Supabase

Supabase

An open application backend that combines database, APIs, authentication, storage, realtime, edge functions, an official MCP server, and guidance for deploying customer-owned MCP services.

Interface hosts, builders & integration infrastructureInterface host and orchestration layerBYO-UI-ready platform
An illustration of access surfaces surrounding a governed system.
System roleInterface host and orchestration layer
Access maturityBYO-UI-ready platform
MCP supportOfficial MCP server
Reference updatedJul 12, 2026
BYO-UI reviewedJul 22, 2026

Concrete capability record

Data, retrieval, actions, identity, and operating limits

A field-by-field summary of what the reviewed first-party references actually support. Publisher update dates and BYO-UI review dates are shown separately below.

01 · Records and state owned

Projects, organizations, Postgres schemas and tables, migrations, SQL, logs, advisors, Edge Functions, branches, documentation, and optional storage configuration exposed as development tools.

02 · Data you can retrieve

Inspect schemas, tables, extensions, migrations, logs, advisors, project URLs and keys, Edge Functions, branches, organizations, costs, storage configuration, and documentation within enabled feature groups.

03 · Actions and write paths

Unless read-only mode is enabled, tools may execute SQL, apply migrations, deploy Edge Functions, manage project lifecycle and branches, confirm costs, and update storage configuration.

04 · Authentication and permissions

Hosted clients authorize in a browser and grant organization access. Project scope, read-only mode, and feature groups then constrain the projects, database execution, and tools exposed.

05 · Monitoring, approval, and recovery

Use a development project with non-production or obfuscated data, keep manual tool approval enabled, select one project, and expose only the feature groups needed for the task.

06 · Limits and caveats

Supabase limits this MCP to development and testing and warns against production data or customer access because the server operates under the connected developer's permissions.

First-party MCP tool catalog

32 named MCP tools · Supabase MCP server

The exact feature-group tool names published for Supabase's hosted and local development MCP server configurations. Reviewed Jul 10, 2026. The available catalog changes with project_ref, read_only, and feature selections. Storage tools are disabled by default, Branching is experimental and paid-plan dependent, and project scoping removes account-management tools. Supabase warns against connecting this development-oriented server to production data.

First-party exact listComplete list on cited pageSupabase hosted and local development MCP server
32 shown
Database5
list_tablesreadlist_extensionsreadlist_migrationsreadapply_migrationconsequential writeexecute_sqlconsequential write
Debugging and development5
get_logsreadget_advisorsreadget_project_urlreadget_publishable_keysreadgenerate_typescript_typesread
Edge Functions3
list_edge_functionsreadget_edge_functionreaddeploy_edge_functionconsequential write
Projects, organizations, and cost9
list_projectsreadget_projectreadcreate_projectconsequential writepause_projectconsequential writerestore_projectconsequential writelist_organizationsreadget_organizationreadget_costreadconfirm_costwrite
Documentation1
search_docsread
Experimental branching6
create_branchconsequential writelist_branchesreaddelete_branchconsequential writemerge_branchconsequential writereset_branchconsequential writerebase_branchconsequential write
Storage configuration3
list_storage_bucketsreadget_storage_configreadupdate_storage_configconsequential write
Catalog evidence: Supabase MCP Server

Agent access

MCP support

Official MCP serverSupabase-hosted project MCP and local Supabase CLI MCP for development toolingCurrent developer tooling for non-production projects; customer-facing and production-data use is explicitly discouraged

Support: Official MCP server

Read scope: Read database metadata, logs, advisors, project metadata, functions, branches, organizations, costs, storage settings, and documentation exposed by the selected project and feature groups.

Write scope: 13 of 32 reviewed named tools have a write, draft, or mixed action label, including apply_migration, execute_sql, deploy_edge_function, create_project, pause_project, and others. Read each catalog boundary before enabling them.

Authentication: Hosted clients use browser authorization and dynamic client registration by default. CI may use a personal access token; clients needing fixed credentials may use a manually created OAuth app.

Approval boundary: Keep per-tool confirmation enabled for SQL, migrations, function deployment, project lifecycle, branches, costs, and storage changes; Supabase warns that prompt injection can cause unintended actions.

Protocol does not erase product boundaries.

Confirm the current tool catalog, plan, region, scopes, rate limits, terms, and write behavior before implementation.

Editorial assessment

Access-maturity dimensions

A comparative architecture lens—not a quality score, market ranking, or buying recommendation. Scale: 1–5.

Data access4
Action access4
Event access4
Identity4
Governance4
Agent access4
UI extensibility4
Portability4
Observability4
Documentation5

Proposed customer-shaped experiences

What customers could create on top.

The output could be an export, report, graph, artifact, application, agent, workflow, or downstream feed. These proposals are derived from documented access—not claims that Supabase ships them.

Single-platform patterns

  • Governed application backend for customer-owned interfaces
  • BYO-UI application shell
  • Capability gateway
  • Agent and tool operations console
Use in the brief builder →

Multi-platform compositions

  • Supabase + systems of record: byo-ui application shell
  • Supabase + systems of production + systems of engagement: cross-system decision workspace
Explore composition recipes →

Evidence and dates

First-party references, with publisher and review dates separated

“Publisher updated” is shown only when the page exposes an update date. “BYO-UI reviewed” records when this research checked the reference. A missing publisher date is reported as missing—not replaced with the review date.

7 recorded sources
MCPRepresentative source
https://supabase.com/docs/guides/ai-tools/mcp ↗

Hosted and local CLI deployment, tool groups, authentication paths, project and read-only configuration, manual approval, and development-only safety boundary

Publisher updated
Jul 12, 2026
BYO-UI reviewed
Jul 22, 2026

Supabase MCP tools, authentication, configuration, and security guidance reviewed 2026-07-22

AI toolsSource inventory
https://supabase.com/docs/guides/ai-tools ↗

First-party agent and MCP overview.

Publisher updated
Jul 12, 2026
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

APISource inventory
https://supabase.com/docs/reference ↗

First-party API documentation.

Publisher updated
Jul 12, 2026
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

Build MCPSource inventory
https://supabase.com/docs/guides/ai-tools/byo-mcp ↗

First-party guide to deploying customer-owned MCP servers.

Publisher updated
Jul 12, 2026
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

DocumentationSource inventory
https://supabase.com/docs ↗

First-party platform documentation.

Publisher updated
Jul 12, 2026
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

HomepageSource inventory
https://supabase.com/ ↗

Platform overview.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

Webhooks / extensionsSource inventory
https://supabase.com/docs/guides/database/webhooks ↗

First-party event, extension, or embedding documentation.

Publisher updated
Jul 12, 2026
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

Verified fact

Tied to cited first-party evidence reviewed for this profile.

Source inventory

Official links recorded for deeper research but not necessarily reopened endpoint by endpoint.

Editorial assessment

System role, maturity interpretation, and architectural boundary.

Proposed design

Interface patterns and compositions—not vendor product claims.