Home/Tools/Supabase RLS Policy Generator
100% Free Developer Utility

Supabase Row Level Security (RLS) Policy Generator

AI scaffolding tools love creating Supabase tables without enabling Row Level Security. That leaves your database tables completely open to any browser with an anon key. Generate clean, battle-tested PostgreSQL RLS migrations in seconds.

Select Access Pattern

The Missing Index Trap

When you enable RLS on a table with 20,000 rows without an index on user_id, PostgreSQL has to scan all 20,000 rows on every single query to verify ownership.

Adding CREATE INDEX makes policy lookups instantaneous (under 2ms).

Generated PostgreSQL Migration
-- Step 1: Enable Row Level Security (RLS) on projects
ALTER TABLE public.projects ENABLE ROW LEVEL SECURITY;

-- Step 2: Policy: Users can view only their own records
CREATE POLICY "Users can view own projects"
  ON public.projects
  FOR SELECT
  TO authenticated
  USING (auth.uid() = user_id);

-- Step 3: Policy: Users can insert rows scoped to their auth.uid()
CREATE POLICY "Users can insert own projects"
  ON public.projects
  FOR INSERT
  TO authenticated
  WITH CHECK (auth.uid() = user_id);

-- Step 4: Policy: Users can update their own records
CREATE POLICY "Users can update own projects"
  ON public.projects
  FOR UPDATE
  TO authenticated
  USING (auth.uid() = user_id)
  WITH CHECK (auth.uid() = user_id);

-- Step 5: Policy: Users can delete their own records
CREATE POLICY "Users can delete own projects"
  ON public.projects
  FOR DELETE
  TO authenticated
  USING (auth.uid() = user_id);

-- Step 6: Critical Performance Index (stops sequential table scan on every RLS check)
CREATE INDEX IF NOT EXISTS idx_projects_user_id ON public.projects (user_id);
1-Click Cursor Prompt to Apply
Apply this PostgreSQL migration in Supabase to secure table "projects":
```sql
-- Step 1: Enable Row Level Security (RLS) on projects
ALTER TABLE public.projects ENABLE ROW LEVEL SECURITY;

-- Step 2: Policy: Users can view only their own records
CREATE POLICY "Users can view own projects"
  ON public.projects
  FOR SELECT
  TO authenticated
  USING (auth.uid() = user_id);

-- Step 3: Policy: Users can insert rows scoped to their auth.uid()
CREATE POLICY "Users can insert own projects"
  ON public.projects
  FOR INSERT
  TO authenticated
  WITH CHECK (auth.uid() = user_id);

-- Step 4: Policy: Users can update their own records
CREATE POLICY "Users can update own projects"
  ON public.projects
  FOR UPDATE
  TO authenticated
  USING (auth.uid() = user_id)
  WITH CHECK (auth.uid() = user_id);

-- Step 5: Policy: Users can delete their own records
CREATE POLICY "Users can delete own projects"
  ON public.projects
  FOR DELETE
  TO authenticated
  USING (auth.uid() = user_id);

-- Step 6: Critical Performance Index (stops sequential table scan on every RLS check)
CREATE INDEX IF NOT EXISTS idx_projects_user_id ON public.projects (user_id);
```

Please verify:
1. Ensure the migration runs cleanly and idempotently.
2. Confirm Row Level Security is active and verified for authenticated clients.
3. Test that queries from unauthenticated users or different user IDs are properly rejected.
Did your AI assistant forget RLS on other tables?

Supabase RLS is Check 14 of our 108 launch criteria. The Founder Pass ($15 one-time) scans your migration files and database schemas to ensure zero tables leak data to unauthorized anon keys.