# Supabase solution docs

- [Server code should stop using the anon key, and must not reach for the service role instead](https://agenticboilerplate.com/cookbook/supabase/beyond-the-anon-key-on-the-server): The anon key is a public identifier, not a credential. Server work needs either the caller's JWT or a deliberate, audited service-role call. Here is how to tell which.
- [Supabase gives you three connection strings: pick the right one or production falls over](https://agenticboilerplate.com/cookbook/supabase/direct-vs-pooler-connection-strings): Direct on 5432, session pooler on 5432, transaction pooler on 6543. Which one serverless needs, why prepared statements break, and what to run migrations on.
- [Stopping Supabase generated types from drifting out of the schema](https://agenticboilerplate.com/cookbook/supabase/generated-types-drift): Generated database types are only true at the moment they were generated. Commit them, regenerate them in the same commit as the migration, and check them in verify.
- [Local Supabase or a hosted branch - pick per environment, not per team](https://agenticboilerplate.com/cookbook/supabase/local-dev-vs-supabase-branches): The CLI stack and Supabase branching solve different problems. Use local for the inner loop, a branch for preview deploys, and never share one dev project.
- [Row level security when an ORM is doing the querying](https://agenticboilerplate.com/cookbook/supabase/rls-with-an-orm-in-front): Your ORM connects as the postgres superuser, so RLS never runs. Here is how to keep policies meaningful without giving up typed queries.

---

Agentic Boilerplate: A Next.js repo your agent already knows. Free during launch, then $99 once.

- Site map for agents: https://agenticboilerplate.com/llms.txt
- Public API: https://agenticboilerplate.com/openapi.json
- Contact: agenticstudio@gmail.com
