The Supabase MCP server connects an AI assistant to your Supabase projects so it can interact with and query them on your behalf. It is hosted at mcp.supabase.com/mcp and uses OAuth dynamic client registration, so there is no personal access token to create during setup. Supabase lists a long set of supported clients, including Claude Code, Codex, Gemini CLI, GitHub Copilot, Cursor, VS Code, and Devin Desktop.
The tool set is broad. It covers database work (listing tables, extensions, and migrations, applying migrations, and running SQL), development helpers such as generating TypeScript types and fetching project URLs and API keys, deploying and managing Edge Functions, reading logs and the security and performance advisors, managing projects and organizations, and searching Supabase’s docs. Branching is experimental and limited to paid plans, and storage tools are disabled by default.
Supabase is direct about the risk: connecting an LLM to your projects carries security risks, mainly prompt injection, where instructions hidden in your data try to steer the model. It wraps SQL results with extra instructions to discourage that, but says this is not foolproof. Its guidance is to use the server as an internal developer tool rather than a customer-facing feature, keep manual approval on for interactive work, and lean on the safeguards it provides: a read-only mode that runs queries as a read-only Postgres user, project scoping, and enabling only the tool groups you need.
Verdict: very useful if you build on Supabase, as long as you treat it as a development tool and start read-only and scoped. That matches the “start read-only” advice in our best MCP servers for developers, and Context7 is a good companion for up-to-date docs.
Source: Supabase’s MCP documentation, checked on September 20, 2026.
