selfhosted-supabase-mcp

MCP.Pizza Chef: HenkDz

Aimed at people running their own Supabase installation rather than the hosted version. Forty-three tools list tables, columns, indexes and access rules, read logs and database statistics, inspect file storage, and create, update or delete login accounts. You supply your Supabase address and its public key; anything that writes also needs the private service key or a direct database connection string. The read-only switch on the query tool is passed along but never actually enforced, so a query marked read-only can still change data.

Coding
Data

Use This MCP server To

See which tables and columns my database actually has Check which access rules are switched on for a table Look up a signed-up user by their email address Read recent database logs when something stops working Find slow or unused indexes that waste space List the files sitting in my storage buckets

README

Self-Hosted Supabase MCP Server

License: MIT smithery badge

Overview

This project provides a Model Context Protocol (MCP) server designed specifically for interacting with self-hosted Supabase instances. It bridges the gap between MCP clients (like IDE extensions) and your local or privately hosted Supabase projects, enabling database introspection, management, and interaction directly from your development environment.

This server was built from scratch, drawing lessons from adapting the official Supabase cloud MCP server, to provide a minimal, focused implementation tailored for the self-hosted use case.

Purpose

The primary goal of this server is to enable developers using self-hosted Supabase installations to leverage MCP-based tools for tasks such as:

  • Querying database schemas and data.
  • Managing database migrations.
  • Inspecting database statistics and connections.
  • Managing authentication users.
  • Interacting with Supabase Storage.
  • Generating type definitions.

It avoids the complexities of the official cloud server related to multi-project management and cloud-specific APIs, offering a streamlined experience for single-project, self-hosted environments.

Features (Implemented Tools)

Tools are categorized by privilege level:

  • Regular tools are accessible by any authenticated Supabase JWT (authenticated or service_role role).
  • Privileged tools require a service_role JWT (HTTP mode) or direct database/service-key access (stdio mode).

Schema & Migrations

selfhosted-supabase-mcp FAQ

Does this work with Supabase's hosted cloud service?
No. It is built for installations you run yourself, and deliberately leaves out the cloud-only account management pieces.
What sign-in details does it need?
Your Supabase address and its public key at minimum. Anything that writes or reads private tables also needs the private service key, or a direct database connection string.
Is there a safe read-only mode?
Not really. The query tool takes a read_only setting, but the database helper it calls ignores it and runs the query anyway, so a query you marked read-only can still delete or overwrite data.
Can I use this to clean up leftover test accounts?
Yes, and it deletes them the moment you ask. There is no confirmation prompt and no undo, so be specific about which account you mean.
Which apps does it work in?
Claude Desktop, Cursor, VS Code, Cline and Windsurf all work, using the same short configuration snippet.
The tool list marks some things as privileged. Is that enforced?
Only when you run it in the browser-facing mode with a signing secret. In the normal desktop setup every one of the 43 tools is callable, including the ones that change data.
How hard is setup?
It is a paste-a-snippet job, but you need the Bun runtime installed first, and you point it at your own Supabase address and keys.