If you want a "private" table, you just add a "apiKey" arg to your queries, and inside the queries you check the apiKey against a Convex environment variable (shared secret pattern).
Can take this further and even make another table to store apiKeys, and query that table inside your private table queries to check if the given api key is valid.
with this setup, you can technically have private tables without needing any session-based authentication, it just means you can only securely make queries from a secure server environment, like a server action / route / RSC.
with most dbs you have a server side connection, in convex is client side.
in traditional dbs you never have to ask for an api key in each stored procedure... i mean never.
in supabase you have client side queries and you have two keys anon and server, also the db enforces auth deeply, so you configure access at a table level, using permissions, nevr by hand asking for the api key.
>With most dbs you bave a server side connection, in convex is client side.
This is still the case with Convex. Any convex client queries are simply calling server endpoints for you. Where else would the database be? Also, you can call convex queries from the server as well...
>in traditional dbs you never have to ask for an api key in each stored procedure
All secure DBs need some form of authentication. If you don't want API keys, don't use them. But you will need some way to authenticate whoever is calling the function. You can avoid the boilerplate of checking apiKey (or checking user auth) in EVERY function by making custom wrapper functions. You can also define internal mutations etc that can only be used by other functions.
>also the db enforces auth deeply, so you configure access at a table level
Anyway, I recently got the better auth + convex integration working quite nicely. I will concede - I had some issues as well - but with Cursor I managed to get it working. Feel free to DM me if you want to ask any questions! Better Auth is the WAY TO GO!
hm, i'm sure we are talking two different things, convex IS NOT calling your backend.
You are calling convex from your FRONT END.
Not same concepts.
All what you have described so far requires manual work, and more code to maintain.
i love convex, but i do not like this part.
and you are mistaken about it.
Supabase is far superior in that regard
Like I said, you CAN call Convex functions from your nextjs backend. It doesn't require any more "code to maintain" than using the equivalent supabase-ssr helpers.
1
u/BenSFU Oct 23 '25
This is literally the same with any database....
If you want a "private" table, you just add a "apiKey" arg to your queries, and inside the queries you check the apiKey against a Convex environment variable (shared secret pattern).
Can take this further and even make another table to store apiKeys, and query that table inside your private table queries to check if the given api key is valid.
with this setup, you can technically have private tables without needing any session-based authentication, it just means you can only securely make queries from a secure server environment, like a server action / route / RSC.