Skip to content
FIRERUN.

The BaaS & deploy-platform newsroom for builders

Subscribe

Supabase

Supabase Kills Four Framework Adapters in @supabase/server Dec. 1

Supabase deprecated the Hono, H3, Elysia and NestJS adapters in @supabase/server and will remove them Dec. 1, 2026. Copy a bridge into your project.

Hand-drawn editorial illustration for "Supabase Kills Four Framework Adapters in @supabase/server Dec. 1"

Supabase deprecated the four framework adapters in its @supabase/server package on Oct. 5 and will delete them on Dec. 1, 2026. Anyone importing the Hono, H3, Elysia or NestJS adapters has about eight weeks to move (Supabase changelog, Oct. 5, 2026).

The affected entry points are @supabase/server/adapters/hono, /h3, /elysia and /nestjs. withSupabase(config, handler), its single-argument form and the @supabase/server/middleware/* entries are not deprecated, Supabase said.

Why it’s going

The changelog says each adapter wrapped one call, withSupabase, for one framework. That meant “a published entry point, a peer dependency range, and a release cycle per framework.” Supabase published @supabase/middleware 1.0 on Sept. 30 as a small MIT-licensed engine for per-request logic on Web Fetch handlers. @supabase/server has run on it since version 1.5.1.

What to do

Supabase’s migration notes say the replacement bridges need @supabase/server 1.6.0 or later and Node 22 or later. The steps:

  • Search for @supabase/server/adapters to find every registration.
  • Add @supabase/middleware as a direct dependency.
  • Copy the bridge for your framework from the examples repository into your project.
  • Replace auth: 'user' with withRequiredClaims(). Leave auth: 'none' ungated.
  • Update call sites to flat keys such as c.var.supabase and c.var.jwtClaims instead of nested objects.
  • Typecheck, then confirm unauthenticated requests still get a 401.

Supabase warns against swapping in withClaims() for auth: 'user'. It handles anonymous access differently.

Key Takeaways

  • The Hono, H3, Elysia and NestJS adapters in @supabase/server are deprecated as of Oct. 5, 2026, and removed Dec. 1.
  • Replacements need @supabase/server 1.6.0+ and Node 22+.
  • withSupabase and the middleware entries stay.
  • The auth swap is the risky part: withRequiredClaims(), not withClaims().

The take

Moving the framework glue into your repo is a fair trade for Supabase. It no longer has to track four frameworks’ major versions. You do, and the work touches auth code. A wrong swap quietly opens an endpoint. Run the 401 check on every route before you ship the change, well before December.

Stay in the loop

Get new articles in your inbox

We'll only email you when a new article drops. Unsubscribe anytime.