← All guides

Supabase storage rescue

Supabase storage uploads and downloads fail in production

SupabaseVPSDomain

Short answer

Supabase storage working correctly with proper policies, CORS, and URL configuration.

Why this matters

File uploads and downloads work locally but fail in production with permission errors or CORS blocks.

Walkthrough

  1. 01

    Check bucket policies

    Storage buckets need policies to allow uploads and downloads.

    • Verify the bucket exists in the Supabase dashboard.
    • Check that the bucket has a public or authenticated policy depending on your needs.
    • Test uploads and downloads in the Supabase SQL editor.
  2. 02

    Configure CORS for your domain

    Browser requests to Supabase storage need CORS headers.

    • Add your production domain to the Supabase storage CORS allowlist.
    • Test uploads from the production domain in the browser.
    • Verify the response includes the correct Access-Control headers.
  3. 03

    Update the app and test

    Ensure the app uses the correct storage URL and keys.

    • Confirm the app uses the production Supabase URL for storage calls.
    • Test upload, download, and delete operations from the production app.
    • Verify file URLs are accessible from the production domain.

Where RepoAssistant fits

RepoAssistant configures Supabase storage with correct policies and CORS during production deployment.