supabase_vault
Store secrets encrypted with a key only the server can read.
What it is for
Vault stores secrets (API keys for third-party services, signing secrets) encrypted at rest. The encryption key is not stored in the database, so a dump or a backup holds only ciphertext. Read secrets back through the vault.decrypted_secrets view from trusted server-side code.
Enable it
create extension if not exists supabase_vault;Its library is preloaded when the database starts (shared_preload_libraries), so CREATE EXTENSION is all you need.
Example
select vault.create_secret('my-webhook-signing-secret', 'webhook_secret', 'Signs outgoing webhooks');
select decrypted_secret
from vault.decrypted_secrets
where name = 'webhook_secret';Questions
How do I enable supabase_vault?
Run create extension if not exists supabase_vault; in the SQL editor, or switch it on from the Extensions page in the console. You do not need superuser access.
Which version of supabase_vault is installed?
0.3.1, on Postgres 17.6, as read from the running engine on 2026-10-08. Check yours with: select extversion from pg_extension where extname = 'supabase_vault';
Upstream project: github.com/supabase/vault