Supabase Security & compliance

Manual account linking enabled without a product need

Part of the Auth hardening & exposure config check · fix arrives as a guide

What it is

Manual account linking is enabled on the project without a product feature that requires it.

Why it matters

It lets one identity be attached to another account through the API. Without a deliberate flow around it, it widens the surface for account takeover for a capability nothing in the product uses.

How to fix it

Disable manual linking unless a feature depends on it. Where it is needed, gate it behind a re-authentication step so linking requires proving control of the existing account.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.