Supabase is Postgres, so the native driver talks to it directly — and its JWTs verify in front of the route.
How Air Pipe reaches Supabase
Supabase has a native driver in the engine. A query action takes the statement and its parameters separately — so the values are bound, never interpolated into SQL — and the connection is pooled for you. Every statement becomes a span in the request's trace, with its timing attached.
- name: ListRows database: main query: SELECT * FROM public.profiles WHERE id = $1 params: [a|jwt::sub|]
Route: Native database driver
Auth: Connection string · JWT
The same config is four things at once
Whatever you build against Supabase is not locked to one surface. The same config can expose HTTP routes, run on a cron schedule, receive webhooks, and be called by an agent as an MCP tool — with one auth model and one deploy. You do not rebuild the workflow to make it callable, and you do not bolt an MCP node onto the end of a canvas.
HTTP routes with OpenAPI docs generated from the config
Cron schedules and webhooks in the same file as the API
MCP tools with input schemas derived from the route's own assertions
OpenTelemetry traces and Prometheus metrics on all of it
Readable config you own, managed or self-hosted
The artifact is a config you can read, diff and review in a pull request — not a canvas stored in a vendor's database. Run it on Air Pipe's managed cloud or self-host the single binary, with the same config either way, and your credentials and data staying on your infrastructure when you choose to self-host.
Frequently asked questions
Is there a Supabase connector I have to install? No. Supabase is reached through a native action that ships with the engine — nothing to install, enable or version separately.
Where do the credentials live? In managed variables or secrets, referenced from the config by name — never in the config text. Any action that mints a token should also carry hide_data_on_success: true, or the token comes back in the response body.
Can an agent call this? Yes, and you do not build anything extra for it. Mark the interface mcp: true and the same route becomes an MCP tool, with its input schema derived from the assertions the route already carries. An agent calling it gets the same auth, the same validation and the same traces as an HTTP client.
What do I get to see when it fails? An end-to-end OpenTelemetry trace covering the request, each action and each database call, Prometheus counters and durations on /metrics, and the run history for the deployment. None of it is written by you and none of it is a separate product.