Supabase Storage returns 403 “signature verification failed” for service_role request #51269
Replies: 1 comment 3 replies
|
Have you tried that service role key with the database REST API? Did you revoke the legacy keys? |
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hi Supabase community,
I’m investigating a hosted Supabase Storage authentication issue.
A read-only request to the Storage API:
GET /storage/v1/bucketusing the current
service_role/ legacy credential in both theapikeyandAuthorization: Bearerheaders returns:403 Unauthorized — signature verification failedI refreshed the local credential directly from the current Management API
service_rolelisting immediately before testing, and the result was unchanged.Additional observations:
iss=supabaseandrole=service_role./storage/v1/versionresponds successfully.I have opened a Supabase Support request as well.
Question: Is this behavior consistent with a Storage-side legacy JWT verification/key-material synchronization issue? If not, what is the recommended safe diagnostic for distinguishing a Storage verification problem from a problem with the legacy
service_rolecredential?I will not post any API keys, JWTs, secrets, project identifiers, or other sensitive information.
Thanks.
All reactions