Supabase Security & compliance

Email OTP expiry over 1 hour (interception window)

Part of the Auth hardening & exposure config check · fix arrives as a guide

What it is

The email OTP expiry is configured to more than an hour.

Why it matters

The code stays valid for the whole window, so an intercepted email — a shared inbox, a forwarded message, a compromised mail account — remains usable long after the user has finished with it.

How to fix it

Reduce the OTP expiry to an hour or less; 15 minutes is comfortable for most flows. Supabase recommends keeping it short, and users who need a new code can request one.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.