From 75a722c4e4b518ee32ab656c2418c66c68d12072 Mon Sep 17 00:00:00 2001 From: Barry Roodt Date: Fri, 21 Aug 2026 14:22:55 +0200 Subject: [PATCH] chore(studio): update self-hosted MCP server to 0.11.0 (#49379) ## Summary - Update `apps/studio` to `@supabase/mcp-server-supabase` `^0.11.0` and add its required `@modelcontextprotocol/server` `^2.0.0` peer. - Keep `@modelcontextprotocol/sdk` `^1.29.0` for Studio's existing transports. `@supabase/mcp-utils` resolves transitively to `0.7.0`, so it remains indirect. [AI-1107](https://linear.app/supabase/issue/AI-1107/2b-update-self-hosted-remote-mcp-server) ## Testing - Five focused MCP test files passed, 47 tests total. - Studio production build passed with `SKIP_ASSET_UPLOAD=1`. - A real `POST` initialize request to the built self-hosted `/api/mcp` endpoint returned HTTP 200 with `serverInfo.version` `0.11.0`. - Studio typecheck still reports one pre-existing error in unchanged `packages/ui-patterns/src/McpUrlBuilder/components/InstructionBlocks.tsx:20`: `string` is not assignable to `StaticImageData`. ## Summary by CodeRabbit - **Improvements** - Improved compatibility with the latest MCP server capabilities. - Refreshed the Supabase MCP integration for a more up-to-date experience. - Verified that the available MCP tools remain consistent after the update. --- .../buildAPIPermissionScopeMap.test.ts | 3 -- apps/studio/package.json | 3 +- pnpm-lock.yaml | 46 +++++++++++++------ 3 files changed, 35 insertions(+), 17 deletions(-) diff --git a/apps/studio/app/api/scoped-access-token-permissions/buildAPIPermissionScopeMap.test.ts b/apps/studio/app/api/scoped-access-token-permissions/buildAPIPermissionScopeMap.test.ts index d59a83bbd63..65a5ee62fc1 100644 --- a/apps/studio/app/api/scoped-access-token-permissions/buildAPIPermissionScopeMap.test.ts +++ b/apps/studio/app/api/scoped-access-token-permissions/buildAPIPermissionScopeMap.test.ts @@ -194,9 +194,6 @@ describe('MCPToolScopeMappings', () => { ) }) - // Drift guard: the exact tool registry of @supabase/mcp-server-supabase@0.8.1, the version the - // platform pins. When the platform bumps the MCP server, this list (and the mapping) must be - // re-derived from the controller's assertMcpOAuthScope calls. test('covers exactly the tool registry of the deployed MCP server', () => { expect(Object.keys(MCPToolScopeMappings).sort()).toEqual([ 'apply_migration', diff --git a/apps/studio/package.json b/apps/studio/package.json index c420cf881fb..0f891700b14 100644 --- a/apps/studio/package.json +++ b/apps/studio/package.json @@ -59,6 +59,7 @@ "@hookform/resolvers": "^3.1.1", "@mjackson/multipart-parser": "^0.10.1", "@modelcontextprotocol/sdk": "^1.29.0", + "@modelcontextprotocol/server": "^2.0.0", "@monaco-editor/react": "catalog:", "@next/bundle-analyzer": "16.2.3", "@number-flow/react": "^0.3.2", @@ -72,7 +73,7 @@ "@stripe/stripe-js": "9.1.0", "@stripe/sync-engine": "1.0.32", "@supabase/auth-js": "catalog:", - "@supabase/mcp-server-supabase": "^0.10.0", + "@supabase/mcp-server-supabase": "^0.11.0", "@supabase/pg-meta": "workspace:*", "@supabase/realtime-js": "catalog:", "@supabase/shared-types": "0.1.91", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index f71fbfbc995..7687f30f3a9 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -944,6 +944,9 @@ importers: '@modelcontextprotocol/sdk': specifier: ^1.29.0 version: 1.29.0(supports-color@8.1.1)(zod@3.25.76) + '@modelcontextprotocol/server': + specifier: ^2.0.0 + version: 2.0.0 '@monaco-editor/react': specifier: 'catalog:' version: 4.8.0-rc.3(monaco-editor@0.52.2)(react-dom@19.2.6(react@19.2.6))(react@19.2.6) @@ -984,8 +987,8 @@ importers: specifier: 'catalog:' version: 2.112.3 '@supabase/mcp-server-supabase': - specifier: ^0.10.0 - version: 0.10.0(@modelcontextprotocol/sdk@1.29.0(supports-color@8.1.1)(zod@3.25.76))(zod@3.25.76) + specifier: ^0.11.0 + version: 0.11.0(@modelcontextprotocol/server@2.0.0)(zod@3.25.76) '@supabase/pg-meta': specifier: workspace:* version: link:../../packages/pg-meta @@ -4798,6 +4801,10 @@ packages: '@mjackson/node-fetch-server@0.2.0': resolution: {integrity: sha512-EMlH1e30yzmTpGLQjlFmaDAjyOeZhng1/XCd7DExR8PNAnG/G1tyruZxEoUe11ClnwGhGrtsdnyyUx1frSzjng==} + '@modelcontextprotocol/core@2.0.0': + resolution: {integrity: sha512-pJCEwGG7Lfr/+PQp9ZTwKXNeO5wzbfKL7H3MYpCorM4oFBoQrdjnBgEoqG+RjhsvS1FKrDbKux+M1HhlnGWqcA==} + engines: {node: '>=20'} + '@modelcontextprotocol/sdk@1.29.0': resolution: {integrity: sha512-zo37mZA9hJWpULgkRpowewez1y6ML5GsXJPY8FI0tBBCd77HEvza4jDqRKOXgHNn867PVGCyTdzqpz0izu5ZjQ==} engines: {node: '>=18'} @@ -4808,6 +4815,10 @@ packages: '@cfworker/json-schema': optional: true + '@modelcontextprotocol/server@2.0.0': + resolution: {integrity: sha512-YhHWdHfpFMQfd0prsEnxKeS3Qz3ytIGmsS0sth4KDjnacIT7hxk6hXHkJ9KysxlkvTM+WZAtQbbcUhdoP4Hvtw==} + engines: {node: '>=20'} + '@monaco-editor/loader@1.7.0': resolution: {integrity: sha512-gIwR1HrJrrx+vfyOhYmCZ0/JcWqG5kbfG7+d3f/C1LXk2EvzAbHSg3MQ5lO2sMlo9izoAZ04shohfKLVT6crVA==} @@ -7514,17 +7525,17 @@ packages: resolution: {integrity: sha512-gfv481mTOVWtZIJgXupxZpni2V2UWPf6jeF/jOK7HdMHdH+mt6sU0sHHwf0POsPip8ltlulu9OUHgwVzl5ddRw==} engines: {node: '>=22.0.0'} - '@supabase/mcp-server-supabase@0.10.0': - resolution: {integrity: sha512-CVnB+4wBFsQeYwr5phNZyG33nNPUVBAJFB99vn55Z5Zn5+sxopybBPeYtrz8J9rqLkXad/xb7Xow4sz0JMq/XQ==} + '@supabase/mcp-server-supabase@0.11.0': + resolution: {integrity: sha512-++eAgAmq3SAnj3nf2Ic0i2Si9oFmTn9ppEJOioABf7+DZ/w3blPuxLlSTSBZV5+Sf1SdueMpTvYvkKJh0zx+/Q==} hasBin: true peerDependencies: - '@modelcontextprotocol/sdk': ^1.25.2 + '@modelcontextprotocol/server': ^2.0.0 zod: ^3.25.0 || ^4.0.0 - '@supabase/mcp-utils@0.6.0': - resolution: {integrity: sha512-4r7RTEMZgFw4VqTgsQrM0KUWXdEOASPHEjIfuBaGb0SXPHIIe6W8xBnocidjtfQnKagxMJb0RXY4rqwwShJ2zw==} + '@supabase/mcp-utils@0.7.0': + resolution: {integrity: sha512-PDTPOn/0AEPWwAXc8I98wruYucGwNLCAfiCu0eZS1mE+E/e0xZhdSY3nfE2n+sh8p5aaep5Kqd9Wt0rThAKgdQ==} peerDependencies: - '@modelcontextprotocol/sdk': ^1.25.2 + '@modelcontextprotocol/server': ^2.0.0 zod: ^3.25.0 || ^4.0.0 '@supabase/phoenix@0.4.5': @@ -20775,6 +20786,10 @@ snapshots: '@mjackson/node-fetch-server@0.2.0': {} + '@modelcontextprotocol/core@2.0.0': + dependencies: + zod: 4.4.3 + '@modelcontextprotocol/sdk@1.29.0(supports-color@8.1.1)(zod@3.25.76)': dependencies: '@hono/node-server': 1.19.17(hono@4.13.1) @@ -20797,6 +20812,11 @@ snapshots: transitivePeerDependencies: - supports-color + '@modelcontextprotocol/server@2.0.0': + dependencies: + '@modelcontextprotocol/core': 2.0.0 + zod: 4.4.3 + '@monaco-editor/loader@1.7.0': dependencies: state-local: 1.0.7 @@ -23897,20 +23917,20 @@ snapshots: dependencies: tslib: 2.8.1 - '@supabase/mcp-server-supabase@0.10.0(@modelcontextprotocol/sdk@1.29.0(supports-color@8.1.1)(zod@3.25.76))(zod@3.25.76)': + '@supabase/mcp-server-supabase@0.11.0(@modelcontextprotocol/server@2.0.0)(zod@3.25.76)': dependencies: '@mjackson/multipart-parser': 0.10.1 - '@modelcontextprotocol/sdk': 1.29.0(supports-color@8.1.1)(zod@3.25.76) - '@supabase/mcp-utils': 0.6.0(@modelcontextprotocol/sdk@1.29.0(supports-color@8.1.1)(zod@3.25.76))(zod@3.25.76) + '@modelcontextprotocol/server': 2.0.0 + '@supabase/mcp-utils': 0.7.0(@modelcontextprotocol/server@2.0.0)(zod@3.25.76) common-tags: 1.8.2 gqlmin: 0.3.1 graphql: 16.11.0 openapi-fetch: 0.13.8 zod: 3.25.76 - '@supabase/mcp-utils@0.6.0(@modelcontextprotocol/sdk@1.29.0(supports-color@8.1.1)(zod@3.25.76))(zod@3.25.76)': + '@supabase/mcp-utils@0.7.0(@modelcontextprotocol/server@2.0.0)(zod@3.25.76)': dependencies: - '@modelcontextprotocol/sdk': 1.29.0(supports-color@8.1.1)(zod@3.25.76) + '@modelcontextprotocol/server': 2.0.0 zod: 3.25.76 '@supabase/phoenix@0.4.5': {}