Supabase for AI agents

Supabase is an open-source backend platform providing a Postgres database, authentication, storage, and real-time APIs for building applications. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Developer toolsOAuth 2.0MCP + RESTsupabase.com
AUDIT LOG · SUPABASEPOLICY: acme-support
09:41:07 · claude · u_8f2read
supabase.list_tables
List Database Tables✓ allowed · 212ms
09:41:08 · claude · u_8f2read
supabase.get_branch
Get a database branch✓ allowed · 164ms
09:41:09 · claude · u_8f2write
supabase.create_function
Create a function✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
supabase.delete_project
Delete a project✕ blocked · policy: deny
EVERY SUPABASE CALL, ON THE RECORD
01 · USE CASES

What agents do in Supabase.

01

Create a new database branch

Create a database branch to test schema changes without touching the production database directly.

02

Run a query for a read check

Execute a read query against the project database to check data before making any changes.

03

Apply a migration after approval

Apply a database migration only after the user reviews and approves the SQL it will run.

02 · ACTIONS

129 Supabase actions, graded by risk.

Every Supabase action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

50

Look things up. Allowed by default.

  • supabase.get_branch
    Get a database branch
  • supabase.get_health
    Get API Health Status
  • supabase.get_project
    Get project
  • supabase.list_tables
    List Database Tables
  • supabase.get_function
    Retrieve a function
  • supabase.list_backups
    List project database backups
  • supabase.list_buckets
    List all buckets
  • supabase.list_secrets
    List all secrets
  • supabase.get_migration
    Get a migration
  • supabase.list_branches
    List database branches
  • supabase.get_action_run
    Get action run status
  • supabase.list_functions
    List all functions
  • supabase.get_auth_config
    Get project auth config
  • supabase.get_sql_snippet
    Get a specific SQL snippet
  • supabase.get_organization
    Get information about an organization
  • supabase.get_project_logs
    Get project logs
+ 34 MORE

write

61

Create and change things. Allow, or ask the user first.

  • supabase.update_branch
    Update branch configuration
  • supabase.update_api_key
    Update API key
  • supabase.update_project
    Update a project
  • supabase.create_function
    Create a function
  • supabase.create_a_project
    Create new project
  • supabase.update_functions
    Bulk update functions
  • supabase.create_login_role
    Create CLI login role
  • supabase.update_a_function
    Update a function
  • supabase.create_bulk_secrets
    Bulk create secrets
  • supabase.create_organization
    Create an organization
  • supabase.create_sso_provider
    Create SSO provider configuration
  • supabase.update_sso_provider
    Update an SSO provider by its UUID
  • supabase.create_database_branch
    Create a database branch
  • supabase.update_pgsodium_config
    Update pgsodium root key
  • supabase.update_database_password
    Update database password
  • supabase.update_jit_access_config
    Update JIT access config
+ 45 MORE

destructive

18

Delete, cancel or archive. Ask first, or deny outright.

  • supabase.delete_project
    Delete a project
  • supabase.delete_secrets
    Bulk delete secrets
  • supabase.delete_function
    Delete an edge function by slug
  • supabase.delete_login_roles
    Delete CLI login roles
  • supabase.delete_all_branches
    Delete all branches
  • supabase.delete_sso_provider
    Remove an SSO provider
  • supabase.delete_edge_function
    Delete edge function
  • supabase.delete_database_branch
    Delete branch by id
  • supabase.delete_custom_hostname_config
    Delete custom hostname config
  • supabase.delete_project_vanity_subdomain
    Delete vanity subdomain for project
  • supabase.merge_branch
    Merge a database branch
  • supabase.alpha_delete_api_key
    Delete an API key from the project
  • supabase.reset_database_branch
    Reset a database branch
  • supabase.beta_remove_network_bans
    Remove project network bans
  • supabase.beta_remove_read_replica
    Remove read replica
  • supabase.disable_project_readonly
    Disable project readonly mode
+ 2 MORE
03 · HOW IT WORKS

Supabase in three steps.

  1. 01Your users connect SupabaseThey sign in to Supabase on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “create a function” can wait for the user, and “delete a project” can be denied outright.
  3. 03Any agent can actYour agent calls Supabase through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('supabase', {
  read: 'allow',
  write: 'ask',        // create_function
  destructive: 'deny',  // delete_project
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Supabase connects.

Users sign in to Supabase on Arc0 Connect and approve the scopes you request. Build with Arc0’s Supabase OAuth app, or bring your own so the Supabase consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same Supabase connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key · OAuth 2.0
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Supabase from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Supabase and Arc0, answered.

Q01

Can I use Supabase with Claude, ChatGPT or Cursor?

Yes. Connect Supabase to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Supabase actions you allow.

Q02

How do users connect Supabase?

Users sign in to Supabase on Arc0 Connect and approve the scopes you request. Build with Arc0’s Supabase OAuth app, or bring your own so the Supabase consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which Supabase actions can my agent take?

129 in total: 50 read, 61 write and 18 destructive, such as “create a function”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Supabase?

Yes. Actions like “delete a project” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Supabase too?

Yes. The same Supabase connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Supabase into your agent.

Your users connect Supabase once, under your brand. Your agent gets 129 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan