supabase personal access token dashboard shown once
What to do when a Supabase personal access credential was shown only once and is now lost. Use when the dashboard wont reveal the value again, when an agent stored it somewhere unreachable, or when a teammate left with the only copy. Not for project API keys, for OAuth client ids, or for database passwords.
TL;DR
Supabase shows a personal access credential's secret exactly once at creation and never again, so a lost value is unrecoverable by design. Revoke the lost credential in the dashboard and generate a new one, then store the new value in your secret manager immediately.
supabase personal access token dashboard shown onceUse this when
- You clicked away before copying the credential value
- An agent generated the credential and didnt persist it
- The only copy lived with someone who is gone
Not for this skill when
- You need a project anon or service key (Project Settings \u2192 API shows those anytime)
- The problem is an OAuth client id (thats an integration, not a shown-once secret)
- You need the database password (that can be reset, not revealed)
Steps
- Confirm the value is truly unrecoverable: open the account credentials page and look for a reveal option:
Dashboard > avatar > Account \u2192 Access Credentials: no reveal button existsExpected output: each entry shows name and creation date only. This confirms there is nothing to recover; stop searching.
- Revoke the lost credential so it cant be abused:
Access Credentials \u2192 find the entry \u2192 RevokeExpected output: the entry shows as revoked. A credential nobody can find is a credential nobody controls, so revocation is the safe move.
- Generate a replacement with a clear purpose name:
Generate new \u2192 name it e.g. "ci-management-2026-10" > copy the value immediatelyExpected output: the new secret displays once. Paste it into your vault before doing anything else.
- Update every automation that used the old credential:
grep -rl "OLD_VALUE_HINT" ~/projectsExpected output: the list of configs referencing the old credential. You wont have the old value to grep for, so instead grep for where the credential is consumed (env var names, config keys) and update those.
Variant phrasings
can support recover my personal access credential
No. Shown-once secrets are not stored recoverably; support will tell you to revoke and re-create.
I screenshotted it, is that safe
It works as a backup but the screenshot is now a secret; move the value into a proper vault and delete the image.
Why it happens
The dashboard warns that the value is shown once, but the warning looks like routine UI chrome and people click past it. Agents are worse: they generate the credential via the flow, print the value to a log or hold it in context, and then the run ends. The design is deliberate (recoverable secrets are a liability), so the only fix is process: copy first, then continue.
Edge cases
- If the lost credential was the only admin-level credential, create the replacement before revoking so you dont lock yourself out mid-flow.
- Audit what the old credential could touch before revoking; if it had broad access, check for unexpected usage first.
- Name credentials with dates or purposes so the next person knows which entry is safe to revoke.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_e0bsYVsrnE2H8LT08f1Eyw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.