OAUTH2
supabase_oauth
Developer setup
- Client idclient_id · stringRequired
- Client secretclient_secret · stringRequired
- Redirect URIoauth_redirect_uri · stringOptional
- Scopesscopes · stringOptional
User connection
- Base URLfull · stringRequired
SUPABASE
Supabase is an open-source backend-as-a-service providing a Postgres database, authentication, storage, and real-time subscription APIs for building modern applications
Description is untrusted, display-only upstream metadata. It never becomes policy, OAuth scope authority, or an agent instruction.
Pakkawork boundary
Research catalogue metadata only. No Pakkawork OAuth, credential, host, quota, executor, or verifier is enabled.
129
Action summaries
Display-only definitions
0
Trigger types
Not installed instances
2
Auth modes
Field names, never values
No
Execution
No runtime adapter
Authentication map
OAUTH2
API_KEY
No fields declared in this snapshot.
Capability index
Showing 61–90 of 129 actions
SUPABASE_GET_LEGACY_SIGNING_KEY
Retrieves the signing key information for the JWT secret imported as signing key for this project. This endpoint is deprecated and will be removed in the future; check for HTTP 404 Not Found which indicates the endpoint is no longer available.
Untrusted display-only summary
SUPABASE_GET_MIGRATION
Retrieves a specific database migration entry from the migration history using its version identifier. Use when you need to inspect migration details, SQL statements, or rollback commands for a specific migration version.
Untrusted display-only summary
SUPABASE_GET_ORGANIZATION
Fetches comprehensive details for a specific Supabase organization using its unique slug.
Untrusted display-only summary
SUPABASE_GET_PERFORMANCE_ADVISORS
Retrieves project performance advisors for a Supabase project. Returns a list of performance lints that identify potential issues and optimization opportunities. Note: This endpoint is deprecated.
Untrusted display-only summary
SUPABASE_GET_PROJECT
Retrieves detailed information about a specific Supabase project by its unique reference ID. Use when you need to get comprehensive project details including status, database configuration, and metadata. Authentication: - Requires a valid Bearer token in the Authorization header. - Token format: 'Bearer ' where access…
Untrusted display-only summary
SUPABASE_GET_PROJECT_API_KEY
Retrieves details of a specific API key for a Supabase project by its UUID. Use when you need to inspect a single key's configuration, type, or metadata.
Untrusted display-only summary
SUPABASE_GET_PROJECT_API_KEYS
Retrieves all API keys for an existing Supabase project, specified by its unique reference ID (`ref`); this is a read-only operation.
Untrusted display-only summary
SUPABASE_GET_PROJECT_LEGACY_API_KEYS
Checks whether JWT-based legacy API keys (anon, service_role) are enabled for a Supabase project. This API endpoint is deprecated and may be removed in the future (returns HTTP 404 Not Found when unavailable).
Untrusted display-only summary
SUPABASE_GET_PROJECT_LOGS
Retrieves analytics logs for a Supabase project. Use this to fetch and analyze project logs including edge function logs, database logs, and API logs for monitoring and debugging.
Untrusted display-only summary
SUPABASE_GET_PROJECT_PGBOUNCER_CONFIG
Retrieves the active PgBouncer configuration (PostgreSQL connection pooler) for a Supabase project, used for performance tuning, auditing, or getting the connection string.
Untrusted display-only summary
SUPABASE_GET_PROJECT_POSTGRES_CONFIG
Retrieves the current read-only PostgreSQL database configuration for a specified Supabase project's `ref`, noting that some advanced or security-sensitive details might be omitted from the response.
Untrusted display-only summary
SUPABASE_GET_PROJECT_POSTGREST_CONFIG
Retrieves the PostgREST configuration for a specific Supabase project.
Untrusted display-only summary
SUPABASE_GET_PROJECT_READONLY_MODE_STATUS
Retrieves the read-only mode status for a specified Supabase project to check its operational state; this action does not change the read-only state.
Untrusted display-only summary
SUPABASE_GET_PROJECT_SIGNING_KEYS
Tool to list all signing keys for a Supabase project. Use when you need to retrieve JWT signing keys for authentication verification or rotation management.
Untrusted display-only summary
SUPABASE_GET_PROJECT_SUPAVISOR_CONFIG
Retrieves the Supavisor (connection pooler) configuration for a specified Supabase project, identified by its reference ID.
Untrusted display-only summary
SUPABASE_GET_PROJECT_UPGRADE_ELIGIBILITY
Checks a Supabase project's eligibility for an upgrade, verifying compatibility and identifying potential issues; this action does not perform the actual upgrade.
Untrusted display-only summary
SUPABASE_GET_PROJECT_UPGRADE_STATUS
Retrieves the latest status of a Supabase project's database upgrade for monitoring purposes; does not initiate or modify upgrades.
Untrusted display-only summary
SUPABASE_GET_RESUMABLE_UPLOAD_BASE_OPTIONS
Handles OPTIONS request for TUS Resumable uploads to discover server capabilities. Use when preparing resumable upload requests to verify supported TUS protocol versions and extensions.
Untrusted display-only summary
SUPABASE_GET_RESUMABLE_UPLOAD_OPTIONS
Handles OPTIONS request for TUS Resumable uploads to discover server capabilities. Use when preparing resumable upload requests to verify supported TUS protocol versions and extensions.
Untrusted display-only summary
SUPABASE_GET_SECURITY_ADVISORS
Retrieves security advisor findings and recommendations for a Supabase project. Use when you need to audit project security posture, identify SQL-based security issues, or get remediation guidance. Note: This endpoint is deprecated and may be removed in future API versions.
Untrusted display-only summary
SUPABASE_GETS_PROJECT_S_AUTH_CONFIG
Retrieves the project's complete read-only authentication configuration, detailing all settings (e.g., providers, MFA, email/SMS, JWT, security policies) but excluding sensitive secrets.
Untrusted display-only summary
SUPABASE_GETS_PROJECT_S_SERVICE_HEALTH_STATUS
Retrieves the current health status for a Supabase project, for specified services or all services if the 'services' list is omitted.
Untrusted display-only summary
SUPABASE_GET_SQL_SNIPPET
Retrieves a specific SQL snippet by its unique identifier.
Untrusted display-only summary
SUPABASE_GET_SSO_PROVIDER
Retrieves the configuration details for a specific Single Sign-On (SSO) provider (e.g., SAML, Google, GitHub, Azure AD), identified by its UUID, within a Supabase project.
Untrusted display-only summary
SUPABASE_GET_TABLE_SCHEMAS
Retrieves column details, types, and constraints for multiple database tables to help debug schema issues and write accurate SQL queries. Use the SUPABASE_LIST_TABLES action first to discover available tables, the fetch their detailed schemas.
Untrusted display-only summary
SUPABASE_HANDLE_RESUMABLE_UPLOAD_SIGN_OPTIONS
Handles CORS preflight OPTIONS request for TUS resumable upload signing. Use when preparing cross-origin resumable upload requests to verify allowed methods and headers.
Untrusted display-only summary
SUPABASE_HANDLE_RESUMABLE_UPLOAD_SIGN_OPTIONS_WITH_ID
Handles CORS preflight OPTIONS request for TUS resumable upload signing endpoints. Use when preparing cross-origin resumable upload requests to verify allowed methods and headers.
Untrusted display-only summary
SUPABASE_INVOKE_EDGE_FUNCTION
Tool to invoke a deployed Supabase Edge Function over HTTPS. Use for testing and debugging Edge Functions with configurable method, headers, body, and authentication.
Untrusted display-only summary
SUPABASE_LIST_ALL_ORGANIZATIONS
Lists all organizations (ID and name only) associated with the Supabase account, excluding project details within these organizations.
Untrusted display-only summary
SUPABASE_LIST_ALL_PROJECTS
Retrieves a list of all Supabase projects, including their ID, name, region, and status, for the authenticated user. Authentication: - Requires a valid Bearer token in the Authorization header. - Token format: 'Bearer ' where access_token is either: - A Personal Access Token (PAT) generated from https://supabase.com/d…
Untrusted display-only summary
Provenance
The detail snapshot comes from an attributed MIT-licensed repository revision. Safe local icons use exact-match CC0 Simple Icons symbols; unmatched brands use monograms.
Remote text is plain display metadata only. It must never become an agent prompt, execution policy, OAuth grant, or executable instruction.