mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
The enterprise-managed MCP authentication guide said an organization owner authorizes the MCP client from the Authorized Apps page. That page only lists and revokes apps that are already approved, so readers had no way to follow the instruction. Approval actually happens when an owner or admin connects the MCP client through the standard sign-in flow and approves it for the organization on the consent screen. Both roles can grant that approval, not only owners. This updates the prerequisites, the validation step, the "why use it" summary, and the security considerations to: - Name owners and admins as the roles that can authorize the client - Describe the consent-screen approval as the way to authorize it - Point to Authorized Apps as the place to review or revoke approved clients