# Supabase Storage solution docs

- [Cleaning up orphaned uploads before they become the bill](https://agenticboilerplate.com/cookbook/supabase-storage/cleaning-up-orphaned-uploads): Every abandoned upload and every deleted row leaves an object nothing references. Here is where orphans come from, the sweeper that finds them, and the two-phase delete that stops making more.
- [Serving images from Supabase Storage without shipping 4 MB avatars](https://agenticboilerplate.com/cookbook/supabase-storage/image-transformation): On-the-fly transformation resizes at read time, but it is metered and it fights your cache. When to transform, when to resize on upload, and how signed URLs complicate both.
- [Public bucket or private bucket: decide once, per bucket, on purpose](https://agenticboilerplate.com/cookbook/supabase-storage/public-vs-private-buckets): A public bucket serves every object to anyone who guesses a key, forever. A private one costs you a signing step and a cache problem. Here is how to choose, and why mixing them in one bucket goes wrong.
- [Row level security on storage buckets, and why yours might not be running](https://agenticboilerplate.com/cookbook/supabase-storage/rls-on-storage-buckets): Storage policies are SQL against storage.objects keyed on the path. Here is the policy set that works, the key layout it depends on, and why the service role key silently bypasses all of it.
- [Signed upload URLs versus proxying the file through your server](https://agenticboilerplate.com/cookbook/supabase-storage/signed-upload-urls-vs-proxying): Proxying uploads through a route handler hits body limits, doubles the transfer and bills you for the wait. Sign a URL instead, and get the order of the checks right.

---

Agentic Boilerplate: A Next.js repo your agent already knows. Free during launch, then $99 once.

- Site map for agents: https://agenticboilerplate.com/llms.txt
- Public API: https://agenticboilerplate.com/openapi.json
- Contact: agenticstudio@gmail.com
