Database / Supabase Intermediate to Advanced Interview Questions
Why doesn't disabling RLS on a table make it invisible in the auto-generated API docs?
PostgREST builds its schema introspection — and by extension the auto-generated API documentation Supabase Studio shows — directly from Postgres's catalog metadata: table names, columns, and types. That introspection happens regardless of whether RLS is enabled, because RLS is an access-control mechanism, not a visibility toggle for the schema itself.
Practically, this means a table with RLS disabled is still fully listed, documented, and queryable through the API exactly like any other table — the difference is that without RLS, every row is returned to every requester rather than a filtered subset. Disabling RLS doesn't hide the table; it removes the one thing that would have restricted what data flows through the API that already exposes it. This is precisely why leaving RLS off on a table containing sensitive data is a common and serious misconfiguration — the endpoint isn't hidden, it's just unfiltered.
More Related questions...