OAUTH 2.1
DATABASE OPS
Your Postgres database, branches, and edge functions all live behind the Supabase Management API. Supabase MCP gives your agent authenticated access scoped to the user who authorized it.
import { ScalekitClient } from "@scalekit-sdk/node";
import { createReactAgent } from "@langchain/langgraph/prebuilt";
const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
// Supabase MCP tools, scoped to the signed-in user
const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["supabasemcp"], toolNames: [
"supabasemcp_apply_migration",
"supabasemcp_confirm_cost",
"supabasemcp_create_branch"
] },
pageSize: 100,
});
const agent = createReactAgent({ llm, tools });
await agent.invoke({ messages: [{ role: "user", content: "Which migrations are pending on the staging branch?" }] });import OpenAI from "openai";
import { ScalekitClient } from "@scalekit-sdk/node";
const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
// Supabase MCP tools, scoped to the signed-in user
const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["supabasemcp"], toolNames: [
"supabasemcp_apply_migration",
"supabasemcp_confirm_cost",
"supabasemcp_create_branch"
] },
pageSize: 100,
});
const openai = new OpenAI();
const res = await openai.responses.create({
model: "gpt-5",
tools: tools.map((t) => t.openai),
input: "Which migrations are pending on the staging branch?",
});import Anthropic from "@anthropic-ai/sdk";
import { ScalekitClient } from "@scalekit-sdk/node";
const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
// Supabase MCP tools, scoped to the signed-in user
const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["supabasemcp"], toolNames: [
"supabasemcp_apply_migration",
"supabasemcp_confirm_cost",
"supabasemcp_create_branch"
] },
pageSize: 100,
});
const anthropic = new Anthropic();
const msg = await anthropic.messages.create({
model: "claude-opus-4-6",
max_tokens: 1024,
tools: tools.map((t) => t.anthropic),
messages: [{ role: "user", content: "Which migrations are pending on the staging branch?" }],
});import { Agent } from "@google/adk/agents";
import { ScalekitClient } from "@scalekit-sdk/node";
const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
// Supabase MCP tools, scoped to the signed-in user
const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["supabasemcp"], toolNames: [
"supabasemcp_apply_migration",
"supabasemcp_confirm_cost",
"supabasemcp_create_branch"
] },
pageSize: 100,
});
const agent = new Agent({
name: "supabasemcp_agent",
model: "gemini-2.5-pro",
instruction: "Act as the DevOps agent for the signed-in user.",
tools,
});
await agent.run("Which migrations are pending on the staging branch?");// shared token
audit → bot_service_account
user_filter → broken
// scalekit
audit → user_abc
scope → enforced ✓