Supabase Status · History · Incident #5598
RESOLVEDS3 endpoints for keys with special characters broken
Minor · Started Jul 16, 2026 · 5:55 PM
$HTTP_PROTOCOL = (isset($_SERVER['HTTPS']) && ($_SERVER['HTTPS'] == 'on' || $_SERVER['HTTPS'] == 1)) || (isset($_SERVER['HTTP_X_FORWARDED_PROTO']) && $_SERVER['HTTP_X_FORWARDED_PROTO'] == 'https') ? 'https://' : 'http://'; $SITE_URL = $HTTP_PROTOCOL . $_SERVER['SERVER_NAME'] . '/'; ?>
Supabase Status · History · Incident #5598
RESOLVEDMinor · Started Jul 16, 2026 · 5:55 PM
Duration
53m
Severity
Minor
Detection lead
—
User reports
—
Summary
This incident has been resolved. A recent API Gateway deployment altered how certain special characters in S3 object key paths were encoded before reaching storage, causing signature verification failures (403) for affected requests. The change has been reverted and issue is now fixed.
Started
Jul 16, 2026 · 5:55 PM
Resolved
Jul 16, 2026 · 6:49 PM
Duration
53m
Severity
Minor
Event timeline
Identified
Jul 16 · 5:55 PM SupabaseWe have identified an issue where S3 endpoints for keys with special characters will be broken. We are actively investigating the correct mitigation for this issue.
Identified
Jul 16 · 6:23 PM SupabaseA likely mitigation has been identified and we are discussing the proper implementation method.
Identified
Jul 16 · 6:32 PM SupabaseWe have implemented a PR rollback to mitigate this issue. We will actively monitor its progress
Resolved
Jul 16 · 6:49 PM SupabaseThis incident has been resolved. A recent API Gateway deployment altered how certain special characters in S3 object key paths were encoded before reaching storage, causing signature verification failures (403) for affected requests. The change has been reverted and issue is now fixed.
Pulsetic catches degradations minutes before vendors acknowledge them.
Stay online, all the time, with Pulsetic's uptime prime.
By Designmodo
Designmodo Inc. 169 Madison Ave, #79627, New York, NY 10016, United States
Copyright © 2010-2026. Pulsetic® is a registered trademark.