Supabase MCP
a model first-party implementation, and the best security cautionary tale
everything a vendor server should be — remote, oauth 2.1, scoped, registered — and the exact server behind the industry's canonical data-exfiltration writeup.
config is a single url: `https://mcp.supabase.com/mcp`, with oauth 2.1 handling login and org selection. it manages tables, fetches project config, queries data, reads docs and handles branches. the url accepts parameters — `project_ref`, `read_only=true`, `features=database,docs` — which is a genuinely good scoping primitive.
there are local cli and self-hosted paths too, both with a reduced tool subset and no oauth 2.1.
the description above is ours, condensed from the ranking. pricing moves — check it on the vendor's own page before you rely on it.
- category
- mcp servers
- pricing
- free — Apache-2.0
- website
- github.com
everything a vendor server should be — remote, oauth 2.1, scoped, registered — and the exact server behind the industry's canonical data-exfiltration writeup.
we researched this category against vendors' own pricing pages and licence files. that is where this line comes from — not from the vendor, and not from anything they paid for.