## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Dependency update.
## What is the current behavior?
`apps/studio` depends on `@supabase/mcp-server-supabase` `^0.11.0`,
which pulls in `@supabase/mcp-utils` `0.7.0` transitively.
## What is the new behavior?
- Bump `@supabase/mcp-server-supabase` to `^0.12.0`. The lockfile moves
it to `0.12.0` and its `@supabase/mcp-utils` dep to `0.8.0` (still
indirect). Nothing else in the lockfile changes.
- Peer deps are unchanged (`@modelcontextprotocol/server ^2.0.0`, `zod
^3.25.0 || ^4.0.0`).
No studio code change needed. 0.12.0 adds an optional `costConfirmation`
server option for `create_project` / `create_branch`; the self-hosted
route doesn't set it, and self-hosted never registers those tools in the
first place. The exported tool set is the same 33 schemas, so the
tool-name guard in `lib/ai/tools/mcp-tools.ts` still passes.
`get_advisors` now groups lints inside its result, which studio forwards
to the model without parsing. Release notes: [mcp-server-supabase
v0.12.0](https://github.com/supabase/mcp/releases/tag/mcp-server-supabase-v0.12.0)
and [mcp-utils
v0.8.0](https://github.com/supabase/mcp/releases/tag/mcp-utils-v0.8.0).
## Additional context
[AI-1178](https://linear.app/supabase/issue/AI-1178/2b-update-self-hosted-remote-mcp-server)
Testing:
- `pnpm install --frozen-lockfile` passes.
- Studio `pnpm typecheck` is clean.
- MCP-related vitest files: 13 files, 108 tests passed.
- In-memory smoke of `createSupabaseMcpServer` with the self-hosted
route's options reports `serverInfo.version` `0.12.0` and 11 tools.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Updated the Supabase MCP integration dependency to version 0.12.0.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Summary
- Update `apps/studio` to `@supabase/mcp-server-supabase` `^0.11.0` and
add its required `@modelcontextprotocol/server` `^2.0.0` peer.
- Keep `@modelcontextprotocol/sdk` `^1.29.0` for Studio's existing
transports. `@supabase/mcp-utils` resolves transitively to `0.7.0`, so
it remains indirect.
[AI-1107](https://linear.app/supabase/issue/AI-1107/2b-update-self-hosted-remote-mcp-server)
## Testing
- Five focused MCP test files passed, 47 tests total.
- Studio production build passed with `SKIP_ASSET_UPLOAD=1`.
- A real `POST` initialize request to the built self-hosted `/api/mcp`
endpoint returned HTTP 200 with `serverInfo.version` `0.11.0`.
- Studio typecheck still reports one pre-existing error in unchanged
`packages/ui-patterns/src/McpUrlBuilder/components/InstructionBlocks.tsx:20`:
`string` is not assignable to `StaticImageData`.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **Improvements**
- Improved compatibility with the latest MCP server capabilities.
- Refreshed the Supabase MCP integration for a more up-to-date
experience.
- Verified that the available MCP tools remain consistent after the
update.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Bug fix. Complete App configurations produce the same auth options as
before.
## What is the current behavior?
Without the docs GitHub App private key, two things fail for a
contributor:
- `pnpm run embeddings` aborts before doing any work. The lint warnings
source throws, and every source shares one `Promise.all` in
[`fetchAllSources()`](https://github.com/supabase/supabase/blob/master/apps/docs/scripts/search/sources/index.ts).
- `pnpm --filter docs build` exits 1 in prebuild, so the `npm run build`
pre-flight CONTRIBUTING.md asks for cannot run either:
```
Error: DOCS_GITHUB_APP_PRIVATE_KEY environment variable is required
at octokit (apps/docs/lib/octokit.ts:21:13)
at fetchAiSkills (apps/docs/scripts/federated-content/fetch-federated-content.ts:258:36)
```
Both read public content, so this is a rate-limit guard rather than
access control: App auth landed in #43015 because unauthenticated calls
(60 req/hr per IP) went flaky on shared runners.
## What is the new behavior?
`apps/docs/lib/octokit.auth.ts` adds one rung below the App: a token
from `GH_TOKEN`, then `GITHUB_TOKEN` (the precedence [`gh help
environment`](https://cli.github.com/manual/gh_help_environment)
documents), so `export GH_TOKEN=$(gh auth token)` is enough to build
locally. Still authenticated, so #43015's fix holds, and still an
authenticated Octokit client, so #44274 holds.
A partially configured App is now an error naming the missing vars,
rather than falling through to a token.
Used by the lint warnings loader and `lib/octokit.ts`. The two token
vars are declared in `apps/docs/turbo.jsonc` for
`turbo/no-undeclared-env-vars`.
## Additional context
With only `GH_TOKEN` set, `turbo run build --filter=docs --force` passes
4/4 and search-index source loading completes. `pnpm test` passes (20
files, 164 tests), and `tsc --noEmit` plus `pnpm run lint` match
`origin/master`. For a complete App config the auth options are
identical to before. Happy to post the fuller verification as a comment.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **New Features**
- Added flexible GitHub authentication for documentation services,
supporting GitHub App credentials or personal access tokens.
- GitHub App authentication is preferred when fully configured, with
token-based fallback when unavailable.
- Added support for both `GH_TOKEN` and `GITHUB_TOKEN`, with clear
precedence rules.
- **Bug Fixes**
- Improved configuration validation with clear errors for missing or
incomplete authentication settings.
- Standardized authentication across GitHub content and lint-warning
retrieval.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
docs update
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Updated the site’s public people listing to include Barry Roodt in the
team section.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->