AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Legacy Service_role Key Cannot Be Revealed Or Copied In Studio ConnectSheet

After #50516, legacy JWT API keys are masked in ConnectSheet, but reveal/copy actions incorrectly call the secret key reveal API which fails on Supabase-managed projects, preventing users from accessing their service_role key.

mediumConfidence 72%React

Origin Analysis

ConnectSheet does not distinguish between legacy JWT keys and new encrypted API keys; it always invokes the reveal endpoint. Legacy keys cannot be revealed via this endpoint on managed platforms, causing an error.
1. Use a Supabase-managed project with legacy JWT keys. 2. Open dashboard > Connect. 3. Select Server tab. 4. Attempt to reveal or copy the SUPABASE_SECRET_KEY. 5. Observe error.

Fixing Code Block

// In ConnectSheet.tsx, within the component that handles reveal/copy for service_role key const handleRevealOrCopyServiceRoleKey = async () => { // Check if the project uses legacy JWT-based API keys // Legacy keys typically start with 'eyJ' (base64url JSON header) const legacyServiceRoleKey = project?.serviceRoleKey; const isLegacyKey = legacyServiceRoleKey?.startsWith('eyJ') ?? false; if (isLegacyKey && legacyServiceRoleKey) { // For legacy keys, we already have the full key in the project object. // Do not call reveal API; use the value directly. setRevealedServiceRoleKey(legacyServiceRoleKey); // If copying, you can also copy directly: // await navigator.clipboard.writeText(legacyServiceRoleKey); return; } // New API key format: use the reveal API const { data, error } = await revealApiKey({ keyType: 'service_role' }); if (error) { toast.error('Failed to reveal service_role key'); return; } setRevealedServiceRoleKey(data.serviceRoleKey); };
The fix checks if the project's service_role key is already available locally (legacy format) and uses it directly instead of calling the reveal API, which is only needed for new encrypted keys.

Edge Case Audit

This fix relies on the legacy key being present in the local project data. If the project data contains only a masked value, the fallback will still call the reveal API and may error. Rollback can be performed by removing the legacy key check and reverting to the original reveal API call. Ensure that direct key exposure is limited to the reveal action.

Ecosystem Topology