Skip to main content
Hostwares

How to Protect Next.js Routes with Supabase Auth

sowad sheikh··1 min read

A login page alone doesn't protect your application.

If your dashboard contains private information, the application also needs to verify authentication before showing protected pages.

Identify Private Routes

Start by deciding which routes require authentication. For example: /dashboard /settings /account /billing

Public pages can remain accessible to everyone.

Check the Session

Your Next.js application can check the Supabase authentication session before rendering protected content. If there is no valid session, redirect the visitor to the login page.

Don't Trust the Frontend Alone

Hiding a navigation link isn't security. A user should not be able to access private data simply by manually entering a URL. Your backend/database permissions should also protect the underlying data.

Add Row Level Security

Supabase PostgreSQL supports Row Level Security policies. These policies can restrict which records an authenticated user can read or modify.

Test as Different Users

Create multiple test accounts. Make sure User A cannot access User B's private records. That test is more important than simply checking whether the dashboard redirects unauthenticated visitors.

Ready to deploy?

Launch your app on Hostwares — start for $1.00/mo with auto-scaling & global CDN.

Start for $1.00/mo

Ready to deploy? Start for $1.00/mo

Deploy now