Put saves in a public table with an owner column, enable Row Level Security on it, and write a policy that only lets each authenticated user (or anonymous auth user) read and write their own rows. Query it from the browser with a publishable key, never a service key.
At a glance
| Fact | Value | Source |
|---|---|---|
| Table without RLS is fully open | readable/writable by any grant holder | supabase.com |
| RLS blocks all access until policies exist | no data via publishable key | supabase.com |
| Anonymous auth users get row-level access | via anonymous auth | supabase.com |
Design one saves table in the public schema with a user_id column referencing auth.users, then enable Row Level Security on it and add a policy that only lets a role read or write rows where user_id = auth.uid(). A table in an exposed schema without RLS is readable and writable by any role with a grant on it, and once RLS is enabled no data is reachable through the Data API with a publishable key until you write policies (Supabase RLS docs). Combine RLS with Supabase Auth so the browser-to-database path is scoped per user rather than trusting the client.
If you prefer not to manage backend saves, the Playgama Bridge Storage module automatically persists data across platforms, including cloud saves.
What to check before shipping
- Use
signInAnonymously()for players who never log in – it behaves like a permanent user but progress is lost if they clear browser data or switch devices, unless later linked to a real identity. - Always connect from the browser with the publishable key, never a service key; the Data API only reaches schemas you’ve explicitly exposed and granted.
- Split shared tables (leaderboards everyone reads) from per-user tables (saves only the owner reads) – each needs its own policy, and the shared one is easy to forget.
- If you publish on portals with their own profile system, check the portal’s rules on external accounts.
Sources
- Row Level Security | Supabase Docs
- Securing your data | Supabase Docs
- Tables and data | Supabase Docs
- Anonymous Sign-Ins | Supabase Docs
- Account integration – CrazyGames Documentation
- Playgama Bridge Storage docs
Related questions
Can I skip auth and just use an anonymous device ID for saves?
Yes with signInAnonymously() – it creates a real auth user so RLS policies still apply, but progress is lost if the player clears browser data or switches device.
Does RLS slow down every save request?
It runs inside Postgres as part of the query plan; the bigger risk is forgetting to write a policy at all, which blocks every request with a publishable key.
Last updated: 30 September 2026