Skip to content

API keys

Every project has two kinds of API keys. Manage them in the dashboard under API → Keys.

Key Prefix Use in Database role
Publishable lb_pub_... browsers, mobile apps, anywhere anon, or authenticated once a user is signed in. RLS applies.
Secret lb_sec_... your servers, CI and scripts only service_role. Bypasses RLS.

Safe to embed in client code. It identifies the project; what a visitor can do is decided by your RLS policies.

The full key is shown once when you create it. Only a hash is stored, so a lost key must be replaced. Revoking a key takes effect within about a second.

The SDK exchanges the secret key for a short-lived service_role token and sends only that token to the data, storage and realtime APIs.

import { createClient } from "@potalab/base"
// server only
const admin = createClient({ url: process.env.POTALAB_BASE_URL!, key: process.env.POTALAB_BASE_SECRET_KEY! })
await admin.from("orders").select("*") // bypasses RLS

Repeated invalid secret keys from one IP address are rate limited (429).