Supabase
Security & compliance
Manual account linking enabled without a product need
Part of the Auth hardening & exposure config check · fix arrives as a guide
What it is
Manual account linking is enabled on the project without a product feature that requires it.
Why it matters
It lets one identity be attached to another account through the API. Without a deliberate flow around it, it widens the surface for account takeover for a capability nothing in the product uses.
How to fix it
Disable manual linking unless a feature depends on it. Where it is needed, gate it behind a re-authentication step so linking requires proving control of the existing account.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.