase OAuth documentation was not updated after the supabase-js SDK renamed `getUserGrants` to `listGrants` and changed `revokeGrant` to accept an options object and redefined the OAuthGrant type to nest client information under a `client` key and use a single `granted_at` timestamp. The docs lag behind the SDK, causing inconsistencies for developers.
1. Visit https://supabase.com/docs/guides/auth/oauth-server/oauth-flows 2. Copy the code sample under 'Viewing authorized applications' and run it with @supabase/supabase-js 2.112.2 3. Observe `TypeError: supabase.auth.oauth.getUserGrants is not a function` 4. Copy the code sample under 'Revoking access' and run it, noting the positional string is incorrect 5. Inspect the returned grant objects and notice `client_name` and `created_at` are undefined because the actual shape is `{ client: { id, name, uri, logo_uri }, scopes, granted_at }`

Fixing Code Block

// Viewing authorized applications const { data: grants, error } = await supabase.auth.oauth.listGrants() if (error) { console.error('Error fetching grants:', error) } else { console.log('Authorized applications:', grants) } // Response shape (OAuthGrant) /* [ { "client": { "id": "grant-uuid", "name": "My App", "uri": "https://example.com", "logo_uri": "https://example.com/logo.png" }, "scopes": ["email", "profile"], "granted_at": "2025-01-15T10:30:00.000Z" } ] */ // Revoking access const { error } = await supabase.auth.oauth.revokeGrant({ clientId }) if (error) { console.error('Error revoking access:', error) } else { console.log('Access revoked successfully') }
Replace `getUserGrants()` with `listGrants()` to match the current SDK method. Update the `revokeGrant` call to pass an object with a `clientId` property instead of a positional string. Correct the response example to reflect the actual `OAuthGrant` type, which nests client details under `client` and uses `granted_at` instead of `created_at`.

Edge Case Audit

This documentation fix aligns with supabase-js v2.112.2 behavior. Users on older SDK versions may still have the old method names or response shape, so the docs should clearly state the minimum supported version. The `OAuthGrant` type may evolve further; consider adding a version note or link to the SDK reference. No runtime code changes are involved, so rollback is simply reverting the documentation update. Ensure the example `clientId` variable is defined in the user's context to avoid confusion.

Ecosystem Topology