mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 17:35:10 +03:00
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update for the MCP cost confirmation launch ([AI-1161](https://linear.app/supabase/issue/AI-1161/write-the-docs)). ## What is the current behavior? The MCP server guide lists `get_cost` / `confirm_cost` but doesn't describe the elicitation-based cost confirmation flow that `@supabase/mcp-server-supabase` 0.12.0 introduces for `create_project` and `create_branch` on form-capable clients. ## What is the new behavior? - New **Cost confirmation** section in the MCP server guide: how the elicitation flow works (accept / decline / expiry / rate-change outcomes, all side-effect-free except accept), the zero-cost skip, client support, and how to tell which cost flow a connection uses. - New troubleshooting entry: "Cost confirmations do not appear in your MCP client". - Three `supa-mdx-lint` dictionary additions the new prose needs (`elicitation(s)`, `dialogs`, `pauses`). ## Additional context **Draft — hold until launch.** Merge gates before publishing: 1. The feature is enabled for hosted connections. 2. The client support table is re-verified against launch verification results (there's a matching `{/* ... */}` reviewer note above the table). Client support moves quickly; the table reflects verification as of 2026-09-04. Needs review: - **Rate-change behavior follows the shipped code, not the spec docs**: on any change to the computed cost between confirmation and creation (including a decrease), the server reissues a fresh confirmation rather than proceeding (`account-tools.ts` redemption path in supabase/mcp). Flagging in case the intent was lower-or-equal proceeds. - No exact confirmation expiry is stated because the TTL is deployment-configured (`ttlSeconds`). - Wording deliberately says "client-mediated" style confirmation and avoids claiming a person approved each action, since clients can answer elicitations via hooks. Test plan: `supa-mdx-lint` clean on both files; Prettier (repo config) clean. No runnable snippets, so no sandbox verification needed. Vercel preview link will appear below. 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added advanced options to hosted MCP connections for skipping selected cost or destructive-SQL confirmations when supported. Available options depend on connection scope, enabled features, and read-only settings. * The configuration panel explains when skip selections are unavailable or ignored by certain client configurations. * **Documentation** * Added guidance on cost and SQL confirmation prompts, Edge Function secret entry, and troubleshooting missing prompts or unavailable secret collection. This includes client requirements, fallback behavior, and relevant security considerations. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Barry Roodt <barry.roodt@supabase.io>