scribase
Security and secretsversion 0.3.1preloaded

supabase_vault

Store secrets encrypted with a key only the server can read.

What it is for

Vault stores secrets (API keys for third-party services, signing secrets) encrypted at rest. The encryption key is not stored in the database, so a dump or a backup holds only ciphertext. Read secrets back through the vault.decrypted_secrets view from trusted server-side code.

Enable it

sql
create extension if not exists supabase_vault;

Its library is preloaded when the database starts (shared_preload_libraries), so CREATE EXTENSION is all you need.

Example

sql
select vault.create_secret('my-webhook-signing-secret', 'webhook_secret', 'Signs outgoing webhooks');

select decrypted_secret
from vault.decrypted_secrets
where name = 'webhook_secret';

Questions

How do I enable supabase_vault?

Run create extension if not exists supabase_vault; in the SQL editor, or switch it on from the Extensions page in the console. You do not need superuser access.

Which version of supabase_vault is installed?

0.3.1, on Postgres 17.6, as read from the running engine on 2026-10-08. Check yours with: select extversion from pg_extension where extname = 'supabase_vault';

Upstream project: github.com/supabase/vault

More security and secrets extensions

  • pgcrypto Hashing, password hashing and encryption functions.
  • pgaudit Write detailed audit lines for the statements you choose.