An independent script and web app that uses the Supabase SDK to discover and extract data from all available objects in a Supabase instance. The web UI (SupaMole) runs entirely in the browser for security, GDPR and data-leak checks.
- CLI:
extract-data.js— Node script for automation/CI. - Web app (SupaMole): Vite-built static site:
index.html— Single-page app shell and styles.public/— Entrymain.js, app logicapp.js, assets (logo, favicon, etc.).
- Build:
npm run dev(Vite dev server),npm run build(output indist/).
npm installThe scan runs entirely in the browser; no server is required and credentials are not stored.
Development:
npm run devOpen the URL shown (e.g. http://localhost:5173), enter your Supabase URL and anon key (and optional auth), then run the scan.
Production:
npm run build
npx serve distServe the dist/ folder with any static file server.
node extract-data.js --url YOUR_SUPABASE_URL --key YOUR_ANON_KEYnode extract-data.js --url YOUR_SUPABASE_URL --key YOUR_ANON_KEY --email your@email.com --password yourpasswordnode extract-data.js --url YOUR_SUPABASE_URL --key YOUR_ANON_KEY --token YOUR_BEARER_TOKENnode extract-data.js --url YOUR_SUPABASE_URL --key YOUR_ANON_KEY --fast-discovery--url(required): Your Supabase project URL--key(required): Your Supabase anon key--email(optional): Email for authentication--password(optional): Password for authentication--token(optional): Bearer token (JWT from Supabase Auth); overrides email/password if both are set--fast-discovery(optional): Skip comprehensive table name discovery for faster execution
The script uses multiple methods to discover tables across schemas:
- information_schema.tables / pg_tables — Public and auth schemas
- RPC functions — Custom stored procedures (if available)
- information_schema.views — Database views
- Auth schema tables — Known Supabase auth tables (auth.users, auth.sessions, etc.)
- REST API introspection — OpenAPI analysis
- GraphQL introspection — Types/tables via GraphQL endpoint
- Common name discovery — Tests many common table names (skippable with
--fast-discovery)
- Introspects
/graphql/v1, analyzes Query type and queryable object types - Converts PascalCase types to snake_case for extraction
- Excludes scalars and pagination types
Tests and extracts (with sensitive masking where appropriate) from auth tables such as auth.users, auth.sessions, auth.identities, auth.refresh_tokens, auth.audit_log_entries, and others.
- Lists discovered tables/views with types, column info, row counts
- Sample data (e.g. first rows), rate limiting, and error handling
- Scans columns and sample values for suspected PII (name, DoB, address, phone, etc.)
- Reports findings with examples for GDPR review; in the web UI, “Tables with suspected PII” summarizes these.
- Lists Storage buckets and config (public/private, file size limit)
- Indexes objects (root and one level of subfolders) up to a cap
- For public buckets, checks whether sample object URLs are reachable without auth
- Results in CLI output and web UI under “Storage analysis”
- Anonymous, email/password, and bearer token auth
- Bearer token takes precedence when both token and email/password are provided
- No persistent storage of credentials; in the web app they are used only in memory for the run.
This project is licensed under CC BY-NC-SA 4.0 (Creative Commons Attribution-NonCommercial-ShareAlike 4.0). You may use, share, and adapt it for non-commercial purposes with attribution; derivatives must use the same license. See LICENSE and the full legal code.
Created by The Distance. Source: TheDistanceHQ/supamole.
