Commit Graph
8276 Commits
Author SHA1 Message Date
Aditya MaruvadaandAditya Maruvada d21c20eae6 docs: add Multigres early access request link to the Multigres docume… (#51297)
…ntation

## Problem

Currently there's no way for users to request access to private alpha
for Multigres.

## Solution

Add a link to the form to fillout for customers to get access.


## Checklist

Check all before review:

- [X] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [X] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)

Co-authored-by: Aditya Maruvada <aditya@Adityas-MacBook-Pro.local>
2026-10-05 17:16:16 -07:00
Miranda Limonczenko 17512de71d docs(database): connect security definer to the default execute grant (#50817)
Closes DOCS-1319

Part 4 of 4 in stack #50823. This PR carries **additions**: content the
page never had.
Style, structure, and snippet fixes land below it in #50820, #50821, and
#50822.

## Problem

Developers and AI agents read the Database functions guide. The guide
shows how to write a function inside the database.

A function runs in one of two modes. In `invoker` mode it runs as the
caller. In `definer` mode it runs as the creator.

The guide gives one rule for `definer` mode. The rule is to set the
`search_path`. A reader who obeys that rule still gets an unsafe
function.

I wrote a function that obeys the rule. I pinned the search path to the
empty string. Then I called it three times.

| Caller | Result |
| --- | --- |
| The order's owner | 4330 cents, correct |
| A different signed-in customer | 8660 cents, another customer's order
|
| Nobody, no session at all | 8660 cents |

Every role can call a new function in `public`. The guide states that
fact under Function privileges. It never connects the fact to the
`definer` rule. A reader has no reason to look.

Customers report the same failure. AI tools choose `definer` mode. The
function then answers the front end with no session. The hole is hard to
find, because no policy is involved in it.

## Solution

- **Joins the two halves in the Security definer subsection.** A
`danger` admonition states three facts:
  - The function runs with its creator's privileges.
- A function created in the Dashboard or by a migration is owned by
`postgres`, which bypasses Row Level Security.
  - Every role can call the function by default.

The admonition then gives the fix. Check ownership inside the function
body, and narrow the execute privilege as well.

- **Applies the regrant to both ways of restricting execute.** The
`grant execute` block sat inside the second way. A reader who took the
first way saw no way to restore their own app's access.

**Not changed:** the existing definer paragraph, the page structure, and
the Function privileges statements. The lower PRs in the stack own
those.

**No eval re-run.** The guide scored 6 of 6 on three baseline runs, so
the score has no room to move. All three runs chose `invoker` mode. The
eval never enters the branch this PR fixes. Measuring it needs a new
check, not a re-run.

**Diff size:** one file, 15 lines added and 4 removed.

## Manual testing

1. Open the [Security definer vs invoker
section](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions#security-definer-vs-invoker)
on the deploy preview. The admonition renders as a red `danger` panel
below the definer paragraph. The two fixes appear as bullets.
2. Click the `Function privileges` link inside the admonition. It jumps
to the [Function privileges
section](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions#function-privileges)
on the same page.
3. Read that section. The `grant execute` block sits after the numbered
list. It applies to both ways of restricting execute.
4. Run `pnpm build:guides-markdown` from `apps/docs`. Read
`apps/docs/public/markdown/guides/database/functions.md`. The admonition
appears as a `Danger:` paragraph. Discard the `manifest.json` change.
5. Run `npx prettier --check
apps/docs/content/guides/database/functions.mdx`. Clean.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Expanded guidance on the security risks of `security definer`
functions, including their privileges, interaction with Row Level
Security, and default execution access.
* Added recommendations for checking data ownership and restricting
execution to intended roles.
* Clarified that pinning `search_path` does not limit execution
privileges.
* Presented the function-privileges example separately from the
default-privileges instructions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

## Preview links

| Site | Live | Preview | Search for |
| --- | --- | --- | --- |
| Docs |
[/docs/guides/database/functions](https://supabase.com/docs/guides/database/functions)
|
[/docs/guides/database/functions](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions)
| `every signed-in caller` |

## Review instructions

This PR adds one admonition and moves one code block. The question is
whether the admonition is correct and whether an agent reading the page
would act on it.

1. Open the preview at [Security definer vs
invoker](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions#security-definer-vs-invoker).
A red `danger` panel sits below the definer paragraph.
2. **Read the first paragraph for accuracy.** It claims the function
runs with its creator's privileges, that a function created in the
Dashboard or by a migration is owned by `postgres`, and that `postgres`
bypasses Row Level Security. This matches [Use security definer
functions](https://supabase.com/docs/guides/database/postgres/row-level-security#use-security-definer-functions)
in the RLS guide. Flag any drift.
3. **Read the two bullets for sufficiency.** The ownership check is the
primary fix. The execute grant is listed as a complement, not an
alternative, because granting to `authenticated` still returns any
user's row to every signed-in caller. Confirm the wording can't be read
as "either one is enough."
4. Click the `Function privileges` link inside the admonition. It jumps
down the same page.
5. In the Function privileges section, confirm the `grant execute` block
sits after the numbered list rather than inside item 2, so it applies to
both ways of restricting execute.
6. **Check the agent-facing copy.** Open [the markdown
export](https://docs-git-docs-definer-function-privileges-supabase.vercel.app/docs/guides/database/functions.md)
and find `Danger:`. This is what an agent reads, and it is the audience
this PR exists for.

**If you only have two minutes:** do steps 3 and 6. Step 3 is the
correctness of the advice. Step 6 is whether the audience that prompted
the ticket actually receives it.

**A note on running SQL from this page.** Don't hand-paste from the
rendered page. Blocks are split across tabs, and the Data tab in
Returning data sets holds markdown tables that look pasteable but are
not SQL. Use the `.md` export of the page, which flattens every tab in
page order. #50822 has a copy-paste command for this.
2026-10-05 15:18:01 -07:00
Miranda Limonczenko d8b0a3e87f docs(database): make the guide's snippets run in document order (#50822)
Part 3 of 4 in stack #50823. This PR carries **technical revision
only**: claims that produce a wrong outcome for a reader.

## Problem

This PR came from running a technical assessment using `/test-the-docs`.

A reader pastes the guide top to bottom. Two snippets fail.

The `planets` table uses a `serial` primary key, then the seed sets ids
explicitly. Explicit ids don't advance the sequence, so it stays at 0.
The `add_planet('Jakku')` example then draws id 1, which the seed
already used:

```
ERROR:  duplicate key value violates unique constraint "planets_pkey"
DETAIL:  Key (id)=(1) already exists.
```

The `security definer` example re-creates `hello_world` with `create`
rather than `create or replace`, so it collides with the function from
Basic functions:

```
ERROR:  function "hello_world" already exists with same argument types
```

The Data tab spells the planet Tatooine. The SQL tab spells it Tattoine.

Two debugging snippets read `attendance_table` and `some_table`. No
fence creates either, and neither is marked as omitted.

## Solution

- **Seeds `planets` and `people` without explicit ids.** The sequence
advances, so `add_planet` succeeds. This also settles Tattoine against
Tatooine.
- **Uses `create or replace` in the definer example**, so it no longer
collides.
- **Marks the two assumed tables** in the debugging snippets with a
comment.
- **Points the CREATE FUNCTION link at the current Postgres docs.** It
pointed at 9.1, while the intro already links the current version of the
same page.

**Verification.** I ran every `sql` fence from the guide in document
order against Postgres 15 in a throwaway container, with `anon` and
`authenticated` created first. Before these changes, two fences errored.
After them, the sequence runs clean.

## Manual testing

1. Start a throwaway Postgres: `docker run --rm -d --name pgcheck -e
POSTGRES_PASSWORD=pw postgres:15`.
2. Create the Supabase roles the guide references: `docker exec -i
pgcheck psql -U postgres -c "create role anon; create role
authenticated;"`.
3. Paste every `sql` block from the guide, in page order, into `docker
exec -i pgcheck psql -U postgres`. No statement errors.
4. Run `select * from planets;`. Tatooine, Alderaan, Kashyyyk, and
Jakku, with sequential ids.
5. Remove it: `docker rm -f pgcheck`.

## Preview links

| Site | Live | Preview | Search for |
| --- | --- | --- | --- |
| Docs |
[/docs/guides/database/functions](https://supabase.com/docs/guides/database/functions)
|
[/docs/guides/database/functions](https://docs-git-docs-functions-technical-supabase.vercel.app/docs/guides/database/functions)
| `('Tatooine')` |
| Docs | New page, 404 in production |
[/docs/guides/database/debugging-functions](https://docs-git-docs-functions-technical-supabase.vercel.app/docs/guides/database/debugging-functions)
| `assumes an attendance_table` |




<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **Documentation**
  - Clarified the required column types in database function examples.
- Expanded guidance on function return values, including `INSERT`,
`UPDATE`, and `DELETE` statements with `RETURNING` clauses.
- Updated SQL examples to show table creation and automatically
generated IDs, corrected the spelling of “Tatooine,” and refreshed the
PostgreSQL reference link.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 15:18:00 -07:00
Miranda Limonczenko 8b148f93c1 docs(database): regroup the database functions guide and split out debugging (#50821)
Part 2 of 4 in stack #50823. This PR carries **structure only**: moves,
regrouping, and the connective text the new shape needs. Reworded prose
already landed in #50820.

## Problem

This PR is running a structure edit.

A reader arrives from search and has to find one thing. The guide gave
them eight top-level headings, no grouping, and no opening outline. The
style guide caps a group at 5 ± 1.

Four of those headings are the action path: Getting started, Basic
functions, Returning data sets, and Passing parameters. Nothing marked
them as one sequence.

`Suggestions` held four unrelated things: an Edge Functions comparison,
two security topics, and a three-part debugging reference. The heading
names nothing the reader is doing.

Debugging was the largest thing on the page. It sat at H3 with three H4
children, and it shared only the word "function" with the rest of the
guide.

## Solution

- **Groups the four procedures** under `Create a database function`, so
the action path is one unbroken sequence.
- **Moves the Edge Functions comparison ahead of the procedures.** A
reader choosing between the two needs it before the steps, not after
them.
- **Groups the two security sections** under `Secure a database
function`.
- **Splits debugging onto its own page**,
`guides/database/debugging-functions`. It is registered in the Database
sidebar and cross-referenced from the guide.
- **Folds `Deep dive` into `Resources`.** Two trailing headings did one
job.
- **Adds an opening outline** linking each group and saying when to use
it.
- **Renames the frontmatter title** to sentence case, `Database
functions`.

## Manual testing

1. Open the [guide on the deploy
preview](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/functions).
Five top-level headings, with the opening outline linking each group.
2. Open the [new debugging
page](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/debugging-functions).
It appears in the Database sidebar under Managing database functions.
3. Follow a repointed link. Open [Postgres log
config](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/postgres/postgres-log-config)
and click Database Function Logging. It lands on the new page at General
logging.
4. Run `pnpm build:guides-markdown` from `apps/docs`. Both pages appear
under `public/markdown/guides/database/`. Discard the `manifest.json`
change.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added a guide to debugging Postgres database functions, with examples
for logging, error handling, and inspecting query results.
* Added the guide to Database navigation and updated related resources
to link to it.
* Reorganized the database functions guide to clarify function creation,
security, and privileges.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

## Preview links

| Site | Live | Preview | Search for |
| --- | --- | --- | --- |
| Docs |
[/docs/guides/database/functions](https://supabase.com/docs/guides/database/functions)
|
[/docs/guides/database/functions](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/functions)
| `Secure a database function` |
| Docs | New page, 404 in production |
[/docs/guides/database/debugging-functions](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/debugging-functions)
| `Debugging database functions` |
| Docs |
[/docs/guides/database/postgres/postgres-log-config](https://supabase.com/docs/guides/database/postgres/postgres-log-config)
|
[/docs/guides/database/postgres/postgres-log-config](https://docs-git-docs-functions-structure-supabase.vercel.app/docs/guides/database/postgres/postgres-log-config)
| `Database Function Logging` |

## Review instructions

This PR moves content. The risk is a broken link, not bad prose.

1. Open the preview of the guide. Count the top-level headings in the
right-hand outline. There are five, down from eight.
2. Read the four bullets at the top of the page. Each links to a group,
and each says when to use it. Click all four and confirm each lands on
its section.
3. Open the new debugging page from the second row. Confirm it appears
in the left sidebar under **Managing database functions**.
4. **Check the three locked anchors.** Append each to the preview guide
URL and confirm the page jumps: `#quick-demo`,
`#security-definer-vs-invoker`. Then append `#general-logging` to the
**debugging page** URL. Four other pages link to these.
5. Open the Postgres log config preview from the third row. Find
**Database Function Logging** in the Resources list and click it. It
lands on the new debugging page, not on a dead anchor.
6. Compare the prose against the live page. **No sentence should have
changed** beyond the new opening outline and the cross-reference to the
debugging page.

**If you only have two minutes:** do steps 4 and 5. A moved section that
leaves a dead anchor is the failure this PR could cause.

**A note on running SQL from this page.** Don't hand-paste from the
rendered page. Blocks are split across tabs, and the Data tab in
Returning data sets holds markdown tables that look pasteable but are
not SQL. Use the `.md` export of the page, which flattens every tab in
page order. #50822 has a copy-paste command for this.
2026-10-05 15:18:00 -07:00
Miranda Limonczenko 63c165311e docs(functions): act on the Edge Function auth eval findings (#50886)
Closes DOCS-1318

## Problem

An agent was asked to build an Edge Function returning the order history
for whoever is signed in and calling it. Three runs, all correct: each
one used the page's `auth: 'user'` pattern and read through the
caller-scoped client. The eval scores 7 of 7, including the guide-read
check.

These are the gaps that showed up around it.

| Finding | What the page does now | Why it matters |
| --- | --- | --- |
| Two clients, no guidance | The first example destructures `supabase`
and `supabaseAdmin` together and labels the second "bypasses RLS
(service role)" | A reader skimming for the client to use sees two, and
one of them is wrong for that section |
| No consequence named | "Bypasses RLS" is the strongest phrasing
anywhere | A handler querying a shared table through the privileged
client without a filter returns every user's rows. The page never said
so |
| `verify_jwt` as a value to set | Appears six times, five of them as
something to change | Switching it off to clear a 401 in development is
a reported failure. The page never said the default is the safe one |


## Solution

- **Say which client to reach for**, in the section where both are
handed over.
- **Name the outcome** in a `danger` admonition: a handler that queries
a shared table through `ctx.supabaseAdmin` without filtering by the
caller's ID returns every user's rows.
- **Frame `verify_jwt = true` as the default to leave alone** on
user-facing functions, and say what turning it off costs.
- **Say every project starts with a secret key named `default`.**

**Not asserted here:** the eval is not re-run. It was already at 7 of 7,
so there is no headroom to measure an improvement. A candidate new check
is proposed on DOCS-1318.

## Preview links

| Site | Live | Preview | Search for |
| ---- | ---- | ------- | ---------- |
| Docs |
[/docs/guides/functions/auth](https://supabase.com/docs/guides/functions/auth)
|
[/docs/guides/functions/auth](https://docs-git-docs-functions-auth-eval-findings-supabase.vercel.app/docs/guides/functions/auth)
| returns every user's rows |

## Review instructions

1. Open the live and preview links side-by-side.
2. Read Authenticated user calls on the preview. See a paragraph on
choosing between `ctx.supabase` and `ctx.supabaseAdmin`, then a `danger`
admonition naming the every-user's-rows outcome.
3. See the same section say to leave `verify_jwt = true` on for
user-facing functions.
4. Read the note under Service-to-service calls. See it mention the
`default` secret key.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Clarified that `secret` and `publishable` authentication modes accept
the `default` key, and documented how default, wildcard, and additional
keys are handled.
* Explained that JWT verification is enabled by default and that
disabling it leaves `withSupabase` as the only caller-verification step.
* Added guidance that admin queries bypass row-level security and should
be scoped to the caller when accessing shared tables.
* Clarified that service-to-service authentication with `secret`
validates only the `default` key.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 15:14:27 -07:00
Miranda Limonczenko 259dbe11f1 docs/functions auth structure (#50885)
## Problem

Restructure the topic based off of the PRed Style Guide.

## Solution

- **Group the seven sections into three.** A concept opener, `Choose an
auth mode`, holds the mode table. `Secure your function` holds the six
patterns. `Environment variables` stays last as the fact group.
- **Add an intro outline** linking the three groups, and a group
introduction for the patterns.
- **Move the Authorization headers link below the mode table**, so the
sentence that introduces the table sits next to it.
- **Correct the content listing entry** to match the page's own title.

**Anchors:** every heading text is unchanged. Five headings move from
`##` to `###`, which preserves the slug. The in-page link to
`#external-webhooks` and the two existing redirects in
`apps/www/lib/redirects.js` all still resolve. Verified by grepping the
repo for `functions/auth#` before and after.


## Preview links

| Site | Live | Preview | Search for |
| ---- | ---- | ------- | ---------- |
| Docs |
[/docs/guides/functions/auth](https://supabase.com/docs/guides/functions/auth)
|
[/docs/guides/functions/auth](https://docs-git-docs-functions-auth-structure-supabase.vercel.app/docs/guides/functions/auth)
| Choose an auth mode |
| Docs |
[/docs/guides/functions](https://supabase.com/docs/guides/functions) |
[/docs/guides/functions](https://docs-git-docs-functions-auth-structure-supabase.vercel.app/docs/guides/functions)
| Securing Edge Functions |

## Review instructions

1. Open the live and preview links side-by-side.
2. See three top-level entries in the preview's table of contents, with
six nested under `Secure your function`.
3. Load `/docs/guides/functions/auth#external-webhooks` on the preview.
See the page jump to that section.
4. Open the second preview link. See the listing card read "Securing
Edge Functions" rather than "With supabase-js".

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Reorganized the authentication guide with a table of contents and
clearer sections on choosing an auth mode and securing a function.
* Clarified that the guide covers all supported auth modes, combining
modes, and custom error responses.
* Renamed the guide listing to “Securing Edge Functions” and updated its
description to mention declaring accepted credentials.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 15:14:27 -07:00
Anthony Lio dcf266c360 feat(docs): update search v2 ui (#51175) 2026-10-05 20:33:19 +00:00
Miranda Limonczenko a5688423d0 docs(cli): restructure and tighten the CLI getting started guide (#50736)
Closes DOCS-1320

Was the bottom of a two-PR stack. The commit from #50680 moved here, so
that PR is closed and this one carries both changes.

## Problem

The CLI getting started guide had accumulated structural and prose
problems, none of which change what the page claims:

- **Nine flat H2 headings**, with Beta channel and Updating the Supabase
CLI sitting between installing and running. A first-time reader crossed
about 150 lines of beta and upgrade tabs before reaching `supabase
init`.
- **The introduction opened with a two-step procedure under no
heading**, listing `init` and `start` before the CLI is installed. Its
first sentence named the tool and where it runs rather than what the
reader gets.
- **Running a local Supabase project ran concept, fact, procedure, and
process together** as one stretch of prose, so the two commands the
reader has to run sat in paragraphs between the Docker background and
the first-run note.
- **Task headings mixed gerunds with imperatives:** Installing, Running,
Stopping, and Updating next to Access and Manage.
- **No navigation.** A long guide that mixes information types opened
straight into commands, with no outline of its major groups. The sidebar
contents is not a substitute: it isn't part of the document, and the
generated markdown an agent reads has no sidebar at all.
- **Four more sequences were prose.** Installing via npm, installing a
Linux package, the pre-upgrade backup, and opting out of telemetry each
had to be followed in order with nothing marking the order.
- **Smaller things:** the Studio screenshot's alt text named the topic
its heading already states, two links used "note above" and "here" as
their text, and an admonition restated where `sb_publishable_...` comes
from.

## Solution

Twelve commits, one change type each, plus a master merge and its fixup.

- **Style.** The install-method callout drops from four blocks to two
paragraphs and uses the documented `title` prop. Active voice on the
Postgres, analytics, and telemetry instructions. Descriptive link text.
Alt text that describes the Studio screenshot rather than naming it. Cut
the admonition restating `sb_publishable_...`.
- **Structure.** Beta channel and Updating the Supabase CLI move out of
the getting started path.
- **Grouping.** Local setup goes under Set up a local project, updating
and beta builds under Change your CLI version. The intro's `init` and
`start` list gets a Quickstart heading.
- **Value statement.** The opening sentence now says what the reader
gets.
- **Procedure format.** Running a local Supabase project leads with the
container runtime prerequisite, then four numbered actions, then the
first-run download as an outcome. Starting the container runtime is its
own step, since the old prose only assumed it with "with a container
runtime running".
- **Imperative headings.** Install, Run, Access, Stop, Update, Use the
beta channel.
- **Four more procedures.** npm install, Linux packages, the pre-upgrade
backup, and telemetry opt-out. The three pre-upgrade commands were one
unexplained block inside an admonition, so each step now says what its
command does. Re-enabling telemetry moves to a sentence, since it's the
reverse action rather than a step.
- **Intro navigation** listing the major groups, each line saying what
the reader gets from it.
- **Connect to a hosted project** (from #50680). A new section between
Stop local services and Change your CLI version, saying the stack runs
only on the reader's machine and nothing reaches a hosted project until
they sign in and link one, then pointing at the page that owns the
procedure. No commands. The `init` step gains a sentence saying it
creates local files only, and the value statement and intro navigation
cover the added goal.
- **Style guide and word list fixes** from an audit of the page against
`CONTRIBUTING.md` and `WORD_LIST.md`. `directory` over `folder` in
command-line contexts, `might` over `may`, present tense over `will`, a
noun after `this`, no `above` as a pointer, concrete verbs over
`manage`, no time-relative `latest`, no parentheses for supplementary
information, and an impact-first `caution` on the pre-upgrade callout.
The container runtime list becomes a table of tool and platforms, and
the group heading becomes Change your CLI version.


## Preview links

| Site | Live | Preview | Search for |
| ---- | ---- | ------- | ---------- |
| Docs |
[/docs/guides/local-development/cli/getting-started](https://supabase.com/docs/guides/local-development/cli/getting-started)
|
[/docs/guides/local-development/cli/getting-started](https://docs-git-docs-cli-getting-started-edits-supabase.vercel.app/docs/guides/local-development/cli/getting-started)
| Change your CLI version, Connect to a hosted project |

## Manual testing

1. Open the docs preview link above.
2. Read the introduction. It opens with a value statement, then links
the four major groups. Under Quickstart, the install-method callout
explains how the install method changes the command you run.
3. Read the On this page list. It nests: Quickstart, Set up a local
project with four sections under it, Change your CLI version with two
sections under it, Telemetry, Learn more.
4. Check Run a local Supabase project renders four numbered steps, with
code blocks inside steps 3 and 4. Check the npm tab of Install the
Supabase CLI renders three, and How to opt out renders two.
5. Load the page at `#installing-the-supabase-cli`, `#beta-channel`, and
`#updating-the-supabase-cli`. All three land on their sections despite
the renamed headings.
6. Load the legacy path
`/docs/guides/cli/getting-started#updating-the-supabase-cli`. It
redirects to the current path and keeps the fragment.
7. Check the introduction's group list includes Connect to a hosted
project, and that the section appears in the On this page list between
Stop local services and Change your CLI version.
8. Check that section is two sentences and a pointer, with no commands.
9. In Run a local Supabase project, select the "Connect to a hosted
project" link in step 3. The page scrolls to that section.
10. Follow both outbound links from the new section and confirm they
resolve, including the `#configure-github-actions` fragment.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Reorganized the local development guide with a clearer quickstart,
setup steps, service access instructions, and CLI version guidance.
* Expanded installation examples to include bun and clarified
package-runner commands.
* Clarified upgrade, backup, container cleanup, and telemetry
instructions.
  * Added a reference to the Microsoft Writing Style Guide.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 11:22:13 -07:00
Jeremias Menichelli 53ecbf9f2a chore: Add telemetry to search v2 user actions (#51146)
## Problem

We need to collect data from search v2 experiment usage.

## Solution

Add telemetry to search v2 modal being opened, closing, sending a query
and clicking a search v2 result.

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

1. Open the preview link and add the search v2 flag query:
`?docs-search-v2=search-v2-active`
2. Trigger all actions mentioned above
3. Telemetry data should be sent on the network tab


## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Improvements**
* Documentation search activity is now recorded when the dialog opens
from the keyboard shortcut or search input, and when it closes. Search
submissions include the query and whether results were found; selected
results include their destination and the highlighted query. This adds
visibility into key search interactions without changing how search
results or highlighting work.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 13:22:22 -03:00
Jeremias Menichelli 42dc4dbe90 chore: Add observability to search_v2 route (#51149)
## Problem

Our new Search V2 edge function can fail, we want to know when that
happens.

## Solution

Added the common Sentry wrapping plus try/catch strategy to the edge
function so we can add alerts to our Sentry dashboards and report
channels.

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

There's no way to reproduce this for the moment.


## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Search requests that encounter unexpected server-side errors now
receive a handled 500 response instead of an unhandled failure. Errors
returned by the search service also produce a 500 response, making
failure behavior more consistent for clients. The search query and
result-limit behavior remain unchanged.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 13:22:12 -03:00
Katerina Skroumpelou d7cac841c4 docs: state the adapter removal date in the server frameworks guide (#51276)
The server frameworks guide still said the adapters "will be deprecated
soon" and would be "removed in a future major". They have been
deprecated since `@supabase/server` 1.9.0, with `@deprecated` tags
shipping in 1.9.1, and the removal date is December 1, 2026. This PR
updates the two sentences to state that date and drops the wording about
the release shape, which is not decided.
2026-10-05 16:08:24 +00:00
Katerina Skroumpelou 0f453c89fa docs: add @supabase/middleware install step to server frameworks guide (#51266)
The framework bridges in the `@supabase/server` reference import
`@supabase/middleware` directly, but the guide never said to install it.
`@supabase/server` depends on it, so npm and yarn users get it through
hoisting, while pnpm users hit "Cannot find module
'@supabase/middleware'" the moment they copy a bridge. This PR adds the
direct-dependency note to the Versions admonition, an `npm install
@supabase/middleware` line to the copy-the-bridge step, and the same
instruction to the agent migration prompt.
2026-10-05 16:56:05 +03:00
Wen Bo Xie f414a68e1b docs(cli): address final review feedback on supabase stack guides (#51217)
- Add stack = true under the existing [experimental] table instead of
pasting a duplicate table, which leaves the setting off.
- Note that db dump targets the linked project unless --local is passed,
and that --db-url reaches a named local project through DB_URL.
- Qualify offline destroy on the host data being deletable, and scope
the shared Docker volume cleanup note to volume-backed projects.
- Say Docker database storage is chosen when the local project is
created.
- Allow GitHub's release download host alongside github.com, or the S3
host alone, in allowlisted sandboxes.
- www: most services stop when idle (not Functions), and state the
[experimental] stack prerequisite in the native runtime entry.
2026-10-05 09:26:52 -04:00
Tanun Turbo Chalermsinsuwan 77e3b4382f feat(role): Allow eligible organizations to invite users as 'No-access' base role (#50922)
## Problem

As the API has allow inviting users into `None / No-access` role for
team, enterprise, and platform tier organization, we need to update the
documentation and descriptions for this new role on the invitation form.

## Solution

1. Updated `apps/docs/content/guides/platform/access-control.mdx` to
include the role
2. Added the role description on
`apps/studio/components/interfaces/Organization/TeamSettings/Roles.constants.tsx`
3. Add the roles into the proper sorting order at
`apps/studio/data/organization-members/organization-roles-query.ts`
4. Add logic to invitation components to disable the role when inviting
user into project(s), as the backend does not allow it.

## Testing and verification steps
The UI:
https://studio-staging-aa8is1m07-supabase.vercel.app/dashboard/org
Documentation:
https://docs-kht98bi78-supabase.vercel.app/docs/guides/platform/access-control

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->


## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary

* **Updates**
* The **None** role is labeled **No-access** and describes the lack of
organization and project resource access.
* **None** is included after **Read-only** in the role list. When
inviting a member with project-only access, **None** is disabled with an
explanation.
* **Documentation**
* Clarified plan coverage for **Read-Only** and **No access**, and added
guidance on assigning **No access** at the organization level before
granting project-specific roles.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-05 19:54:55 +07:00
Ben Fritsch 901d1915b6 add Ben Fritsch to humans.txt (#51265)
Adding myself to humans.txt
2026-10-05 14:32:29 +02:00
Johan Bergström 63718b4b84 feat(docs): render experimental badge for Management API endpoints
Management API endpoints now supports expressing an "experimental" stage
where we previously only marked it as deprecated.

We now render the badge as experimental instead and avoid the strikethrough.

This clearly shows that the endpoint is not to be removed, but rather being
tested for inclusion.

PR: https://github.com/supabase/supabase/pull/51045
2026-10-05 07:35:51 +01:00
Riccardo Busetti 4ab54b9359 ref(docs): Make ClickHouse, Snowflake and DuckLake in public alpha (#51195) 2026-10-02 18:40:44 +00:00
b0597aa5fa Add health advisor doc (#51144)
Add docs with bare min information abotut he addition of the 4 new
health advisors

## Problem

no docs on health advisors

## Solution

added docs covering health advisors


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added health advisors for persistently high error rates in the Data
API, Auth, Storage, and Edge Functions.
* Findings include links to relevant troubleshooting guidance and
instructions for reviewing recent errors or failed invocations in Studio
Logs, MCP, or the Management API.

* **Documentation**
* Updated the advisors guide to describe health, security, and
performance checks, with examples and links to access advisors in Studio
and the Management API.
* Clarified that findings may be intentional and can take time to clear
after a fix.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Saxon Fletcher <saxonafletcher@gmail.com>
Co-authored-by: Nik Richers <nrichers@gmail.com>
2026-10-02 12:33:25 -05:00
Raúl BarrosoandClaude Sonnet 5 11488801f7 docs(byo-mcp): how to use with custom domains (#51085)
## Problem

As part of my investigation of this
[issue](https://linear.app/supabase/issue/AI-1263/test-byo-mcp-with-custom-domains)
I realized that, in order for byo-mcp to work with custom domains,
there's a tweak needed, and I'm documenting it here.

The long term use to fix it lives
[here](https://linear.app/supabase/issue/FDBKIN-20212/use-custom-domain-in-oidc-and-oauth-well-known-discovery-endpoints).
With that one in place, we could remove the clarification and the
experience would be much much simpler.

Fixes AI-1263

## Solution

I'm documenting for now, and will follow up if something else needs a
change.

## Review instructions

Provide a clear numbered procedure that the PR reviewer can walk
through.

1. Visit `docs/guides/ai-tools/byo-mcp` and read the added text. 
2. See if it all makes sense.
3. Ask @raulb if something's not clear or confusing. 

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added guidance for configuring MCP authorization metadata with a
custom domain, including setting the authorization server to the
Supabase Auth project issuer and checking it against the advertised
metadata.
* Clarified that the resource URL continues to use the domain requested
by the client, and that leaving the issuer setting unset locally retains
the default.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-02 19:07:46 +02:00
Nik RichersandNik Richers 0405b31b26 docs: re-publish Multigres Private Alpha docs — merge on October 2, 2026 (#50664)
## I have read the CONTRIBUTING.md file.

YES

## What kind of change does this PR introduce?

Re-add. Reapplies the Multigres Private Alpha docs section removed in
#50662, ready to merge once Sugu gives the go-ahead. Do not merge until
then.

Linear: MUL-1621 (follow-up to MUL-452).

## What is the current behavior?

Multigres docs section is down (per #50662): no overview/compatibility
pages, no sidebar entry, no features-table row, no "What you get" cards.

## What is the new behavior?

Exact reapply of #49020 (with Multigres marked Private Alpha): overview
guide at `/docs/guides/database/multigres`, compatibility stub, Database
sidebar entry, features-table row, "What you get" cards, and the
`ContentListings` optional-`href` support they rely on.

Base branch is the revert PR (#50662) so the diff here is legible now;
retarget to `master` once #50662 merges.

## Additional context

- `pnpm --filter docs exec vitest run lib/content-listings.test.ts` — 22
passed
- Blocked on Sugu's go-ahead — `do-not-merge` label applied

---------

Co-authored-by: Nik Richers <nik@validmind.ai>
2026-10-02 09:18:25 -07:00
Anthony Lio b13d6c2878 feat(chore): add a lint ratchet for shadcn rules (#51014)
## Problem

shadcn lint rules has been soft landed in #50676 and are now on as
warnings in every app, but nothing stops a PR from adding new violations

linear: FE-4473

## Solution

- moved the ratchet script and its tests from `apps/studio/scripts` to
`packages/eslint-config-supabase` so every app runs one copy
- added a shared rule list,
`packages/eslint-config-supabase/ratchet-rules.json` with the shadcn
rules
- www, docs, design-system, ui-library and learn get `lint-ratchet.yml`
with one job per changed app (triggered by the app, `packages/**` or the
lockfile) + a weekly `lint-ratchet-decrease.yml` (as for studio ratchet)
- package tests run in `eslint-config-supabase-tests.yml`

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

1. run `pnpm --filter ./apps/www run lint:ratchet`
2. add `p-[13px]` to a `className` in any www component and run it
again. it fails with `shadcn/no-arbitrary-values` and the file name with
`(+1)`
3. revert change
4. run `pnpm --filter eslint-config-supabase test` and see 6 tests pass
5. in ci, check `Ratchet studio lint checks` and the `ratchet (<app>)`
jobs for the apps this pr touches

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Developer Improvements**
* Expanded automated lint checks to cover additional apps and shared
package changes.
* Added checks for arbitrary Tailwind values, unknown classes, and raw
colors across supported apps.
* Added automated baseline updates that can open or update a pull
request when lint counts change.
* Added tests for the lint configuration and support for combining
multiple rule files.
* Updated Studio lint notifications to exclude Shadcn rules with
zero-baseline counts.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-02 14:13:59 +03:00
Kunal IngawaleandKaterina Skroumpelou 73260dfaba docs: correct the built-in retry behaviour in the supabase-js retry guide (#50749)
## Problem

[The built-in retry
guide](https://supabase.com/docs/guides/api/automatic-retries-in-supabase-js)
describes retry behaviour that `supabase-js` doesn't have. Three claims
in the "Built-in retries for PostgREST queries" section don't match the
code:

| The page says | The code does |
| --- | --- |
| "POST requests (used by PostgREST) are retried" | POST is **never**
retried |
| Retries cover "408, 409, 503 and 504" | Only `503` and `520` |
| "exponential backoff with jitter" | No jitter — the delay is
deterministic |

**The POST claim is the serious one.** It tells a reader that their
writes are retried when they aren't, which invites exactly the wrong
conclusion about how to handle a failed insert. Someone reading this
page would reasonably skip their own retry or idempotency handling on
writes, on the strength of a guarantee the library doesn't make.

The source of truth, from
`packages/core/postgrest-js/src/types/common/common.ts` on `supabase-js`
master:

```ts
export const RETRYABLE_STATUS_CODES = [520, 503] as const
export const RETRYABLE_METHODS = ['GET', 'HEAD', 'OPTIONS'] as const
export const DEFAULT_MAX_RETRIES = 3
export const getRetryDelay = (attemptIndex: number): number =>
  Math.min(1000 * 2 ** attemptIndex, 30000)
```

`shouldRetry` in `packages/core/postgrest-js/src/fetchWithRetry.ts`
gates on both constants, so a request is retried only when the method is
in `RETRYABLE_METHODS` *and* the status is in `RETRYABLE_STATUS_CODES`.
`getRetryDelay` is a pure function of the attempt index, with no random
component — hence no jitter.

There's a fourth, subtler consequence. The intro says built-in retries
apply to `.from()` and `.rpc()`, but `.rpc()` sends POST unless you pass
`{ get: true }` or `{ head: true }`, so RPC calls aren't retried by
default. A reader who takes the intro at face value would expect retries
on exactly the calls that don't get them.

## Solution

Corrected the three claims in place. No restructuring, no new sections,
no change to the `fetch-retry` half of the page.

- **Methods.** Replaced the sentence claiming POST is retried with the
actual rule, and stated the consequence plainly — a write is never sent
twice.
- **Status codes.** `503 Service Unavailable` and `520 Unknown Error` in
place of 408, 409, 503 and 504.
- **Jitter.** Dropped the word, since the backoff has none.
- **`.rpc()`.** Added one sentence noting that RPC sends POST by
default, so it isn't retried unless called with `{ get: true }`.

The diff is 3 changed lines and 2 added, all in one paragraph group.
This is a technical correction only — I deliberately left the page's
style and structure alone, so the diff stays readable as a single change
of one kind.

### Note on an incoming change

supabase/supabase-js#2699 proposes adding `521`, `522`, `523` and `524`
to `RETRYABLE_STATUS_CODES`. It is open, not merged. This PR documents
what `master` does today, and if that one lands the status sentence here
needs `520-524` rather than `520`. Happy to follow up with that change
once it merges, or to fold it in if you'd rather wait and land both
together.

## Review instructions

1. Open `packages/core/postgrest-js/src/types/common/common.ts` in
`supabase/supabase-js` on `master` and read `RETRYABLE_STATUS_CODES` and
`RETRYABLE_METHODS`.
2. Compare them against the live page's second paragraph. The status
list and the method list both differ.
3. Read `shouldRetry` in
`packages/core/postgrest-js/src/fetchWithRetry.ts` and confirm it
returns `false` for any method outside `RETRYABLE_METHODS`, POST
included.
4. Read `getRetryDelay` in the same `common.ts` and confirm there is no
random component, so "with jitter" doesn't hold.
5. Check `rpc()` in `packages/core/postgrest-js/src/PostgrestClient.ts`
and confirm the method is POST unless `get` or `head` is passed.
6. Read the preview page and confirm the corrected paragraphs say the
same thing the code does.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide

## Additional context

One suggestion, which I've deliberately left out of the diff because
it's an addition rather than a correction — your call whether it belongs
on this page.

The guide sets no request timeout anywhere, in either the built-in
section or the `fetch-retry` examples. That matters because a retry only
fires once a request has failed. A request that is merely hanging never
fails, so it never triggers a retry, and the caller waits for whatever
the platform's own timeout turns out to be.

This isn't hypothetical. During a Cloudflare edge incident on 22
September 2026, PostgREST calls from Edge Functions stalled for 20 to 60
seconds and returned `522`. Supabase Support confirmed the elevated 522s
were platform-wide at the time rather than specific to one project. The
built-in retry fired on none of them — partly because `522` isn't in the
list, but also because a stalled request never reaches the retry check
at all.

A sentence pointing readers at `AbortSignal.timeout` alongside the retry
would close that gap:

```javascript
const { data, error } = await supabase
  .from('your_table')
  .select('*')
  .abortSignal(AbortSignal.timeout(10_000))
```

Happy to write that up as a short subsection if you want it — tell me
where you'd like it to sit and I'll open a separate PR so this
correction stays reviewable on its own.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Clarified that automatic retries apply only to idempotent GET, HEAD,
and OPTIONS requests that encounter HTTP 503 or 520 responses, or
network failures.
* Documented that RPC calls use POST by default and are not retried, and
that `{ get: true }` or `{ head: true }` can use retryable methods.
* Added guidance for using `AbortSignal.timeout(10_000)` to limit
requests that hang before retry handling.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Katerina Skroumpelou <sk.katherine@gmail.com>
2026-10-02 14:13:39 +03:00
531431cd77 docs: document MCP cost confirmation via elicitations (#50017)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Docs update for the MCP cost confirmation launch
([AI-1161](https://linear.app/supabase/issue/AI-1161/write-the-docs)).

## What is the current behavior?

The MCP server guide lists `get_cost` / `confirm_cost` but doesn't
describe the elicitation-based cost confirmation flow that
`@supabase/mcp-server-supabase` 0.12.0 introduces for `create_project`
and `create_branch` on form-capable clients.

## What is the new behavior?

- New **Cost confirmation** section in the MCP server guide: how the
elicitation flow works (accept / decline / expiry / rate-change
outcomes, all side-effect-free except accept), the zero-cost skip,
client support, and how to tell which cost flow a connection uses.
- New troubleshooting entry: "Cost confirmations do not appear in your
MCP client".
- Three `supa-mdx-lint` dictionary additions the new prose needs
(`elicitation(s)`, `dialogs`, `pauses`).

## Additional context

**Draft — hold until launch.** Merge gates before publishing:

1. The feature is enabled for hosted connections.
2. The client support table is re-verified against launch verification
results (there's a matching `{/* ... */}` reviewer note above the
table). Client support moves quickly; the table reflects verification as
of 2026-09-04.

Needs review:

- **Rate-change behavior follows the shipped code, not the spec docs**:
on any change to the computed cost between confirmation and creation
(including a decrease), the server reissues a fresh confirmation rather
than proceeding (`account-tools.ts` redemption path in supabase/mcp).
Flagging in case the intent was lower-or-equal proceeds.
- No exact confirmation expiry is stated because the TTL is
deployment-configured (`ttlSeconds`).
- Wording deliberately says "client-mediated" style confirmation and
avoids claiming a person approved each action, since clients can answer
elicitations via hooks.

Test plan: `supa-mdx-lint` clean on both files; Prettier (repo config)
clean. No runnable snippets, so no sandbox verification needed. Vercel
preview link will appear below.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added advanced options to hosted MCP connections for skipping selected
cost or destructive-SQL confirmations when supported. Available options
depend on connection scope, enabled features, and read-only settings.
* The configuration panel explains when skip selections are unavailable
or ignored by certain client configurations.

* **Documentation**
* Added guidance on cost and SQL confirmation prompts, Edge Function
secret entry, and troubleshooting missing prompts or unavailable secret
collection. This includes client requirements, fallback behavior, and
relevant security considerations.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Barry Roodt <barry.roodt@supabase.io>
2026-10-02 08:58:34 +02:00
Wen Bo Xie ffd2754c7a docs(cli): document experimental supabase stack commands and native runtime (#50391)
Add two guides under Local Development for the experimental `supabase
stack` commands, wire them into the docs nav, the CLI reference, the
marketing features list, and the pages that readers reach with a port
conflict.

New pages:
- guides/local-development/parallel-projects: run one local project per
app, git worktree, branch, or named environment on a single machine.
Covers identity, automatic port assignment, removing fixed ports from
config.toml, named projects, finding endpoints, stop and destroy, the
`[experimental] stack` setting, and current limitations.
- guides/local-development/runtimes: the Docker and native runtimes, how
the CLI picks one, native platform requirements, artifact download and
cache locations, and runtime limitations.

Cross-links and context:
- Local development index, CLI getting started, CLI workflows, managing
environments, AI tools, MCP, and the edge functions port troubleshooting
entry now point readers to the new guides where a second `supabase
start` fails on a port conflict.
- CLI reference: `supabase stack`, `stack start`, `stack stop`, `stack
destroy`, the `experimental.stack` config key, and a note on `supabase
start` and `[experimental] stack`.
- www: two feature entries and copy tweaks on the hosted Postgres and
innovation teams solution pages.
- supa-mdx-lint: allow worktree, glibc, musl, and checksum.
2026-10-02 08:39:18 +02:00
Danny White 6143441493 fix(pipelines): clarify DuckLake destination setup (#51013)
## Problem

The DuckLake setup form makes it hard to choose between Supabase
projects and external connection details. Bucket creation, catalog
settings, and the guide do not clearly follow the setup flow.

## Solution

- Show **Configuration method** as two clear choices: **Select Supabase
projects** and **Enter connection details**.
- Group catalog and storage fields, move **Pool size** to **Advanced
settings**, and add **New bucket** to the bucket selector.
- Clarify the custom Postgres and S3 fields, including the metadata
schema, connection URL, and storage options.
- Update the [DuckLake destination
guide](https://docs-git-dnywh-ducklake-pipelines-setup-supabase.vercel.app/docs/guides/database/replication/pipelines/ducklake)
to follow the form and explain resource preparation and validation.

| Before | After |
| --- | --- |
| <img width="1280" height="1323" alt="50587"
src="https://github.com/user-attachments/assets/bf5997cf-9fc4-48a8-ad4f-13fa991d56f9"
/> | <img width="1280" height="1323" alt="61914"
src="https://github.com/user-attachments/assets/2c1dd7ef-797f-4302-9e2e-93a5f1e6e515"
/> |

## Review instructions

1. Open **Database > Pipelines > Add pipeline** and select **DuckLake**.
2. Select **Select Supabase projects**. Check the catalog and storage
fields, create a bucket from the bucket selector, and find **Pool size**
under **Advanced settings**.
3. Select **Enter connection details**. Check the Catalog URL, S3 URL
style, and Use SSL guidance.
4. Compare both routes with the [DuckLake destination
guide](https://docs-git-dnywh-ducklake-pipelines-setup-supabase.vercel.app/docs/guides/database/replication/pipelines/ducklake).

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] I used the `/edit-the-docs` skill and the docs [style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* DuckLake destinations support Supabase-managed projects or an existing
Postgres catalog with S3-compatible storage.
* Select a storage bucket using search, configure a metadata schema, and
access clearer guidance for catalog and storage settings.
* Advanced settings provide a connection pool size from 1 to 6, with a
default of 4. Credential fields include show and hide controls.
* **Documentation**
* Updated setup steps, configuration guidance, query credential details,
and troubleshooting instructions for both configuration modes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-02 10:34:49 +10:00
Steven EubankandClaude Opus 4.8 26010d80ce docs(observability): rename "Hire an agent" to "Agent prompts" (#51148)
The "Hire an agent" and "monitor" wording oversold the feature: it is
just a prompt you give an agent to check health, security, performance,
or resources, optionally on a schedule. Rename the group to "Agent
prompts", drop "monitor" from the four child pages (Health, Security,
Performance, Resources), and use plainer framing across the landing page
and observability hub. URL slugs are unchanged.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Renamed the Observability section to “Agent prompts” and updated its
page titles and descriptions to describe project checks.
* Clarified that prompts read project data without changing it, and that
findings can be sent through existing harness connections.
* Updated setup guidance to refer to running prompts and using “checks”
in task names.
* Renamed the Health, Security, Performance, and Resources entries. The
related links, schedules, and reporting details remain unchanged.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-10-01 23:20:06 +00:00
Andrey A. da2d0c46d7 docs(self-hosting): refresh the overview page (#51127) 2026-10-01 15:45:43 -07:00
Jonathan Smock 0fbd5f3037 chore: Add Jonathan Smock to humans.txt (#51115)
## Problem

I have an onboarding task to add myself to humans.txt

## Solution

I have added the characters "Jonathan Smock\n" to humans.txt

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

Please verify that I've inserted my name alphabetically and correctly
spelled.

## Checklist

Check all before review:

- [X] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [ ] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which applies the docs
[style
guide](https://github.com/supabase/supabase/tree/master/apps/docs/style-guide)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Added a team member to the team listing.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-10-01 13:22:40 +00:00
Julien GouxandIvan Vasilov 7b08726d3a docs(cli): document OrioleDB initialization and db.orioledb_version (#50908)
Document `supabase init --use-orioledb` in the CLI reference. Add
`db.orioledb_version` to the CLI config reference, and mark
`experimental.orioledb_version` as deprecated.

This complements the general OrioleDB beta guide update in #50813.

Companion CLI PR: https://github.com/supabase/cli/pull/6828, released in
[v2.119.0](https://github.com/supabase/cli/releases/tag/v2.119.0).


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Documented the `supabase init --use-orioledb` option, which sets the
OrioleDB image version in `supabase/config.toml`.
* Added configuration guidance for `db.orioledb_version`, including its
PostgreSQL version requirements.
* Marked `experimental.orioledb_version` as deprecated and directed
users to `db.orioledb_version`. The CLI continues to read the
experimental setting and warns when it is set.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Ivan Vasilov <vasilov.ivan@gmail.com>
2026-10-01 13:13:19 +02:00
Luiz Felipe Machado cf063c4ae8 docs: clarify self-hosted function timeout limits (#50807) 2026-09-30 18:07:29 -07:00
Pamela Chia 232eb921ed fix(docs): omit category sections from reference sitemap (#51069)
The Docs sitemap lists a `/reference/<sdk>/undefined` URL for every
reference category header, on both latest and versioned paths (for
example `/reference/kotlin/v1/undefined`). `generateReferencePages`
turns every flattened section into a link, and category headers never
carry a slug. Search engines get a 404 for the `api/undefined` entries
and a soft 404 for the SDK ones.

I filtered the sections with the same predicate the reference static
params already use (`type !== 'category' && !!slug` in
`Reference.utils.ts`). I ran the generator locally before and after the
change: the only entries it removes are the `/undefined` ones (about 4%
of the sitemap), and it adds none.

**Note:** `getFlattenedSections` stays unchanged because the crawler
route and the reference pages share it.

## To test

Tested on Vercel preview:
- [x] Fetch `/docs/sitemap.xml` on the Docs preview and search for
`/undefined</loc>`: expect no matches
- [x] In the same file, search for `/docs/reference/javascript/select`
and `/docs/reference/kotlin/v1/select`: expect both still listed

## Linear
- fixes GROWTH-1310


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Reference pages no longer generate links for category sections or
sections without a slug. Existing link paths and priorities remain
unchanged.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 17:13:52 -07:00
Pamela Chia 5a7c0d6d84 fix(docs): resolve legacy sdk reference urls (#51064)
I made the crawler renderer resolve legacy JavaScript and Dart reference
slugs to their current sections, and updated authored guide and SDK spec
links to use them. Exact slugs still win, ambiguous bare slugs still
return 404, and `file-buckets-listv2` remains a section slug in
canonical links. I kept the www redirect work in a separate draft PR
because the apps deploy independently.

## To test

- [x] On the Docs preview, request `reference/javascript/order` and
`reference/dart/get-user` with a bot user agent. Expect the intended
heading and canonical URL.
- [x] Request `reference/javascript/file-buckets-listv2` with bot and
browser user agents. Expect it to open the list v2 section.
- [x] Request `reference/swift/get-user` and the Kotlin reference root
with a bot user agent. Expect the intended heading.
- [x] Open the Storage quickstart guide and follow its upload reference
link. Expect the current JavaScript upload section.

## Linear

refs GROWTH-1293


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Reference pages now resolve legacy aliases and ambiguous slugs more
accurately, with canonical links that preserve explicit SDK versions.
* SDK version paths are recognized only when the full path segment
matches the version format, improving reference-page routing.

* **Documentation**
* Updated API reference links across authentication, storage, security,
and SDK guides to point to current pages.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 17:11:53 -07:00
Miranda Limonczenko 9a60894bfa docs(functions): edit the secrets guide against the new style guide (#50763)
Production secrets sat after two non-procedure sections, so the reader
setting up a key crossed reference material to get from the local steps
to the production ones. Move it up to follow Local secrets, which runs
all four procedure sections unbroken before the reference sections.

Group "Where local values come from" and "Default secrets" under a
Reference heading. Both answer "what are its parts?", so both are
Structure under the style guide's information types, and Reference is
the group the worked outline ends with. They demote from H2 to H3,
which keeps them in the page TOC, since it is built from h2 and h3.

No heading is renamed, so the anchors Studio deep-links into
(#default-secrets, #using-the-cli) and the one the secrets-limit
troubleshooting page uses (#accessing-environment-variables) are
intact. Changing a heading's level preserves its slug.

Glue the new shape needs: an outline of the three section groups at the
top, a transition out of the troubleshooting section, and an opening
line under Reference.
2026-09-30 14:36:29 -07:00
Miranda Limonczenko e29f4e0736 docs(database): style pass on the database functions guide (#50820)
Inline rewording only. Nothing moves and no claim changes.

Addresses reader-facing "we", UI labels in quotes rather than bold, "allows
you to", "e.g.", future tense, and title-case common nouns in body prose.
2026-09-30 14:36:17 -07:00
Miranda Limonczenko 19188ece58 docs(functions): style pass on the Edge Function auth guide (#50884)
Apply the docs style guide to Securing Edge Functions. Inline changes only.

- Open the page with a value statement
- Split the sentences that ran past the 26-word aim, and keep one
  relationship per sentence
- Replace dash-bounded asides with separate sentences
- Lift `(the default)` out of parentheses so it reads as a claim
- Name the section instead of "above" and "the sections below"
- Introduce the mode table in the sentence before it
- Raise the `auth: 'none'` admonition to `danger`, and state it in the
  positive form
- Stop restating that admonition in the Public functions section
- Spell out Row Level Security, and name `@supabase/server` rather than
  "the SDK"
- Use Supabase Dashboard and Supabase Platform consistently
- Use "function" rather than "endpoint", and spell out "db"
- Link `@supabase/server` once, and name it as a GitHub destination
- Rewrite the Secret keys alt text to describe both rows, the column
  headers, and the masked key format
2026-09-30 14:36:05 -07:00
Jeremias Menichelli 99103b3571 feat: Add edge function and hooks for search V2 (#51103) 2026-09-30 18:12:07 -03:00
Andrew ValleteauandClaude 2cb70302b0 docs(cli): recommend OrbStack as primary Docker alternative on macOS (#51101)
## Problem

The documentation currently lists Docker Desktop as the preferred option
for all platforms, but OrbStack is a superior alternative on macOS that
offers better performance (faster startup, lower CPU/memory/disk usage).
Users on macOS should be guided toward OrbStack first.

## Solution

Reordered and updated the container runtime recommendations to:
1. Highlight OrbStack as the recommended option specifically for macOS
2. Position Docker Desktop as the recommended option for Windows and
Linux
3. Moved OrbStack higher in the list to reflect its priority on macOS
4. Added a dedicated paragraph in the CLI getting started guide
explaining OrbStack's benefits and why it's recommended over Docker
Desktop on macOS

The changes improve the developer experience by directing macOS users
toward the more performant option while maintaining clear guidance for
other platforms.

## Review instructions

1. Open the preview links for the modified documentation pages
2. Verify that OrbStack is now listed first and marked as "recommended
on macOS"
3. Verify that Docker Desktop is now marked as "recommended on Windows
and Linux"
4. Check the CLI getting started guide to confirm the new paragraph
about OrbStack's benefits is clear and helpful
5. Ensure the information is consistent across both modified files

## Checklist

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] Documentation changes follow the docs style guide

https://claude.ai/code/session_01Nbp9LwhMkqxEvQJzEVUbwt

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated local development guidance to recommend OrbStack for macOS and
Docker Desktop for Windows and Linux.
* Clarified that OrbStack supports extended file attributes on mounted
volumes and container networking, and added startup and resource-use
comparisons with Docker Desktop.
* Listed Rancher Desktop and Podman as alternatives; the CLI guide also
lists Colima.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-09-30 17:04:49 +00:00
supabase-supabase-autofixer[bot]andzamotany e54394cfd8 feat: update mgmt api docs (#49743)
This PR updates Management API docs automatically.

This regenerates:

- Management API specs and sections
- Personal Access Tokens permission-to-endpoint table
- Personal Access Tokens MCP tool permissions table

Sources include the live Management API specs, MCP permission map,
and Studio's shared permission catalog.

Co-authored-by: zamotany <17573635+zamotany@users.noreply.github.com>
2026-09-30 18:34:09 +02:00
samroseandArtur Zakirov 9946747579 docs(orioledb): update OrioleDB docs for public beta (#50813)
> [!IMPORTANT]
> Don't merge until the OrioleDB public beta launches. Docs deploy on
merge.

## What

Updates the OrioleDB guide (`guides/database/orioledb`) for the public
beta:

- States that OrioleDB is in public beta and that OrioleDB projects have
access to the same paid features as other Supabase projects.
- Replaces the outdated "choose `OrioleDB Public Alpha` Postgres
version" instruction and its screenshot with text steps that match the
current project creation form (**Advanced Configuration** → **Postgres
Type** → **Postgres with OrioleDB**). It also notes that OrioleDB can't
be added to or removed from an existing project. A new screenshot will
follow once the dashboard shows the beta labels.
- Corrects the `orioledb.default_compress` range to `-1` to `22`. Values
outside that range are rejected.
- Updates the `EXPLAIN` output for the primary key lookup to match what
OrioleDB returns (`Custom Scan (o_scan)`).
- Replaces the benchmark chart's alt text with a description of the
chart.

Headings, frontmatter, and navigation are unchanged, so existing links
to this page and its sections still work.

## Checked against upstream OrioleDB

Checked the page's claims against the [OrioleDB
docs](https://github.com/orioledb/orioledb/tree/main/doc/usage) and
codebase on `main`:

- The concepts section, the `orioledb.serializable` values, and the
compression settings match.
- The limitations link still resolves (`#current-limitations`).
- Doc changes on `main` since beta17 (collations, sparse files,
concurrent unique bridged indexes) don't affect claims on this page.

## Verification (`/test-the-docs`)

| Snippet / step | Class | Sandbox | Result | Notes |
| --- | --- | --- | --- | --- |
| `create table blog_post …` | runnable-local | DinD + runner,
`supabase/postgres:17.9.0.028-orioledb` | pass | Table created with the
`orioledb` access method (default) |
| `create index …` (2 indexes) | runnable-with-setup | same | pass | |
| `insert …` + `select …` | runnable-with-setup | same | pass |
Timestamp differs, as expected |
| `explain` (3 statements) | runnable-with-setup | same | pass | Primary
key lookup output updated in this PR to match |
| `select … from pg_settings where name like 'orioledb.%'` |
runnable-local | same | pass | All 10 automatically tuned settings
present |
| `alter database … default_compress to 1` | runnable-local | same |
pass | |
| Compression range `-1`–`22` | claim check | same | pass | `23`
rejected: "outside the valid range (-1 .. 22)" |
| User-configurable settings have `user` context | claim check | same |
pass | `serializable` values match the page |
| Hidden `ctid` key when no primary key is defined | claim check | same
| pass | |
| HNSW index via index bridging | claim check | same | fail (product
bug) | Index misses rows inserted after it's created. Known upstream as
orioledb/orioledb#1118, fixed after beta17. The tested image bundles an
earlier OrioleDB release. Re-test on an image with beta18 before
merging. |
| Dashboard project creation steps | deferred | — | deferred | Needs a
hosted project; labels checked against Studio source |

**Tier A path:** every SQL block on the page, run in page order against
the Supabase OrioleDB image.

**Environment:** Docker 29.4.0 (linux/aarch64); compose sandbox from
`test-the-docs`; all SQL run inside the runner container.

**Build:** `pnpm build:guides-markdown` passes; the generated markdown
for this page includes all changes.

## Self-review

**Blockers:** none.

**Before merging:**

- [ ] Re-run the HNSW check on an image with OrioleDB beta18.
- [ ] Re-check the page against the `beta18` tag once it's published.

**Nits left for a follow-up (existing text, outside this PR's scope):**

- The page spells `pg_vector`; the extension is `pgvector`.
- Index support is described twice, in the top note and again under
"Creating indexes".
- The markdown export (`internals/markdown-schema/Admonition.ts`) drops
admonition titles on every page. This PR avoids relying on a title for
the beta status.

Linear: DOCS-1399

🤖 Generated with [Claude Code](https://claude.com/claude-code)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated the OrioleDB guide with benchmark results for an 8xlarge
instance, including a 1.8x speedup and throughput data across 32–256
connections.
* Clarified that OrioleDB projects have access to the same paid features
as other Supabase projects, and added guidance to review its
limitations.
* Updated project setup instructions, noting that OrioleDB must be
selected when creating a project and cannot be added later or removed.
* Revised the query plan example and documented compression levels from
`0` through `22`.
* **Product Updates**
  * Updated OrioleDB’s availability stage to public beta.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Artur Zakirov <zaartur@gmail.com>
2026-09-30 11:42:21 -04:00
Paweł Gulbinowiczandcoderabbitai[bot] 032c71c5bf fix(docs): use summary instead of slug for webhooks api spec (#51088)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix

## What is the current behavior?

Operations names for webhooks in Organizations webhooks and Project
webhooks use titles derived from slug, which produces wrong/incoherent
titles, for example: `Organizations slug webhooks deliveries id get`.

## What is the new behavior?

For Organizations webhooks and Project webhooks use `summary` from the
OpenAPI spec as the title instead of deriving it from the operation id.

## Additional context

Once this PR is merged, an _Update Mgmt Api Docs_ workflow needs to be
run to regenerate the sections and the spec.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Management API documentation section titles for organization and
project operations now use the OpenAPI summary when one is available. If
no summary is provided, the title falls back to the existing name-based
format. Titles for other operations continue to use the existing format,
so their presentation is unchanged.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-09-30 17:25:17 +02:00
Kevin Webb 525c1de326 chore: Add Kevin Webb to humans.txt (#51093)
## Problem

Kevin Webb joined team and needs to add name to humans.txt as part of
onboarding

## Solution

Edited humans.txt and added Kevin Webb 

## Review instructions

Confirm name is correctly alphabetized.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated the team listing to include Kevin Webb, keeping the published
team information current. This change is visible in the project’s public
documentation.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 14:39:01 +00:00
Katerina Skroumpelou 2013ebf417 docs: drop alpha labels and pin server and middleware imports to a major (#51031)
## Problem

`@supabase/middleware` ships as 1.0.0. The docs still label the
`pipeline` entry form of `withSupabase` alpha, and several snippets
import `npm:@supabase/server` and `npm:@supabase/middleware` with no
version or with a `^0.5.0` pin. A snippet without a version leaves
readers and tools to guess one, and a guessed version fails on deploy.

## Solution

- Removes the alpha wording from the middleware reference intro and
usage examples, the server frameworks partial, and the Bring your own
MCP guide. The `@supabase/server` 1.6.0 floor stays.
- Pins every `npm:@supabase/server` and `npm:@supabase/middleware`
import in the guides to a major range, `@1`, following the
`npm:@supabase/supabase-js@2` convention in Managing dependencies.
- Bumps the authenticated-mcp-server example to middleware `^1.0.0` and
server `^1.9.0`.

~~Blocked by supabase/middleware#49. The `@1` range resolves once 1.0.0
is on npm.~~




<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated authentication, API key, and MCP examples to use versioned
Supabase server and middleware packages.
* Clarified that pipeline and nested composition behave the same, and
that both require `@supabase/server` 1.6.0 or later.
* Removed alpha-status labels from `withSupabase` guidance while
retaining the 1.6.0 minimum-version requirement.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 17:27:44 +03:00
mkaruzaandmkaruza b59447d310 chore: Add Mario Karuza to humans.txt (#50710)
## What kind of change does this PR introduce?

Docs update

## What is the current behavior?

humans.txt doesn't list my name.

## What is the new behavior?

Add to humans.txt

## Additional context

Done as part of the onboarding tasks.

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated the public team information to include Mario Karuza. The
listed team members now reflect this addition.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: mkaruza <mkaruza@users.noreply.github.com>
2026-09-30 16:02:12 +02:00
Andrey A. e811d984ad docs(auth): inline the Remix code in the OAuth troubleshooting (#50854) 2026-09-30 07:44:50 -06:00
Andrey A. c8b665caf2 feat(self-hosted): add api gateway logic for functions (#46810) 2026-09-30 11:14:47 +02:00
Steven Eubank ad0ed2cdbc Update docs based on SRE Agent findings (#50910)
## Problem

SRE Agent running against a project which is read-only due to disk being
full.

## Solution

The SRE agent struggled to find the information which is now included in
this PR.

<!--
## Preview links

If relevant, include links to changed pages for easy review access.

Copy the preview base URL from the Vercel bot comment on this PR. Use
the following table as an example template.

| Site | Live | Preview | Search for |
| -------------- |
-------------------------------------------------------------------------
|
------------------------------------------------------------------------------------------------------------
| ----------------------------- |
| WWW | [/blog/your-post](https://supabase.com/blog/your-post) |
[/blog/your-post](https://zone-www-dot-com-git-branch-name-supabase.vercel.app/blog/your-post)
| unique phrase from the change |
| Docs |
[/docs/guides/your-page](https://supabase.com/docs/guides/your-page) |
[/docs/guides/your-page](https://docs-git-branch-name-supabase.vercel.app/docs/guides/your-page)
| unique phrase from the change |
| Studio | [/dashboard](https://supabase.com/dashboard) |
[/dashboard](https://studio-git-branch-name-supabase.vercel.app/dashboard)
| unique phrase from the change |
| Design system | [/design-system](https://supabase.com/design-system) |
[/design-system](https://design-system-git-branch-name-supabase.vercel.app/design-system)
| unique phrase from the change |
| UI library | [/library](https://supabase.com/library) |
[/library](https://ui-library-git-branch-name-supabase.vercel.app/library)
| unique phrase from the change |
| Knowledge base |
[/kb/guides/your-page](https://supabase.com/kb/guides/your-page) |
[/kb/guides/your-page](https://kb-git-branch-name-supabase.vercel.app/kb/guides/your-page)
| unique phrase from the change |
-->

<!-- ## Additional context

Optionally add any other context or screenshots.

-->

## Review instructions

- https://supabase.com/docs/guides/api/rest/postgrest-error-codes
- https://supabase.com/docs/guides/observability/advanced-log-filtering
- https://supabase.com/docs/guides/platform/database-size

## Checklist

Check all before review:

- [x] I have read
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
- [x] If I wrote a new docs topic or edited an existing topic, I used
the `/write-the-docs` or `/edit-the-docs` skill, which references
[WORD_LIST](https://github.com/supabase/supabase/blob/master/apps/docs/WORD_LIST.md)
and the docs
[CONTRIBUTING](https://github.com/supabase/supabase/blob/master/apps/docs/CONTRIBUTING.md)
guide


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added guidance for recognizing platform-related PostgreSQL errors,
including read-only mode, disk exhaustion, connection-pool limits, and
database restarts or failovers.
* Added SQL queries for grouping PostgreSQL errors and reviewing recent
error events while filtering out selected platform-level codes.
* Clarified that read-write transaction settings apply only to the
current session, and that background writes resume automatically after
read-only mode ends.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 20:55:02 -05:00
Saxon FletcherandClaude Opus 5.5 a9c594a820 chore(library): rename mcp-server block to mcp (#50999)
Renames the `mcp-server` Library block to `mcp`. Installing it now
creates `supabase/functions/mcp`, so the server is served at
`/functions/v1/mcp`.

- Block, Edge Function folder, and docs page renamed
(`/docs/headless/mcp`)
- Headless App block now installs its tools into
`supabase/functions/mcp` and configures `[functions.mcp]`
- Links in the BYO MCP and MCP authentication guides updated
- Permanent redirects keep `/r/mcp-server.json` and
`/docs/headless/mcp-server` working
- `public/r` rebuilt


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
* The MCP Server block is now named `mcp` across its documentation,
installation links, and setup instructions.
  * Updated function endpoints and deployment commands to use `/mcp`.
* Added permanent redirects from the previous `mcp-server` documentation
and install URLs to their new locations.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 11:46:35 +10:00
Danny White 6b7c91a773 docs(pipelines): clarify ClickHouse setup and form copy (#51009)
## Problem

The ClickHouse destination guide leaves parts of resource setup unclear.
The pipeline form suggests the `default` ClickHouse user and database
even when a dedicated user and database are prepared.

## Solution

- Clarify the ClickHouse setup path, connection details, engine choice,
and query example in the guide.
- Align the pipeline form's labels, examples, and help text with that
setup path.
- Include **Start pipeline** in the BigQuery guide before the cost
confirmation and **Create and start pipeline**.

## Review instructions

1. Open **Database → Pipelines**, add a pipeline, and choose
**ClickHouse**. Check the endpoint label, user and database examples,
and table engine help.
2. Read the [ClickHouse destination
guide](https://supabase.com/docs/guides/database/replication/pipelines/clickhouse),
especially **Prepare ClickHouse resources** and **Configure ClickHouse
as a destination**.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Updated the BigQuery guide to explain the pipeline validation, cost
review, and start steps.
* Expanded the ClickHouse guide with destination setup requirements,
engine behavior, and querying guidance for current-state views and
append-only history.
* **User Experience**
* Clarified ClickHouse connection field labels and descriptions,
password visibility controls, and table-engine options in the setup
form.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-30 09:44:06 +10:00
Pamela Chia 07c75e84fc fix(docs): repair internal content links (#51050)
I fixed stale links in six Docs pages. Guide links now include the Docs
base path, and links to the old Database Hooks route point directly to
the Dashboard Webhooks page.

## To test

- Open the Logs ingest guide in the Docs preview and follow the updated
guide links. Each destination should load.
- Open each affected Docs page in the preview and follow its Webhooks
link. The Dashboard Webhooks page should load after sign-in.

## Linear

- fixes GROWTH-1301


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Updated webhook setup and troubleshooting links to point to the
Integrations Webhooks dashboard.
* Updated Postgres configuration and log-setting links to use current
documentation paths.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-29 16:06:18 -07:00
Wen Bo Xie ed6217a169 docs: clarify how owners and admins authorize MCP clients for enterprise auth (#50832)
The enterprise-managed MCP authentication guide said an organization
owner authorizes the MCP client from the Authorized Apps page. That page
only lists and revokes apps that are already approved, so readers had no
way to follow the instruction.

Approval actually happens when an owner or admin connects the MCP client
through the standard sign-in flow and approves it for the organization
on the consent screen. Both roles can grant that approval, not only
owners.

This updates the prerequisites, the validation step, the "why use it"
summary, and the security considerations to:

- Name owners and admins as the roles that can authorize the client
- Describe the consent-screen approval as the way to authorize it
- Point to Authorized Apps as the place to review or revoke approved
clients
2026-09-29 08:56:54 -07:00