clr-supabase-mcp
MCP server for self-hosted Supabase instances with multi-instance support.
Features
- Schema introspection, SQL execution, migrations
- Auth user management (GoTrue)
- Storage bucket/object management
- Edge function management
- Multi-instance support via credentials.json
- Module-based tool loading (
--modulesflag) - Read-only mode
Installation
pip install clr-supabase-mcp
Configuration
Step 1: Create the credentials directory
mkdir -p ~/.config/supabase
Step 2: Find your Supabase credentials
You need three values from your self-hosted Supabase deployment:
1. Supabase URL — The public Kong gateway URL for your instance. This is the URL you use to access the Supabase API (e.g. https://supabase.example.com). If you're running Supabase locally via Docker, this is typically http://localhost:8000.
2. Service Role Key — The service_role JWT key that grants admin access. Find it in your Supabase .env file:
# In your Supabase deployment directory:
grep SERVICE_ROLE_KEY .env
# or look for the value of SUPABASE_SERVICE_ROLE_KEY
This key looks like eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9... (a long JWT token).
3. Database URL — Direct PostgreSQL connection string. Build it from values in your Supabase .env file:
postgresql://postgres:YOUR_POSTGRES_PASSWORD@YOUR_DB_HOST:5432/postgres
Find the password:
grep POSTGRES_PASSWORD .env
The DB host depends on your setup:
- Docker on same machine:
localhost(or the mapped port, checkdocker compose ps) - Remote server: The hostname/IP of your database server
- Docker network name:
db(if connecting from within the same Docker network)
Step 3: Create credentials.json
Single instance:
cat > ~/.config/supabase/credentials.json << 'EOF'
{
"url": "https://supabase.example.com",
"service_key": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
"db_url": "postgresql://postgres:your-db-password@db-host:5432/postgres"
}
EOF
chmod 600 ~/.config/supabase/credentials.json
Multiple instances:
cat > ~/.config/supabase/credentials.json << 'EOF'
{
"instances": {
"prod": {
"url": "https://supabase-prod.example.com",
"service_key": "eyJ...-prod-key",
"db_url": "postgresql://postgres:prodpass@prod-db:5432/postgres"
},
"dev": {
"url": "https://supabase-dev.example.com",
"service_key": "eyJ...-dev-key",
"db_url": "postgresql://postgres:devpass@dev-db:5432/postgres"
}
},
"default": "prod"
}
EOF
chmod 600 ~/.config/supabase/credentials.json
Credential fields
| Field | Required | Description |
|---|---|---|
url |
Yes | Supabase Kong gateway URL |
service_key |
Yes | Service role JWT (admin access for auth/storage/edge tools) |
db_url |
For SQL/schema tools | Direct PostgreSQL connection URL |
anon_key |
No | Anon key (not needed when service_key is set) |
Note: db_url is only required for schema introspection and SQL tools (core and sql modules). Auth, storage, and edge modules only need url and service_key.
Environment variable fallback
If no credentials file exists, the server falls back to environment variables:
export SUPABASE_URL="https://supabase.example.com"
export SUPABASE_SERVICE_KEY="eyJ..."
export SUPABASE_DB_URL="postgresql://postgres:pass@db-host:5432/postgres"
Usage
All modules (default)
clr-supabase-mcp
Specific modules
# Schema introspection only
clr-supabase-mcp --modules core
# SQL + auth
clr-supabase-mcp --modules sql,auth
Available modules: core, sql, auth, storage, edge
Read-only mode
Disable write operations (SQL execution, migrations, user creation, etc.):
export SUPABASE_READ_ONLY=true
clr-supabase-mcp
Modules
| Module | Tools | API | Requires |
|---|---|---|---|
| core | 19 | Direct Postgres | db_url |
| sql | 13 | Direct Postgres | db_url |
| auth | 5 | GoTrue REST /auth/v1/ |
url + service_key |
| storage | 4 | Storage REST /storage/v1/ |
url + service_key |
| edge | 5 | Functions REST /functions/v1/ |
url + service_key |
Metadata
Release files for clr-supabase-mcp 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| clr_supabase_mcp-1.0.0.tar.gz | 15.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| clr_supabase_mcp-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 34.1 kB
Release files / clr_supabase_mcp-1.0.0.tar.gz
| Download URL | clr_supabase_mcp-1.0.0.tar.gz |
|---|---|
| Size | 15.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
05b465a8a3e565211cc61e050f4a3a18625c1a330653dea2c6961856e63037b2
|
|
BLAKE2b-256 checksum How to use checksums |
fca05b1bdac8c19ddeeb4ff78fa2989e3d4d8826a52e34e6272e659aa0e75f80
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 10, 2026.
Transparency logRelease files / clr_supabase_mcp-1.0.0-py3-none-any.whl
| Download URL | clr_supabase_mcp-1.0.0-py3-none-any.whl |
|---|---|
| Size | 19.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
aed90e8d4a9a746df159989b6a326c78024fef5ef2e3d334db96a8cb5b1d59d6
|
|
BLAKE2b-256 checksum How to use checksums |
b56c56fbe3714e09b7a9c1ff202b84dca31d5bc821e41a254f662f33864524eb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 10, 2026.
Transparency log