Supabase
Security & compliance
Signed URL TTL long enough to act as a public URL
Part of the Storage safety check · fix arrives as a guide
What it is
A signed URL is created with a TTL long enough that it functions as a permanent link — days or more.
Why it matters
A signed URL cannot be revoked before it expires. A long TTL that leaks through a referrer header, a shared screenshot, or a chat message stays valid for the rest of its life.
How to fix it
Set the TTL from how long the link is genuinely needed — seconds to minutes for a download, an hour at most for an embedded asset. Generate a fresh URL per view instead of storing one.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.