Forge
Provides tools for working with Supabase, including listing tables, policies, and functions, explaining SQL query plans, proposing RLS policies, and running read-only SQL queries as the authenticated user with RLS enforced.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@ForgeShow me the tables in the public schema and their RLS policies."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Forge
MCP server + assistant de debugging sobre Supabase Edge Functions.
El agente lista schema, explica planes SQL, propone politicas RLS y corre queries de solo lectura respetando el JWT del usuario. Nada de service_role en el cliente.
Proyecto hosted: HOSTED.md
Repo: https://github.com/mcontrerasmalpar-pixel/forge-mcp-supabase
Que demuestra (senal para Supabase / AI tooling)
MCP hospedado en Edge Functions (Deno)
Tools con allowlist (sin DDL destructivo)
RLS como autorizacion (no checks en el frontend)
Demo multi-tenant: org visible
acme-alphavs ocultabeta-shadowAssistant UI con sesion JWT y boton Cargar demo RLS
LLM del chat opcional (Azure OpenAI u otro); el MCP funciona sin el
Related MCP server: mcp-server-postgres
Arquitectura
Cursor / Assistant UI
| MCP JSON-RPC (user JWT)
v
Edge Function mcp-server
| Postgres + RLS
v
PostgresLa function chat solo orquesta un LLM + tool calls. Si no hay API de modelo configurada, responde que uses el MCP directo (Cursor).
Demo hosted (sin Azure)
Crea proyecto Supabase y linkea este repo (o
supabase db push+functions deploy).apps/web/.env.local:
NEXT_PUBLIC_SUPABASE_URL=https://YOUR_REF.supabase.co
NEXT_PUBLIC_SUPABASE_ANON_KEY=eyJ... # legacy anon o publishablecd apps/web && npm install && npm run devDesactiva Confirm email en Auth → Providers → Email.
Solo entrar → debe decir
JWT: si.Cargar demo RLS → JSON con
your_org: acme-alphayhidden_org: beta-shadow.
Con eso ya demuestras multi-tenant + RLS + bootstrap. El chat en la UI es extra.
MCP desde Cursor (sin Azure)
Copia .cursor/mcp.json.example a .cursor/mcp.json y apunta a tu function:
{
"mcpServers": {
"forge": {
"url": "https://YOUR_REF.supabase.co/functions/v1/mcp-server",
"headers": {
"Authorization": "Bearer USER_JWT",
"apikey": "SUPABASE_ANON_KEY"
}
}
}
}El USER_JWT es el access_token de una sesion iniciada (mismo usuario de la demo). Las tools heredan RLS de ese JWT.
Tools
Tool | Guardrail |
list_tables | catalog only |
list_policies | read only |
list_functions | read only |
explain_query | blocks writes |
propose_rls | draft, does not apply |
run_readonly_sql | SELECT/WITH/EXPLAIN + read-only txn |
LLM opcional (Azure u otro)
Azure for Students a menudo tiene cuota 0 en modelos OpenAI; no es bloqueante.
Si mas adelante tienes endpoint + key:
npx supabase secrets set AZURE_OPENAI_ENDPOINT=https://YOUR.openai.azure.com
npx supabase secrets set AZURE_OPENAI_API_KEY=...
npx supabase secrets set AZURE_OPENAI_DEPLOYMENT=gpt-4o-mini
npx supabase functions deploy chat --project-ref YOUR_REFSin secrets, chat responde que uses MCP desde Cursor.
Seguridad
Cliente: anon/publishable key + user JWT.
run_readonly_sqlrechaza INSERT/UPDATE/DELETE/DROP/ALTER.propose_rlsno aplica migraciones.Rate limit por
auth.uid()en el servidor MCP.
npm run evalsMIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Your Supabase account in natural language: run SQL, apply migrations, manage tables, storage, edge f
Deterministic safety, correctness & cost gate that vets Postgres SQL before your AI agent runs it.
Generate, fix, explain and run read-only SQL on PostgreSQL, MySQL and SQL Server
Safe, read-only Postgres and MySQL access for AI agents. Audit log + column-level controls.
Related MCP Servers
- FlicenseAqualityCmaintenanceEnables read-only exploration of a Postgres database using natural language, with multiple safety layers to prevent any modifications.5-
- AlicenseNot gradedqualityCmaintenanceEnables AI assistants to query PostgreSQL, inspect schemas, and explain queries, designed for local and development databases with read-only safety by default.37 npmMIT
- AlicenseNot gradedqualityCmaintenanceEnables an AI assistant to run guarded, read-only SQL queries against a Postgres database with enforced limits and validation.MIT
- FlicenseNot gradedqualityCmaintenanceEnables AI assistants to safely inspect and query PostgreSQL databases with read-only enforcement, row/timeout limits, and audit logging, providing tools for schema/table listing, read-only queries, query explanations, and table statistics.-