NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1880 most downloaded on npm
Isomorphic Javascript SDK for Supabase
Last release 2 days ago
02 Oct 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
2 versions withdrawn
withdrawn after publishing
7 years old
838 releases · first in 2020
One column per quarter.
Nothing published for this version
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
realtime: guard sessionStorage access in restricted-storage browsers
auth: return null from getItemAsync on JSON parse failure
postgrest: restore non-Error abort detection in fetch catch
auth: narrow OAuth/CustomProvider types to fix downstream consumer typecheck
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
auth: add toJSON to WebAuthnError for correct JSON serialization
auth: forward lockAcquireTimeout to SupabaseAuthClient (#2309, #2310)
misc: reduce any usage across packages
⚠️ postgrest: wrap error in PostgrestError instance on processResponse
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
misc: widen enum-like unions with (string & {}) for forward compat
realtime: surface real Error on transport-level CHANNEL_ERROR
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
auth: add passkey support with WebAuthn registration, authentication, and management
storage: forward duplex option for stream uploads via uploadToSignedUrl
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
realtime: annotate Timer/Vsn getters to avoid deep phoenix imports
storage: apply metadata, headers, and cacheControl dedupe to uploadToSignedUrl
auth: add passkey support with WebAuthn registration, authentication, and management
postgrest: narrow column types after not(column, is, null)
auth: emit PASSWORD_RECOVERY event for PKCE recovery flows
realtime: Realtime deferred disconnect
supabase: propagate custom fetch to realtime client
postgrest: restore runtime test files to tstyche scope
⚠️ obsolete deprecated features
client.user(), client.session(), and client.refreshSession() (23ffc6e7)Buffer and NodeJS.ReadableStream support (#5)createSignedUrls method (#32).nullsfirst/.nullslast by default (378471cf)null in response (a7aa83c9)setSession support for a SSR context (c0c046fb)signInWithSSO method as @experimental (#526)listUsers() method (#537)listUsers() method (#544, #537)->/->> for column names (01ab2392)skipBrowserRedirect option to signInWithOAuth (#575, #417)signInWithIdToken for Apple, Google (#603)localStorage support check (#600, #436)BroadcastChannel is not supported (#626)UserIdentity nullable (#619)SIGNED_IN event on PASSWORD_RECOVERY (#629)signInWithSSO, update docs (#643)signInWithSSO types to work with docs (#644)Deno.unrefTimer to stop runtime from hanging (#632, #617)Deno.unrefTimer to stop runtime from hanging (#659, #632)onAuthStateChange callbacks (#685, #276)messageId when using otp (#706)_recoverAndRefresh does not remove session on retryable error (#710)_handleRequest (#708)_recoverAndRefresh (#711)<= for auto refresh token threshold (#716)signOut() scope option (#713)_useSession semantics (#726)_useSession semantics for unknown issue (#732, #726)_useSession semantics (#734, #726, #732)_getSessionFromURL to be easier to read (#733)navigatorLock check for spec compatibility (#761)expires_at if present (#735, #733)persistSession is false or localStorage is not supported (#774)SIGNED_OUT event if token refresh fails (#815)AuthWeakPasswordError (#817)weakPassword information after sign-in (#824)navigatorLock on browsers (#807)getSession() when isServer on storage (#846)cache: no-store in fetch (#847)() (#445)count (#498, #447, #479).from() (#528).rpc() with GET (cf20ecbc)cache: no-store as it breaks cloudflare (#886)SIGNED_OUT when JWT session_id is invalid (#905)signInWithWeb3 with solana (#1037)getClaims() non experimental, add global cache (#1078)getUser() if the kid of the JWT is not found (#1080)signInWithWeb3 (#1082)userStorage option to facilitate lower cookie sizes (#1545)linkIdentity for oidc / native sign-in (#1096)onAuthStateChange with async function (#1580)token_endpoint_auth_method to OAuth client create/update (#2132)custom: prefix in Provider type (#2134)copyBindings functionality (#2197)postgres_changes event listener after joining (#2201)string & values to unknown (dd4dc91c)or filter (a0bc38fc)(), for values (b99ff1b8)columns param on bulk INSERT (b4ff9df8)removeUser method from the client (cf2dad49)columns query param (0ddf7820)createSignedUrls() instead of just paths (45753731).from() (c3309b1a)application/json in Content-Type header (#429)data option for sign ins (baefbca5)captcha_token in verifyOtp (#525)EXPIRY_MARGIN on getSession" (#533, #482, #529)captchaToken option on verifyOtp deprecated (#532, #795)getUser() in listFactors() (#570)location.assign() instead of location.href (#573, #155)unref on setInterval to stop tests from hanging (#599, #564, #597)null if return=minimal (c6c49b8e)notifyAllSubscribers in the constructor (#623)generatePKCEVerifier and fix parameter of _handleProviderSignIn (#638)_isPKCEFlow is not being awaited (#653)?columns= on upsert (e9615e45)details on FetchError (39e8a1b1)persistSession is true with no storage option (#697, #539)_initialize before loading the session (#747)Note truncated.
deps: bump next to patch RCE in realtime-js example
postgrest: avoid instantiation depth errors for large relationship unions
This was a version bump only for @supabase/supabase-js to align it with other projects, there were no code changes.
postgrest: avoid instantiation depth errors for large relationship unions
auth: return stored session when a refresh loses to another tab
auth: return stored session when a refresh loses to another tab
auth: enable passkey API by default and deprecate experimental passkey opt-in
auth: enable passkey API by default and deprecate experimental passkey opt-in
auth: forward options.mediation to navigator.credentials.get in signInWithPasskey
auth: add MFA recovery codes API
auth: add MFA recovery codes API
storage: drop legacy prefix from lifecycles
auth: silence commit-guard-discarded refresh in initial session
storage: add bucket lifecycle configuration
supabase: warn when schema is passed outside db options
postgrest: add getOpenApiSpec()
postgrest: add getOpenApiSpec()
storage: object versioning updates
This was a version bump only for @supabase/supabase-js to align it with other projects, there were no code changes.
storage: object versioning updates
realtime: allow wait for pg changes
This was a version bump only for @supabase/supabase-js to align it with other projects, there were no code changes.
realtime: allow wait for pg changes
auth: warn on deprecated lock option and prevent unhandled refresh rejection
This was a version bump only for @supabase/supabase-js to align it with other projects, there were no code changes.
auth: warn on deprecated lock option and prevent unhandled refresh rejection
auth: convert stolen-lock AbortError when acquireTimeout is 0
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
postgrest: move override fixtures out of generated types, repair codegen
supabase: add trace context headers to canonical CORS allow-list
supabase: add trace context headers to canonical CORS allow-list
realtime: prevent duplicate on bindings
This was a version bump only for @supabase/supabase-js to align it with other projects, there were no code changes.
realtime: clear stale join payload on sign-out
Your coding agent can read these notes before it upgrades. Set up the MCP server →