Supabase Mcp Server

by medieage

365 downloads Not rated yet
GitHub

About

# Query MCP (Supabase MCP Server) <p align="center"> <picture> <source media="(prefers-color-scheme: dark)" srcset="https://github.com/user-attachments/assets/4a363bcd-7c15-47fa-a72a-d159916517f7" /> <source media="(prefers-color-scheme: light)"…

Explore

- 💻 Compatible with Cursor, Windsurf, Cline and other MCP clients supporting stdio protocol
- 🔐 Control read-only and read-write modes of SQL query execution
- 🔍 Runtime SQL query validation with risk level assessment
- 🛡️ Three-tier safety system for SQL operations: safe, write, and destructive
- 🔄 Robust transaction handling for both direct and pooled database connections
- 📝 Automatic versioning of database schema changes
- 💻 Manage your Supabase projects with Supabase Management API
- 🧑‍💻 Manage users with Supabase Auth Admin methods via Python SDK
- 🔨 Pre-built tools to help Cursor & Windsurf work with MCP more effectively
- 📦 Dead-simple install & setup via package manager (uv, pipx, etc.)

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Supabase Mcp Server
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

Installing the server requires the following on your system:
- Python 3.12+

If you plan to install via uv, ensure it's installed.

PostgreSQL installation is no longer required for the MCP server itself, as it now uses asyncpg which doesn't depend on PostgreSQL development libraries.

However, you'll still need PostgreSQL if you're running a local Supabase instance:

MacOS

brew install postgresql@16

Windows
- Download and install PostgreSQL 16+ from https://www.postgresql.org/download/windows/
- Ensure "PostgreSQL Server" and "Command Line Tools" are selected during installation

Since v0.2.0 I introduced support for package installation. You can use your favorite Python package manager to install the server via:


pipx install supabase-mcp-server

uv pip install supabase-mcp-server

pipx is recommended because it creates isolated environments for each package.

You can also install the server manually by cloning the repository and running pipx install -e . from the root directory.

If you would like to install from source, for example for local development:

uv venv

uv pip install -e .

You can find the full instructions on how to use Smithery.ai to connect to this MCP server here.

The Supabase MCP server requires configuration to connect to your Supabase database, access the Management API, and use the Auth Admin SDK. This section explains all available configuration options and how to set them up.

The server uses the following environment variables:

| Variable | Required | Default | Description |
|----------|----------|---------|-------------|
| SUPABASE_PROJECT_REF | Yes | 127.0.0.1:54322 | Your Supabase project reference ID (or local host:port) |
| SUPABASE_DB_PASSWORD | Yes | postgres | Your database password |
| SUPABASE_REGION | Yes* | us-east-1 | AWS region where your Supabase project is hosted |
| SUPABASE_ACCESS_TOKEN | No | None | Personal access token for Supabase Management API |
| SUPABASE_SERVICE_ROLE_KEY | No | None | Service role key for Auth Admin SDK |

> Note: The default values are configured for local Supabase development. For remote Supabase projects, you must provide your own values for SUPABASE_PROJECT_REF and SUPABASE_DB_PASSWORD.

> 🚨 CRITICAL CONFIGURATION NOTE: For remote Supabase projects, you MUST specify the correct region where your project is hosted using SUPABASE_REGION. If you encounter a "Tenant or user not found" error, this is almost certainly because your region setting doesn't match your project's actual region. You can find your project's region in the Supabase dashboard under Project Settings.

The server looks for configuration in this order (highest to lowest priority):

1. Environment Variables: Values set directly in your environment
2. Local .env File: A .env file in your current working directory (only works when running from source)
3. Global Config File:
- Windows: %APPDATA%\supabase-mcp\.env
- macOS/Linux: ~/.config/supabase-mcp/.env
4. Default Settings: Local development defaults (if no other config is found)

> ⚠️ Important: When using the package installed via pipx or uv, local .env files in your project directory are not detected. You must use either environment variables or the global config file.

Set environment variables directly in your MCP client configuration (see client-specific setup instructions in Step 3). Most MCP clients support this approach, which keeps your configuration with your client settings.

Create a global .env configuration file that will be used for all MCP server instances:

``bash

If you're running the server from source (not via package), you can create a .env file in your project directory with the same format as above.

In general, any MCP client that supports stdio` protocol should work with this MCP server. This server was explicitly tested to work with:
- Cursor
- Windsurf
- Cline
- Claude Desktop

Additionally, you can also use smithery.ai to install this server a number of clients, including the ones above.

Follow the guides below to install this MCP server in your client.

command: supabase-mcp-server

command: uv run supabase-mcp-server

safe

Read-only operations (SELECT) - always allowed

write

Data modifications (INSERT, UPDATE, DELETE) - require unsafe mode

destructive

Schema changes (DROP, CREATE) - require unsafe mode + confirmation

get_schemas

Lists schemas with sizes and table counts

get_tables

Lists tables, foreign tables, and views with metadata

get_table_schema

Gets detailed table structure (columns, keys, relationships)

execute_postgresql

Executes SQL statements against your database

confirm_destructive_operation

Executes high-risk operations after confirmation

retrieve_migrations

Gets migrations with filtering and pagination options

live_dangerously

Toggles between safe and unsafe modes

send_management_api_request

Sends arbitrary requests to Supabase Management API with auto-injection of project ref

get_management_api_spec

Gets the enriched API specification with safety information

get_management_api_safety_rules

Gets all safety rules with human-readable explanations

unsafe

State-changing operations (POST, PUT, PATCH, DELETE) - require unsafe mode

blocked

Destructive operations (delete project, etc.) - never allowed

get_auth_admin_methods_spec

to retrieve documentation for all available Auth Admin methods

call_auth_admin_method

to directly invoke Auth Admin methods with proper parameter handling

get_user_by_id

Retrieve a user by their ID

list_users

List all users with pagination

create_user

Create a new user

delete_user

Delete a user by their ID

invite_user_by_email

Send an invite link to a user's email

generate_link

Generate an email link for various authentication purposes

update_user_by_id

Update user attributes by ID

delete_factor

Delete a factor on a user (currently not implemented in SDK)

Since v0.3+ server provides comprehensive database management capabilities with built-in safety controls:

- SQL Query Execution: Execute PostgreSQL queries with risk assessment
- Three-tier safety system:
- safe: Read-only operations (SELECT) - always allowed
- write: Data modifications (INSERT, UPDATE, DELETE) - require unsafe mode
- destructive: Schema changes (DROP, CREATE) - require unsafe mode + confirmation

- SQL Parsing and Validation:
- Uses PostgreSQL's parser (pglast) for accurate analysis and provides clear feedback on safety requirements

- Automatic Migration Versioning:
- Database-altering operations operations are automatically versioned
- Generates descriptive names based on operation type and target

- Safety Controls:
- Default SAFE mode allows only read-only operations
- All statements run in transaction mode via asyncpg
- 2-step confirmation for high-risk operations

- Available Tools:
- get_schemas: Lists schemas with sizes and table counts
- get_tables: Lists tables, foreign tables, and views with metadata
- get_table_schema: Gets detailed table structure (columns, keys, relationships)
- execute_postgresql: Executes SQL statements against your database
- confirm_destructive_operation: Executes high-risk operations after confirmation
- retrieve_migrations: Gets migrations with filtering and pagination options
- live_dangerously: Toggles between safe and unsafe modes

Since v0.3.0 server provides secure access to the Supabase Management API with built-in safety controls:

- Available Tools:
- send_management_api_request: Sends arbitrary requests to Supabase Management API with auto-injection of project ref
- get_management_api_spec: Gets the enriched API specification with safety information
- Supports multiple query modes: by domain, by specific path/method, or all paths
- Includes risk assessment information for each endpoint
- Provides detailed parameter requirements and response formats
- Helps LLMs understand the full capabilities of the Supabase Management API
- get_management_api_safety_rules: Gets all safety rules with human-readable explanations
- live_dangerously: Toggles between safe and unsafe operation modes

- Safety Controls:
- Uses the same safety manager as database operations for consistent risk management
- Operations categorized by risk level:
- safe: Read-only operations (GET) - always allowed
- unsafe: State-changing operations (POST, PUT, PATCH, DELETE) - require unsafe mode
- blocked: Destructive operations (delete project, etc.) - never allowed
- Default safe mode prevents accidental state changes
- Path-based pattern matching for precise safety rules

Note: Management API tools only work with remote Supabase instances and are not compatible with local Supabase development setups.

I was planning to add support for Python SDK methods to the MCP server. Upon consideration I decided to only add support for Auth admin methods as I often found myself manually creating test users which was prone to errors and time consuming. Now I can just ask Cursor to create a test user and it will be done seamlessly. Check out the full Auth Admin SDK method docs to know what it can do.

Since v0.3.6 server supports direct access to Supabase Auth Admin methods via Python SDK:
- Includes the following tools:
- get_auth_admin_methods_spec to retrieve documentation for all available Auth Admin methods
- call_auth_admin_method to directly invoke Auth Admin methods with proper parameter handling
- Supported methods:
- get_user_by_id: Retrieve a user by their ID
- list_users: List all users with pagination
- create_user: Create a new user
- delete_user: Delete a user by their ID
- invite_user_by_email: Send an invite link to a user's email
- generate_link: Generate an email link for various authentication purposes
- update_user_by_id: Update user attributes by ID
- delete_factor: Delete a factor on a user (currently not implemented in SDK)

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "supabase mcp server": {
            "supabase-mcp-server-medieage": {
                "command": "uv",
                "args": [
                    "pip",
                    "install",
                    "supabase-mcp-server"
                ]
            }
        }
    }
}

McpServers

{
    "supabase-mcp-server-medieage": {
        "command": "uv",
        "args": [
            "pip",
            "install",
            "supabase-mcp-server"
        ]
    }
}

Query MCP (Supabase MCP Server)

<p align="center">
<picture>
<source media="(prefers-color-scheme: dark)" srcset="https://github.com/user-attachments/assets/4a363bcd-7c15-47fa-a72a-d159916517f7" />
<source media="(prefers-color-scheme: light)" srcset="https://github.com/user-attachments/assets/d255388e-cb1b-42ea-a7b2-0928f031e0df" />
Supabase
</picture>
&nbsp;&nbsp;
<picture>
<source media="(prefers-color-scheme: dark)" srcset="https://github.com/user-attachments/assets/38db1bcd-50df-4a49-a106-1b5afd924cb2" />
<source media="(prefers-color-scheme: light)" srcset="https://github.com/user-attachments/assets/82603097-07c9-42bb-9cbc-fb8f03560926" />
MCP
</picture>
</p>

<p align="center">
<strong>Enable your favorite IDE to safely execute SQL queries, manage your database end-to-end, access Management API, and handle user authentication with built-in safety controls.</strong>
</p>

<p align="center">
<a href="https://thequery.dev">Control Supabase with natural language</a>
</p>

<p align="center">
<a href="https://pypi.org/project/supabase-mcp-server/">PyPI version</a>
<a href="https://github.com/alexander-zuev/supabase-mcp-server/actions">CI Status</a>
<a href="https://codecov.io/gh/alexander-zuev/supabase-mcp-server">Code Coverage</a>
<a href="https://www.python.org/downloads/">Python 3.12+</a>
<a href="https://github.com/astral-sh/uv">uv package manager</a>
<a href="https://pepy.tech/project/supabase-mcp-server">PyPI Downloads</a>
<a href="https://smithery.ai/server/@alexander-zuev/supabase-mcp-server">Smithery.ai Downloads</a>
<a href="https://modelcontextprotocol.io/introduction">MCP Server</a>
<a href="LICENSE">License</a>
</p>

🎉 The Future of Supabase MCP Server -> Query MCP

I'm thrilled to announce that Supabase MCP Server is evolving into thequery.dev!

While I have big plans for the future, I want to make these commitments super clear:
- The core tool will stay free forever - free & open-source software is how I got into coding
- Premium features will be added on top - enhancing capabilities without limiting existing functionality
- First 2,000 early adopters will get special perks - join early for an exclusive treat!

🚀 BIG v4 Launch Coming Soon!

👉 Join Early Access at thequery.dev

Table of contents

<p align="center"> <a href="#getting-started">Getting started</a> • <a href="#feature-overview">Feature overview</a> • <a href="#troubleshooting">Troubleshooting</a> • <a href="#changelog">Changelog</a> </p>

✨ Key features

- 💻 Compatible with Cursor, Windsurf, Cline and other MCP clients supporting stdio protocol - 🔐 Control read-only and read-write modes of SQL query execution - 🔍 Runtime SQL query validation with risk level assessment - 🛡️ Three-tier safety system for SQL operations: safe, write, and destructive - 🔄 Robust transaction handling for both direct and pooled database connections - 📝 Automatic versioning of database schema changes - 💻 Manage your Supabase projects with Supabase Management API - 🧑‍💻 Manage users with Supabase Auth Admin methods via Python SDK - 🔨 Pre-built tools to help Cursor & Windsurf work with MCP more effectively - 📦 Dead-simple install & setup via package manager (uv, pipx, etc.)

Getting Started

Prerequisites

Installing the server requires the following on your system: - Python 3.12+

If you plan to install via uv, ensure it's installed.

PostgreSQL Installation

PostgreSQL installation is no longer required for the MCP server itself, as it now uses asyncpg which doesn't depend on PostgreSQL development libraries.

However, you'll still need PostgreSQL if you're running a local Supabase instance:

MacOS

brew install postgresql@16

Windows
- Download and install PostgreSQL 16+ from https://www.postgresql.org/download/windows/
- Ensure "PostgreSQL Server" and "Command Line Tools" are selected during installation

Step 1. Installation

Since v0.2.0 I introduced support for package installation. You can use your favorite Python package manager to install the server via:

```bash

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.