Supabase MCP server
Last verified: 2026-09
Talk to a Supabase project: tables, auth, edge functions.
Community Databases & data Needs a secret Claude Desktop, Cursor, Windsurf, Claude Code, VS Code
What it does
Official-ish Supabase MCP (@supabase/mcp-server-supabase). Manages projects, tables, and config through a personal access token. Tool list lives on supabase.com/mcp and changes — connect and list tools rather than memorizing names.
It sits in Databases & data: A database MCP is SQL or an API with your credentials.
Good for
- List projects the PAT can see, then tables on staging.
- Inspect schema without opening the dashboard.
- Use readonly flags from supabase.com/mcp on a prod org.
- Skip this and use Postgres if you only have a connection string.
Tools
- project / organization tools — List and inspect projects the token can see.
- database / table / SQL tools — Schema and queries — often behind a project_ref and a readonly flag.
- docs on supabase.com/mcp — Canonical current list.
Config (Claude Desktop / Cursor / Windsurf)
Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets.
Windows paths look like C:\\Users\\you\\project, not /path/to.
Host-side steps →
Claude Desktop
| OS | Config file |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json
(usually C:\Users\<you>\AppData\Roaming\Claude\) |
| Linux | ~/.config/Claude/claude_desktop_config.json |
Cursor
| Scope | macOS / Linux | Windows |
|---|---|---|
| This project | .cursor/mcp.json in the repo root | |
| This user | ~/.cursor/mcp.json |
%USERPROFILE%\.cursor\mcp.json |
Windsurf
| OS | Config file |
|---|---|
| macOS / Linux | ~/.codeium/windsurf/mcp_config.json |
| Windows | %USERPROFILE%\.codeium\windsurf\mcp_config.json |
{
"mcpServers": {
"supabase": {
"command": "npx",
"args": [
"-y",
"@supabase/mcp-server-supabase"
],
"env": {
"SUPABASE_ACCESS_TOKEN": "sbp_..."
}
}
}
}
Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.
One-liner: npx -y @supabase/mcp-server-supabase
Secrets it wants: SUPABASE_ACCESS_TOKEN
How to get started
- Create a Supabase PAT. Prefer an org-scoped token.
- Pass the project ref and enable readonly in the client config when the docs show that flag.
- Ask it to list tables on a staging project first.
Access risk
A PAT can rotate keys, read secrets, and change RLS. Readonly is not optional on a prod org.
When to skip it
Skip it if you only need SQL on a connection string (Postgres) and do not need the Supabase management API.
Instead: PostgreSQL, Neon, Airtable.
Vs alternatives
| Server | Official? | Needs a secret? | Best for |
|---|---|---|---|
| Supabase | No | Yes | Talk to a Supabase project: tables, auth, edge functions. |
| PostgreSQL | Yes | Yes | Run SQL against a Postgres database. |
| Neon | No | Yes | Manage and query Neon Postgres. |
| Airtable | No | Yes | Read and write Airtable bases. |
More in Databases & data
FAQ
Where is the tool list?
supabase.com/mcp — it changes. Connect and list tools rather than memorizing names.
What can a PAT do?
Rotate keys, read secrets, change RLS, run SQL. Org-scoped + readonly is the starting point.
Self-hosted Supabase?
The docs mention self-hosting the MCP endpoint. Confirm that path if you are not on supabase.com.
Supabase or Neon?
Vendor you already pay. Do not give both write PATs to one chat.