Skip to content
Scalekit Docs
Talk to an Engineer Dashboard

Connect AI agents to Supabase

Scalekit connector
Open markdown

The Supabase connector lets your AI agent act in each user's Supabase account. Each user signs in to Supabase once, and Scalekit stores and refreshes their tokens, so your agent never handles credentials. It comes with 163 tools.

Tools
163
What they doRead · write · destructive
77 · 52 · 3477 read52 write34 destructive
Users sign in with
OAuth app
Your own Supabase app

Setup

  1. Install the SDK

    Terminal window
    npm install @scalekit-sdk/node dotenv
  2. Set your credentials

    Add your Scalekit credentials to your .env file. Find values in app.scalekit.com > Developers > API Credentials.

    .env
    SCALEKIT_ENVIRONMENT_URL=<your-environment-url>
    SCALEKIT_CLIENT_ID=<your-client-id>
    SCALEKIT_CLIENT_SECRET=<your-client-secret>
  3. Create the Supabase connection

    In AgentKit > Connections, create a Supabase connection and copy its redirect URI. The name you give it is the connection_name your code passes. See Configure connections.

  4. Register an OAuth app

    Supabase connections use your own OAuth app. Register one with Supabase and add the redirect URI you copied.

    Then enter the app's Client ID and Client Secret on the Supabase connection.

    Console steps with screenshots

    Register your Scalekit environment with Supabase so Scalekit handles the OAuth flow and token lifecycle for your users. Create a Supabase OAuth app, then add its Client ID and Client Secret to your Scalekit connection.

    1. Copy the redirect URI from Scalekit

      • In the Scalekit dashboard, go to AgentKit > Connections > Create Connection. Find Supabase and click Create.

      • Click Use your own credentials and copy the redirect URI. It looks like https://<SCALEKIT_ENVIRONMENT_URL>/sso/v1/oauth/<CONNECTION_ID>/callback.

    2. Create an OAuth app in Supabase

      • Sign in to the Supabase dashboard and go to your organization’s Settings > OAuth Apps.

      • Under Published apps, click Publish OAuth app.

      • Give the app a Name (for example, Agent Connect).

        Supabase OAuth Apps page showing Published apps and Authorized apps tables

    3. Add the redirect URI

      • Open the app you created and add the redirect URI you copied from Scalekit under Authorization callback URLs.

      • Click Add URL, then save your changes.

    4. Copy your Client ID and Client Secret

      • Copy the Client ID shown in the Published apps table, or from the app’s detail panel next to the app name.

      • Under Client secrets, click Generate new secret and copy it immediately — Supabase only shows the full secret once.

        Supabase Update OAuth application panel showing the application ID, callback URLs, and client secrets

    5. Add credentials in Scalekit

      • Return to the connection you created in Scalekit and enter:
        • Client ID — from your Supabase OAuth app
        • Client Secret — from your Supabase OAuth app
      • Click Save.
  5. Authorize a user and make your first call

    quickstart.mts
    import { ScalekitClient } from '@scalekit-sdk/node'
    import 'dotenv/config'
    import { createInterface } from 'node:readline/promises'
    const scalekit = new ScalekitClient(
    process.env.SCALEKIT_ENVIRONMENT_URL,
    process.env.SCALEKIT_CLIENT_ID,
    process.env.SCALEKIT_CLIENT_SECRET,
    )
    const actions = scalekit.actions
    const connector = 'supabase'
    const identifier = 'user_123'
    // Generate an authorization link for the user
    const { link } = await actions.getAuthorizationLink({ connectionName: connector, identifier })
    console.log('Authorize Supabase:', link)
    const rl = createInterface({ input: process.stdin, output: process.stdout })
    await rl.question('Press Enter after authorizing...')
    rl.close()
    // Make your first call
    const result = await actions.executeTool({
    connector,
    identifier,
    toolName: 'supabase_get_profile',
    toolInput: {},
    })
    console.log(result)
    Terminal window
    npx tsx quickstart.mts

    Each user signs in once. See Authorize a user for the full flow and statuses.

Tools

Pass the exact name to execute_tool
Try in PlaygroundRequest a tool
  • supabase_diff_branch[Beta] Diff a Supabase database branch against production, returning a plain-text schema diff (SQL statements) that can be reviewed or applied as a migration.Read-only

    Diff Branch

    [Beta] Diff a Supabase database branch against production, returning a plain-text schema diff (SQL statements) that can be reviewed or applied as a migration. Use this to preview schema changes made on a development branch before merging. By default uses the Migra diffing engine; set pgdelta to true to use pg-delta instead. Optionally restrict the diff to specific schemas.

    Inputs

    branch_id_or_refstringrequired
    The 20-character branch reference (lowercase letters, same format as a project ref) or, for legacy branches, the branch UUID. Found in the Supabase dashboard for the branch you want to diff.
    included_schemasstring
    Comma-separated list of Postgres schema names to include in the diff (e.g. "public,auth"). If omitted, the API's default schema selection is used.
    pgdeltaboolean
    When true, use pg-delta instead of Migra to compute the schema diff. Defaults to false (Migra).default false
  • supabase_generate_typescript_typesGenerate TypeScript type definitions for a Supabase project's database schema, for use with supabase-js.Read-only

    Generate TypeScript Types

    Generate TypeScript type definitions for a Supabase project's database schema, for use with supabase-js. Requires the project ref; optionally scope generation to specific comma-separated schemas (defaults to public). The response is a JSON object with a single 'types' field containing the generated TypeScript source as a string — it is not a general-purpose JSON object with typed fields.

    Inputs

    refstringrequired
    Project reference ID (the 20-character lowercase project ref shown in the Supabase dashboard URL).
    included_schemasstring
    Comma-separated list of database schemas to include when generating types. Example: public,auth. Defaults to public.default public
  • supabase_get_action_runGet the current status of a Supabase Environments action run (the automated clone/pull/health/configure/migrate/seed/deploy pipeline used to spin up a preview branch).Read-only

    Get Action Run

    Get the current status of a Supabase Environments action run (the automated clone/pull/health/configure/migrate/seed/deploy pipeline used to spin up a preview branch). Returns the run's id, branch_id, per-step run_steps array (name, status, timestamps), workdir, check_run_id, and created_at/updated_at.

    Inputs

    refstringrequired
    The 20-character project reference ID (lowercase letters only). Found in the project's Supabase dashboard URL or Settings > General.
    run_idstringrequired
    The unique ID of the action run to look up, as returned by list_action_runs or when a branch action was triggered.
  • supabase_get_action_run_logsGet the plain-text logs produced by a Supabase Environments action run (the clone/pull/health/configure/migrate/seed/deploy pipeline used to spin up a preview branch).Read-only

    Get Action Run Logs

    Get the plain-text logs produced by a Supabase Environments action run (the clone/pull/health/configure/migrate/seed/deploy pipeline used to spin up a preview branch). Useful for diagnosing why a branch action step failed. Returns the raw log output as text, not JSON.

    Inputs

    refstringrequired
    The 20-character project reference ID (lowercase letters only). Found in the project's Supabase dashboard URL or Settings > General.
    run_idstringrequired
    The unique ID of the action run whose logs you want to retrieve, as returned by list_action_runs or get_action_run.
  • supabase_get_auth_service_configGet a project's Auth (GoTrue) service configuration.Read-only

    Get Auth Service Config

    Get a project's Auth (GoTrue) service configuration. Returns a large object describing signup restrictions, external OAuth provider settings (Apple, Azure, Bitbucket, Google, etc.), SMTP/email settings, rate limits, session settings, and more. Requires only the project ref.

    Inputs

    refstringrequired
    The Supabase project reference ID, a 20-character lowercase string that identifies the project. Found in the project URL or Project Settings.
  • supabase_get_available_regions[Beta] Get the list of regions available for creating a new Supabase project under an organization, along with recommended regions.Read-only

    Get Available Regions

    [Beta] Get the list of regions available for creating a new Supabase project under an organization, along with recommended regions. Optionally narrow recommendations by continent and desired compute instance size. Returns a recommendations object (a smartGroup and specific regions) and an all object listing every available region grouped the same way.

    Inputs

    organization_slugstringrequired
    The organization's slug identifier, as shown in the Supabase dashboard URL (e.g. app.supabase.com/org/<slug>).
    continentstring
    Continent code used to bias region recommendations. One of NA (North America), SA (South America), EU (Europe), AF (Africa), AS (Asia), OC (Oceania), AN (Antarctica).one of NASAEUAFASOCAN
    desired_instance_sizestring
    Desired compute instance size, used to filter regions that support it. Omit to default to the smallest possible size. One of nano, micro, small, medium, large, xlarge, 2xlarge, 4xlarge, 8xlarge, 12xlarge, 16xlarge, 24xlarge, 24xlarge_optimized_memory, 24xlarge_optimized_cpu, 24xlarge_high_memory, 48xlarge, 48xlarge_optimized_memory, 48xlarge_optimized_cpu, 48xlarge_high_memory.one of nanomicrosmallmediumlargexlarge2xlarge4xlarge8xlarge12xlarge16xlarge24xlarge24xlarge_optimized_memory24xlarge_optimized_cpu24xlarge_high_memory48xlarge48xlarge_optimized_memory48xlarge_optimized_cpu48xlarge_high_memory
  • supabase_get_backup_scheduleGet the daily backup schedule configured for a Supabase project.Read-only

    Get Backup Schedule

    Get the daily backup schedule configured for a Supabase project. Requires only the project ref. Returns schedule_for (the UTC time of day backups run, in HH:MM:SS format) and updated_at (when the schedule was last changed). Only available on the Enterprise organization plan.

    Inputs

    refstringrequired
    Project reference ID (the 20-character lowercase project ref shown in the Supabase dashboard URL).
  • supabase_get_branchFetch a specific database branch of a Supabase project by its name.Read-only

    Get Branch

    Fetch a specific database branch of a Supabase project by its name. Returns the branch's id, project_ref, git_branch, persistent flag, status, timestamps, and related metadata.

    Inputs

    namestringrequired
    Name of the branch to retrieve, e.g. 'preview-login-page'.
    refstringrequired
    Project reference ID (20-character lowercase string) that owns the branch.