AgentsReady
Verified deep dive · Devtools

Supabase

Run the agent liveReport a change
5 minTime to key
NoNo-human path
1Human gates
8/10Onboarding score
Email verification

Fastest path to a key

  1. human signs up at supabase.com/dashboard/sign-up (GitHub, ChatGPT, SSO or email+password)
  2. Email verification
    if email+password: verify email
  3. `supabase login`: browser flow (or `--no-browser` prints URL + verification code). Alternatively dashboard > Account > Access Tokens > create PAT (sbp_...)
  4. Management API (`POST /v1/projects`) creates a project in the default org; `GET/POST /v1/projects/{ref}/api-keys` returns publishable/secret keys
  5. MCP: `claude mcp add --transport http supabase https://mcp.supabase.com/mcp` then OAuth via DCR, picking the org
  6. Working API key

Biggest gap

No anonymous or claimable database for a lone agent (claim tokens exist only for platforms with their own org), so a human account is always needed first

Worth copying

MCP URL params (project_ref, read_only=true, features=...) plus OAuth scopes give agents least-privilege access without custom tokens

Sources (8) · checked 2026-10-11
96Readiness score / 100
L4 Agent-nativeBeats 99% of 1,846 companies
Access20/20
Context20/20
Interfaces32/32
Onboarding19/19
Trust5/9
llms.txt · root
MCP · https://mcp.supabase.com/mcp
OpenAPI · https://supabase.com/openapi.json

Biggest gains

  1. +4 Agent manifests. Publish an MCP server card (/.well-known/mcp.json) or A2A agent card.
All 20 checks
  • PASSAgents get the real page, not a bot wall10
  • PASSrobots.txt lets user-triggered agents in6
  • PASSContent is server-rendered4
  • PASSllms.txt exists8
  • PASSllms-full.txt exists3
  • PASSDocs available as markdown6
  • PASSSitemap2
  • PASSStructured metadata1
  • PASSPublic developer docs4
  • PASSMachine-readable API spec8
  • PASSRemote MCP server for the product12
  • PASSDocs MCP or searchable docs4
  • PASSSDKs and a CLI4
  • PASSOAuth discovery metadata5
  • PASSAgents can self-register OAuth clients6
  • PASSSelf-serve API keys5
  • PASSFree tier or test mode3
  • FAILAgent manifests4
  • PASSsecurity.txt2
  • PASSPublic status page3

Your fix pack: 2 changes, up to +4 points

Each change is ready to paste, filled in for supabase.com, with a command to check it worked. Or hand the whole list to your coding agent.

A server card lets agents discover your MCP server from your domain alone.

Where: https://supabase.com/.well-known/mcp.json
{
  "name": "Supabase",
  "description": "<What an agent can do with Supabase, in one sentence>",
  "url": "https://mcp.supabase.com/mcp",
  "transport": "streamable-http",
  "authentication": { "type": "oauth2", "resource_metadata": "https://mcp.supabase.com/.well-known/oauth-protected-resource" },
  "documentation": "https://docs.supabase.com",
  "tools": ["<tool_one>", "<tool_two>"]
}
Check it worked:curl -s https://supabase.com/.well-known/mcp.json

Add the badge to your README

AgentsReady badge for supabase.com
[![AgentsReady](https://agentsready.dev/badge/supabase.com)](https://agentsready.dev/c/supabase.com)