Purpose
Sessions are refreshed correctly on the server and never leak between users.
The standard
Use
@supabase/ssr:createBrowserClientin client components,createServerClientin server components/actions/route handlers, each insrc/lib/supabase/.middleware.tscallssupabase.auth.getUser()on every request to refresh cookies; it redirects only the routes that require login.In server code, trust
getUser()(validates with Supabase), notgetSession()(reads the cookie).Never cache authenticated data at the route level (
export const dynamic = 'force-dynamic'or per-request fetch).Logout is a route handler that calls
signOut()and redirects.Password reset and invite links land on
/auth/callback, which exchanges the code and redirects.
Anti-patterns
Creating a Supabase client at module scope in server code; passing the user object from client to server as truth.
Owner: Matt · Last reviewed: 2026-09