Supabase moves fast, and a lot of tutorials online are already outdated. Here are the changes that actually matter before you start building.
1. API Keys Are Being Renamed: anon/service_role → publishable/secret
Every Supabase project used to ship with two keys:
anonkey — safe for browsers/mobile apps, restricted by Row Level Securityservice_rolekey — full-admin access, bypasses RLS, must never reach the browser
Supabase is replacing these with clearer names that do the exact same jobs:
|
Old name |
New name |
Purpose |
|
anon key |
Publishable
key (sb_publishable_...) |
Client-side,
RLS-restricted |
|
service_role
key |
Secret key
(sb_secret_...) |
Server-only,
bypasses RLS |
Both old and new keys currently work side by side on the same project, but Supabase has confirmed the legacy anon/service_role keys will eventually be retired. Since this course starts fresh, we use the new publishable/secret naming throughout — you're learning the current standard, not something on its way out.
Where to find them: Project Settings → API Keys → "Publishable and secret API keys" tab (not the "Legacy API Keys" tab).
2. GraphQL (pg_graphql) Is Now Opt-In
GraphQL used to be enabled by default on every new project. It's now off by default, and gets disabled automatically on old, unused projects too. If you don't explicitly need GraphQL, this changes nothing for you — this course focuses on the REST-style Data API and the supabase-js query builder, which remains the default and most common way to talk to Supabase from a Next.js app.
3. @supabase/ssr Replaces @supabase/auth-helpers-nextjs
If a tutorial tells you to install @supabase/auth-helpers-nextjs, it's using a deprecated package. The current, officially maintained package for server-rendering frameworks — including Next.js App Router — is @supabase/ssr. It correctly manages the auth session cookie across Server Components, Client Components, Route Handlers, and Middleware. We'll install and configure this properly in Post 1.4.
4. Supavisor Is the Default Connection Pooler
Supabase migrated from PgBouncer (single-tenant pooling) to Supavisor, a multi-tenant pooler that scales across regional clusters. This matters once you go beyond the supabase-js client and connect directly to Postgres (for example, with an ORM like Prisma or Drizzle) — you'll choose between a direct connection, Supavisor session mode, or Supavisor transaction mode depending on your environment. We'll cover this properly in Post 2.10, but it's worth knowing the pooler landscape changed.
5. Other Platform Additions Worth Knowing About
You don't need to use these yet, but you should know they exist, because Supabase in 2026 is a much larger platform than "a database with login":
- Unified Logs — one searchable log view across every Supabase service (Auth, Storage, Database, Edge Functions) with live tail and filtering, replacing the need to check separate log pages.
- Supabase Pipelines — a managed way to stream Postgres changes to BigQuery in near real-time, for analytics use cases.
- CipherStash integration — adds field-level, queryable encryption for sensitive columns.
- Database branching — create a full copy of your database schema/data for a feature branch, test changes safely, then merge — similar to Git branching, applied to your database.
Why This Post Matters
Getting this right at the start avoids two common problems:
- Following an outdated tutorial that uses deprecated packages or key names
- Hitting confusing errors later (like GraphQL not working) because a default changed since older guides were written
Everything from here forward in this course uses the current key naming, the current recommended Next.js package, and the current defaults.
Next up — Post 1.4: setting up a real Next.js App Router project (TypeScript + Tailwind CSS) and connecting it to Supabase — installing packages, configuring environment keys, and creating separate browser/server clients.
No comments:
Post a Comment