## TL;DR
Supabase shows a personal access credential's secret exactly once at creation and never again, so a lost value is unrecoverable by design. Revoke the lost credential in the dashboard and generate a new one, then store the new value in your secret manager immediately.

```text
supabase personal access token dashboard shown once
```

## Use this when
- You clicked away before copying the credential value
- An agent generated the credential and didnt persist it
- The only copy lived with someone who is gone

## Not for this skill when
- You need a project anon or service key (Project Settings \u2192 API shows those anytime)
- The problem is an OAuth client id (thats an integration, not a shown-once secret)
- You need the database password (that can be reset, not revealed)

## Steps

1. Confirm the value is truly unrecoverable: open the account credentials page and look for a reveal option:

```text
Dashboard > avatar > Account \u2192 Access Credentials: no reveal button exists
```
Expected output: each entry shows name and creation date only. This confirms there is nothing to recover; stop searching.

2. Revoke the lost credential so it cant be abused:

```text
Access Credentials \u2192 find the entry \u2192 Revoke
```
Expected output: the entry shows as revoked. A credential nobody can find is a credential nobody controls, so revocation is the safe move.

3. Generate a replacement with a clear purpose name:

```text
Generate new \u2192 name it e.g. "ci-management-2026-10" > copy the value immediately
```
Expected output: the new secret displays once. Paste it into your vault before doing anything else.

4. Update every automation that used the old credential:

```bash
grep -rl "OLD_VALUE_HINT" ~/projects
```
Expected output: the list of configs referencing the old credential. You wont have the old value to grep for, so instead grep for where the credential is consumed (env var names, config keys) and update those.

## Variant phrasings

### can support recover my personal access credential
No. Shown-once secrets are not stored recoverably; support will tell you to revoke and re-create.

### I screenshotted it, is that safe
It works as a backup but the screenshot is now a secret; move the value into a proper vault and delete the image.

## Why it happens
The dashboard warns that the value is shown once, but the warning looks like routine UI chrome and people click past it. Agents are worse: they generate the credential via the flow, print the value to a log or hold it in context, and then the run ends. The design is deliberate (recoverable secrets are a liability), so the only fix is process: copy first, then continue.

## Edge cases
- If the lost credential was the only admin-level credential, create the replacement before revoking so you dont lock yourself out mid-flow.
- Audit what the old credential could touch before revoking; if it had broad access, check for unexpected usage first.
- Name credentials with dates or purposes so the next person knows which entry is safe to revoke.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_e0bsYVsrnE2H8LT08f1Eyw
