OneCLI connects AI agents to Supabase through OAuth. Agents can manage projects, run database queries, view edge functions, manage storage buckets, and access auth configuration. The gateway injects OAuth credentials into requests to the Supabase Management API automatically.
Skip this section on OneCLI Cloud. It’s only for self-hosted OneCLI without SUPABASE_CLIENT_ID and SUPABASE_CLIENT_SECRET set, or if you want your own company name on Supabase’s consent screen.
1. Create the OAuth app
In the Supabase dashboard, open your organization’s Settings > OAuth Apps and select Add application. Name it and enter your website URL.
The new OAuth application form in Supabase, with the OneCLI callback URL.
2. Choose the scopes
Tick the scopes your agents need. OneCLI can request:organizations:read, projects:read, database:read, database:write, auth:read, storage:read, edge_functions:read, secrets:read
3. Add the callback URL
In OneCLI, open Connections > Supabase > Custom credentials and copy the Redirect URI. In Supabase, paste it into Authorization callback URLs, and save the app.
Copy the Redirect URI from Custom credentials in OneCLI.
4. Connect with your app
Copy the Client ID and Client secret Supabase shows (the secret is shown once). Paste both into Connections > Supabase > Custom credentials, select Save & Connect, and authorize in Supabase.
Access is per agent: grant the connection to each agent that needs it, choosing per tool what runs freely, what needs human approval, and what stays blocked — a read-only agent is a single grant. Organization rules add guardrails on top, like rate limits and blanket blocks. Everything is checked before credential injection, so a blocked request never reaches Supabase.