01Confirm the request has a user session
Inspect the access token claims and confirm the browser request is authenticated when the insert runs.
What the result tells you: A null auth.uid() means the policy is evaluating an anonymous request.
Appears when: 42501 / RLS violation
The insert reached Postgres, but the active role did not satisfy an INSERT policy for the new row. Inspect the user session, table policy, and row values; do not solve this by turning RLS off.
# Write down the intended access ruleState who may create the row and which ownership values must be present.# Create the narrow policyAdd or correct an INSERT policy whose WITH CHECK expression matches that rule.# Set trusted ownership valuesPopulate user or tenant identity from the authenticated context, not a freely editable client field.# Test allowed and denied casesProve both the valid insert and a cross-user or cross-tenant rejection.Preserve the current working revision, change one proven boundary, and verify the published path in a clean session.
Inspect the access token claims and confirm the browser request is authenticated when the insert runs.
What the result tells you: A null auth.uid() means the policy is evaluating an anonymous request.
Check the WITH CHECK expression for the active role and table. It must be true for the row being inserted.
What the result tells you: A policy scoped to authenticated users still fails when ownership fields do not match the user id.
Verify owner_id, tenant_id, and other policy fields are populated before the insert.
What the result tells you: A missing ownership value often explains why a reasonable policy rejects the write.
| Likely cause | What proves it | First safe action |
|---|---|---|
| No matching INSERT policy | A null auth.uid() means the policy is evaluating an anonymous request. | Write down the intended access rule |
| Session is missing or stale | A policy scoped to authenticated users still fails when ownership fields do not match the user id. | Create the narrow policy |
| Ownership field is wrong | A missing ownership value often explains why a reasonable policy rejects the write. | Set trusted ownership values |
| Policy targets another role | A null auth.uid() means the policy is evaluating an anonymous request. | Test allowed and denied cases |
The insert reached Postgres, but the active role did not satisfy an INSERT policy for the new row. Inspect the user session, table policy, and row values; do not solve this by turning RLS off.
RLS is enabled but the active role has no policy that permits the new row.
The insert runs before authentication is established or with an expired token.
The policy compares auth.uid() to a null or different user or tenant value.
Freeze generated changes, restore the last known working version, reproduce one request, collect the browser and platform logs, and change one layer at a time.
That removes the security boundary instead of repairing it. Keep RLS enabled and correct the session, policy, or row ownership data.
For INSERT and relevant UPDATE operations, it determines whether the new row is allowed by the policy.
A server-side service role has elevated privileges. Its success does not prove that a browser user should be allowed to perform the same write.
Free decision aid
Get a senior view of the constraint, the evidence you have, and the next decision that removes the most risk.
No email required for this decision aid. Dismiss once and this popup stays closed for the session.