Which rows does the request return?

Key in the request
Who is calling
Layer one: grant for that role
Layer two: Row Level Security
  1. Key
  2. Grant
  3. RLS

An illustrative table of twelve rows. Blue squares are the signed-in user's own three rows and orange squares are other people's rows, so any orange square that comes back is a leak. It follows Supabase's documentation: a secret key skips both layers, a missing grant stops a request before any row is read, and with Row Level Security off every row goes to any role that has a grant.