Supabase Security & compliance

Signed URL TTL long enough to act as a public URL

Part of the Storage safety check · fix arrives as a guide

What it is

A signed URL is created with a TTL long enough that it functions as a permanent link — days or more.

Why it matters

A signed URL cannot be revoked before it expires. A long TTL that leaks through a referrer header, a shared screenshot, or a chat message stays valid for the rest of its life.

How to fix it

Set the TTL from how long the link is genuinely needed — seconds to minutes for a download, an hour at most for an embedded asset. Generate a fresh URL per view instead of storing one.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.