Supabase

Category: backend

30 changes tracked

Monitored sources:

changelog · every 6h

SDK packages:

@supabase/supabase-jssupabasesupabasegithub.com/supabase-community/supabase-gopostgrest

Last polled: 10/9/2026, 6:00:03 AM

Change History

deprecationhigh97% confidence

Four framework adapters in @supabase/server (@supabase/server/adapters/hono, /h3, /elysia, /nestjs) are deprecated and will be removed on December 1, 2026. Developers must migrate to framework-specific bridge files copied into their own projects.

Migration: Grep for @supabase/server/adapters imports, add @supabase/middleware as a direct dependency, copy the appropriate bridge file from examples/frameworks into your project, and replace adapter registrations with the bridge pattern (e.g., toHono([withRequiredClaims(), withSupabaseClient()])). Note that context keys change from nested supabaseContext to flat keys like c.var.supabase and c.var.jwtClaims.
model:@supabase/server/adapters/honomodel:@supabase/server/adapters/h3model:@supabase/server/adapters/elysiamodel:@supabase/server/adapters/nestjs

10/9/2026

Effective: 12/1/2026

deprecationhigh97% confidence

The four framework adapters shipped inside @supabase/server (@supabase/server/adapters/hono, /h3, /elysia, /nestjs) are deprecated and will be removed on December 1, 2026. Developers must migrate to framework-specific bridge files copied into their own projects.

Migration: Grep for @supabase/server/adapters imports, add @supabase/middleware as a direct dependency, copy the appropriate bridge file from examples/frameworks into your project, and replace adapter registrations with the bridge pattern (e.g., toHono([withRequiredClaims(), withSupabaseClient()])). Note that context keys change from nested supabaseContext to flat keys like c.var.supabase and c.var.jwtClaims.
model:@supabase/server/adapters/honomodel:@supabase/server/adapters/h3model:@supabase/server/adapters/elysiamodel:@supabase/server/adapters/nestjs

10/7/2026

Effective: 12/1/2026

deprecationhigh97% confidence

The four framework adapters in @supabase/server (@supabase/server/adapters/hono, /h3, /elysia, /nestjs) are deprecated and will be removed on December 1, 2026. Developers should migrate to framework-specific bridge files that compose @supabase/middleware entries instead.

Migration: Copy the appropriate bridge file from examples/frameworks into your project, add @supabase/middleware as a direct dependency (requires @supabase/server 1.6.0+ and Node 22+), then replace adapter registrations with the bridge pattern and update call sites to use flat keys (e.g., c.var.supabase, c.var.jwtClaims) instead of the nested supabaseContext object.
param:@supabase/server/adapters/honoparam:@supabase/server/adapters/h3param:@supabase/server/adapters/elysiaparam:@supabase/server/adapters/nestjs

10/7/2026

Effective: 12/1/2026

deprecationhigh97% confidence

Four framework adapters in @supabase/server (@supabase/server/adapters/hono, /h3, /elysia, /nestjs) are deprecated and will be removed on December 1, 2026. Developers must migrate to framework-specific bridge files that compose @supabase/middleware entries.

Migration: Copy the appropriate bridge file from examples/frameworks into your project, add @supabase/middleware as a direct dependency (requires @supabase/server >=1.6.0 and Node 22+), replace adapter registrations with bridge calls (e.g., toHono([withRequiredClaims(), withSupabaseClient()])), and update call sites to use flat context keys (c.var.supabase, c.var.jwtClaims) instead of the nested supabaseContext object.
endpoint:@supabase/server/adapters/honoendpoint:@supabase/server/adapters/h3endpoint:@supabase/server/adapters/elysiaendpoint:@supabase/server/adapters/nestjs

10/6/2026

Effective: 12/1/2026

breakinghigh95% confidence

PostgreSQL 15.19/17.11 minor release is being rolled out, requiring potential action for users of ltree indexes, pgcrypto with legacy ciphers (bf/blowfish/cast5), btree_gist indexes on float columns with NaN values, and custom operators with non-built-in selectivity estimators. Additionally, the Supabase Management API `logs.all` analytics endpoint was removed on 2026-09-23 and must be migrated to the new ClickHouse-backed `logs` endpoint.

Migration: Run the provided detection queries to identify affected ltree/btree_gist indexes and reindex them with REINDEX INDEX CONCURRENTLY; re-encrypt pgcrypto data using AES instead of bf/blowfish/cast5; update any scripts using the removed `logs.all` endpoint to use the new `logs` endpoint with ClickHouse SQL; recreate custom operators without non-built-in selectivity estimators.
endpoint:logs.allendpoint:logsmodel:ltree indexesmodel:pgcrypto legacy ciphers (bf/blowfish/cast5)model:btree_gist indexes on float columnsmodel:custom operators with non-built-in selectivity estimators

10/5/2026

Effective: 9/28/2026

breakinghigh97% confidence

PostgreSQL 15.19/17.11 minor release is being rolled out, with four potentially breaking changes: ltree indexes may need reindexing, pgcrypto stops decrypting legacy-cipher (bf/blowfish/cast5) PGP data by default, btree_gist indexes on float columns with NaN need reindexing, and custom operators with non-built-in selectivity estimators now require superuser to recreate.

Migration: Run the provided detection queries for each database. If affected: REINDEX INDEX CONCURRENTLY for ltree/btree_gist indexes; re-encrypt pgcrypto data using a modern cipher (e.g., aes256) before or after upgrade; recreate custom operators without non-built-in RESTRICT/JOIN estimators. Upgrade available in dashboard from 2026-09-28.
model:ltree indexesmodel:pgcrypto (pgp_sym_encrypt/pgp_pub_encrypt with bf/blowfish/cast5)model:btree_gist indexes on float columnsmodel:custom operators with non-built-in selectivity estimatorsmodel:PostgreSQL 15.19model:PostgreSQL 17.11

10/5/2026

Effective: 9/28/2026

breakinghigh97% confidence

PostgreSQL 15.19 / 17.11 minor release introduces four potentially breaking changes affecting ltree indexes, pgcrypto legacy ciphers (CVE-2026-14663), btree_gist indexes on float columns with NaN, and custom operators with non-built-in selectivity estimators (CVE-2026-2004). Users must run detection queries and take remediation steps to avoid silent data corruption or future restore failures.

Migration: Run the provided detection queries for ltree, pgcrypto, btree_gist, and custom operators. Reindex affected indexes using REINDEX INDEX CONCURRENTLY, re-encrypt pgcrypto data using AES instead of bf/blowfish/cast5, and recreate custom operators without non-built-in RESTRICT/JOIN estimators before performing any dump/restore or branching.
model:ltree indexesmodel:pgcrypto pgp_sym_encrypt/pgp_pub_encrypt (cipher-algo=bf/blowfish/cast5)model:btree_gist indexes on float columnsmodel:custom operators with non-built-in selectivity estimatorsendpoint:PostgreSQL 15.19 / 17.11 upgrade

10/2/2026

Effective: 9/28/2026

breakinghigh95% confidence

PostgreSQL minor release 15.19/17.11 introduces four potentially breaking changes affecting ltree indexes, pgcrypto legacy cipher decryption (CVE-2026-14663), btree_gist float indexes, and custom operators with non-built-in selectivity estimators. Affected users must run detection queries and may need to reindex or re-encrypt data.

Migration: Run the provided detection queries for each affected area (ltree, pgcrypto, btree_gist, custom operators). Use REINDEX INDEX CONCURRENTLY for affected indexes; re-encrypt pgcrypto data using cipher-algo=aes256; recreate custom operators without non-built-in estimators. Upgrade available in dashboard from 2026-09-28.
model:ltreemodel:pgcryptomodel:btree_gistmodel:pg_operatorendpoint:PostgreSQL 15.19 / 17.11

10/2/2026

Effective: 9/28/2026

breakinghigh95% confidence

PostgreSQL 15.19 / 17.11 minor release introduces four potentially breaking changes: ltree indexes may need reindexing, pgcrypto stops decrypting legacy-cipher (Blowfish/CAST5) PGP data by default, btree_gist indexes on float columns with NaN need reindexing, and custom operators with non-built-in selectivity estimators now require superuser to recreate.

Migration: Run the provided detection queries for each database. Reindex affected ltree and btree_gist indexes using REINDEX INDEX CONCURRENTLY. Re-encrypt pgcrypto data using a modern cipher (e.g., cipher-algo=aes256). Recreate custom operators without RESTRICT/JOIN clauses or use built-in estimators. Upgrade available in the dashboard from 2026-09-28.
model:ltree indexesmodel:btree_gist indexes (float columns)model:pgcrypto pgp_sym_encrypt/pgp_pub_encrypt (bf/blowfish/cast5 cipher-algo)model:custom operators with non-built-in selectivity estimators

10/1/2026

Effective: 9/28/2026

breakinghigh97% confidence

Supabase is rolling out PostgreSQL 15.19/17.11 minor releases that include four potentially breaking changes: ltree indexes may need reindexing, pgcrypto stops decrypting data encrypted with legacy ciphers (bf/blowfish/cast5) by default, btree_gist indexes on float columns containing NaN need reindexing, and custom operators with non-built-in selectivity estimators now require superuser to recreate.

Migration: Run the provided detection queries for each affected area (ltree, pgcrypto, btree_gist, custom operators). If affected: run REINDEX INDEX CONCURRENTLY for ltree/btree_gist indexes; re-encrypt pgcrypto data using AES256 before or after upgrade; recreate custom operators without RESTRICT/JOIN clauses or with built-in estimators. Upgrade available in dashboard from 2026-09-28.
model:ltree indexesmodel:pgcrypto (pgp_sym_encrypt/pgp_pub_encrypt with bf/blowfish/cast5 cipher-algo)model:btree_gist indexes on float4/float8 columnsmodel:custom operators with non-built-in selectivity estimators

9/30/2026

Effective: 9/28/2026

breakinghigh97% confidence

Supabase is rolling out PostgreSQL 15.19/17.11 minor releases that introduce four potentially breaking changes: ltree indexes may need reindexing, pgcrypto stops decrypting legacy-cipher (blowfish/cast5) PGP data by default, btree_gist indexes on float columns with NaN need reindexing, and custom operators with non-built-in selectivity estimators now require superuser to recreate.

Migration: Run the provided detection queries for each affected area (ltree, pgcrypto, btree_gist, custom operators). If affected: reindex ltree/btree_gist indexes using REINDEX INDEX CONCURRENTLY; re-encrypt pgcrypto data with a modern cipher (e.g., aes256); recreate custom operators without non-built-in RESTRICT/JOIN estimators. Upgrade available in dashboard from 2026-09-28.
model:ltree indexesmodel:btree_gist indexes on float columnsmodel:pgcrypto pgp_sym_encrypt/pgp_pub_encrypt with cipher-algo=bf/blowfish/cast5model:custom operators with non-built-in selectivity estimators

9/29/2026

Effective: 9/28/2026

breakinghigh95% confidence

Supabase is rolling out PostgreSQL 15.19/17.11 minor releases that include four potentially breaking changes: ltree indexes may need reindexing, pgcrypto stops decrypting legacy-cipher (Blowfish/CAST5) PGP data by default, btree_gist indexes on float columns with NaN need reindexing, and recreating custom operators with non-built-in selectivity estimators now requires superuser. Upgrade available in dashboard from 2026-09-28.

Migration: Run the provided detection queries for each database. If affected: (1) REINDEX INDEX CONCURRENTLY for ltree/btree_gist indexes, (2) re-encrypt pgcrypto data using AES256 before or after upgrade (use ignore-cipher-failure=1 post-upgrade), (3) recreate custom operators without RESTRICT/JOIN clauses or with built-in estimators.
model:ltree indexesmodel:btree_gist indexes (float columns)model:pgcrypto pgp_sym_encrypt/pgp_pub_encrypt (cipher-algo=bf/blowfish/cast5)model:custom operators with non-built-in selectivity estimators

9/28/2026

Effective: 9/28/2026

breakinghigh92% confidence

The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23 and must be migrated to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL. Additionally, multiple other breaking changes are present including extension version pinning deprecation, Envoy replacing Kong as default API gateway, Realtime schema lockdown, OAuth token endpoint returning HTTP 200 instead of 201, and tables no longer auto-exposed to Data/GraphQL API.

Migration: Immediately migrate scripts using `logs.all` to the new `logs` endpoint with ClickHouse SQL before 2026-09-23. Also: update OAuth token checks to use `response.ok` (2XX) instead of hardcoded 201; opt-in new tables to Data API manually; update self-hosted setups to use Envoy instead of Kong by 2026-08-09; stop using version clauses in CREATE/ALTER EXTENSION before 2026-08-05.
endpoint:GET /projects/{ref}/analytics/endpoints/logs.allendpoint:POST /v1/oauth/tokenendpoint:POST /v2/projects/{ref}/advisors/runparam:extension version clause in CREATE/ALTER EXTENSIONmodel:realtime schemamodel:public schema auto-exposuremodel:pg_graphql introspection

9/25/2026

Effective: 9/23/2026

breakingcritical97% confidence

The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23. Scripts must migrate to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL.

Migration: Migrate all scripts calling the `logs.all` endpoint to the new ClickHouse-backed `logs` endpoint before 2026-09-23; update queries to use ClickHouse SQL syntax.
endpoint:GET /projects/{ref}/analytics/endpoints/logs.allendpoint:logs endpoint (ClickHouse-backed replacement)

9/23/2026

Effective: 9/23/2026

breakingcritical95% confidence

The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23, requiring migration to the new ClickHouse-backed logs endpoint which only accepts ClickHouse SQL. Multiple other breaking changes are also present in this diff, including deprecation of extension version pinning, Envoy replacing Kong as the default API gateway for self-hosted, and Realtime schema lockdown.

Migration: Migrate scripts calling POST /v2/projects/{ref}/analytics/endpoints/logs.all to the new ClickHouse-backed logs endpoint before 2026-09-23; rewrite queries in ClickHouse SQL. Additionally: review extension version pinning deprecation (effective 2026-08-05), update self-hosted gateway config if using Kong-specific features (effective week of 2026-08-09), and ensure no custom objects exist in the realtime schema.
endpoint:POST /v2/projects/{ref}/analytics/endpoints/logs.allendpoint:POST /v2/projects/{ref}/advisors/runendpoint:GET /projects/{ref}/analytics/endpoints/logs.allmodel:realtime schemaparam:CREATE EXTENSION version clausemodel:Kong API gateway (self-hosted)

9/23/2026

Effective: 9/23/2026

breakingcritical97% confidence

The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23. Scripts must migrate to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL syntax.

Migration: Update all scripts calling the `logs.all` endpoint to use the new ClickHouse-backed `logs` endpoint before 2026-09-23. Note that the new endpoint only accepts ClickHouse SQL, so queries may need to be rewritten.
endpoint:GET /projects/{ref}/analytics/endpoints/logs.allendpoint:logs endpoint (ClickHouse-backed replacement)

9/22/2026

Effective: 9/23/2026

breakingcritical95% confidence

The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23. Scripts must migrate to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL.

Migration: Update all scripts calling the `logs.all` endpoint to use the new ClickHouse-backed `logs` endpoint before 2026-09-23. Note the new endpoint only accepts ClickHouse SQL syntax.
endpoint:POST /v2/projects/{ref}/analytics/endpoints/logs.allendpoint:GET /projects/{ref}/analytics/endpoints/logs.all

9/21/2026

Effective: 9/23/2026

breakingcritical92% confidence

The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23, requiring migration to the new ClickHouse-backed `logs` endpoint which accepts ClickHouse SQL only. Multiple other breaking changes are present in this changelog including extension version pinning deprecation, Envoy replacing Kong as default API gateway, Realtime schema lockdown, and several self-hosted configuration changes.

Migration: Migrate scripts calling `logs.all` to the new ClickHouse-backed `logs` endpoint before 2026-09-23. Also review: extension version pinning (deprecated 2026-08-05), Envoy gateway migration (2026-08-09), Realtime schema lockdown (effective 2026-07-14), and OAuth token endpoint returning HTTP 200 instead of 201 (effective 2026-06-01).
endpoint:GET /projects/{ref}/analytics/endpoints/logs.allendpoint:POST /v2/projects/{ref}/advisors/runendpoint:/v1/oauth/tokenendpoint:GET /projects/{ref}/analytics/endpoints/logs.allparam:CREATE EXTENSION version clausemodel:realtime schemamodel:pg_graphqlmodel:API_EXTERNAL_URL

9/20/2026

Effective: 9/23/2026

breakinghigh95% confidence

The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23 and must be migrated to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL. Additionally, several other breaking changes are present in this changelog including extension version pinning deprecation, Envoy replacing Kong as default API gateway, realtime schema lockdown, OAuth token endpoint returning HTTP 200 instead of 201, and tables no longer auto-exposed to the Data/GraphQL API.

Migration: For the logs.all removal: update all scripts calling `logs.all` to use the new `logs` endpoint with ClickHouse SQL before 2026-09-23. For the OAuth token endpoint change (effective 2026-06-01): replace hardcoded `201` status checks with `response.ok` or a `2XX` range check. For new table exposure change: opt-in to the new behavior now before the 2026-10-30 enforcement deadline.
endpoint:GET /projects/{ref}/analytics/endpoints/logs.allendpoint:/v1/oauth/tokenendpoint:GET /projects/{ref}/analytics/endpoints/logsmodel:realtime schemamodel:CREATE EXTENSION / ALTER EXTENSION version pinningmodel:public schema table auto-exposure

9/18/2026

Effective: 9/23/2026

breakinghigh95% confidence

The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23 and must be replaced with the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL. This is one of several breaking changes present in this changelog diff.

Migration: Migrate all scripts calling the `logs.all` endpoint to the new `logs` endpoint before 2026-09-23; rewrite queries in ClickHouse SQL syntax.
endpoint:GET /projects/{ref}/analytics/endpoints/logs.allendpoint:GET /projects/{ref}/analytics/endpoints/logs

9/18/2026

Effective: 9/23/2026

breakinghigh97% confidence

The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23. Scripts must migrate to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL.

Migration: Update all scripts calling the `logs.all` endpoint to use the new ClickHouse-backed `logs` endpoint. Note that the new endpoint requires ClickHouse SQL syntax, so queries may need to be rewritten.
endpoint:logs.allendpoint:/projects/{ref}/analytics/endpoints/logs.all

9/17/2026

Effective: 9/23/2026

breakinghigh97% confidence

The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23. Scripts must migrate to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL.

Migration: Update any scripts calling the `logs.all` endpoint to use the new ClickHouse-backed `logs` endpoint and rewrite queries in ClickHouse SQL before 2026-09-23.
endpoint:GET /projects/{ref}/analytics/endpoints/logs.allendpoint:logs (ClickHouse-backed replacement)

9/17/2026

Effective: 9/23/2026

breakinghigh97% confidence

The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23. Scripts must migrate to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL.

Migration: Update any scripts calling the `logs.all` endpoint to use the new `logs` endpoint with ClickHouse SQL syntax before 2026-09-23.
endpoint:GET /projects/{ref}/analytics/endpoints/logs.allendpoint:GET /projects/{ref}/analytics/endpoints/logs

9/17/2026

Effective: 9/23/2026

breakinghigh95% confidence

The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23. Scripts must migrate to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL syntax.

Migration: Update all scripts calling the `logs.all` endpoint to use the new ClickHouse-backed `logs` endpoint before 2026-09-23. Note that the new endpoint only accepts ClickHouse SQL, so queries may need to be rewritten.
endpoint:logs.allendpoint:logs

9/17/2026

Effective: 9/23/2026

breakingcritical93% confidence

The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23 and must be replaced with the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL syntax. Additionally, multiple other breaking changes are present in this changelog including extension version pinning deprecation, Envoy replacing Kong as default API gateway, realtime schema lockdown, and others.

Migration: Migrate scripts calling `logs.all` to the new ClickHouse-backed `logs` endpoint before 2026-09-23; update queries to use ClickHouse SQL syntax. Also audit other breaking changes: update extension CREATE/ALTER statements to omit version clauses (effective 2026-08-05), review self-hosted Kong dependencies before 2026-08-09 Envoy migration, and check realtime schema modification usage.
endpoint:GET /projects/{ref}/analytics/endpoints/logs.allendpoint:GET /projects/{ref}/analytics/endpoints/logsparam:CREATE EXTENSION / ALTER EXTENSION version clauseendpoint:realtime schema DDL operationsendpoint:/v1/oauth/tokenparam:API_EXTERNAL_URLmodel:pg_graphql introspectionmodel:pgmq delay parameter

9/16/2026

Effective: 9/23/2026

breakingcritical97% confidence

Multiple breaking changes are present in this diff, most critically: the Management API `logs.all` analytics endpoint is being removed on 2026-09-23, the Realtime schema is fully locked down against modifications, self-hosted Supabase is switching from Kong to Envoy as the default API gateway, and several other breaking changes affecting auth schemas, Data API exposure defaults, OAuth token response codes, and more.

Migration: Prioritize by deadline: (1) Migrate from `logs.all` to the new ClickHouse-backed logs endpoint before 2026-09-23; (2) Remove any DDL against the `realtime` schema immediately; (3) Self-hosted users relying on Kong must opt back in before 2026-08-09; (4) Update OAuth token checks from HTTP 201 to any 2XX before 2026-06-01; (5) Review Data API auto-exposure changes (enforced 2026-10-30); (6) Audit all other breaking changes for applicable deadlines.
endpoint:GET /projects/{ref}/analytics/endpoints/logs.allendpoint:/v1/oauth/tokenendpoint:/auth/v1/sso/saml/*model:realtime schemamodel:auth schemamodel:storage schemamodel:pg_graphqlmodel:pgmqparam:CREATE EXTENSION version clauseparam:API_EXTERNAL_URLheader:x-deno-version

9/15/2026

Effective: 8/5/2026

breakingcritical97% confidence

Multiple breaking changes are present in this diff, most urgently the removal of the Management API `logs.all` analytics endpoint on 2026-09-23, requiring migration to the new ClickHouse-backed logs endpoint. Additional active breaking changes include: Envoy replacing Kong as the default API gateway for self-hosted (week of 2026-08-09), realtime schema fully locked down, OAuth token endpoint returning HTTP 200 instead of 201, tables no longer auto-exposed to Data/GraphQL API, OpenAPI spec no longer accessible via anon key, and several others.

Migration: Immediate priorities: (1) Migrate scripts from `logs.all` to the new ClickHouse logs endpoint before 2026-09-23. (2) Self-hosted users: opt back into Kong before 2026-08-09 if relying on its features, or migrate to Envoy. (3) Update OAuth token checks from status 201 to `response.ok` / any 2XX before 2026-06-01. (4) Opt in new tables to Data API explicitly before 2026-10-30 enforcement. (5) Remove anon-key OpenAPI spec access; use service role key instead. (6) Stop using `CREATE/ALTER EXTENSION` with explicit version clauses before 2026-08-05.
endpoint:GET /projects/{ref}/analytics/endpoints/logs.allendpoint:/v1/oauth/tokenendpoint:GET /projects/{ref}/analytics/endpoints/logs (new ClickHouse endpoint)param:CREATE EXTENSION / ALTER EXTENSION version clausemodel:realtime schemamodel:public schema auto-exposure to Data APImodel:pg_graphql introspectionmodel:OpenAPI spec via anon keymodel:API_EXTERNAL_URL /auth/v1 pathmodel:Envoy vs Kong API gateway (self-hosted)model:pgmq delay parameter behaviormodel:realtime-js Node.js <22 ws transportmodel:auth/storage/realtime schema SQL restrictionsmodel:pg_graphql default enablementmodel:Supabase Management API GET /projects/{ref}/analytics/endpoints/logs.all 24h cap

9/14/2026

Effective: 9/23/2026

breakinghigh95% confidence

The diff contains multiple breaking changes across Supabase's platform, including removal of the `logs.all` analytics endpoint (2026-09-23), deprecation of extension version pinning, Envoy replacing Kong as the default API gateway for self-hosted, Realtime schema lockdown, OAuth token endpoint returning HTTP 200 instead of 201, tables no longer auto-exposed to Data/GraphQL API, and several others. The most immediately critical is the `logs.all` endpoint removal on 2026-09-23 and the OpenAPI spec access removal via anon key.

Migration: Audit all breaking changes: (1) Migrate from `logs.all` to the new ClickHouse-backed logs endpoint before 2026-09-23; (2) Update OAuth token checks from status 201 to `response.ok` (2xx) before 2026-06-01; (3) Self-hosted users must switch from Kong to Envoy or opt back into Kong before 2026-08-09; (4) Stop relying on auto-exposure of public schema tables to Data/GraphQL API before 2026-10-30; (5) Use service role key instead of anon key for OpenAPI spec access; (6) Review all other dated breaking changes and adjust timelines accordingly.
endpoint:GET /projects/{ref}/analytics/endpoints/logs.allendpoint:/v1/oauth/tokenendpoint:GET /projects/{ref}/analytics/endpoints/logsendpoint:/auth/v1/sso/saml/*model:realtime schemamodel:public schema table auto-exposuremodel:pg_graphqlmodel:pgmqparam:CREATE EXTENSION version clauseheader:API_EXTERNAL_URL

9/14/2026

breakingcritical97% confidence

Multiple breaking changes are present in this changelog, most critically: the Management API `logs.all` analytics endpoint is being removed on 2026-09-23, the Realtime schema is now fully locked down, self-hosted Supabase is switching from Kong to Envoy as the default API gateway, and several other breaking changes affecting Auth, Data API, pg_graphql, and schema permissions are in effect or upcoming.

Migration: Immediately audit usage of: (1) `logs.all` endpoint → migrate to new ClickHouse-backed logs endpoint before 2026-09-23; (2) Realtime schema modifications → remove any DDL against `realtime` schema; (3) Self-hosted Kong → opt back in or migrate to Envoy before 2026-08-09; (4) Extension version pinning in CREATE/ALTER EXTENSION → remove explicit version clauses before 2026-08-05; (5) OAuth token endpoint → check for HTTP 200 instead of 201 from `/v1/oauth/token`; (6) Tables auto-exposed to Data API → opt in explicitly before 2026-10-30.
endpoint:GET /projects/{ref}/analytics/endpoints/logs.allendpoint:/v1/oauth/tokenendpoint:realtime schema DDLendpoint:GET /projects/{ref}/analytics/endpoints/logsparam:CREATE EXTENSION version clauseparam:ALTER EXTENSION version clausemodel:realtime schemamodel:auth schemamodel:storage schemamodel:pg_graphqlmodel:API_EXTERNAL_URLheader:x-deno-version

9/9/2026

Effective: 9/23/2026

breakinghigh95% confidence

The Supabase Management API `logs.all` analytics endpoint is being removed on 2026-09-23 and must be migrated to the new ClickHouse-backed `logs` endpoint, which only accepts ClickHouse SQL. Additionally, multiple other breaking changes are present in this changelog batch, including removal of the `realtime` schema modification access, deprecation of extension version pinning, and Envoy replacing Kong as the default API gateway for self-hosted deployments.

Migration: Migrate any scripts using the `logs.all` endpoint to the new `logs` endpoint with ClickHouse SQL before 2026-09-23. Review all other breaking changes (Envoy gateway, realtime schema lockdown, extension version pinning) and update self-hosted configurations and API integrations accordingly.
endpoint:GET /v1/analytics/endpoints/logs.allendpoint:GET /v1/analytics/endpoints/logsmodel:realtime schemaparam:CREATE EXTENSION version clausemodel:API_EXTERNAL_URLendpoint:/auth/v1/sso/saml/*

9/8/2026

Effective: 9/23/2026

Get alerts when Supabase changes affect your code

Connect your GitHub repos and Breakwatch will map your Supabase usage and alert you about relevant changes.

Get started for free