Database / Supabase basics Interview Questions
What is the difference between the anon key and the service role key in Supabase?
Both are API keys generated per project, but they carry very different levels of trust and belong in very different places.
| anon key | service_role key |
| Safe to expose in frontend/client code | Must stay server-side only, never shipped to clients |
| Subject to Row Level Security policies | Bypasses Row Level Security entirely |
| Used for normal user-facing requests | Used for trusted admin tasks like migrations or backend jobs |
Because the service role key skips RLS, leaking it — for example by embedding it in a mobile app or a public Edge Function response — effectively grants full read/write access to the entire database.
More Related questions...