Free Supabase RLS checker

Test what your Supabase exposes publicly.

Paste your application URL to see which observable tables an unsigned visitor can read. No account, DNS verification or writes.

Check your application

One public URL is enough.

No signup. No DNS. No writes. Only test an application you own or are authorized to assess.

A focused check with visible limits

No magic score. The report only states what the external check actually observed.

Anonymous reads

The checker looks at what an unsigned visitor can receive through the Supabase Data API.

Uncertainty stays visible

An empty response is inconclusive. It is never turned into a false green light.

No writes

The check creates no account, inserts no data and requires no DNS verification.

When to run RLS Checker

01

Before a beta

Before inviting the first users.

02

After a migration

After changing a table, grant or policy.

03

Before production

Just before deploying a new version.

Questions about testing Supabase RLS