Supabase Connector
Connector implementation
Build the Supabase integration
Open-source Firebase alternative with Postgres database, Auth, REST API, Realtime subscriptions, Storage, and Edge Funct
Implementation Overview
Implement a Supabase connector that authenticates to the vendor surface, normalizes source records in Tajo, and activates eligible data in Brevo.
Treat this as an implementation guide. Build and validate the auth, mapping, sync, and operations paths before production use.
mcp.supabase.com/mcp
| Property | Value |
|---|---|
| Integration surface | API + MCP |
| Implementation status | Implementation required |
| Category | Data Warehouses |
| Setup complexity | medium |
| Vendor documentation | supabase.com/docs/reference/api/introduction |
| Allowed host | Not recorded |
| Base URL | Not recorded |
| OpenAPI schema | api.supabase.com/api/v1 |
| MCP server | mcp.supabase.com/mcp |
| Last researched | 2026-08-07 |
Management API OpenAPI spec + official MCP server. The MCP endpoint was verified by handshake on 2026-08-07: 401 with RFC 9728 metadata naming api.supabase.com. It accepts a project_ref query parameter to scope a session to one project.
Authentication
-
OAuth 2.0 (MCP mode).
- Authorize: api.supabase.com/v1/oauth/authorize
- Token: api.supabase.com/v1/oauth/token
- Scopes:
organizations:read,projects:read,projects:write,database:read,database:write,analytics:read,secrets:read,edge_functions:read
-
Use api.supabase.com/api/v1 to generate or validate typed API clients and request models.
-
Validate the MCP server endpoint at mcp.supabase.com/mcp and document required headers, auth grants, and tool availability.
-
Keep supabase.com/docs/reference/api/introduction linked from the connector runbook so operators can confirm vendor behavior during incidents.
-
Store credentials per Tajo workspace and keep tenant-specific secrets out of connector configuration files.
-
Add a credential smoke test that verifies read access to a harmless resource before running backfills or enabling webhooks.
Data To Sync
Start with these inferred data domains, then confirm exact vendor resources and permissions from the source documentation:
- Commerce, payment, or subscription objects
- Custom objects and operational metadata
The connector should make source records idempotent by keeping a stable key such as a vendor object ID, email address, event ID, ticket ID, order ID, or campaign ID. If the vendor only exposes list APIs, Tajo should store the cursor strategy and replay policy explicitly.
Sync Shape
No typed contract exists for Supabase, so the direction of each resource and its conflict handling are not recorded. Direction is declared per resource on a connector contract; see the connector catalog for how contracts are promoted.
Mapping To Tajo/Brevo
No Brevo projection is recorded for Supabase. A projection is declared on a typed connector contract, and Supabase does not have one yet, so this page will not state a mapping it cannot source.
The conventions that apply to every connector — stable external IDs, normalization, backfill and sync strategy, error handling, and the builder checklist — are documented once under “Applies to every connector” on the connector catalog.