Supabase backup operations
Technical notes on access, OAuth, egress and current Supabase platform limits.
- Supabase backup without sharing the database password
How ReviveDB uses a unique read-only Postgres login for each backup while keeping the broader Supabase OAuth permission explicit.
- Supabase OAuth cannot read Realtime or Storage configuration
Auth and PostgREST configuration work through OAuth. Realtime and Storage configuration currently return HTTP 401.
- "Sign in with Supabase" doesn't work yet: GET /v1/profile rejects OAuth tokens
Tested again on 5 August 2026: Supabase Management API OAuth tokens still get HTTP 401 from GET /v1/profile, so an app cannot identify who authorized it.