The enterprise-managed MCP authentication guide said an organization owner authorizes the MCP client from the Authorized Apps page. That page only lists and revokes apps that are already approved, so readers had no way to follow the instruction. Approval actually happens when an owner or admin connects the MCP client through the standard sign-in flow and approves it for the organization on the consent screen. Both roles can grant that approval, not only owners. This updates the prerequisites, the validation step, the "why use it" summary, and the security considerations to: - Name owners and admins as the roles that can authorize the client - Describe the consent-screen approval as the way to authorize it - Point to Authorized Apps as the place to review or revoke approved clients
Reference Docs
Supabase Reference Docs
Maintainers
If you are a maintainer of any tools in the Supabase ecosystem, you can use this site to provide documentation for the tools & libraries that you maintain.
DocSpec
We use documentation specifications which can be used to generate human-readable docs.
- OpenAPI: for documenting API endpoints.
- SDKSpec (custom to Supabase): for SDKs and client libraries.
- ConfigSpec (custom to Supabase): for configuration options.
- CLISpec (custom to Supabase): for CLI commands and usage.
The benefit of using custom specifications is that we can generate many other types from a strict schema (eg, HTML and manpages). It also means that we can switch to any documentation system we want. On this site we use Next.js, but on Supabase's official website, we use a custom React site and expose only a subset of the available API for each tool.
Contributing
To contribute to docs, see the style guide for how to write a page, and the developers' guide and contributing guide for repo mechanics. If you write with an AI coding agent, use the /write-the-docs skill to draft and /edit-the-docs to revise an existing page.