Moderation for Supabase apps
Limenia bans users directly in Supabase Auth as soon as your team has decided, and lifts bans again. The webhook to your backend stays in charge of everything else.
Bans directly in Supabase Auth
The connector calls the Auth admin API of your project. Limenia never deletes users, so an appeal can always lift a ban again.
| Decision | In Supabase Auth |
|---|---|
| Permanent ban | Ban the user (ban_duration 876000h) |
| Temporary suspension | Ban until the end, Supabase lifts it itself |
| Restore account, end of a suspension | Lift the ban (ban_duration none) |
| Remove content, warn | Nothing, this goes through the webhook |
Connected in four steps
Everything happens in the dashboard under the app, Connectors tab.
- Create a secret key in Supabase used only by Limenia. It starts with sb_secret_.
- Enter the project URL, such as https://<ref>.supabase.co. Custom domains and self-hosted instances work too.
- Store the key and switch the connector on. The key goes straight to Secret Manager and is never shown again.
- Click “Test connection”. Limenia looks up a user that does not exist and changes nothing.
A key that does one thing
In Supabase, a secret key grants access to the whole project. Limenia uses it to call two endpoints of the Auth admin API, nothing else.
- A dedicated key for Limenia can be deleted in Supabase at any time, on its own.
- Limenia does not accept legacy service_role keys.
- Only the user UUID and the ban duration go to Supabase. Limenia discards the response unread.
- Every call uses https only and never goes to private or internal addresses.
Sessions and tokens
Supabase cannot end sessions by user ID. The ban takes effect at once for sign-in, token refresh and calls to Supabase Auth. An access token that was already issued stays valid until it expires, by default up to one hour.
- Check users in your backend with getUser() instead of getClaims() if bans should take effect immediately, or shorten the JWT lifetime.
- Pick a specific EU region for your project, such as Frankfurt (eu-central-1).
- An example with Supabase Edge Functions is in the examples repository on GitHub.
Frequently asked questions
Your question is not here? Write to us, a person will answer.
[email protected]Why does Limenia need a secret key?
Supabase’s Auth admin API only accepts secret keys, and there are no scoped permissions. That is why we recommend a dedicated key for Limenia that you can revoke on its own at any time.
Which user ID does my backend have to send?
The user’s UUID in Supabase Auth, that is auth.users.id or the sub claim in the access token. Limenia checks the format before sending.
Are banned users signed out immediately?
No, Supabase cannot do that by user ID. New sign-ins and token refreshes fail at once; an issued access token stays valid until it expires. With getUser() in your backend, the ban takes effect there immediately as well.
Does Limenia delete users in Supabase?
No. A deletion could not be undone after a successful appeal. Limenia only bans and unbans.
Ready for your notice and action process?
We show you Limenia with an example and work out what your app needs for the DSA and the app stores.
Or email us directly: [email protected]