apps/docs/content/guides/storage/serving/downloads.mdx
As mentioned in the Buckets Fundamentals all files uploaded in a public bucket are publicly accessible and benefit a high CDN cache HIT ratio.
You can access them by using this conventional URL:
https://[project_id].supabase.co/storage/v1/object/public/[bucket]/[asset-name]
You can also use the Supabase SDK getPublicUrl to generate this URL for you
import { createClient } from '@supabase/supabase-js'
const supabase = createClient('your_project_url', 'your_supabase_api_key')
// ---cut---
const { data } = supabase.storage.from('bucket').getPublicUrl('filePath.jpg')
console.log(data.publicUrl)
If you want the browser to start an automatic download of the asset instead of trying serving it, you can add the ?download query string parameter.
By default it will use the asset name to save the file on disk. You can optionally pass a custom name to the download parameter as following: ?download=customname.jpg
When using the SDK's download() method, you can pass additional query parameters to customize the download behavior:
<Tabs scrollable size="small" type="underlined" defaultActiveId="js" queryGroup="language"
<TabPanel id="js" label="JavaScript">
import { createClient } from '@supabase/supabase-js'
const supabase = createClient('your_project_url', 'your_supabase_api_key')
// ---cut---
// Download with custom filename
const { data, error } = await supabase.storage.from('avatars').download('avatar1.png', {
download: 'my-custom-name.png',
})
// Download with additional query parameters
final response = await supabase.storage
.from('avatars')
.download(
'avatar1.png',
queryParams: {
'download': 'my-custom-name.png',
},
);
// Download with additional query parameters
let response = try await supabase.storage
.from("avatars")
.download(
path: "avatar1.png",
queryItems: [
URLQueryItem(name: "download", value: "my-custom-name.png")
]
)
Assets stored in a non-public bucket are considered private and are not accessible via a public URL like the public buckets.
You can access them only by:
https://[project_id].supabase.co/storage/v1/object/authenticated/[bucket]/[asset-name] and the user Authorization headerStorage signed URLs are signed with a dedicated internal key that is separate from your project's Auth JWT signing key. Each project has its own signing key.
Because signed URLs use this separate key, they are not affected by:
Signed URLs remain valid until their expiry time regardless of any Auth key changes.
If you need to revoke signed URLs, contact Supabase support.
</Admonition> You can sign a time-limited URL that you can share to your users by invoking the `createSignedUrl` method on the SDK.import { createClient } from '@supabase/supabase-js'
const supabase = createClient('your_project_url', 'your_supabase_api_key')
// ---cut---
const { data, error } = await supabase.storage
.from('bucket')
.createSignedUrl('private-document.pdf', 3600)
if (data) {
console.log(data.signedUrl)
}