← All guides
Supabase storage rescue
Supabase storage uploads and downloads fail in production
SupabaseVPSDomain
Short answer
Supabase storage working correctly with proper policies, CORS, and URL configuration.
Why this matters
File uploads and downloads work locally but fail in production with permission errors or CORS blocks.
Walkthrough
- 01
Check bucket policies
Storage buckets need policies to allow uploads and downloads.
- Verify the bucket exists in the Supabase dashboard.
- Check that the bucket has a public or authenticated policy depending on your needs.
- Test uploads and downloads in the Supabase SQL editor.
- 02
Configure CORS for your domain
Browser requests to Supabase storage need CORS headers.
- Add your production domain to the Supabase storage CORS allowlist.
- Test uploads from the production domain in the browser.
- Verify the response includes the correct Access-Control headers.
- 03
Update the app and test
Ensure the app uses the correct storage URL and keys.
- Confirm the app uses the production Supabase URL for storage calls.
- Test upload, download, and delete operations from the production app.
- Verify file URLs are accessible from the production domain.
Where RepoAssistant fits
RepoAssistant configures Supabase storage with correct policies and CORS during production deployment.