Supabase Extract Jwt

yoanbernabeu/supabase-pentest-skills/skills/extraction/supabase-extract-jwt

作者 yoanbernabeu0f9612276b49f241584f9d779767e35ae519875a無授權條款收錄於 2026年10月9日更新於 2026年10月9日

Extract and decode Supabase-related JWTs from client-side code, cookies, and local storage patterns.

僅含說明Security
AI 產生的概覽

從用戶端程式碼、Cookie 與儲存模式中擷取並解碼與 Supabase 相關的 JWT。

功能
此技能會掃描目標網頁應用程式的用戶端程式碼,尋找與 Supabase 相關的 JSON Web Token,包括 anon key、硬編碼使用者權杖與儲存鍵模式。它會解碼權杖標頭與內容,分析標準宣告與 Supabase 專屬宣告,並標記暴露的 service role key 或含個人資料的硬編碼使用者權杖等問題。發現結果會逐步寫入情境、稽核與證據檔案,並產出格式化擷取報告。
適用情境
適用於稽核以 Supabase 為後端的應用程式中,用戶端程式碼暴露的 JWT。適合需要找出硬編碼使用者權杖、檢視權杖宣告與到期時間,或了解驗證流程的安全審查。前提是目標應用程式可連線,且已完成或可自動觸發 Supabase 偵測。
執行需求
需要可連線的目標應用程式,以及事先完成或自動觸發的 Supabase 偵測。會寫入 .sb-pentest-context.json、.sb-pentest-audit.log,以及 .sb-pentest-evidence/02-extraction/ 下的證據目錄。不附帶指令碼,僅為指示。

Supabase JWT Extraction

🔴 CRITICAL: PROGRESSIVE FILE UPDATES REQUIRED

You MUST write to context files AS YOU GO, not just at the end.

  • Write to .sb-pentest-context.json IMMEDIATELY after each discovery
  • Log to .sb-pentest-audit.log BEFORE and AFTER each action
  • DO NOT wait until the skill completes to update files
  • If the skill crashes or is interrupted, all prior findings must already be saved

This is not optional. Failure to write progressively is a critical error.

This skill extracts and analyzes JSON Web Tokens (JWTs) related to Supabase from client-side code.

When to Use This Skill

  • To find all JWT tokens exposed in client code
  • To analyze token claims and expiration
  • To detect hardcoded user tokens (security issue)
  • To understand the authentication flow

Prerequisites

  • Target application accessible
  • Supabase detection completed (auto-invokes if needed)

Types of JWTs in Supabase

TypePurposeClient Exposure
Anon KeyAPI authentication✅ Expected
Service Role KeyAdmin access❌ Never
Access TokenUser session⚠️ Dynamic only
Refresh TokenToken renewal⚠️ Dynamic only

Detection Patterns

1. API Keys (Static)

javascript
// Supabase API keys are JWTsconst SUPABASE_KEY = 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...'

2. Hardcoded User Tokens (Problem)

javascript
// ❌ Should never be hardcodedconst userToken = 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwiZW1haWwiOiJ1c2VyQGV4YW1wbGUuY29tIn0...'

3. Storage Key Patterns

javascript
// Code referencing where JWTs are storedlocalStorage.getItem('supabase.auth.token')localStorage.getItem('sb-abc123-auth-token')sessionStorage.getItem('supabase_session')

Usage

Basic Extraction

Extract JWTs from https://myapp.example.com

With Claim Analysis

Extract and analyze all JWTs from https://myapp.example.com

Output Format

═══════════════════════════════════════════════════════════ JWT EXTRACTION RESULTS═══════════════════════════════════════════════════════════
 Found: 3 JWTs
 ───────────────────────────────────────────────────────── JWT #1: Supabase Anon Key ───────────────────────────────────────────────────────── Type: API Key (anon) Status: ✅ Expected in client code
 Header: ├── alg: HS256 └── typ: JWT
 Payload: ├── iss: supabase ├── ref: abc123def ├── role: anon ├── iat: 2021-12-20T00:00:00Z └── exp: 2031-12-20T00:00:00Z
 Location: /static/js/main.js:1247
 ───────────────────────────────────────────────────────── JWT #2: Hardcoded User Token ⚠️ ───────────────────────────────────────────────────────── Type: User Access Token Status: ⚠️ P1 - Should not be hardcoded
 Header: ├── alg: HS256 └── typ: JWT
 Payload: ├── sub: 12345678-1234-1234-1234-123456789012 ├── email: [email protected] ├── role: authenticated ├── iat: 2025-01-15T10:00:00Z └── exp: 2025-01-15T11:00:00Z (EXPIRED)
 Location: /static/js/debug.js:45
 Risk: This token may belong to a real user account.       Even if expired, it reveals user information.
 ───────────────────────────────────────────────────────── JWT #3: Storage Reference ───────────────────────────────────────────────────────── Type: Storage Key Pattern Status: ℹ️ Informational
 Pattern: localStorage.getItem('sb-abc123def-auth-token') Location: /static/js/auth.js:89
 Note: This is the expected storage key for user sessions.       Actual token value is set at runtime.
═══════════════════════════════════════════════════════════

JWT Claim Analysis

The skill identifies key claims:

Standard Claims

ClaimDescriptionSecurity Impact
subUser IDIdentifies specific user
emailUser emailPII exposure if hardcoded
rolePermission levelservice_role is critical
expExpirationExpired tokens less risky
iatIssued atIndicates when created

Supabase-Specific Claims

ClaimDescription
refProject reference
issShould be "supabase"
aalAuthenticator assurance level
amrAuthentication methods used

Security Findings

P0 - Critical

🔴 Service role key exposed (role: service_role)   → Immediate key rotation required

P1 - High

🟠 User token hardcoded with PII (email, sub visible)   → Remove from code, may need to notify user

P2 - Medium

🟡 Expired test token in code   → Clean up, potential information disclosure

Context Output

Saved to .sb-pentest-context.json:

json
{  "jwts": {    "found": 3,    "api_keys": [      {        "type": "anon",        "project_ref": "abc123def",        "location": "/static/js/main.js:1247"      }    ],    "user_tokens": [      {        "type": "access_token",        "hardcoded": true,        "severity": "P1",        "claims": {          "sub": "12345678-1234-1234-1234-123456789012",          "email": "[email protected]",          "expired": true        },        "location": "/static/js/debug.js:45"      }    ],    "storage_patterns": [      {        "pattern": "sb-abc123def-auth-token",        "storage": "localStorage",        "location": "/static/js/auth.js:89"      }    ]  }}

Common Issues

❌ Problem: JWT appears truncated ✅ Solution: May span multiple lines. The skill attempts to reassemble.

❌ Problem: JWT won't decode ✅ Solution: May be encrypted (JWE) or custom format. Noted as undecodable.

❌ Problem: Many false positives ✅ Solution: Base64 strings that look like JWTs. Skill validates structure.

Remediation for Hardcoded Tokens

Before (Wrong)

javascript
// ❌ Never hardcode user tokensconst adminToken = 'eyJhbGciOiJIUzI1NiI...'fetch('/api/admin', {  headers: { Authorization: `Bearer ${adminToken}` }})

After (Correct)

javascript
// ✅ Get token from Supabase sessionconst { data: { session } } = await supabase.auth.getSession()fetch('/api/admin', {  headers: { Authorization: `Bearer ${session.access_token}` }})

MANDATORY: Progressive Context File Updates

⚠️ This skill MUST update tracking files PROGRESSIVELY during execution, NOT just at the end.

Critical Rule: Write As You Go

DO NOT batch all writes at the end. Instead:

  1. Before starting any action → Log the action to .sb-pentest-audit.log
  2. After each discovery → Immediately update .sb-pentest-context.json
  3. After each significant step → Log completion to .sb-pentest-audit.log

This ensures that if the skill is interrupted, crashes, or times out, all findings up to that point are preserved.

Required Actions (Progressive)

  1. Update .sb-pentest-context.json with extracted data:

    json
    {  "jwts": {    "found": 3,    "api_keys": [ ... ],    "user_tokens": [ ... ],    "storage_patterns": [ ... ]  }}
  2. Log to .sb-pentest-audit.log:

    [TIMESTAMP] [supabase-extract-jwt] [START] Beginning JWT extraction[TIMESTAMP] [supabase-extract-jwt] [SUCCESS] Found 3 JWTs[TIMESTAMP] [supabase-extract-jwt] [CONTEXT_UPDATED] .sb-pentest-context.json updated
  3. If files don't exist, create them before writing.

FAILURE TO UPDATE CONTEXT FILES IS NOT ACCEPTABLE.

MANDATORY: Evidence Collection

📁 Evidence Directory: .sb-pentest-evidence/02-extraction/

Evidence Files to Create

FileContent
extracted-jwts.jsonAll JWTs found with analysis

Evidence Format

json
{  "evidence_id": "EXT-JWT-001",  "timestamp": "2025-01-31T10:08:00Z",  "category": "extraction",  "type": "jwt_extraction",
  "jwts_found": [    {      "type": "anon_key",      "severity": "info",      "location": "/static/js/main.js:1247",      "decoded_payload": {        "iss": "supabase",        "ref": "abc123def",        "role": "anon"      }    },    {      "type": "hardcoded_user_token",      "severity": "P1",      "location": "/static/js/debug.js:45",      "decoded_payload": {        "sub": "[REDACTED]",        "email": "[REDACTED]@example.com",        "role": "authenticated",        "exp": "2025-01-15T11:00:00Z"      },      "expired": true,      "issue": "Hardcoded user token with PII"    }  ],
  "storage_patterns_found": [    {      "pattern": "localStorage.getItem('sb-abc123def-auth-token')",      "location": "/static/js/auth.js:89"    }  ]}

Related Skills

  • supabase-extract-anon-key — Specifically extracts the anon key
  • supabase-extract-service-key — Checks for service key (critical)
  • supabase-audit-auth-config — Analyzes auth configuration

來源與署名

來源:yoanbernabeu/supabase-pentest-skills位於skills/extraction/supabase-extract-jwt提交0f96122

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架