Supabase now offers enterprise-managed authentication for its MCP server, built with Anthropic and Okta, generally available on Team and Enterprise plans. IT admins can grant, restrict, and revoke access to Supabase within Claude directly from Okta, scoped to each employee's existing Supabase role and permissions. Previously, each user had to individually approve OAuth consent and only organization owners could authorize the connection; now a single admin authorization covers the whole organization, with onboarding, offboarding, and access reviews flowing through the identity provider. SCIM-based provisioning for the platform is planned next.
Table of contents
Access that follows each person's role #Manage Supabase in Claude like any other app #Get started #Questions this post answers
How does enterprise-managed auth work for the Supabase MCP server with Claude?
An IT admin authorizes the Supabase connector once through Okta, and every employee signing into Claude gets Supabase access automatically scoped to their existing Supabase role and permissions. This replaces the previous flow where each person had to approve their own OAuth consent and only organization owners could authorize the connection at all. It requires a Supabase Team or Enterprise plan with Okta SSO enabled and a Claude Team or Enterprise plan. Teams rolling out AI coding tools across an org can track integration changes like this on daily.dev.
What happens to someone's Supabase access in Claude when they're offboarded in Okta?
Offboarding someone in Okta automatically removes their Supabase access in Claude, since access is tied to identity provider group membership rather than individual manual grants. This lets security teams run onboarding, offboarding, and access reviews for Supabase inside Claude through the same identity provider workflows they already use for other applications. Security teams standardizing AI tool access reviews follow updates like this via daily.dev.