Scenarios
RDS Supabase Model Context Protocol (MCP) is a standard for connecting AI coding tools and agents to the Supabase backend ecosystem (such as PostgreSQL database, SQL execution, Auth, RLS, storage, Realtime, monitoring and statistics). With MCP, AI tools and agents can understand, manage, and operate the entire backend project. This fundamentally transforms the traditional full-stack development process.
You can add the RDS Supabase MCP toolset to programming IDEs (such as CodeArts Agent) and AI tools (such as Claude) to interact with Huawei Cloud RDS Supabase applications in natural language. This enables automated operations and O&M of Supabase applications and their hosted databases, significantly lowering the usage threshold, greatly simplifying the operation process, and significantly improving development efficiency.
Advantages of MCP
- AI agents can directly call the Data API through MCP, and no additional interface layer needs to be developed.
- Agent operations are restricted by RLS policies to ensure secure data isolation.
- Combined with pgvector, agents can implement semantic search-driven intelligent decision-making.
Prerequisites
- A Supabase application has been created, and both the application and hosted instance are running normally.
- A DNAT gateway with an EIP and access port has been associated with Supabase. For details, see Binding and Unbinding a DNAT Gateway Address.
In public network access scenarios, an EIP must be bound to the Supabase application. Otherwise, the network is disconnected.
- The hosted DB instance has an EIP bound and can be accessed from the public network.
- An AI encoding tool or related agent has been installed and can call the AI foundation model capabilities. The model compute resources are sufficient.
For example, you have installed Huawei Cloud CodeArts Agent, and the token quota of the foundation model is sufficient.
- Bun has been installed.
- Git has been installed.
MCP Tool List
The following table lists the core tools of Supabase MCP supported by RDS.
Table 1 Database schema and metadata | Tool | Function | Precautions |
| list_tables | Lists all accessible tables (grouped by schema). | - |
| list_table_columns | Lists the columns and metadata (type, default value, and constraint) of a table. | - |
| list_constraints | Lists all constraints (PK, FK, UNIQUE, CHECK, and EXCLUDE). | You can filter the constraints by schema, table, or type. |
| list_foreign_keys | Lists all foreign key relationships. | You can filter the relationships by schema or table. |
| list_indexes | Lists all indexes and their definitions and sizes. | You can filter indexes by schema or table. |
| list_migrations | Lists the database migration records that have been applied. | - |
| list_extensions | Lists all installed PostgreSQL extensions. | - |
| list_available_extensions | Lists all extensions that can be installed (including installed extensions). | - |
Table 2 Database objects and logic | Tool | Function | Precautions |
| list_triggers | Lists all triggers. | You can filter triggers by schema or table. |
| get_trigger_definition | Obtains the complete definition of a trigger (including the function source code). | - |
| list_database_functions | Lists user-defined database functions. | SECURITY DEFINER functions can be identified. |
| get_function_definition | Obtains the complete source code definition of a database function. | To overload a function, you need to specify argument_types. |
Table 3 Security and RLS | Tool | Function | Precautions |
| list_rls_policies | Lists all RLS policies. | You can filter policies by schema or table. |
| get_rls_status | Checks whether RLS is enabled for a table and checks the number of policies if RLS is enabled. | You can filter policies by schema or table. |
| get_advisors | Obtains security and performance suggestions (based on Splinter rules). | Problems such as missing RLS can be identified. |
Table 4 Authentication and user management | Tool | Function | Precautions |
| list_auth_users | Lists users in auth.users. | - |
| get_auth_user | Obtains details of a specified user by ID. | - |
| create_auth_user | Creates a user in auth.users. | - |
| update_auth_user | Updates the user field in auth.users. | The password processing is insecure, and the service_role role is required. |
| delete_auth_user | Deletes a user from auth.users by ID. | The service role key and direct connection to the database are required. |
Table 5 Object storage | Tool | Function | Precautions |
| list_storage_buckets | Lists all buckets. | - |
| list_storage_objects | Lists objects in a bucket. | You can filter objects by prefix. |
| get_storage_config | Obtains the bucket configuration (size limit, MIME, and publicness). | - |
| update_storage_config | Updates the bucket configuration. | - |
Table 6 SQL execution and migration | Tool | Function | Precautions |
| execute_sql | Executes any SQL query. | A service role key or direct connection to the database is required. |
| apply_migration | Applies the SQL migration script and records it to the migration table. | The script is executed in a transaction to ensure atomicity. |
| explain_query | Obtains the SQL execution plan. | The ANALYZE mode actually performs write operations. |
Table 7 Vector indexes (pgvector) | Tool | Function | Precautions |
| list_vector_indexes | Lists pgvector indexes (ivfflat and hnsw). | If pgvector is not installed, an empty array is returned. |
| get_vector_index_stats | Obtains the usage statistics and size of pgvector indexes. | - |
Table 8 Real-time subscription | Tool | Function | Precautions |
| list_realtime_publications | Lists PostgreSQL publications (for Realtime). | - |
Table 9 Monitoring and diagnosis | Tool | Function | Precautions |
| get_database_connections | Obtains information about active database connections (pg_stat_activity). | - |
| get_database_stats | Obtains database activity statistics and background writer statistics. | - |
| get_index_stats | Obtains detailed usage statistics of an index. | - |
| get_logs | Obtains Supabase service logs. | By default, the logs of the last 24 hours are queried. The analysis stack is queried first. |
Table 10 Project configuration and tools | Tool | Function | Precautions |
| get_project_url | Obtains the URL of the current Supabase project. | - |
| verify_jwt_secret | Checks whether the JWT key has been configured. | - |
| generate_typescript_types | Generates TypeScript types from the database schema. | You can use CLI to run supabase gen types. |
| rebuild_hooks | Restarts the pg_net worker. | The pg_net extension needs to be installed. |
Interconnecting with and Using Supabase MCP
Interconnecting with and Using Supabase MCP Through Claude
The following describes how to use Claude to interconnect with and use Supabase MCP in a public network environment.
- Obtain the API keys, including an anon key and a service role key, by referring to Viewing API Keys.
Figure 1 Supabase application API key list
- Enable public access to the Supabase application and bind an EIP to it for connecting to the external network.
- On the details page of the Supabase application, click the name of the hosted instance to go to the instance details page.
- In the navigation pane, choose Connectivity & Security. Bind an EIP to the hosted database instance by referring to Binding and Unbinding an EIP.
Figure 3 Configuring parameters for the hosted DB instance connection
As shown in the figure, obtain the public IP address and database port of the instance.
- Before installing Bun locally, ensure that your network is normal and you can access Internet resources.
Bun is a fast, modern, and integrated toolkit for JavaScript, TypeScript, and JSX, used to deploy the Supabase MCP Server.
- Download the source code of the Supabase MCP Server open-source project to a local directory and use Bun to install related dependencies.
Before running the command, ensure that Git has been installed. For details about the installation, visit the
Git official website.
git clone https://github.com/HenkDz/selfhosted-supabase-mcp.git
cd selfhosted-supabase-mcp
bun install
- Open the Claude configuration file .claude.json and add the configuration of the Supabase MCP Server to mcpServers. The following is a template:
{
"mcpServers": {
"selfhosted-supabase": {
"command": "bun",
"args": [
"run",
"<path-to-mcp-code-dist>/selfhosted-supabase-mcp/src/index.js",
"--url",
"<your-supabase-url>",
"--anon-key",
"<your-anon-key>",
"--service-key",
"<your-service-role-key>",
"--db-url",
"<your-db-url>"
}
}
} Configure the parameters based on Table 11. Replace the entire content of <xxx> (including the < and > symbols) with the actual application and hosted instance configuration.
Table 11 Parameters for interconnecting with Supabase MCP | Parameter | Mandatory | Value Description | Example Value | Precautions |
| <path-to-mcp-code-dist> | Yes | Enter the root directory of the downloaded Supabase source code. | D:/workspace/rds-supabase/mcp/ | Ensure that the selfhosted-supabase-mcp git project has been downloaded to the directory and the folder exists. |
| <your-supabase-url> | Yes | Enter the public network address for accessing the Supabase application. Formats: - SSL enabled: http(s)://EIP of the Supabase application:Access port of the Supabase application
- SSL disabled: http://EIP of the Supabase application:Access port of the Supabase application
| http://10.0.0.0:8443 | Ensure that the IP address can be accessed locally. |
| <your-anon-key> | Yes | Enter the anon key of the Supabase application. | ********** | If the anon key has been reset, enter the value of the latest API key that takes effect. |
| <your-service-role-key> | No | Enter the service role key of the Supabase application. | ********** | If the service role key has been reset, enter the value of the latest API key that takes effect. |
| <your-db-url> | No | Enter the direct connection address of the PostgreSQL database instance hosted by the Supabase application. Formats: postgresql://root:<login-password>@<instance-EIP>:<instance-access-port>/<database-name> - <login-password>: Enter the password of the root account of the hosted database instance.
- <instance-EIP>: Enter the EIP of the hosted database instance.
- <instance-access-port>: Enter the access port of the hosted database instance. The default port is 5432.
- <database-name>: Enter the name of the database on the instance. Currently, the name can only be supabase_db.
| postgresql://root:xxx@10.0.0.0:5432/supabase_db | If the login password of the database instance contains special characters, use URLEncode to encode the characters. For example, the at sign (@) is encoded as %40. Otherwise, the function is unavailable. |
- In the CLI window, run the following command to check whether the Supabase MCP is connected properly:
claude mcp get supabase
Figure 4 Checking the connection status of RDS Supabase MCP
- After the RDS Supabase MCP tool is configured, you can access, operate, and manage Supabase applications and their hosted database services in natural language in the Claude dialog box.
- Query basic information about a Supabase project (the direct connection information of the database instance is not configured during MCP interconnection).
Enter the following information:
Query basic information about the Supabase project.
- Query the current database table information of a PostgreSQL instance (the direct connection information of the database instance has been configured during MCP interconnection).
Enter the following information:
Query the overview of the current service database tables in Supabase.
Interconnecting with and Using Supabase MCP Through CodeArts Agent
The following describes how to use CodeArts Agent to interconnect with and use Supabase MCP in a public network environment.
- Obtain the API keys, including an anon key and a service role key, by referring to Viewing API Keys.
Figure 5 Supabase application API key list
- Associate a DNAT gateway and obtain its EIP and access port by referring to Binding and Unbinding a DNAT Gateway Address.
Figure 6 Supabase application details page
- On the details page of the Supabase application, click the name of the hosted instance to go to the instance details page.
- In the navigation pane, choose Connectivity & Security. Bind an EIP to the hosted database instance by referring to Binding and Unbinding an EIP.
Figure 7 Configuring parameters for the hosted DB instance connection
As shown in the figure, obtain the public IP address and port number of the instance.
- Before installing Bun locally, ensure that your network is normal and you can access Internet resources.
Bun is a fast, modern, and integrated toolkit for JavaScript, TypeScript, and JSX, used to deploy the Supabase MCP Server.
- Download the source code of the Supabase MCP Server open-source project to a local directory and use Bun to install related dependencies.
Before running the command, ensure that Git has been installed. For details about the installation, visit the
Git official website.
git clone https://github.com/HenkDz/selfhosted-supabase-mcp.git
cd selfhosted-supabase-mcp
bun install
- Open the local CodeArts Agent IDE and go to the page for editing the MCP configuration file mcp_settings.json.
Add the configuration of the Supabase MCP Server in
mcpServers. The template is as follows:
{
"mcpServers": {
"selfhosted-supabase": {
"command": "bun",
"args": [
"run",
"<path-to-mcp-code-dist>/selfhosted-supabase-mcp/src/index.js",
"--url",
"<your-supabase-url>",
"--anon-key",
"<your-anon-key>",
"--service-key",
"<your-service-role-key>",
"--db-url",
"<your-db-url>"
}
}
} Configure the parameters based on Table 12. Replace the entire content of <xxx> (including the < and > symbols) with the actual application and hosted instance configuration.
Table 12 Parameters for interconnecting with Supabase MCP | Parameter | Mandatory | Value Description | Example Value | Precautions |
| <path-to-mcp-code-dist> | Yes | Enter the root directory of the downloaded Supabase source code. | D:/workspace/rds-supabase/mcp/ | Ensure that the selfhosted-supabase-mcp git project has been downloaded to the directory and the folder exists. |
| <your-supabase-url> | Yes | Enter the public network address for accessing the Supabase application. Formats: - SSL enabled: http(s)://EIP of the Supabase application:Access port of the Supabase application
- SSL disabled: http://EIP of the Supabase application:Access port of the Supabase application
| http://10.0.0.0:8443 | Ensure that the IP address can be accessed locally. |
| <your-anon-key> | Yes | Enter the anon key of the Supabase application. | ********** | If the anon key has been reset, enter the value of the latest API key that takes effect. |
| <your-service-role-key> | No | Enter the service role key of the Supabase application. | ********** | If the service role key has been reset, enter the value of the latest API key that takes effect. |
| <your-db-url> | No | Enter the direct connection address of the PostgreSQL database instance hosted by the Supabase application. Formats: postgresql://root:<login-password>@<instance-EIP>:<instance-access-port>/<database-name> - <login-password>: Enter the password of the root account of the hosted database instance.
- <instance-EIP>: Enter the EIP of the hosted database instance.
- <instance-access-port>: Enter the access port of the hosted database instance. The default port is 5432.
- <database-name>: Enter the name of the database on the instance. Currently, the name can only be supabase_db.
| postgresql://root:xxx@10.83.34.105:5432/supabase_db | If the login password of the database instance contains special characters, use URLEncode to encode the characters. For example, the at sign (@) is encoded as %40. Otherwise, the function is unavailable. |
- After the configuration is complete, return to the MCP tool page. Check the Supabase MCP connection status and toolset information.
- In the CodeArts Agent dialog box, you can use natural language to access, operate, and manage the Supabase applications and hosted database services.
- Query basic information about a Supabase project (the direct connection information of the database instance has been configured during MCP interconnection).
Enter the following information:
Query basic information about the Supabase project.
- Query the current database table information of a PostgreSQL instance (the direct connection information of the database instance has been configured during MCP interconnection).
Enter the following information:
Query the overview of the current service database tables in Supabase.