API keys
Every project has two kinds of API keys. Manage them in the dashboard under API → Keys.
| Key | Prefix | Use in | Database role |
|---|---|---|---|
| Publishable | lb_pub_... |
browsers, mobile apps, anywhere | anon, or authenticated once a user is signed in. RLS applies. |
| Secret | lb_sec_... |
your servers, CI and scripts only | service_role. Bypasses RLS. |
Publishable key
Section titled “Publishable key”Safe to embed in client code. It identifies the project; what a visitor can do is decided by your RLS policies.
Secret key
Section titled “Secret key”The full key is shown once when you create it. Only a hash is stored, so a lost key must be replaced. Revoking a key takes effect within about a second.
The SDK exchanges the secret key for a short-lived service_role token and sends only that token to the data, storage and realtime APIs.
import { createClient } from "@potalab/base"
// server onlyconst admin = createClient({ url: process.env.POTALAB_BASE_URL!, key: process.env.POTALAB_BASE_SECRET_KEY! })await admin.from("orders").select("*") // bypasses RLSRepeated invalid secret keys from one IP address are rate limited (429).