cd /news/ai-tools/enterprise-managed-auth-for-the-supa… · home topics ai-tools article
[ARTICLE · art-109222] src=supabase.com ↗ pub= topic=ai-tools verified=true sentiment=↑ positive

Enterprise-managed auth for the Supabase MCP server

Supabase has made enterprise-managed auth for its Model Context Protocol (MCP) server generally available on Team and Enterprise plans, built with Anthropic and Okta. The feature lets IT admins control access to Supabase in Claude through their identity provider, allowing them to grant, restrict, and revoke access organization-wide. Access is tied to each employee's existing Supabase role, and admins can restrict access to Okta groups, with offboarding in Okta automatically revoking Supabase access in Claude.

read2 min views1 publishedAug 24, 2026
Enterprise-managed auth for the Supabase MCP server
Image: Supabase Blog

Enterprise-managed auth for the Supabase MCP server is now generally available on Supabase Team and Enterprise plans. Built with Anthropic and Okta, it moves access control for Supabase in Claude to your identity provider, so IT admins can grant, restrict, and revoke that access for the whole organization from one place.

Before, each person connecting Claude to Supabase approved their own OAuth consent, and only organization owners could authorize the connection at all. Now an admin authorizes the Supabase connector once, and every employee who signs in to Claude finds Supabase ready to use, scoped to the projects and permissions they already have.

Access that follows each person's role# #

Access is tied to the individual employee rather than the organization owner, so what someone can do through Claude matches what they can already do in Supabase:

  • Developers and read-only members get working Supabase MCP access with the role they already have
  • Every query and management action runs with that person's existing role and permissions in Supabase, nothing more than they'd already have signing in directly

Manage Supabase in Claude like any other app# #

Your security team already runs onboarding, offboarding, and access reviews through your identity provider, and those workflows now cover Supabase in Claude:

  • Restrict Supabase MCP access to an Okta group instead of approving each connection by hand
  • Offboard someone in Okta and their Supabase access in Claude goes with it
  • Point a security review of AI tool usage at one centrally enforced policy instead of individual grants

Enterprise-managed auth joins SSO, project-scoped roles, and SOC 2 and HIPAA compliance as part of how enterprises run Supabase. And this is just the start, with SCIM-based provisioning for the platform on the roadmap.

Get started# #

Enterprise-managed auth is available today for organizations on a Supabase Team or Enterprise plan with Okta SSO enabled and a Claude Team or Enterprise plan.

── more in #ai-tools 4 stories · sorted by recency
── more on @supabase 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/enterprise-managed-a…] indexed:0 read:2min 2026-08-24 ·