Make API key reviews a small weekly habit
Get a regular snapshot of your project's API keys so unusual or unclear entries are easier to notice.
Trigger
Recurring schedule
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Action
Get project API keys
Retrieves all api keys for an existing supabase project, specified by its unique reference id (`ref`); this is a read-only operation.
Why this helps
Security housekeeping gets postponed when it requires remembering another dashboard check.
- Create a predictable review rhythm.
- See key descriptions in a concise report.
- Spot keys that need clarification without a manual dashboard search.
Setup
Build it in a few focused steps.
- 1Connect Supabase to Notis once through the portal.
- 2Create a scheduled automation in the portal or ask Notis to set one up.
- 3Tell Notis to retrieve the project's API keys and report a concise inventory, highlighting unclear descriptions for review without changing any keys.
- 4Choose a weekly Notis cron schedule and a channel for run reports.
- 5Run it once and compare the report with the current Supabase key list.
Questions about this workflow
Does this workflow change or revoke keys?
No. It retrieves the key list for a read-only review.
Can I choose when it runs?
Yes. Choose a weekly schedule when setting up the Notis cron trigger.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link GetTranscribe to Supabase. A trigger fires from one place; an action lands in another.
GetTranscribe triggers
Supabase actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Create project api key
Creates a 'publishable' or 'secret' api key for an existing supabase project, optionally with a description; 'secret' keys can have customized jwt templates.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Delete an API key from the project
Permanently deletes a specific api key (identified by `id`) from a supabase project (identified by `ref`), revoking its access.
Get a third-party integration
Retrieves the detailed configuration for a specific third-party authentication (tpa) provider, identified by `tpa id`, within an existing supabase project specified by `ref`.
List third-party auth integrations for project
Lists all configured third-party authentication provider integrations for an existing supabase project (using its `ref`), suitable for read-only auditing or verifying current authentication settings.
Delete third party auth config
Removes a third-party authentication provider (e.g., google, github) from a supabase project's configuration; this immediately prevents users from logging in via that method.
Update an API key for the project
Updates an existing supabase project api key's `description` and/or `secret jwt template` (which defines its `role`); does not regenerate the key string.
Beta activate custom hostname for project
Activates a previously configured custom hostname for a supabase project, assuming dns settings are verified externally.
Activate vanity subdomain for project
Activates a vanity subdomain for the specified supabase project, requiring subsequent dns configuration for the subdomain to become operational.
Connect any two apps with Notis in the middle.
GetTranscribe and Supabase, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Supabase.