library · inferred from evidence
@supabase/supabase-js
The main Supabase JavaScript client library for interacting with Supabase services.
- SvelteKit + Supabase: cookie-based SSR client in hooks.server.ts, per request
SvelteKit agents either skip SSR auth entirely or share one client across requests. The current docs pattern: createServerClient per request in hooks.server.ts with the SvelteKit cookie interface, browser client in the load functions that r
- React SPA (Vite) + Supabase: one singleton client, PKCE flow, and session restore on load
In a Vite SPA the failure modes are different from SSR: recreating the client per render, missing the auth callback, and assuming the session is ready on first paint. One module-level client plus an explicit session restore fixes all three.
- Next.js Pages Router + Supabase: auth-helpers is deprecated, build the server client per request with @supabase/ssr
Training data still teaches @supabase/auth-helpers-nextjs for the Pages Router. It is deprecated. The current pattern is createServerClient from @supabase/ssr inside getServerSideProps, bound to that request's cookies.
- Next.js App Router + Supabase: browser client for Client Components, fresh server client per request
Agents break Supabase auth on App Router by reusing one client everywhere. The rule from the current docs: createBrowserClient in Client Components, createServerClient per request on the server, never a module-level singleton.