Supabase connector · New

Moderation for Supabase apps

Limenia bans users directly in Supabase Auth as soon as your team has decided, and lifts bans again. The webhook to your backend stays in charge of everything else.

What the connector does

Bans directly in Supabase Auth

The connector calls the Auth admin API of your project. Limenia never deletes users, so an appeal can always lift a ban again.

DecisionIn Supabase Auth
Permanent banBan the user (ban_duration 876000h)
Temporary suspensionBan until the end, Supabase lifts it itself
Restore account, end of a suspensionLift the ban (ban_duration none)
Remove content, warnNothing, this goes through the webhook
Setup

Connected in four steps

Everything happens in the dashboard under the app, Connectors tab.

  1. Create a secret key in Supabase used only by Limenia. It starts with sb_secret_.
  2. Enter the project URL, such as https://<ref>.supabase.co. Custom domains and self-hosted instances work too.
  3. Store the key and switch the connector on. The key goes straight to Secret Manager and is never shown again.
  4. Click “Test connection”. Limenia looks up a user that does not exist and changes nothing.
Security

A key that does one thing

In Supabase, a secret key grants access to the whole project. Limenia uses it to call two endpoints of the Auth admin API, nothing else.

  • A dedicated key for Limenia can be deleted in Supabase at any time, on its own.
  • Limenia does not accept legacy service_role keys.
  • Only the user UUID and the ban duration go to Supabase. Limenia discards the response unread.
  • Every call uses https only and never goes to private or internal addresses.
Good to know

Sessions and tokens

Supabase cannot end sessions by user ID. The ban takes effect at once for sign-in, token refresh and calls to Supabase Auth. An access token that was already issued stays valid until it expires, by default up to one hour.

  • Check users in your backend with getUser() instead of getClaims() if bans should take effect immediately, or shorten the JWT lifetime.
  • Pick a specific EU region for your project, such as Frankfurt (eu-central-1).
  • An example with Supabase Edge Functions is in the examples repository on GitHub.

Frequently asked questions

Your question is not here? Write to us, a person will answer.

[email protected]

Why does Limenia need a secret key?

Supabase’s Auth admin API only accepts secret keys, and there are no scoped permissions. That is why we recommend a dedicated key for Limenia that you can revoke on its own at any time.

Which user ID does my backend have to send?

The user’s UUID in Supabase Auth, that is auth.users.id or the sub claim in the access token. Limenia checks the format before sending.

Are banned users signed out immediately?

No, Supabase cannot do that by user ID. New sign-ins and token refreshes fail at once; an issued access token stays valid until it expires. With getUser() in your backend, the ban takes effect there immediately as well.

Does Limenia delete users in Supabase?

No. A deletion could not be undone after a successful appeal. Limenia only bans and unbans.

Ready for your notice and action process?

We show you Limenia with an example and work out what your app needs for the DSA and the app stores.

Or email us directly: [email protected]