## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Fixes AI-1009 Updates the BYO-MCP guide so it includes information about the new middleware that will let users authenticate much more easily when building their own MCP server. This one includes a couple of clarifications which are important to document (use of environment variables, etc.) ## What is the new behavior? - Updated the existing guide (and example) for deploying an MCP server to use `@modelcontextprotocol/server` v2 with `createMcpHandler`. - Added new bits related to the new middleware which helps with authentication specifying the required versions of supabase/server and supabase/middleware, and also the auth prerequisites - Includes a table of where each MCP client takes the URL. - Added a new example to `examples/edge-functions/supabase/functions/mcp/` to illustrate the authentication example `authenticated-mcp-server`. ## Publish order > [!IMPORTANT] > There will be a companion PR to include the library components so this PR is blocked until https://github.com/supabase/supabase/pull/49579 ships. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added comprehensive guidance for deploying authenticated MCP servers with OAuth 2.1, Supabase Auth, and user-scoped data access. * Added an authenticated MCP server example with `list_todos` and `create_todo` tools, protected by row-level security. * Added setup instructions for OAuth configuration, consent screens, local testing, and deployment. * **Documentation** * Updated authentication guidance and MCP security warnings across related guides. * Added links to MCP server and OAuth consent resources. * **Refactor** * Simplified the unauthenticated MCP server example and updated its tooling configuration. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
Supabase Edge Function Examples
What are Supabase Edge Functions?
Supabase Edge Functions are written in TypeScript, run via Deno, and deployed with the Supabase CLI. Please download the latest version of the Supabase CLI, or upgrade it if you have it already installed.
Example Functions
We're constantly adding new Function Examples, check our docs for a complete list!
Develop locally
- Run
supabase start(make sure your Docker daemon is running.) - Run
cp ./supabase/.env.local.example ./supabase/.env.localto create your local.envfile. - Set the required variables for the corresponding edge functions in the
.env.localfile. - Run
supabase functions serve --env-file ./supabase/.env.local --no-verify-jwt - Run the CURL command in the example function, or use the invoke method on the Supabase client or use the test client app.
Test Client
This example includes a create-react-app in the ./app/ directory which you can use as a sort of postman to make test requests both locally and to your deployed functions.
Test locally
cd appnpm installnpm start
Note: when testing locally, the select dropdown doesn't have any effect, and invoke simply calls whatever function is currently served by the CLI.
Deploy
-
Generate access token and log in to CLI
- Navigate to https://supabase.com/dashboard/account/tokens
- Click "Generate New Token"
- Copy newly created token
- Run
supabase login - Input your token when prompted
-
Link your project
- Within your project root run
supabase link --project-ref your-project-ref
- Within your project root run
-
Set up your secrets
- Run
supabase secrets set --env-file ./supabase/.env.localto set the environment variables.
(This is assuming your local and production secrets are the same. The recommended way is to create a separate
.envfile for storing production secrets, and then use it to set the environment variables while deploying.)- You can run
supabase secrets listto check that it worked and also to see what other env vars are set by default.
- Run
-
Deploy the function
- Within your project root run
supabase functions deploy your-function-name
- Within your project root run
-
In your
./app/.envfile remove theSUPA_FUNCTION_LOCALHOSTvariable and restart your Expo app.
Test deployed functions
This example includes a create-react-app in the ./app/ directory which you can use as a sort of postman to make test requests both locally and to your deployed functions.
cd appcp .env.example .env- Fill in your env vars from https://supabase.com/dashboard/project/_/settings/api
npm installnpm start
Deploy via GitHub Actions
This example includes a deploy GitHub Action that automatically deploys your Supabase Edge Functions when pushing to or merging into the main branch.
You can use the setup-cli GitHub Action to run Supabase CLI commands in your GitHub Actions, for example to deploy a Supabase Edge Function:
name: Deploy Function
on:
push:
branches:
- main
workflow_dispatch:
jobs:
deploy:
runs-on: ubuntu-latest
env:
SUPABASE_ACCESS_TOKEN: ${{ secrets.SUPABASE_ACCESS_TOKEN }}
PROJECT_ID: your-project-id
steps:
- uses: actions/checkout@v3
- uses: supabase/setup-cli@v1
with:
version: latest
- run: supabase functions deploy --project-ref $PROJECT_ID
Since Supabase CLI v1.62.0 you can deploy all functions with a single command.
Individual function configuration like JWT verification and import map location can be set via the config.toml file.
[functions.hello-world]
verify_jwt = false
👁⚡️👁
\o/ That's it, you can now invoke your Supabase Function via the supabase-js and supabase-dart client libraries. (More client libraries coming soon. Check the supabase-community org for details).
For more info on Supabase Functions, check out the docs and the examples.