LinuxWindows

Where Does the Supabase CLI Store Config and Tokens?

Where the Supabase CLI keeps per project config.toml files plus the global login token on disk.

Last updated

The Supabase CLI splits its files two ways: per project config in supabase/config.toml (plus migrations and functions), and a global login token in OS credentials or ~/.supabase/access-token. Local dev data lives in Docker volumes.

That split decides what to commit and what to guard. config.toml minus secrets belongs in git; the access token belongs in a vault or env var. Local volumes are disposable by design, so db dumps are the only real backup for dev data. The link command ties folders to cloud projects.

Where Supabase CLI stores this, by platform

Linux
<project>/supabase/config.toml

config.toml plus migrations/, functions/, tests/, and seed files here per project. SUPABASE_WORKDIR overrides the root. Linked project IDs tie the folder to its cloud counterpart for db push and pull.

Windows
<project>\supabase\config.toml

Same per project layout on every OS since the CLI is cross platform. The fallback token file sits at %USERPROFILE%\.supabase\access-token when native storage is unavailable.

Frequently asked questions

where is the supabase config file

In supabase/config.toml at the project root (created by supabase init), with migrations/, functions/, and tests/ beside it. Commit the config minus secrets; reference env() values from a gitignored .env. The --workdir flag relocates the project root when needed.

where does supabase store the access token

In native OS credentials storage after supabase login, falling back to ~/.supabase/access-token as plain text. Prefer the SUPABASE_ACCESS_TOKEN env var in CI so no file exists at all. Rotate tokens from the dashboard when a workstation is lost.

does supabase local persist data

Yes for local development: supabase start spins Postgres plus services with data in Docker volumes. supabase stop --backup keeps a snapshot; plain stop drops the volumes. The db/ dump commands export properly for real backups.

Notice an outdated path? Let us know.