FixRLSFixRLS
RLS Errorservice_role KeyPublishable KeyAnon KeyMCP Setup

Supabase MCP safe setup for Cursor and Claude Code

Use this guide to keep Supabase MCP scoped, read-only where possible, and manually approved. It does not request PATs, access tokens, service_role keys, or project secrets.

Configure MCP guardrails

Scope Supabase MCP access without pasting tokens or production secrets.

Issue

Pick a shortcut, then tune the settings below.

Fix settings

These controls restore the original page behavior.

Placeholders

Use schema names only. Do not paste secrets.

No secrets needed. Placeholder-only.

MCP safe setup

Use project_ref scoping, read_only=true, minimum features, manual approval, and no committed access tokens.

Copy in one click
Supabase MCP safe setup guidance:

Example read-only MCP URL:
https://mcp.supabase.com/mcp?project_ref=YOUR_PROJECT_REF&read_only=true&features=database,docs

Use these guardrails:
1. Scope the connection to a specific project_ref, not broad account access.
2. Use read_only=true where possible.
3. Limit feature groups to the minimum needed, such as database and docs.
4. Do not connect production data during development.
5. Keep manual approval enabled in Cursor, Claude Code, Lovable, Bolt, or any MCP client.
6. Do not commit PATs, access tokens, or MCP config containing secrets.
7. Do not use MCP with sensitive user-submitted content unless you review the resulting tool calls.

Copy outputs

Copy the companion outputs for agent repair, testing, and key placement.

{}

Copy AI repair prompt

Paste this into Cursor, Claude Code, or Lovable for an agent fix tailored to your schema.

Copy proof-of-fix test

Get a checklist and SQL test script to confirm the fix works as intended.

{}

Copy secondary RLS SQL

Use after matching placeholders to your schema and validating with the proof-of-fix test.

Copy key placement note

Use this to check publishable, anon, service_role, and secret key placement.

Launch Safety Pack

Early-access pack with 15 bundles: AI repair prompts, test scripts, policy templates, MCP guards, and more.

© 2026 FixRLSPrivacyTerms