isPublicApiKey function

bool isPublicApiKey(
  1. String apiKey
)

Returns true when apiKey is a client-side key (publishable or legacy anon JWT) that hosted Supabase projects no longer accept for the OpenAPI schema.

Implementation

bool isPublicApiKey(String apiKey) {
  if (apiKey.startsWith('sb_publishable_')) return true;

  final parts = apiKey.split('.');
  if (parts.length != 3) return false;
  try {
    final payload = jsonDecode(
        utf8.decode(base64Url.decode(base64Url.normalize(parts[1]))));
    return payload is Map && payload['role'] == 'anon';
  } catch (_) {
    return false;
  }
}