Overview
What Supabase MCP Server does
Supabase MCP provides a hosted endpoint for connecting an agent to Supabase projects through browser-based authorization. Its feature groups cover database work, development diagnostics, Edge Functions, project administration, documentation, experimental branching, and optional Storage controls. Project scoping, read-only execution, and feature selection make it possible to reduce the server's reach for a particular workspace.
Best for
- Designing and inspecting a Supabase schema from an IDE
- Running development queries and reading service logs
- Managing migrations, types, branches, and Edge Functions during app development
Not ideal for
- Direct customer-facing access under a developer identity
- Unsupervised writes to production databases
- Exposing a self-hosted Supabase MCP endpoint directly to the public internet
Capabilities
What an agent can do
- 01
Table, extension, migration, and SQL operations
- 02
Project and organization management
- 03
Logs and TypeScript type generation
- 04
Edge Function inspection and deployment
- 05
Documentation search
- 06
Branching and opt-in Storage operations
Representative tools and operations
list_tablesexecute_sqlapply_migrationget_logsgenerate_typescript_typesdeploy_edge_functionsearch_docscreate_branch
Installation
Connect Supabase MCP Server
Use the publisher’s current instructions as the source of truth. The examples below were checked on .
Claude CodeConnect to hosted Supabase MCP
claude mcp add --scope project --transport http supabase https://mcp.supabase.com/mcp
Authenticate from the client's MCP menu, then select the intended Supabase organization.
Generic MCP clientScope hosted access to one project in read-only mode
https://mcp.supabase.com/mcp?project_ref=YOUR_PROJECT_REF&read_only=true
Add a features query parameter to expose only the required groups, such as database,docs.
Trust and access
Authentication and security notes
Authentication: The hosted service uses a browser OAuth flow and no longer requires a manually created PAT. The legacy/local npm route can use a Supabase personal access token; the local CLI endpoint follows local development authentication.
Review before connecting
- Use a development project with synthetic or obfuscated data whenever possible.
- Scope the connection to one project and enable read-only mode for investigation tasks.
- Keep per-call confirmation enabled and review SQL or deployment operations before approval.
- Do not expose the self-hosted MCP route to the internet; use a VPN or SSH tunnel as documented.
Known limitations
- Hosted authorization grants organization access and does not yet offer fully granular permission selection.
- Branching tools are experimental and require an eligible paid plan.
- Storage tools are disabled by default.
- Read-only mode reduces database writes but does not replace careful review of all enabled feature groups.
Evidence
Sources used for this guide
Facts were checked against primary publisher material. Descriptions and guidance are original Graphify summaries.
FAQ
Questions about Supabase MCP Server
Should Supabase MCP be connected to production?
Supabase recommends a development project. If production access is unavoidable, use project scoping, read-only mode, limited feature groups, and manual approval.
Is a personal access token still required?
Not for the hosted service, which uses browser authorization. Token setup remains relevant to some local or legacy package workflows.