58
grade D
10 days ago
npm

supabase-mcp

MCP server for Supabase CRUD operations

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 3 credentials: MCP_API_KEY, SUPABASE_ANON_KEY, SUPABASE_SERVICE_ROLE_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretMCP_API_KEYyour_secret_api_key
configMCP_SERVER_HOST
configMCP_SERVER_PORTThe HTTP server attempts to find an available port automatically. You can manually specify a different port in your .env file by changing the value.
🔐 secretSUPABASE_ANON_KEYyour_supabase_anon_key
🔐 secretSUPABASE_SERVICE_ROLE_KEYyour_supabase_service_role_key
configSUPABASE_URLyour_supabase_project_url
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/npm-https-github-com-cappahccino-sb-mcp)](https://m8ven.ai/mcp/npm-https-github-com-cappahccino-sb-mcp)
commit: eff6c4beb6a7272731bc89c3825cabe8339023da
code hash: f4ed13525588a82f898594418848d088119f96cb4bd2f84a5a002d9af6ee8b99
verified: 4/11/2026, 1:41:28 PM
view raw JSON →