Replies: 1 comment
-
|
See PR #47640 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
What's Changing?
The week of July 6, 2026, the default self-hosted Supabase configuration for
API_EXTERNAL_URLwill change to include the/auth/v1path prefix:API_EXTERNAL_URLwill default tohttp://localhost:8000/auth/v1(previouslyhttp://localhost:8000)GOTRUE_JWT_ISSUERindocker-compose.ymlwill change to${API_EXTERNAL_URL}(the actual URL will stay unchanged)docker-compose.ymlwill become${API_EXTERNAL_URL}/callback/sso/saml/*to/auth/v1/sso/saml/*, so SAML ACS and metadata endpoints become…/auth/v1/sso/saml/acsand…/auth/v1/sso/saml/metadataThis aligns self-hosted Supabase with the platform behavior, and the CLI.
Why?
API_EXTERNAL_URLbehaves identically on platform, self-hosted, and CLI.API_EXTERNAL_URL + /callback. With the prefix now in the base URL, that resolves to…/auth/v1/callbackand matches the existing API gateway route./auth/v1convention used by every other auth endpoint, rather than living at a bare/sso/saml/*path.API_EXTERNAL_URL" is now literally true, instead of relying on the/auth/v1prefix being manually prepended in the compose file.Am I Affected?
You are affected if you run self-hosted Supabase from the
./dockerdirectory and pull updates frommaster, and any of the following apply:API_EXTERNAL_URLin your.env(e.g.https://my-domain.com) - you'll need to change it tohttps://my-domain.com/auth/v1.docker-compose.ymlwith OAuth providers - the redirect URIs change from${API_EXTERNAL_URL}/auth/v1/callbackto${API_EXTERNAL_URL}/callbackto avoid a doubled/auth/v1prefix./sso/saml/*endpoints and must be updated to/auth/v1/sso/saml/*. This is the main breaking case.You are not affected if you:
…/auth/v1/callback), so no re-registration in the provider's developer console is neededdocker-compose.ymland.env.exampletogether without local changes - the defaults stay consistentWhat Should I Do?
If you pull the updated
docker-compose.ymland.env.exampletogether with no customizations, no action is required unless you use SAML SSO.If you've customized
API_EXTERNAL_URL:/auth/v1to your value (e.g.https://my-domain.com→https://my-domain.com/auth/v1)${API_EXTERNAL_URL}/auth/v1/callbackto${API_EXTERNAL_URL}/callbackIf you use SAML SSO:
docker-compose.yml(or update your Kong and Envoy routes to/auth/v1/sso/saml/acsand/auth/v1/sso/saml/metadata){API_EXTERNAL_URL}/auth/v1/sso/saml/metadataand update your IdP (ACS URL, SP entity ID) with the new endpointsIf you'd rather defer: keep your existing
API_EXTERNAL_URLwithout the/auth/v1suffix and retain your current OAuth/SAML configuration. This is a default change, not a removal - but we recommend aligning soon, since custom OAuth providers won't work without it.Rollout
Beta Was this translation helpful? Give feedback.
All reactions