Supabase Mcp Server
About
# Query MCP (Supabase MCP Server) <p align="center"> <picture> <source media="(prefers-color-scheme: dark)" srcset="https://github.com/user-attachments/assets/4a363bcd-7c15-47fa-a72a-d159916517f7" /> <source media="(prefers-color-scheme: light)"…
Explore
- 💻 Compatible with Cursor, Windsurf, Cline and other MCP clients supporting stdio protocol
- 🔐 Control read-only and read-write modes of SQL query execution
- 🔍 Runtime SQL query validation with risk level assessment
- 🛡️ Three-tier safety system for SQL operations: safe, write, and destructive
- 🔄 Robust transaction handling for both direct and pooled database connections
- 📝 Automatic versioning of database schema changes
- 💻 Manage your Supabase projects with Supabase Management API
- 🧑💻 Manage users with Supabase Auth Admin methods via Python SDK
- 🔨 Pre-built tools to help Cursor & Windsurf work with MCP more effectively
- 📦 Dead-simple install & setup via package manager (uv, pipx, etc.)
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
Supabase Mcp ServerCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
Installing the server requires the following on your system:
- Python 3.12+
If you plan to install via uv, ensure it's installed.
PostgreSQL installation is no longer required for the MCP server itself, as it now uses asyncpg which doesn't depend on PostgreSQL development libraries.
However, you'll still need PostgreSQL if you're running a local Supabase instance:
MacOS
brew install postgresql@16
Windows
- Download and install PostgreSQL 16+ from https://www.postgresql.org/download/windows/
- Ensure "PostgreSQL Server" and "Command Line Tools" are selected during installation
Since v0.2.0 I introduced support for package installation. You can use your favorite Python package manager to install the server via:
pipx install supabase-mcp-server
uv pip install supabase-mcp-server
pipx is recommended because it creates isolated environments for each package.
You can also install the server manually by cloning the repository and running pipx install -e . from the root directory.
If you would like to install from source, for example for local development:
uv venv
uv pip install -e .
You can find the full instructions on how to use Smithery.ai to connect to this MCP server here.
The Supabase MCP server requires configuration to connect to your Supabase database, access the Management API, and use the Auth Admin SDK. This section explains all available configuration options and how to set them up.
The server uses the following environment variables:
| Variable | Required | Default | Description |
|----------|----------|---------|-------------|
| SUPABASE_PROJECT_REF | Yes | 127.0.0.1:54322 | Your Supabase project reference ID (or local host:port) |
| SUPABASE_DB_PASSWORD | Yes | postgres | Your database password |
| SUPABASE_REGION | Yes* | us-east-1 | AWS region where your Supabase project is hosted |
| SUPABASE_ACCESS_TOKEN | No | None | Personal access token for Supabase Management API |
| SUPABASE_SERVICE_ROLE_KEY | No | None | Service role key for Auth Admin SDK |
> Note: The default values are configured for local Supabase development. For remote Supabase projects, you must provide your own values for SUPABASE_PROJECT_REF and SUPABASE_DB_PASSWORD.
> 🚨 CRITICAL CONFIGURATION NOTE: For remote Supabase projects, you MUST specify the correct region where your project is hosted using SUPABASE_REGION. If you encounter a "Tenant or user not found" error, this is almost certainly because your region setting doesn't match your project's actual region. You can find your project's region in the Supabase dashboard under Project Settings.
The server looks for configuration in this order (highest to lowest priority):
1. Environment Variables: Values set directly in your environment
2. Local .env File: A .env file in your current working directory (only works when running from source)
3. Global Config File:
- Windows: %APPDATA%\supabase-mcp\.env
- macOS/Linux: ~/.config/supabase-mcp/.env
4. Default Settings: Local development defaults (if no other config is found)
> ⚠️ Important: When using the package installed via pipx or uv, local .env files in your project directory are not detected. You must use either environment variables or the global config file.
Set environment variables directly in your MCP client configuration (see client-specific setup instructions in Step 3). Most MCP clients support this approach, which keeps your configuration with your client settings.
Create a global .env configuration file that will be used for all MCP server instances:
``bash
If you're running the server from source (not via package), you can create a .env file in your project directory with the same format as above.
In general, any MCP client that supports stdio` protocol should work with this MCP server. This server was explicitly tested to work with:
- Cursor
- Windsurf
- Cline
- Claude Desktop
Additionally, you can also use smithery.ai to install this server a number of clients, including the ones above.
Follow the guides below to install this MCP server in your client.
command: supabase-mcp-server
command: uv run supabase-mcp-server
safe
Read-only operations (SELECT) - always allowed
write
Data modifications (INSERT, UPDATE, DELETE) - require unsafe mode
destructive
Schema changes (DROP, CREATE) - require unsafe mode + confirmation
get_schemas
Lists schemas with sizes and table counts
get_tables
Lists tables, foreign tables, and views with metadata
get_table_schema
Gets detailed table structure (columns, keys, relationships)
execute_postgresql
Executes SQL statements against your database
confirm_destructive_operation
Executes high-risk operations after confirmation
retrieve_migrations
Gets migrations with filtering and pagination options
live_dangerously
Toggles between safe and unsafe modes
send_management_api_request
Sends arbitrary requests to Supabase Management API with auto-injection of project ref
get_management_api_spec
Gets the enriched API specification with safety information
get_management_api_safety_rules
Gets all safety rules with human-readable explanations
unsafe
State-changing operations (POST, PUT, PATCH, DELETE) - require unsafe mode
blocked
Destructive operations (delete project, etc.) - never allowed
get_auth_admin_methods_spec
to retrieve documentation for all available Auth Admin methods
call_auth_admin_method
to directly invoke Auth Admin methods with proper parameter handling
get_user_by_id
Retrieve a user by their ID
list_users
List all users with pagination
create_user
Create a new user
delete_user
Delete a user by their ID
invite_user_by_email
Send an invite link to a user's email
generate_link
Generate an email link for various authentication purposes
update_user_by_id
Update user attributes by ID
delete_factor
Delete a factor on a user (currently not implemented in SDK)
Since v0.3+ server provides comprehensive database management capabilities with built-in safety controls:
- SQL Query Execution: Execute PostgreSQL queries with risk assessment
- Three-tier safety system:
- safe: Read-only operations (SELECT) - always allowed
- write: Data modifications (INSERT, UPDATE, DELETE) - require unsafe mode
- destructive: Schema changes (DROP, CREATE) - require unsafe mode + confirmation
- SQL Parsing and Validation:
- Uses PostgreSQL's parser (pglast) for accurate analysis and provides clear feedback on safety requirements
- Automatic Migration Versioning:
- Database-altering operations operations are automatically versioned
- Generates descriptive names based on operation type and target
- Safety Controls:
- Default SAFE mode allows only read-only operations
- All statements run in transaction mode via asyncpg
- 2-step confirmation for high-risk operations
- Available Tools:
- get_schemas: Lists schemas with sizes and table counts
- get_tables: Lists tables, foreign tables, and views with metadata
- get_table_schema: Gets detailed table structure (columns, keys, relationships)
- execute_postgresql: Executes SQL statements against your database
- confirm_destructive_operation: Executes high-risk operations after confirmation
- retrieve_migrations: Gets migrations with filtering and pagination options
- live_dangerously: Toggles between safe and unsafe modes
Since v0.3.0 server provides secure access to the Supabase Management API with built-in safety controls:
- Available Tools:
- send_management_api_request: Sends arbitrary requests to Supabase Management API with auto-injection of project ref
- get_management_api_spec: Gets the enriched API specification with safety information
- Supports multiple query modes: by domain, by specific path/method, or all paths
- Includes risk assessment information for each endpoint
- Provides detailed parameter requirements and response formats
- Helps LLMs understand the full capabilities of the Supabase Management API
- get_management_api_safety_rules: Gets all safety rules with human-readable explanations
- live_dangerously: Toggles between safe and unsafe operation modes
- Safety Controls:
- Uses the same safety manager as database operations for consistent risk management
- Operations categorized by risk level:
- safe: Read-only operations (GET) - always allowed
- unsafe: State-changing operations (POST, PUT, PATCH, DELETE) - require unsafe mode
- blocked: Destructive operations (delete project, etc.) - never allowed
- Default safe mode prevents accidental state changes
- Path-based pattern matching for precise safety rules
Note: Management API tools only work with remote Supabase instances and are not compatible with local Supabase development setups.
I was planning to add support for Python SDK methods to the MCP server. Upon consideration I decided to only add support for Auth admin methods as I often found myself manually creating test users which was prone to errors and time consuming. Now I can just ask Cursor to create a test user and it will be done seamlessly. Check out the full Auth Admin SDK method docs to know what it can do.
Since v0.3.6 server supports direct access to Supabase Auth Admin methods via Python SDK:
- Includes the following tools:
- get_auth_admin_methods_spec to retrieve documentation for all available Auth Admin methods
- call_auth_admin_method to directly invoke Auth Admin methods with proper parameter handling
- Supported methods:
- get_user_by_id: Retrieve a user by their ID
- list_users: List all users with pagination
- create_user: Create a new user
- delete_user: Delete a user by their ID
- invite_user_by_email: Send an invite link to a user's email
- generate_link: Generate an email link for various authentication purposes
- update_user_by_id: Update user attributes by ID
- delete_factor: Delete a factor on a user (currently not implemented in SDK)
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"supabase mcp server": {
"supabase-mcp-server-medieage": {
"command": "uv",
"args": [
"pip",
"install",
"supabase-mcp-server"
]
}
}
}
}
McpServers
{
"supabase-mcp-server-medieage": {
"command": "uv",
"args": [
"pip",
"install",
"supabase-mcp-server"
]
}
}
Query MCP (Supabase MCP Server)
<p align="center">
<picture>
<source media="(prefers-color-scheme: dark)" srcset="https://github.com/user-attachments/assets/4a363bcd-7c15-47fa-a72a-d159916517f7" />
<source media="(prefers-color-scheme: light)" srcset="https://github.com/user-attachments/assets/d255388e-cb1b-42ea-a7b2-0928f031e0df" />
</picture>
<picture>
<source media="(prefers-color-scheme: dark)" srcset="https://github.com/user-attachments/assets/38db1bcd-50df-4a49-a106-1b5afd924cb2" />
<source media="(prefers-color-scheme: light)" srcset="https://github.com/user-attachments/assets/82603097-07c9-42bb-9cbc-fb8f03560926" />
</picture>
</p>
<p align="center">
<strong>Enable your favorite IDE to safely execute SQL queries, manage your database end-to-end, access Management API, and handle user authentication with built-in safety controls.</strong>
</p>
<p align="center">
<a href="https://thequery.dev"></a>
</p>
<p align="center">
<a href="https://pypi.org/project/supabase-mcp-server/"></a>
<a href="https://github.com/alexander-zuev/supabase-mcp-server/actions"></a>
<a href="https://codecov.io/gh/alexander-zuev/supabase-mcp-server"></a>
<a href="https://www.python.org/downloads/"></a>
<a href="https://github.com/astral-sh/uv"></a>
<a href="https://pepy.tech/project/supabase-mcp-server"></a>
<a href="https://smithery.ai/server/@alexander-zuev/supabase-mcp-server"></a>
<a href="https://modelcontextprotocol.io/introduction"></a>
<a href="LICENSE"></a>
</p>
🎉 The Future of Supabase MCP Server -> Query MCP
I'm thrilled to announce that Supabase MCP Server is evolving into thequery.dev!
While I have big plans for the future, I want to make these commitments super clear:
- The core tool will stay free forever - free & open-source software is how I got into coding
- Premium features will be added on top - enhancing capabilities without limiting existing functionality
- First 2,000 early adopters will get special perks - join early for an exclusive treat!
🚀 BIG v4 Launch Coming Soon!
👉 Join Early Access at thequery.dev
Table of contents
<p align="center"> <a href="#getting-started">Getting started</a> • <a href="#feature-overview">Feature overview</a> • <a href="#troubleshooting">Troubleshooting</a> • <a href="#changelog">Changelog</a> </p>✨ Key features
- 💻 Compatible with Cursor, Windsurf, Cline and other MCP clients supportingstdio protocol
- 🔐 Control read-only and read-write modes of SQL query execution
- 🔍 Runtime SQL query validation with risk level assessment
- 🛡️ Three-tier safety system for SQL operations: safe, write, and destructive
- 🔄 Robust transaction handling for both direct and pooled database connections
- 📝 Automatic versioning of database schema changes
- 💻 Manage your Supabase projects with Supabase Management API
- 🧑💻 Manage users with Supabase Auth Admin methods via Python SDK
- 🔨 Pre-built tools to help Cursor & Windsurf work with MCP more effectively
- 📦 Dead-simple install & setup via package manager (uv, pipx, etc.)
Getting Started
Prerequisites
Installing the server requires the following on your system: - Python 3.12+If you plan to install via uv, ensure it's installed.
PostgreSQL Installation
PostgreSQL installation is no longer required for the MCP server itself, as it now uses asyncpg which doesn't depend on PostgreSQL development libraries.However, you'll still need PostgreSQL if you're running a local Supabase instance:
MacOS
brew install postgresql@16
Windows
- Download and install PostgreSQL 16+ from https://www.postgresql.org/download/windows/
- Ensure "PostgreSQL Server" and "Command Line Tools" are selected during installation
Step 1. Installation
Since v0.2.0 I introduced support for package installation. You can use your favorite Python package manager to install the server via:
```bash
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



