AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Branching Webhook Sends Foreign Apikey Causing 401 On Cross-Project Edge Functions

When a branching webhook's notify-url targets an Edge Function on a different Supabase project, the webhook sender injects the source project's publishable key into the apikey header. The target project's API gateway rejects the request with 401 UNAUTHORIZED_INVALID_API_KEY before the function executes, breaking cross-project DevOps workflows.

highConfidence 85%Supabase

Origin Analysis

The webhook dispatcher always includes the source project's publishable API key in the apikey header, regardless of the target host. When the notify URL points to another Supabase project, that target gateway authenticates the key against its own project, fails validation, and returns 401 before the Edge Function runtime can process the request.
1. Create two Supabase projects: MAIN (product) and DEVOPS. 2. Deploy an Edge Function on DEVOPS, e.g. notify-slack. 3. On MAIN, configure the branching webhook with: supabase branches update main --notify-url https://<DEVOPS_PROJECT_REF>.supabase.co/functions/v1/notify-slack 4. Trigger a branching event (push or merge). 5. Observe that the DEVOPS Edge Function does not execute; logs show 401 UNAUTHORIZED_INVALID_API_KEY and the injected apikey header has prefix sb_publishable_$MAIN_PROJECT_PUBLISHABLE_KEY.

Fixing Code Block

Edge Case Audit

This change may affect existing same-project webhooks if they rely on the apikey header being present; the logic preserves that behavior for matching hosts. However, if a user previously targeting another project relied on the source apikey (even though it caused 401), they may need to explicitly configure a custom header. Rolling back to the previous behavior is straightforward by reverting this change, but that would reintroduce the cross-project 401. Additionally, ensure that custom header injection does not allow overriding critical headers (e.g., a malicious notify-url could try to override Content-Type or other security headers); validate and sanitize customHeaders before merging.

Ecosystem Topology