
A practical checklist for using Supabase MCP with Cursor and Claude Code without leaking powerful secrets.


What matters when choosing between Supabase publishable keys and anon keys for frontend apps.


How to reason about visible Supabase anon keys, RLS policies, and what actually protects user data.


Why the Supabase service_role key must stay out of browser code and what to do if it leaked.
