Files
supabase/apps/studio/lib/ai/tools/index.ts
T
Pedro RodriguesandClaude Opus 4.8 c4c213ce3d feat(studio): switch dashboard assistant to remote MCP server (#47479)
## I have read the
[CONTRIBUTING.md](<https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md>)
file.

YES

## What kind of change does this PR introduce?

Feature / refactor.

## What is the current behavior?

The dashboard assistant runs `@supabase/mcp-server-supabase` in-process
over an in-memory transport (`lib/ai/supabase-mcp.ts`).

## What is the new behavior?

The assistant connects to the **remote MCP server** over HTTP
(`@ai-sdk/mcp`), forwarding the dashboard session token as a bearer. URL
comes from `NEXT_PUBLIC_MCP_URL` with a local-dev fallback;
platform-only, and Nimbus works via the same env var.

* **Tool model unchanged:** UI-controlled `execute_sql` (with
`needsApproval`) and `deploy_edge_function` still come from Studio; the
allowlist (`TOOL_CATEGORY_MAP`) remains the gate keeping the remote's
write tools away from the assistant (`read_only` is defense-in-depth).
* **Attribution:** sends `x-source-name: supabase-studio` (+
`x-source-version`) → logged as `source_name`/`client_name`.
* **Connection lifecycle:** the HTTP client is closed via the request's
`AbortSignal` (tools execute later during streaming); `signal` is
required on `getTools`/`getMcpTools`.
* **Resilience:** a remote-MCP failure degrades to the remaining tools
instead of failing the assistant.
* **Drift protection:** relied-upon tools are typed against `keyof
typeof supabaseMcpToolSchemas`, so a package bump that renames/removes
one fails `pnpm typecheck`; a runtime check also warns if the deployed
server returns fewer tools.
* Adds unit tests for the above.

## Additional context

* Verified end-to-end against a local remote MCP server with a dashboard
token: `initialize` 200, tools listed, a tool executed, client closed
cleanly.
* The remote MCP (mgmt-api) already accepts dashboard session tokens
(GoTrue-JWT auth path) — no backend change needed. `NEXT_PUBLIC_MCP_URL`
must point at each env's `/mcp`.
* `@supabase/mcp-server-supabase` is kept — still used by the
self-hosted `/api/mcp` routes.

Closes
[AI-137](https://linear.app/supabase/issue/AI-137/switch-dashboard-assistant-to-remote-mcp)

## Rollout

* **Rollout:** merges with `USE_REMOTE_MCP` off (in-process); flip it to
`true` per environment (staging → prod → Nimbus) once each one's
prerequisites land.
* **Rollback:** unset `USE_REMOTE_MCP` and redeploy to fall back to the
in-process client — no revert needed.

## Summary by CodeRabbit

* **Bug Fixes**
* Improved AI request handling so tool loading and generation clean up
properly when a request is cancelled or the browser connection closes.
* Added safer fallback behavior when remote tool loading fails, so AI
features can continue with available tools instead of stopping entirely.
* Updated remote tool access to use the current project reference and
preserve the correct access headers.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* AI tools now connect more reliably to remote services and stop cleanly
when requests end or are canceled.
* Tool loading is more resilient, continuing with available tools if
remote access is unavailable.

* **Bug Fixes**
* Improved cleanup to prevent lingering connections during SQL
generation and policy workflows.
  * Added safer handling for remote tool changes and invalid responses.

* **Tests**
* Expanded automated coverage for remote tool setup, cancellation, and
fallback behavior.


<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-07 19:38:21 +01:00

80 lines
2.3 KiB
TypeScript

import { ToolSet } from 'ai'
import { IS_PLATFORM } from 'common'
import { filterToolsByOptInLevel } from '../tool-filter'
import { getFallbackTools } from './fallback-tools'
import { getIncidentTools } from './incident-tools'
import { getMcpTools } from './mcp-tools'
import { getSchemaTools } from './schema-tools'
import { getStudioTools } from './studio-tools'
import { AiOptInLevel } from '@/hooks/misc/useOrgOptedIntoAi'
export const getTools = async ({
projectRef,
connectionString,
authorization,
aiOptInLevel,
accessToken,
baseUrl,
signal,
}: {
projectRef: string
connectionString: string
authorization?: string
aiOptInLevel: AiOptInLevel
accessToken?: string
baseUrl?: string
// Required: tools fetched from the remote MCP server hold an HTTP connection
// that is closed when this signal aborts (i.e. when the request ends).
signal: AbortSignal
}) => {
// Always include studio tools
let tools: ToolSet = getStudioTools({ projectRef, connectionString, authorization, aiOptInLevel })
// If self-hosted, only add fallback tools
if (!IS_PLATFORM) {
tools = {
...tools,
...getFallbackTools({
projectRef,
connectionString,
authorization,
includeSchemaMetadata: aiOptInLevel !== 'disabled',
}),
}
} else if (accessToken) {
// If platform, fetch MCP and other platform specific tools. The MCP tools
// may be fetched from the remote MCP server over the network (see
// `USE_REMOTE_MCP`), so a failure there (outage, timeout, auth) should
// degrade gracefully to the remaining tools rather than break the entire
// assistant.
let mcpTools: ToolSet = {}
try {
mcpTools = await getMcpTools({
accessToken,
projectRef,
aiOptInLevel,
signal,
})
} catch (error) {
console.error('Failed to fetch MCP tools:', error)
}
tools = {
...tools,
...mcpTools,
...getSchemaTools({
projectRef,
connectionString,
authorization,
}),
...(baseUrl ? getIncidentTools({ baseUrl }) : {}),
}
}
// Filter all tools based on the (potentially modified) AI opt-in level
const filteredTools: ToolSet = filterToolsByOptInLevel(tools, aiOptInLevel)
return filteredTools
}