isPublicApiKey function
Returns true when apiKey is a client-side key (publishable or legacy anon
JWT) that hosted Supabase projects no longer accept for the OpenAPI schema.
Implementation
bool isPublicApiKey(String apiKey) {
if (apiKey.startsWith('sb_publishable_')) return true;
final parts = apiKey.split('.');
if (parts.length != 3) return false;
try {
final payload = jsonDecode(
utf8.decode(base64Url.decode(base64Url.normalize(parts[1]))));
return payload is Map && payload['role'] == 'anon';
} catch (_) {
return false;
}
}