@supabase/mcp-server-supabase

MCPcommunitylive
v0.13.0com.supabaseApache-2.0Updated 18d agonpmGitHub

MCP server for interacting with Supabase

Endpoint healthlive
checked 3 days ago · 389ms · auth required
100% of the last 12 checks reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (stdio, streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
76kDownloads/wk
3kGitHub stars
404Forks
18d agoLast update
Needs 1 credential before it runs
  • SUPABASE_ACCESS_TOKENAPI keyrequired

    Personal access token for Supabase API

Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Package
Authorcom.supabase
LicenseApache-2.0
Version0.13.0
Sourcenpm+mcp-registry
Trust Status
F
10/100Untrusted
✓Listed in Forge index+10/10
—Publisher identity verified+0/20
→ Publisher: run `forge publish` from the package repo to claim ownership
—Ed25519 publish signature+0/5
→ Included automatically when the publisher runs `forge publish`
—Domain verification+0/5
→ Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
—npm Trusted Publishing (Sigstore)+0/5
→ Publish from GitHub Actions with --provenance so the attestation binds this package to this repo
—npm maintainer match+0/5
→ Earned once your identity is verified above and that login is an npm maintainer of this package
—CVE scan · not run+0/30
→ Not yet scanned — package must be on npm
—Static analysis · clean+0/20
→ Not yet scanned — package must be on npm
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface—
Security scanN/Avlive · 1mo agoHow well does this scan work?
EvalsNone
IndexedJul 16, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

Behind the vendor's auth1mo ago

The endpoint answers, but requires the vendor's own credentials before it will list its tools. Forge holds no credentials for third-party servers, so the surface is not observable from here. This is a normal state for a commercial hosted server, not a finding against it.

  • https://mcp.supabase.com/mcpauth required
About

MCP server for interacting with Supabase

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This package was last scanned before Forge began storing the resolved tree. The next scan will record it.