## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
- We made the Next step copy a bit more generic so it doesn't read like
it's pointing you back to Inspector UI.
- Added CTA on key stored screen to send you to Edge Function Secrets
directly.
- Tidies up footer area to always be centrally aligned across all
states.
### 1. Enable the feature flag
### 2. Preview states via URL
Mock mode is enabled automatically in local/staging. Navigate to
`/mcp/secrets` with a `state` query param:
http://localhost:8082/mcp/secrets?state=<state>
States that need no other params:
| `state` value | What it shows |
| ----------------- | --------------------------------------- |
| `loading` | Loading skeleton |
| `expired` | Link expired |
| `cancelled` | Request cancelled |
| `paused` | Storing keys paused |
| `wrong-account` | Signed in as the wrong account |
| `error` | Generic failure |
States that need a real project —ame=<KEY_NAME>`:
| `state` value | What it sh |
| -------------------- | ---------------------- |
| `form` | The "st |
| `stored` | Success |
| `stored-timeout` | Successopped waiting |
| `already-stored` | Key was already stored, nothing to do |
Example:
http://localhost:8082/mcp/secretsJECT_REF&name=OPENAI_API_KEY
### 3. What to check
- [ ] `stored` / `already-stored`tions secrets"** button linking to
`/project/<ref>/functions/secrets
- [ ] States without a project re `paused`, `error`) don't show that
button
- [ ] Footer text is centered on
- [ ] `wrong-account` → **Switch its footer is centered
- [ ] The provider-dashboard link` state, use a `name`
like`OPENAI_API_KEY` or `RESEND_API_Khint) is centered too
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **New Features**
* Added a project-specific link to Edge Functions secrets from the MCP
setup screen when a project is available.
* Added a separator to distinguish the secrets link from the remaining
setup guidance.
* **Improvements**
* Updated completion guidance to tell users to return to their agent and
confirm the setup is finished.
* Standardized interstitial footer content with centered guidance and
consistent provider dashboard instructions.
* **Tests**
* Added coverage for displaying the project-specific secrets link and
hiding it when no project is associated.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Ali Waseem <waseema393@gmail.com>
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Initial build of the URL mode interstitial. Has complete mock data to be
able to view different states (this will be stripped out in the end). A
starting point for us to use as an intercept.
This is linked with @barryroodt ticket in the MCP project.
https://github.com/supabase/mcp/pull/412
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **New Features**
- Added an authenticated MCP Secrets page for securely storing API
secrets requested by AI tools.
- Added provider-aware guidance for OpenAI, Anthropic, Resend, and
Stripe keys, including validation warnings and dashboard links.
- Added clear success, cancellation, expiration, error, and
wrong-account states with account switching.
- Added loading placeholders, secret visibility controls, overwrite
warnings, and accessibility announcements.
- **Bug Fixes**
- Improved interstitial animations to respect reduced-motion
preferences.
- Preserved return destinations and related parameters during sign-in
flows.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>