The Supabase connector.
Projects, functions, health and advisors. Connect once with your own key. Every agent your team runs reads the same 6 tools under one permission model.
How access is governed
6
Read tools
Open by default. They run when called, and every call is logged with the endpoint, tool and capability.
0
Write tools
Supabase exposes no write tools. Nothing it does mutates external state.
0
Destructive tools
Supabase defines no destructive tools. Nothing here deletes data.
Defaults come from the capability on each tool definition, and an admin can tighten or open any tool individually. The endpoint's capability ceiling can only tighten that policy. An endpoint scoped to read never surfaces a write tool.
Every Supabase tool
6 tools, named as the agent sees them.
- list_projectsread
List every Supabase project the personal access token can see. Start here: every other tool takes the `ref` returned by this one (a 20-character project ref like "abcdefghijklmnopqrst"), not the project name.
- get_projectread
Get one project including its Postgres version and database host. Takes a project `ref` from list_projects. Use it to confirm a project is ACTIVE_HEALTHY before digging into an incident.
- get_project_healthread
Check the live health of a project's services (auth, db, realtime, rest, storage, pooler). This is the "is Supabase down for us" tool. Takes a project `ref` from list_projects.
- list_functionsread
List the Edge Functions deployed on a project, with deploy status and version. Takes a project `ref` from list_projects. Use it to check what is deployed and when it last shipped.
- list_branchesread
List the preview/database branches on a project, with the git branch and PR each tracks. Takes a project `ref` from list_projects. Use it to see which preview environments are live.
- list_security_advisorsread
Run Supabase's security advisors against a project and return the findings (missing RLS policies, exposed auth tables, mutable function search paths, and similar). Takes a project `ref` from list_projects. Use it for a pre-launch or periodic security sweep.
Use it from any agent
The same Supabase tools reach Claude Code, Cursor, Claude Desktop or your own agent through one MCP endpoint. The endpoint is scoped to a group, the token is issued per group and revocable from the dashboard, and an allowed-tool list and capability ceiling limit what it exposes. Reads run. Gated writes refuse unless an admin opens them. Destructive tools remain unavailable over MCP.
{
"mcpServers": {
"growth": {
"type": "http",
"url": "https://app.notara.ai/mcp/g/acme/growth",
"headers": {
"Authorization": "Bearer ntr_mcp_xxxxxxxxxxxxxxxxxxxx"
}
}
}
}The URL and token are placeholders. Real endpoints are issued per group from the dashboard.
Setup
- 01
Create a Supabase Personal Access Token in your Supabase account (where to find it). The key is yours: Notara stores it encrypted and never sees a bill.
- 02
Paste it into the Notara dashboard. Credentials can be scoped to the workspace or to one person.
- 03
The tools appear with their capability defaults already set. Tighten or open any of them per tool, then invite the agent to a channel or issue an MCP token.
Connect Supabase once. Use it everywhere.
Use Notara directly, or bring us the workflow that needs to be redesigned and built.