Index live · v1.7.0 · OCT 6 2026

Supabase

Official

Supabase's official MCP server provides complete access to the Supabase platform. Manage Postgres databases, authentication, edge functions, file storage, and database branching. Hosted at mcp.supabase.com with ~42K weekly visitors.

Streamable HTTPTypeScriptOAuth
~42K visitors/wk

Configuration

{
  "mcpServers": {
    "supabase": {
      "type": "http",
      "url": "https://mcp.supabase.com/mcp"
    }
  }
}

Run in a terminal. Copied verbatim from the upstream README.

AgenticSkills Audit

Automated framework checks. Deep code review tracked separately. Read the methodology →

1/2
1 of 2 automated checks passed
Audited Aug 7, 2026
Hosted endpoint
TLS-only (HTTPS) endpoint
Mitigates: Plaintext credential interceptionResponded 404 over HTTPS
Evidence
OAuth 2.1 metadata (RFC 9728)
Mitigates: Token mismanagement, audience confusionNo /.well-known/oauth-protected-resource (status 404)
Repo-level checks
SECURITY.md published
Mitigates: Coordinated disclosure pathHosted server — repo-level check not applicable
Commit in last 90 days
Mitigates: Maintainer abandonmentHosted server — no public commit log
≥2 active contributors
Mitigates: Bus-factor of oneHosted server — no public contributor list
CI pipeline configured
Mitigates: Code health regressionHosted server — no public CI
Dependency lockfile committed
Mitigates: Dependency confusionHosted server — repo-level check not applicable
Signed releases (npm provenance)
Mitigates: Supply-chain backdoorHosted server — supply chain via vendor
Software Bill of Materials (SBOM)
Mitigates: Audit trailHosted server — repo-level check not applicable
License declared
Mitigates: Legal ambiguityHosted server — vendor terms of service apply

Deep framework checks (OAuth 2.1 / PKCE implementation, input validation, sandboxing) require human source review and are tracked separately. This scorecard covers programmatically verifiable signals only.

Quick Stats

Trust LevelOfficial
TransportStreamable HTTP
AuthOAuth
LanguageTypeScript
CategoryDatabases & Data

Tags

supabasepostgresauthstorageedge-functions

Looking for Supabase itself?

This page covers the MCP server — how an agent connects to Supabase. For the platform itself, including license, deployment model and pricing model, see Supabase in Developer Tools.

Get new MCP servers in your inbox. What we added, what failed the security audit, and why. See a past issue.