Supabase MCP Server
Infrastructure · tested 2026-08-25 · re-test due 2026-11-23 · by the Hlido desk, not the vendor
In short: The official, hosted MCP bridge to a Supabase project — well-documented, scopable to read-only, and honest enough to open with the security risk rather than bury it.
4 PASS · 1 FAIL of 5 public-surface claims
Quick answer
Supabase MCP Server scores 85/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-08-25). STEADY (85), near the top of the band, because this is a first-party, well-documented, hosted MCP server with genuine scoping controls (per-project, read-only, feature groups) and a security posture that leads with the r Pricing was not findable on the public surface when tested.
The Supabase MCP server does one job and documents it properly: it connects an MCP client — Claude Code, Cursor, and the rest — to a Supabase project so an agent can query and manage it on your behalf. What separates this from the long tail of database MCP servers is that it is first-party, hosted as a remote MCP endpoint at mcp.supabase.com, and shipped with the kind of controls a database connection actually needs. You scope the server to a single project or expose all of them; you toggle read-only; you pick which feature groups (docs, account, database, debugging, development, functions, branching) the agent can touch, and those choices are encoded directly in the server URL. The install path is concrete and copy-pasteable per client, and authentication runs through a real browser login flow rather than a pasted service key. The single most creditable thing on the surface is editorial: the docs lead with 'connecting an LLM to your Supabase projects carries security risks. Read our security best practices before running the MCP server' before they tell you how to install it. For a tool whose whole function is handing an autonomous model access to a production database, putting the warning first is the correct order and most vendors get it backwards. It loses points only where every hosted MCP server does: the blast radius of a mis-scoped or prompt-injected agent against a live database is real, and the read-only default is opt-in rather than the floor. But as an agent integration surface this is close to the reference implementation.
Why STEADY
STEADY (85), near the top of the band, because this is a first-party, well-documented, hosted MCP server with genuine scoping controls (per-project, read-only, feature groups) and a security posture that leads with the risk. It is held just short of VITAL because the powerful defaults skew open — read-only and project-scoping are choices the operator must make, not the safe floor — and because a database MCP's failure mode under prompt injection remains severe by construction. It moves toward VITAL if read-only becomes the default and per-tool audit logging is surfaced on the public docs.
Public-surface checklist
- PASS Homepage loads (required)
- PASS Primary value prop (required) — Connect your AI tools to Supabase using MCP
- PASS Cta present (required) — Remote MCP installation with per-client instructions
- FAIL Pricing or access — No price on the MCP docs page; access is governed by the linked Supabase account plan
- PASS Evidence or demo — Copy-pasteable install commands and .mcp.json config for multiple MCP clients; live server URL
What we saw
1 screenshot captured by the Hlido engine during the reviewed run (run-c72e9219be1ca836-supabase-com). Our own captures — not vendor marketing material.
What it does well
- First-party, official Supabase server — not a community re-wrap of the database protocol
- Hosted as a remote MCP endpoint, so there is no local server process to run or maintain
- Scopable to a single project or all projects, with an explicit read-only toggle
- Feature groups (docs, account, database, debugging, functions, branching) let you narrow the tool surface the agent sees
- Config choices are encoded in the server URL, making the granted scope auditable at a glance
- Documentation leads with the security warning and links best practices before install steps
- Authentication runs through a browser login flow rather than a pasted long-lived key
What it fails at
- Read-only is opt-in rather than the default, so the unsafe configuration is one omission away
- No pricing surfaced on the MCP docs page itself — access is tied to a Supabase account whose plan governs it
- Public docs do not surface per-tool audit logging or an activity trail for what the agent did
- The security burden is placed on the operator ('read our best practices') rather than enforced by conservative defaults
- Like all database MCP servers, a prompt-injected agent with write scope can do real damage to live data
Red flags
- Read-only mode and project scoping are operator opt-ins, not enforced defaults — the most dangerous configuration is the one you get by not choosing
Best for
- Teams already on Supabase who want their coding agent to query and manage projects through a maintained, official server
- Developers who want a hosted MCP endpoint with no local process to run
- Anyone who needs per-project and read-only scoping baked into the connection
Not recommended for
- Users not on Supabase — the server is bound to the Supabase platform
- Environments that require write access to production data to be off by hard policy rather than a toggle
- Buyers needing published per-seat pricing on the MCP surface before adopting
Pricing & access
- Pricing findable on the public surfaceFAIL No price on the MCP docs page; access is governed by the linked Supabase account plan (tested 2026-08-25)
Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-25.
Compared to
-
Neo4j MCP Integrations
first-party-hosted-scoping
Both are database MCP servers, but Neo4j's is graph-native and community-maintained while Supabase's is first-party and hosted with URL-encoded scoping. Supabase for a managed Postgres stack with official support; Neo4j's for graph workloads.
-
MCP Toolbox for Databases
managed-single-vendor
Google's GenAI Toolbox is a general database-tooling server you host yourself across many engines; the Supabase server is a single-vendor hosted endpoint. Toolbox for multi-database, self-hosted control; Supabase for a zero-maintenance official bridge to one platform.
Agent relevance
API CLI MCP Behavioral-testable
Agentic-Commerce Readiness 71/100 · INTEGRABLE
Independent readiness for agent delegation & transaction. How it’s scored · check live
This is itself an MCP server — the integration surface is the point. An agent connects via the hosted endpoint at mcp.supabase.com with scope and feature groups encoded in the URL, authenticates through a browser flow, and then queries or manages the Supabase project through MCP tools. Install is a single `claude mcp add` command or an .mcp.json block. Directly and natively agent-consumable.
Agent-friendly score: 9/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
Evidence
- Official remote MCP server hosted at mcp.supabase.com connecting AI tools to Supabase projects — source (2026-08-25) verified
- Server is scopable to a project, supports a read-only option, and exposes feature groups — source (2026-08-25) verified
- Documentation leads with a security warning before install instructions — source (2026-08-25) verified
- Authentication runs through a browser login flow rather than a pasted key — source (2026-08-25) verified
