Skip to content
Graphify
First-party publisher Source reviewed

Supabase MCP Server

Let development agents inspect and manage Supabase databases, projects, logs, Edge Functions, branches, and documentation.

Overview

What Supabase MCP Server does

Supabase MCP provides a hosted endpoint for connecting an agent to Supabase projects through browser-based authorization. Its feature groups cover database work, development diagnostics, Edge Functions, project administration, documentation, experimental branching, and optional Storage controls. Project scoping, read-only execution, and feature selection make it possible to reduce the server's reach for a particular workspace.

Best for

  • Designing and inspecting a Supabase schema from an IDE
  • Running development queries and reading service logs
  • Managing migrations, types, branches, and Edge Functions during app development

Not ideal for

  • Direct customer-facing access under a developer identity
  • Unsupervised writes to production databases
  • Exposing a self-hosted Supabase MCP endpoint directly to the public internet

Capabilities

What an agent can do

  1. 01

    Table, extension, migration, and SQL operations

  2. 02

    Project and organization management

  3. 03

    Logs and TypeScript type generation

  4. 04

    Edge Function inspection and deployment

  5. 05

    Documentation search

  6. 06

    Branching and opt-in Storage operations

Representative tools and operations

list_tablesexecute_sqlapply_migrationget_logsgenerate_typescript_typesdeploy_edge_functionsearch_docscreate_branch

Installation

Connect Supabase MCP Server

Use the publisher’s current instructions as the source of truth. The examples below were checked on .

Claude CodeConnect to hosted Supabase MCP
Command
claude mcp add --scope project --transport http supabase https://mcp.supabase.com/mcp
Configuration
Authenticate from the client's MCP menu, then select the intended Supabase organization.
Generic MCP clientScope hosted access to one project in read-only mode
Command
https://mcp.supabase.com/mcp?project_ref=YOUR_PROJECT_REF&read_only=true
Configuration
Add a features query parameter to expose only the required groups, such as database,docs.

Trust and access

Authentication and security notes

Authentication: The hosted service uses a browser OAuth flow and no longer requires a manually created PAT. The legacy/local npm route can use a Supabase personal access token; the local CLI endpoint follows local development authentication.

Review before connecting

  • Use a development project with synthetic or obfuscated data whenever possible.
  • Scope the connection to one project and enable read-only mode for investigation tasks.
  • Keep per-call confirmation enabled and review SQL or deployment operations before approval.
  • Do not expose the self-hosted MCP route to the internet; use a VPN or SSH tunnel as documented.

Known limitations

  • Hosted authorization grants organization access and does not yet offer fully granular permission selection.
  • Branching tools are experimental and require an eligible paid plan.
  • Storage tools are disabled by default.
  • Read-only mode reduces database writes but does not replace careful review of all enabled feature groups.

Evidence

Sources used for this guide

Facts were checked against primary publisher material. Descriptions and guidance are original Graphify summaries.

FAQ

Questions about Supabase MCP Server

Should Supabase MCP be connected to production?

Supabase recommends a development project. If production access is unavoidable, use project scoping, read-only mode, limited feature groups, and manual approval.

Is a personal access token still required?

Not for the hosted service, which uses browser authorization. Token setup remains relevant to some local or legacy package workflows.

Editorial review · MCP server

What this page is based on

Server capabilities and operational notes are tied to the recorded source set and review date.

Review basis
MCP server record and linked primary evidence
Last checked
Jul 11, 2026
Evidence links
3 recorded in the page data

Source snapshot is 91 days old; verify upstream details before relying on pricing, availability, or security claims.