Sourcemap Explorer
Stack · npm package

@supabase/supabase-js

Isomorphic Javascript SDK for Supabase

latest 2.112.0· MIT· 806 versions publishedView on npm

About

Isomorphic Javascript SDK for Supabase

javascripttypescriptsupabase

What detecting @supabase/supabase-js tells you about a site

@supabase/supabase-js reveals a Supabase backend — a Postgres database exposed through an auto-generated API, plus auth, storage and realtime — talking directly to the client. Its presence signals a serverless or thin-backend architecture where the front end owns much of the data logic against a hosted Postgres.

Why the exact @supabase/supabase-js version matters

The v2 client unified auth, realtime and storage under one SDK with a different API from v1; the exact version tells you which client contract and auth flow the app uses.

@supabase/supabase-js in a real-world stack

When you find @supabase/supabase-js in a bundle, it rarely travels alone. @supabase/auth-helpers or @supabase/ssr for framework auth, and usually a React/Next.js front end.

Quick facts

Latest version2.112.0
LicenseMIT
AuthorSupabase
Installnpm install @supabase/supabase-js
Direct dependencies5
Peer dependencies@opentelemetry/api

Common pairings

Packages this one expects to find in the same project. Each is also a Sourcemap Explorer detection target.

@opentelemetry/api

What @supabase/supabase-js pulls in

@supabase/supabase-js declares 5 direct dependencies — each one also rides into any bundle that ships @supabase/supabase-js, so they are detection targets too. Reading them is a quick way to understand the package's real footprint .

@supabase/auth-js@supabase/storage-js@supabase/realtime-js@supabase/functions-js@supabase/postgrest-js

How Sourcemap Explorer detects @supabase/supabase-js

@supabase/supabase-js ships as v2.112.0, published 2026-08-03 and carries 5 direct dependencies, 1 peer dependency (@opentelemetry/api), 806 versions on the registry. Those exact numbers are the footprint Sourcemap Explorer matches when @supabase/supabase-js rides inside a deployed bundle — here is how the detection works.

We catch @supabase/supabase-js from two complementary signals: bundled source paths and the embedded package.json. Modern bundlers (webpack, Vite, esbuild, Rollup, Turbopack) preserve the original node_modules/@supabase/supabase-js/ paths inside the JavaScript sourcemap's sources[] array — that's the canonical signal. When the matching package.json is also captured in sourcesContent[], we read the exact version field — patch number included. No regex guessing, no version inference.

  1. 1

    Confirm the site exposes sourcemaps

    In DevTools Network, check the response headers of any application script for `SourceMap` or `X-SourceMap`. Failing that, fetch the script's last 4 KB and look for a `//# sourceMappingURL=` comment — that map is where the `@supabase/supabase-js` paths live.

  2. 2

    Find the package in the bundle

    Open DevTools → Network → reload. Click any application script and look at its sourcemap. Inside, search `sources[]` for entries matching `node_modules/@supabase/supabase-js/` — every match confirms the package is bundled. The matching `sourcesContent[i]` for `node_modules/@supabase/supabase-js/package.json` gives you the exact installed version.

  3. 3

    Read the version directly from package.json

    Run `jq -r '. as $m | $m.sources | to_entries[] | select(.value | endswith("node_modules/@supabase/supabase-js/package.json")) | $m.sourcesContent[.key] | fromjson | .version' bundle.js.map`. Sourcemap Explorer automates the same query in the popup.

Major releases of @supabase/supabase-js

When each major version first landed. Major bumps are where breaking changes live, so this timeline is the fastest way to date the @supabase/supabase-js version a site actually ships against the ecosystem.

Major
First release
Date
v2
2.0.0
2022-10-11
v1
1.0.0
2020-11-02
v0
0.1.1
2020-01-17

Recent versions

Version
Released
2.112.0
2026-08-03
2.111.0
2026-07-28
2.110.9
2026-07-27
2.110.8
2026-07-21
2.110.7
2026-07-16
2.110.6
2026-07-15
2.110.5
2026-07-14
2.110.4
2026-07-14

@supabase/supabase-js README

Live mirror of the GitHub README, for reference. Updated whenever the repo's default branch changes.


Supabase Logo

Supabase JS SDK

Isomorphic JavaScript SDK for Supabase - combining Auth, Database, Storage, Functions, and Realtime.

Guides · Reference Docs · TypeDoc

Build Package License: MIT pkg.pr.new

Usage

First of all, you need to install the library:

npm install @supabase/supabase-js

Then you're able to import the library and establish the connection with the database:

import { createClient } from '@supabase/supabase-js'

// Create a single supabase client for interacting with your database
const supabase = createClient('https://xyzcompany.supabase.co', 'your-publishable-key')

UMD

You can use plain <script>s to import supabase-js from CDNs, like:

<script src="https://cdn.jsdelivr.net/npm/@supabase/supabase-js@2"></script>

or even:

<script src="https://unpkg.com/@supabase/supabase-js@2"></script>

Then you can use it from a global supabase variable:

<script>
  const { createClient } = supabase
  const _supabase = createClient('https://xyzcompany.supabase.co', 'your-publishable-key')

  console.log('Supabase Instance: ', _supabase)
  // ...
</script>

ESM

You can use <script type="module"> to import supabase-js from CDNs, like:

<script type="module">
  import { createClient } from 'https://cdn.jsdelivr.net/npm/@supabase/supabase-js/+esm'
  const supabase = createClient('https://xyzcompany.supabase.co', 'your-publishable-key')

  console.log('Supabase Instance: ', supabase)
  // ...
</script>

Deno

You can use supabase-js in the Deno runtime via JSR:

import { createClient } from 'jsr:@supabase/supabase-js@2'

Custom fetch implementation

supabase-js uses the runtime's global fetch to make HTTP requests, but an alternative fetch implementation can be provided as an option. This is useful in environments where the global fetch is unavailable or where you want to customize request behavior:

import { createClient } from '@supabase/supabase-js'

// Provide a custom `fetch` implementation as an option
const supabase = createClient('https://xyzcompany.supabase.co', 'your-publishable-key', {
  global: {
    fetch: (...args) => fetch(...args),
  },
})

Distributed Tracing with OpenTelemetry

The Supabase JS SDK can attach W3C/OpenTelemetry trace context headers (traceparent, tracestate, baggage) to outgoing requests, enabling end-to-end request tracing from your client application through Supabase services.

Trace propagation is opt-in and disabled by default. When enabled, headers are only attached to requests targeting Supabase domains (*.supabase.co, *.supabase.in, localhost).

Enable trace propagation

Opting in takes two steps: install @opentelemetry/api, and load the tracing runtime by importing the @supabase/supabase-js/tracing subpath once at your application entry point. The main bundle contains no OpenTelemetry code — the subpath import is what wires it up.

import '@supabase/supabase-js/tracing'
import { createClient } from '@supabase/supabase-js'
import { trace } from '@opentelemetry/api'

const supabase = createClient('https://xyzcompany.supabase.co', 'public-anon-key', {
  tracePropagation: true,
})

const tracer = trace.getTracer('my-app')
await tracer.startActiveSpan('fetch-users', async (span) => {
  // This request now includes the active trace context.
  const { data, error } = await supabase.from('users').select('*')
  span.end()
})

The subpath imports @opentelemetry/api directly, so module resolution fails loudly if it is not installed. If tracePropagation is enabled without the subpath import, the SDK logs a one-time warning and sends requests without trace headers; if no active context exists at request time, it silently no-ops.

Trace propagation is not available via the CDN/UMD build (https://cdn.jsdelivr.net/.../supabase.js) — there is no way to load the tracing runtime there.

Advanced configuration
interface TracePropagationOptions {
  // Enable trace propagation (default: false).
  enabled?: boolean

  // Respect upstream sampling decisions (default: true).
  // When true, headers are skipped if the upstream trace is not sampled.
  respectSamplingDecision?: boolean
}
// Always propagate, even for non-sampled traces.
const supabase = createClient('https://xyzcompany.supabase.co', 'public-anon-key', {
  tracePropagation: { enabled: true, respectSamplingDecision: false },
})

Support Policy

This section outlines the scope of support for various runtime environments in Supabase JavaScript client.

Node.js

We only support Node.js versions that are in Active LTS or Maintenance status as defined by the official Node.js release schedule. This means we support versions that are currently receiving long-term support and critical bug fixes.

When a Node.js version reaches end-of-life and is no longer in Active LTS or Maintenance status, Supabase will drop it in a minor release, and this won't be considered a breaking change.

⚠️ Node.js 18 Deprecation Notice

Node.js 18 reached end-of-life on April 30, 2025. As announced in our deprecation notice, support for Node.js 18 was dropped in version 2.79.0.

If you must use Node.js 18, please use version 2.78.0, which is the last version that supported Node.js 18.

⚠️ Node.js 20 Deprecation Notice

Node.js 20 reached end-of-life on April 30, 2026. As announced in our deprecation notice, support for Node.js 20 was dropped in version 2.110.0.

If you must use Node.js 20, please use version 2.109.0, which is the last version that supported Node.js 20.

Deno

We support Deno versions that are currently receiving active development and security updates. We follow the official Deno release schedule and only support versions from the stable and lts release channels.

When a Deno version reaches end-of-life and is no longer receiving security updates, Supabase will drop it in a minor release, and this won't be considered a breaking change.

Browsers

All modern browsers are supported. We support browsers that provide native fetch API. For Realtime features, browsers must also support native WebSocket API.

Bun

We support Bun runtime environments. Bun provides native fetch support and is compatible with Node.js APIs. Since Bun does not follow a structured release schedule like Node.js or Deno, we support current stable versions of Bun and may drop support for older versions in minor releases without considering it a breaking change.

React Native

We support React Native environments with fetch polyfills provided by the framework. Since React Native does not follow a structured release schedule, we support current stable versions and may drop support for older versions in minor releases without considering it a breaking change.

Cloudflare Workers

We support Cloudflare Workers runtime environments. Cloudflare Workers provides native fetch support. Since Cloudflare Workers does not follow a structured release schedule, we support current stable versions and may drop support for older versions in minor releases without considering it a breaking change.

Important Notes

  • Experimental features: Features marked as experimental may be removed or changed without notice

Known Build Warnings

UNUSED_EXTERNAL_IMPORT in Vite / Rollup / Nuxt

When bundling your app, you may see warnings like:

"PostgrestError" is imported from external module "@supabase/postgrest-js" but never used in "...supabase-js/dist/index.mjs".
"FunctionRegion", "FunctionsError", "FunctionsFetchError", "FunctionsHttpError" and "FunctionsRelayError" are imported from external module "@supabase/functions-js" but never used in "...".

This is a false positive — your bundle is fine. Here is why it happens:

@supabase/supabase-js re-exports PostgrestError, FunctionsError, and related symbols so you can import them directly from @supabase/supabase-js. However, our build tool merges all imports from the same package into a single import statement in the built output:

// dist/index.mjs (simplified)
import { PostgrestClient, PostgrestError } from '@supabase/postgrest-js'
//       ^ used internally    ^ re-exported for you

Your bundler checks which names from that import are used in the code body, and flags PostgrestError as unused because it only appears in an export statement — not called or assigned. The export itself is the usage, but downstream bundlers don't track this correctly. This is a known Rollup/Vite limitation with re-exported external imports.

Nothing is broken. Tree-shaking and bundle size are unaffected.

To suppress the warning:

Vite / Rollup (vite.config.js or rollup.config.js):

export default {
  build: {
    rollupOptions: {
      onwarn(warning, warn) {
        if (warning.code === 'UNUSED_EXTERNAL_IMPORT' && warning.exporter?.includes('@supabase/'))
          return
        warn(warning)
      },
    },
  },
}

Nuxt (nuxt.config.ts):

export default defineNuxtConfig({
  vite: {
    build: {
      rollupOptions: {
        onwarn(warning, warn) {
          if (warning.code === 'UNUSED_EXTERNAL_IMPORT' && warning.exporter?.includes('@supabase/'))
            return
          warn(warning)
        },
      },
    },
  },
})

Contributing

We welcome contributions! Please see our Contributing Guide for details on how to get started.

For major changes or if you're unsure about something, please open an issue first to discuss your proposed changes.

Building

# From the monorepo root
pnpm nx build supabase-js

# Or with watch mode for development
pnpm nx build supabase-js --watch

Testing

There's a complete guide on how to set up your environment for running locally the supabase-js integration tests. Please refer to TESTING.md.

Badges

Coverage Status

FAQ

What is @supabase/supabase-js used for?

Isomorphic Javascript SDK for Supabase

How can I tell if a website is using @supabase/supabase-js?

Open the page in Chrome with the Sourcemap Explorer extension installed and read the Stack tab. We catch `@supabase/supabase-js` from two complementary signals: `node_modules/@supabase/supabase-js/` paths inside the JavaScript sourcemap, and the embedded `package.json` we read for exact-version detection. Without the extension you can do the same lookup manually in DevTools — the steps are listed in the "How Sourcemap Explorer detects" section above.

How do I find out which version of @supabase/supabase-js a website is running?

Read it straight from the site's JavaScript sourcemap. When a build ships source maps, the bundled `@supabase/supabase-js/package.json` carries the exact `version` string — Sourcemap Explorer extracts it in one click on the Stack tab, and you can do it by hand in DevTools by opening the `.map` file and searching for `node_modules/@supabase/supabase-js/package.json`. That is far more reliable than inferring the version from an asset-hash or a `?ver=` query string, which is all surface-level detectors have to go on. The current npm release is 2.112.0, but real deployments frequently run an older pinned version — which is exactly why reading the bundled number matters.

What is the latest version of @supabase/supabase-js?

2.112.0, as published on the npm registry. The "Recent versions" table on this page lists the most recent 8 releases with their release dates. Sourcemap Explorer reports the version actually bundled into a site, which can lag the latest release by months on real-world deployments.

Is @supabase/supabase-js actively maintained?

Very actively maintained — the last release shipped within the past three months. The last published release was 2026-08-03. Source code: https://github.com/supabase/supabase-js.

Where can I read more?

Project homepage: https://github.com/supabase/supabase-js/tree/master/packages/core/supabase-js. Source code: https://github.com/supabase/supabase-js. Published on npm: https://www.npmjs.com/package/@supabase/supabase-js. Licensed as MIT.

Detected by Sourcemap Explorer

When a bundle ships sourcemaps, we read the embedded package.json for @supabase/supabase-js and report the precise version (the registry's latest is v2.112.0, published 2026-08-03; the bundled copy is often older). Without sourcemaps, an import / require in the page's scripts is enough to flag it.

Install free on Chrome