## Problem
`@supabase/middleware` ships as 1.0.0. The docs still label the
`pipeline` entry form of `withSupabase` alpha, and several snippets
import `npm:@supabase/server` and `npm:@supabase/middleware` with no
version or with a `^0.5.0` pin. A snippet without a version leaves
readers and tools to guess one, and a guessed version fails on deploy.
## Solution
- Removes the alpha wording from the middleware reference intro and
usage examples, the server frameworks partial, and the Bring your own
MCP guide. The `@supabase/server` 1.6.0 floor stays.
- Pins every `npm:@supabase/server` and `npm:@supabase/middleware`
import in the guides to a major range, `@1`, following the
`npm:@supabase/supabase-js@2` convention in Managing dependencies.
- Bumps the authenticated-mcp-server example to middleware `^1.0.0` and
server `^1.9.0`.
~~Blocked by supabase/middleware#49. The `@1` range resolves once 1.0.0
is on npm.~~
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Updated authentication, API key, and MCP examples to use versioned
Supabase server and middleware packages.
* Clarified that pipeline and nested composition behave the same, and
that both require `@supabase/server` 1.6.0 or later.
* Removed alpha-status labels from `withSupabase` guidance while
retaining the 1.6.0 minimum-version requirement.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Adds a Frameworks partial to the `@supabase/server` reference, after
Installing. It explains how to run `@supabase/middleware` entries inside
Hono, H3, Elysia, NestJS, and TanStack Start through a copyable bridge,
and how to move off the framework adapters: the auth trap
(`withRequiredClaims` versus `withClaims`), the `userClaims` to
`jwtClaims` field remap, how each framework scopes an entry array to a
group of routes, what CORS and body access cost on NestJS, the
step-by-step procedure, and a prompt to hand to a coding agent. The
bridge code for all five frameworks lives in supabase/server#168 and is
linked, not copied. Resolves
[SDK-1599](https://linear.app/supabase/issue/SDK-1599) and
[SDK-1862](https://linear.app/supabase/issue/SDK-1862): the retired
`withSupabase({ middleware })` form is gone from the text.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Documentation**
* Added integration guidance and setup examples for Hono, H3/Nuxt,
Elysia, NestJS, and TanStack Start, including framework-specific
context, response, and route-scoping behavior.
* Documented migration options for authentication requirements, changes
to context and JWT claims, and differences in response and error
handling.
* Added a TanStack Start bridge example and migration and verification
checklists.
* Added the frameworks guide to the API reference navigation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->