Business FAQs

How to use Supabase RLS and schema for browser game saves?

0
(0)

Put saves in a public table with an owner column, enable Row Level Security on it, and write a policy that only lets each authenticated user (or anonymous auth user) read and write their own rows. Query it from the browser with a publishable key, never a service key.

At a glance

Fact Value Source
Table without RLS is fully open readable/writable by any grant holder supabase.com
RLS blocks all access until policies exist no data via publishable key supabase.com
Anonymous auth users get row-level access via anonymous auth supabase.com

Design one saves table in the public schema with a user_id column referencing auth.users, then enable Row Level Security on it and add a policy that only lets a role read or write rows where user_id = auth.uid(). A table in an exposed schema without RLS is readable and writable by any role with a grant on it, and once RLS is enabled no data is reachable through the Data API with a publishable key until you write policies (Supabase RLS docs). Combine RLS with Supabase Auth so the browser-to-database path is scoped per user rather than trusting the client.

If you prefer not to manage backend saves, the Playgama Bridge Storage module automatically persists data across platforms, including cloud saves.

What to check before shipping

  • Use signInAnonymously() for players who never log in – it behaves like a permanent user but progress is lost if they clear browser data or switch devices, unless later linked to a real identity.
  • Always connect from the browser with the publishable key, never a service key; the Data API only reaches schemas you’ve explicitly exposed and granted.
  • Split shared tables (leaderboards everyone reads) from per-user tables (saves only the owner reads) – each needs its own policy, and the shared one is easy to forget.
  • If you publish on portals with their own profile system, check the portal’s rules on external accounts.

Sources

Can I skip auth and just use an anonymous device ID for saves?

Yes with signInAnonymously() – it creates a real auth user so RLS policies still apply, but progress is lost if the player clears browser data or switches device.

Does RLS slow down every save request?

It runs inside Postgres as part of the query plan; the bigger risk is forgetting to write a policy at all, which blocks every request with a publishable key.

Last updated: 30 September 2026


How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

Your email address will not be published. Required fields are marked *

Games categories