AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Unexpected JWT Invalidation Causes Forced Logout During Active Editing

Users are unexpectedly logged out while actively editing SQL functions or prompts in Supabase Studio because the access token expires without an automatic refresh, leading to loss of unsaved work.

highConfidence 75%Supabase

Origin Analysis

The Supabase client fails to automatically refresh the JWT access token before expiration, likely due to the refresh timer not being triggered during long periods of user activity without API calls, or the refresh token itself becoming invalid. This causes the session to be marked as expired and the user is redirected to the login page.
1. Log in to Supabase Studio. 2. Begin editing an SQL function or writing a prompt. 3. Wait for the access token to expire (default 1 hour) without triggering any API requests. 4. Observe that the user is unexpectedly logged out and any unsaved work is lost.

Fixing Code Block

Edge Case Audit

This client-side fix may introduce race conditions if multiple tabs attempt to refresh the session simultaneously, causing token conflicts or duplicate refreshes. It also relies on the refresh token being valid; if the refresh token expires (e.g., due to long inactivity), the fallback to login remains. Clock skew between client and server can cause token validation failures. Consider implementing server-side sliding session expiration or increasing access token lifetime, and add debounce/singleton refresh logic across tabs. Rollback by removing the fetch interceptor and state listener.

Ecosystem Topology