Skip to main content

Overview

OneCLI connects AI agents to Supabase through OAuth. Agents can manage projects, run database queries, view edge functions, manage storage buckets, and access auth configuration. The gateway injects OAuth credentials into requests to the Supabase Management API automatically.

Setup

1

Go to Connections

Open the OneCLI dashboard and navigate to Connections > Supabase.
2

Authorize

Click Connect Supabase. You’ll be redirected to Supabase to authorize OneCLI. Review the permissions and click Authorize.
OneCLI connect window for Supabase on Cloud, showing the Connect to Supabase button.

The Supabase connect window on OneCLI Cloud.

3

Verify

After authorization, you’ll be redirected back to the dashboard. The connection will show as Connected with your Supabase organization name.

What agents can do

Use cases

  • Database management agents that run SQL queries and manage schemas
  • Infrastructure agents that provision and configure Supabase projects
  • Monitoring agents that check database health and connection pool status
  • Agents that manage storage buckets and edge function deployments

Self-hosted: use your own Supabase OAuth app

Skip this section on OneCLI Cloud. It’s only for self-hosted OneCLI without SUPABASE_CLIENT_ID and SUPABASE_CLIENT_SECRET set, or if you want your own company name on Supabase’s consent screen.

1. Create the OAuth app

In the Supabase dashboard, open your organization’s Settings > OAuth Apps and select Add application. Name it and enter your website URL.
Supabase Create OAuth application form with the name OneCLI, website https://onecli.example.com, and the callback URL https://onecli.example.com/v1/apps/supabase/callback.

The new OAuth application form in Supabase, with the OneCLI callback URL.

Tick the scopes your agents need. OneCLI can request:organizations:read, projects:read, database:read, database:write, auth:read, storage:read, edge_functions:read, secrets:read
In OneCLI, open Connections > Supabase > Custom credentials and copy the Redirect URI. In Supabase, paste it into Authorization callback URLs, and save the app.
OneCLI Custom credentials card for Supabase with the setup guide link, the Redirect URI and its copy button, and the client ID and secret fields.

Copy the Redirect URI from Custom credentials in OneCLI.

Copy the Client ID and Client secret Supabase shows (the secret is shown once). Paste both into Connections > Supabase > Custom credentials, select Save & Connect, and authorize in Supabase.

Controlling access

Access is per agent: grant the connection to each agent that needs it, choosing per tool what runs freely, what needs human approval, and what stays blocked — a read-only agent is a single grant. Organization rules add guardrails on top, like rate limits and blanket blocks. Everything is checked before credential injection, so a blocked request never reaches Supabase.