Skip to main content
Glama
abushadab

Self-Hosted Supabase MCP Server

by abushadab

list_storage_objects

Retrieve and filter objects from a specific storage bucket in a self-hosted Supabase instance. Specify bucket ID, limit, offset, and prefix for customized results.

Instructions

Lists objects within a specific storage bucket, optionally filtering by prefix.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
bucket_idYesThe ID of the bucket to list objects from.
limitNoMax number of objects to return
offsetNoNumber of objects to skip
prefixNoFilter objects by a path prefix (e.g., 'public/')

Implementation Reference

  • The execute handler function that performs the core logic: builds and executes a parameterized SQL query on storage.objects table, applies filters, and returns validated list of objects.
    execute: async (
        input: ListStorageObjectsInput,
        context: ToolContext
    ): Promise<ListStorageObjectsOutput> => {
        const client = context.selfhostedClient;
        const { bucket_id, limit, offset, prefix } = input;
    
        console.error(`Listing objects for bucket ${bucket_id} (Prefix: ${prefix || 'N/A'})...`);
    
        if (!client.isPgAvailable()) {
            context.log('Direct database connection (DATABASE_URL) is required to list storage objects.', 'error');
            throw new Error('Direct database connection (DATABASE_URL) is required to list storage objects.');
        }
    
        // Use a transaction to get access to the pg client for parameterized queries
        const objects = await client.executeTransactionWithPg(async (pgClient: PoolClient) => {
            // Build query with parameters
            let sql = `
                SELECT
                    id,
                    name,
                    bucket_id,
                    owner,
                    version,
                    metadata ->> 'mimetype' AS mimetype,
                    metadata ->> 'size' AS size, -- Extract size from metadata
                    metadata,
                    created_at::text,
                    updated_at::text,
                    last_accessed_at::text
                FROM storage.objects
                WHERE bucket_id = $1
            `;
            const params: (string | number)[] = [bucket_id];
            let paramIndex = 2;
    
            if (prefix) {
                sql += ` AND name LIKE $${paramIndex++}`;
                params.push(`${prefix}%`);
            }
    
            sql += ' ORDER BY name ASC NULLS FIRST';
            sql += ` LIMIT $${paramIndex++}`;
            params.push(limit);
            sql += ` OFFSET $${paramIndex++}`;
            params.push(offset);
            sql += ';';
    
            console.error('Executing parameterized SQL to list storage objects within transaction...');
            const result = await pgClient.query(sql, params); // Raw pg result
    
            // Explicitly pass result.rows, which matches the expected structure
            // of SqlSuccessResponse (unknown[]) for handleSqlResponse.
            return handleSqlResponse(result.rows as SqlSuccessResponse, ListStorageObjectsOutputSchema);
        });
    
        console.error(`Found ${objects.length} objects.`);
        context.log(`Found ${objects.length} objects.`);
        return objects;
    },
  • Zod schemas defining input parameters (bucket_id required, optional limit/offset/prefix) and output structure (array of StorageObject with fields like id, name, metadata). Also includes static MCP JSON input schema.
    // Input schema
    const ListStorageObjectsInputSchema = z.object({
        bucket_id: z.string().describe('The ID of the bucket to list objects from.'),
        limit: z.number().int().positive().optional().default(100).describe('Max number of objects to return'),
        offset: z.number().int().nonnegative().optional().default(0).describe('Number of objects to skip'),
        prefix: z.string().optional().describe('Filter objects by a path prefix (e.g., \'public/\')'),
    });
    type ListStorageObjectsInput = z.infer<typeof ListStorageObjectsInputSchema>;
    
    // Output schema
    const StorageObjectSchema = z.object({
        id: z.string().uuid(),
        name: z.string().nullable(), // Name can be null according to schema
        bucket_id: z.string(),
        owner: z.string().uuid().nullable(),
        version: z.string().nullable(),
        // Get mimetype directly from SQL extraction
        mimetype: z.string().nullable(), 
        // size comes from metadata
        size: z.string().pipe(z.coerce.number().int()).nullable(),
        // Keep raw metadata as well
        metadata: z.record(z.any()).nullable(),
        created_at: z.string().nullable(),
        updated_at: z.string().nullable(),
        last_accessed_at: z.string().nullable(),
    });
    const ListStorageObjectsOutputSchema = z.array(StorageObjectSchema);
    type ListStorageObjectsOutput = z.infer<typeof ListStorageObjectsOutputSchema>;
    
    // Static JSON schema for MCP
    export const mcpInputSchema = {
        type: 'object',
        properties: {
            bucket_id: { type: 'string', description: 'The ID of the bucket to list objects from.' },
            limit: { type: 'number', description: 'Max number of objects to return', default: 100 },
            offset: { type: 'number', description: 'Number of objects to skip', default: 0 },
            prefix: { type: 'string', description: "Filter objects by a path prefix (e.g., 'public/')" },
        },
        required: ['bucket_id'],
    };
  • src/index.ts:119-119 (registration)
    Registration of the list_storage_objects tool into the availableTools object used by the MCP server.
    [listStorageObjectsTool.name]: listStorageObjectsTool as AppTool,
  • src/index.ts:33-33 (registration)
    Import of the listStorageObjectsTool module.
    import listStorageObjectsTool from './tools/list_storage_objects.js';

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv1.0.0

TDQS

A3.6/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries full burden. It mentions listing and optional prefix filtering but does not disclose pagination behavior (despite limit/offset in schema), auth requirements, or potential side effects. Adequate but has gaps.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single sentence with 11 words, front-loading the core functionality. No redundancy or fluff.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a tool with 4 parameters and no output schema, the description is minimal. It does not describe the return format (e.g., list of object names, metadata) or any other behavioral details, leaving the agent underinformed.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so baseline is 3. The description adds no extra meaning beyond what is in the schema; it simply reiterates the prefix filter without additional context.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb 'lists', the resource 'objects within a specific storage bucket', and the optional 'prefix' filter, which distinguishes it from sibling tools like list_storage_buckets.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage for listing objects in a bucket but does not provide explicit guidance on when to use versus alternatives like list_storage_buckets, nor any when-not-to-use conditions.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.