Supabase
Connect Supabase as your access review source using a personal access token so that the platform can list the members of your Supabase organization.
The platform reads your organization’s Supabase members through the Supabase ManagementAPI so you can check who has access.
Prerequisites
Section entitled ‘Prerequisites’- the platform organization administrator access
- A Supabase account that is a member of the organization that you want to review.Owner, Administrator, Developer and Read-OnlyA personal access token has the same privileges as the account that created it.
- The Organization Slug Supabase places it in the dashboard URL while the organization is open:
supabase.com/dashboard/org/<organization-slug>
Collected Fields
Section entitled “Collected Fields”| the platform field | Supabase field | Notes |
|---|---|---|
| Name | user_name |
Supabase member's username. There is no feedback, so a member returned without one is listed with an empty name |
email |
||
| Role | role_name |
The organizational roles of Supabase are Owner, Administrator, Developer and Read-Only. |
| Admin | role_name |
Tagged as administrator when role_name is Owner or Administrator, and not for Developer or Read-Only |
| Status | Not supported | |
| MFA | mfa_enabled |
Activated when the flag is true, otherwise disabled. Supabase returns the flag for each member |
| Last login | Not supported | |
| External ID | user_id |
Stable ID used to track your account through reviews |
| Created at | Not supported |
Step 1: Create a Personal Access Token
Step 1: Create a Personal Access Token
- In the Supabase dashboard, go to Account Settings > Access Tokens.
- Click Generate new token, enter a Name (e.g.
Probo Access Review) and the Expires inThe dialog is set to 30 days by default, so choose a window that covers the review cycle or Never. - Click Generate token, then copy the token (
sbp_...) and store it securely. Supabase displays it once and you can't recover it later.
Step 2: Connect in the platform
“Step 2: Connect in the platform”- On the platform, go to Access Reviews > Sources > Add Source.
- Find Supabase, click API KeyPut yourself in the box, enter Organization Slug, and click Connect.
The platform names the source after your organization slug and attracts its members to your campaigns.
Troubleshooting
Section “Troubleshooting”- Token rejected. Confirms that it is a personal access token (
sbp_...) and that it is still listed under Account Settings > Access TokensA project API key, whether it is publicable (sb_publishable_...), secret (sb_secret_...) or inheritedanonorservice_roleJWT, only reaches its own project and cannot read members of the organization. - No members appear. Check that Organization Slug matches the value in the dashboard URL,
supabase.com/dashboard/org/<organization-slug>, and that the account that created the token still belongs to that organization. - Syncs worked and then stopped. The Expires in Default fields up to 30 days. Check if the token is still Access Tokens the page, then generate a replacement and update the source on the platform.
- A scoped token does not work. Supabase also issues scaled personal access tokens, the access to which is more restricted than that of its own account. Access Tokens Use it and use it instead.