Supabase
Security & compliance
Email OTP expiry over 1 hour (interception window)
Part of the Auth hardening & exposure config check · fix arrives as a guide
What it is
The email OTP expiry is configured to more than an hour.
Why it matters
The code stays valid for the whole window, so an intercepted email — a shared inbox, a forwarded message, a compromised mail account — remains usable long after the user has finished with it.
How to fix it
Reduce the OTP expiry to an hour or less; 15 minutes is comfortable for most flows. Supabase recommends keeping it short, and users who need a new code can request one.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.