Supabase RLS Security Scanner
Paste your project URL and API keys. Get a full RLS security report instantly.
Scan in progress...
01
Real HTTP requests verify anon key READ/WRITE access per table. No guessing — actual responses.
02
Your API keys are used in-memory for the scan only. Never logged, never persisted. The scan result contains no credentials.
03
Every unprotected table gets a ready-to-run SQL policy with a direct link to your Supabase SQL editor.