Supabase public buckets still need explicit storage policies
Shows how to fix supabase public buckets still need explicit storage policies. Use it when you hit this exact problem. Skip it when your error message or symptom looks different.
TL;DR
Create insert, select, update, and delete policies on storage.objects for each bucket, even public ones.
Steps
- Create insert, select, update, and delete policies on storage.objects for each bucket, even public ones. Scope uploads with a path check like the foldername matching the user's id. Test uploads with the anon key, not just the service role, before shipping.
When to use
You are seeing this: Scope uploads with a path check like the foldername matching the user's id. Use this skill when you run into "Supabase public buckets still need explicit storage policies".
When not to use
If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.
Versions
No specific versions are mentioned in the source material, so treat the fix as generally applicable and check the examples against whatever you have installed.
Why this happens
The original report does not dig into a root cause. It documents the symptom and the fix that resolved it.