Developer toolsSupabase + Atako
Your AI agents read and modify your Supabase data and browse your storage.
What your agents do in Supabase
Connected to Supabase, your agents act in it directly, not just read from it.
Read & exploration
Your agents query tables and views, apply filters and explore the database structure.
- Read rows from a table with filters
- List exposed tables, views and functions
- Review the full database schema
Data modification
Your agents insert, update and delete rows in tables.
- Insert one or more rows into a table
- Update rows matching filters
- Delete outdated rows
RPC functions
Your agents call PostgreSQL functions to run custom operations.
- Call a function with arguments
- Run server-side business logic
- Trigger a complex operation via RPC
Storage
Your agents list storage buckets and objects to navigate your files.
- List available buckets
- Browse objects in a bucket
- View files under a prefix
How it works
A secure connection, fully under your control.
One-click connection
Paste your Supabase API key: the connection is live in a minute.
Per-agent permissions
Read, write, or both: each agent gets exactly the access it needs.
Encrypted secrets
Your credentials are encrypted and never exposed to the agent.
Full audit trail
Every call to Supabase is logged and reviewable.
Real-world scenarios
What changes day to day.
Database always up to date
The agent checks, fixes and completes the data you assign it to keep the database reliable.
Organised storage
The agent lists buckets and their objects and flags files that need reclassifying.
Automated data operations
The agent triggers reads, inserts or updates on the database as needed.
Schema exploration
The agent discovers the database structure — tables, views and functions — to act more effectively.
Frequently asked questions
How do my agents connect to Supabase?
Via a project secret key (sb_secret_… or the legacy service_role key) and the project reference. Note: these keys bypass Supabase's RLS rules — limit what each agent can do with Atako permissions (read-only, or a handful of write actions).
Is my Supabase key safe?
Yes. Your key is encrypted and never exposed to the agent: it acts through a secure access layer, without ever seeing or handling your credentials.
Can I limit what each agent is allowed to do?
Yes, read and write permissions are configured per agent: some can only view the database, others can modify data or call functions.
What can an agent actually do in Supabase?
Query tables and views, insert, update and delete rows, call RPC functions, list storage buckets and objects, depending on the permissions you grant. Updates and deletes require an explicit filter — to block an agent from deleting anything, simply don't grant it that action.
Can I revoke access at any time?
Yes, in one click from the integration settings. The agent immediately loses all access to Supabase, no action needed on the Supabase side.
What Supabase data is covered?
Tables, views, RPC functions and storage (buckets and objects). Supabase authentication, Edge Functions and realtime are not exposed to agents.
Understand autonomous AI agents
Connect Supabase to your AI agents
14-day free trial, no credit card required.