NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1880 most downloaded on npm
Isomorphic Javascript SDK for Supabase
Last release today
17 Sep 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 60 of the last 60 stable releases
2 versions withdrawn
withdrawn after publishing
7 years old
831 releases · first in 2020
One column per quarter.
supabase: move OpenTelemetry tracing to opt-in /tracing subpath
supabase: move OpenTelemetry tracing to opt-in /tracing subpath
auth: accept uppercase UUIDs in validateUUID
supabase: forward db retry option
auth: store PKCE verifiers in per-flow slots to survive overlapping flows
This was a version bump only for @supabase/supabase-js to align it with other projects, there were no code changes.
auth: store PKCE verifiers in per-flow slots to survive overlapping flows
auth: downgrade stale refresh token console noise
This was a version bump only for @supabase/supabase-js to align it with other projects, there were no code changes.
realtime: preserve presence refs
auth: downgrade stale refresh token console noise
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
repo: override sharp to >=0.35.0 to clear libvips advisory
auth: downgrade aborted/transient fetch failures from console.error to warn
storage: url-encode object key in CDN purge methods
auth: downgrade aborted/transient fetch failures from console.error to warn
functions: clean up cross-signal abort listener on invoke() return
postgrest: correct self-reference inference
realtime: update phoenix to fix presence issue
postgrest: correct self-reference inference
postgrest: type hinted self-referencing embeds as arrays
supabase: warn instead of throw for unrecognized sb_ API key subtypes
realtime: forward opts to send() in track()
postgrest: type hinted self-referencing embeds as arrays
supabase: avoid edge runtime warning
functions: stop sending API key in Authorization header for function calls
functions: stop sending API key in Authorization header for function calls
postgrest: pin tstyche target off floating latest
This was a version bump only for @supabase/supabase-js to align it with other projects, there were no code changes.
## 2.110.3-canary.1 (2026-07-13) ### 🩹 Fixes - auth: preserve pkce verifier (#2513) ### ❤️ Thank You - Vaibhav @7ttp
postgrest: pin tstyche target off floating latest
auth: clear local session on signout failures
This was a version bump only for @supabase/supabase-js to align it with other projects, there were no code changes.
auth: clear local session on signout failures
auth: defer init-time notifications until initializePromise resolves
This was a version bump only for @supabase/supabase-js to align it with other projects, there were no code changes.
auth: defer init-time notifications until initializePromise resolves
Katerina Skroumpelou @mandarini
Katerina Skroumpelou @mandarini
auth: add custom_claims_allowlist to custom providers admin API
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
functions: honor a caller's Content-Type override regardless of casing
realtime: pin @supabase/phoenix and browser test CDN deps
auth: preserve valid session on refresh failure and cooldown repeat failures
This was a version bump only for @supabase/supabase-js to align it with other projects, there were no code changes.
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
realtime: clarify httpSend() 404 error and server migration note
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
release: restore JSR publish flags and enable for beta
release: pin Deno and bound JSR publish to survive stranded-task hangs
auth: preserve valid session on refresh failure and cooldown repeat failures
auth: preserve valid session on refresh failure and cooldown repeat failures
auth: preserve valid session on refresh failure and cooldown repeat failures
auth: preserve valid session on refresh failure and cooldown repeat failures
ci: forward DOGFOOD_APP_CLIENT_ID to dogfood workflow
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
## 2.108.1-canary.1 (2026-06-08) ### 🩹 Fixes - postgrest: then typing (#2349) ### ❤️ Thank You - Vaibhav @7ttp
ci: forward DOGFOOD_APP_CLIENT_ID to dogfood workflow
auth: auth.resend() consistent confirmation flow
This was a version bump only for @supabase/supabase-js to align it with other projects, there were no code changes.
auth: auth.resend() consistent confirmation flow
auth: remove navigator.locks-based mutex; introduce commit guard + dispose()
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
release: publish gotrue-js legacy mirror via pnpm
release: pin workspace:* sibling deps before JSR publish
This was a version bump only, there were no code changes.
This was a version bump only, there were no code changes.
auth): revert fix(auth: encode client-id in oauth requests (#2383, #2417)
Your coding agent can read these notes before it upgrades. Set up the MCP server →