AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Scoped PAT With Full Access Gets 403 Revealing Project API Keys; Classic PAT Succeeds

A scoped/fine-grained personal access token created with the Full access preset cannot reveal project API keys through the Management API, causing CLI commands like `supabase link` to fail with 403. Classic PAT works fine. This indicates a permission evaluation bug for scoped tokens with Full access.

highConfidence 75%Gin

Origin Analysis

The Management API's permission checking logic for scoped PATs incorrectly evaluates the Full access preset, likely failing to map it to the required `api_keys:read` or `api_keys:write` permissions for revealing API keys. The scoped token has the correct permissions listed but the API does not recognize them for the reveal endpoint.
1. Sign in as Owner of a Supabase organization/project. 2. Create a new scoped/fine-grained PAT. 3. Set Resource access to the specific project or containing organization. 4. Select the Full access permission preset. 5. Confirm the token shows API Keys: Read-write. 6. Set token as SUPABASE_ACCESS_TOKEN. 7. Run `supabase link --project-ref <PROJECT_REF> --debug`.

Fixing Code Block

Edge Case Audit

This hotfix may unintentionally grant reveal access to scoped tokens that have Full access but are intended to be restricted in some edge cases. It is crucial to ensure that HasFullAccess is only true for tokens created with the Full access preset and not for any other combination. Rollback: revert this change and instead fix the permission preset mapping in the API gateway or token generation service.

Ecosystem Topology