supabase · Supabase

Supabase CLI Agent 使用指南

在明确环境风险的前提下管理本地 Supabase 开发、迁移、函数和已关联项目。

官方工具操作风险: R1R3docs-verified
Agent 适配度
84/100
证据可信度
docs-verified
文档检查日期
2026-07-10
独立测试版本
尚未独立测试

为 Agent 安装

选择与运行环境匹配的官方安装方式。在团队或 CI 环境中固定版本,并先运行版本检查。

npm development dependency推荐
macos · linux · windows
$ shell
npm install --save-dev supabase
认证与最小权限
只提供任务需要的权限,凭证通过环境变量或平台密钥存储传入,不能写进提示词、仓库或日志。
需要认证支持无界面认证

Token 仅授权目标组织,并在远程命令前确认已关联项目。

认证方式
access token, database password, local development
密钥环境变量
SUPABASE_ACCESS_TOKEN, SUPABASE_DB_PASSWORD
凭据保存位置
无界面运行时,在进程启动时从 CI 或平台密钥管理器注入 SUPABASE_ACCESS_TOKEN、SUPABASE_DB_PASSWORD。本地交互使用时,若官方客户端支持,应优先使用 CLI 或操作系统凭据存储;不要把值写入仓库文件。
Agent 与运行环境兼容性
先确认 Agent 能使用 Shell,再检查平台、网络与凭证是否可用。
claude-codecodexgemini-clicopilot-cli
Environments
local, ci, container, headless, remote
Platforms
macos, linux, windows

用于稳定自动化的结构化输出

优先使用机器可读格式,并把 stdout 作为结果、stderr 作为诊断信息分别处理。

json · text
在支持的命令中使用 --output json,并将诊断日志保留在 stderr。
--output json

尚未记录真实输出样例

当前结构化输出能力来自官方文档。完成有限、非破坏性执行并保存 stdout 前,不展示推测样例或伪造 Schema。

R0–R3 命令风险指南

风险按单条命令判断。R0 是本地或远程只读,R1 是可逆的本地写入,R2 会改变远程状态,R3 可能造成不可逆或生产级影响。

只读不等于可公开

R0 只表示命令不更改本地或远程状态。只读命令仍可能返回令牌、身份信息、配置或生产数据;只展示完成任务所需的最少内容,不得写入日志、Prompt 或提交内容。

R0检查本地状态
读取服务 URL 和本地开发状态。
$ shell
npx supabase status --output json
可重复执行敏感输出
R1生成 Schema 差异
写入本地迁移草案供审查。
$ shell
npx supabase db diff --file migration_name
执行前必须确认可能产生重复变更
R2推送迁移
会改变已关联远程数据库的 Schema。
$ shell
npx supabase db push
执行前必须确认可能产生重复变更
R3重置数据库
若针对错误环境执行,可能清除数据。
$ shell
npx supabase db reset
执行前必须确认可能产生重复变更

Agent Readiness 评分依据

适配度描述 Agent 操作工具的稳定程度,不代表所有命令都安全,也不替代独立执行测试。

文档证据对应的 Agent Readiness 为 84/100;尚未记录本地执行测试。

结构化输出
在支持的命令中使用 --output json,并将诊断日志保留在 stderr。
18/20
x
无界面运行
官方文档描述了非交互认证或执行路径。
14/15
x
安全控制
CLI Finder 将读取命令与需要确认的命令分开。
11/15
x
确定性
命令尽量使用显式参数和文档支持的输出控制。
8/10
x
认证
Token 仅授权目标组织,并在远程命令前确认已关联项目。
8/10
x
文档
本条目引用了 2026-07-10 检查的官方文档。
9/10
x
安装
官方安装路径覆盖 macOS、Linux 和 Windows。
8/8
x
维护状态
条目链接了官方源码仓库,便于检查发布与维护状态。
6/7
x
Agent 产物
CLI Finder 可生成基于注册表的 Skill 和策略;该分数不假定工具自身提供这些产物。
2/5
x

生成 Skill 或 Agent 策略

选择目标 Agent 和安全模式,生成包含安装、允许命令、确认边界与证据说明的可复制产物。

生成结果预览
SKILL.md
---
name: supabase-cli-agent-workflow
description: Use Supabase CLI for local Supabase stack, database migrations, Edge Functions with explicit command risk and evidence boundaries.
---

# Supabase CLI agent workflow

Use this skill when the task needs local Supabase stack, database migrations, Edge Functions, type generation.

## Evidence boundary

- Registry confidence: `docs-verified`
- Documentation checked: `2026-07-10`
- Locally tested version: `not tested`
- Do not describe this CLI as locally verified until its commands have actually been executed in an isolated environment.

## Executed smoke checks

- No local execution record is available.

## Installation

- npm development dependency (macos, linux, windows): `npm install --save-dev supabase`

## Authentication

- Methods: access token, database password, local development
- Secret environment variables: `SUPABASE_ACCESS_TOKEN`, `SUPABASE_DB_PASSWORD`
- Minimum permissions: Use a token limited to the intended organization and verify the linked project before remote commands.
- Credential storage: For headless runs, inject SUPABASE_ACCESS_TOKEN, SUPABASE_DB_PASSWORD from the CI or platform secret manager at process start. For local interactive use, prefer the CLI or operating-system credential store when the official client supports one. Never save values in repository files.
- Never print, persist, or commit credential values.

## Allowed commands (read-only)

- `npx supabase status --output json` — R0: Reads service URLs and local development status.

## Commands requiring explicit approval (read-only)

- None recorded.

## Forbidden commands (read-only)

- R1 `npx supabase db diff --file migration_name` — Writes a local migration draft for review.
- R2 `npx supabase db push` — Changes the linked remote database schema.
- R3 `npx supabase db reset` — Can erase data when used against the wrong environment.

## Execution rules

1. Mode boundary: R0 exact commands may be used; R1, R2, and R3 commands are forbidden.
2. Confirm the selected account, project, context, database, namespace, or environment before any command.
3. Prefer structured output using `--output json`.
4. Capture the exact command, exit code, stdout, and stderr separately.
5. A generated prefix policy must prompt unless that exact prefix is explicitly marked suffix-safe; do not infer safety from the executable name.
6. Never broaden credentials or disable safety controls to make a command succeed.

## Official sources

- [Supabase CLI documentation](https://supabase.com/docs/guides/cli)
- [Supabase CLI documentation source repository](https://github.com/supabase/cli)

这个任务该用 CLI、MCP 还是 API

CLI
适合在开发机、CI 或容器里复用现有 Shell、凭证和脚本,尤其适合短时、可观察的任务。
MCP
当 Agent 需要受控工具定义、委托身份或由服务端集中治理访问时,MCP 可能更合适。
API
当工作流是应用内长期集成、批量调用或事件驱动时,直接 API 往往比启动进程更稳定。
查看 CLI 与 MCP 完整对比

验证记录与官方证据

CLI Finder 分开记录文档检查和真实执行。未执行过的安装、帮助、退出码与输出不能标为 Verified。

当前证据边界
已审阅官方文档,但未在本地执行安装、帮助输出、退出码、无界面行为或结构化输出测试。
证据可信度
docs-verified
独立测试版本
尚未独立测试
测试环境
未记录
官方来源
打开官方资料确认当前版本和命令。

替代工具与相关入口

通过可编排命令查询和管理本地或远程数据库。
通过显式凭据、输出、事务和写入边界,以非交互方式查询 PostgreSQL。
先检查本地项目状态,明确 linked project,再用只读路径访问生产数据。
用确定性本地工具配合 Codex,只在沙箱和审批规则允许时加入远程 CLI。
本地和 CI 的 shell 工作优先 CLI;更看重 typed discovery 和中介式远程权限时选 MCP。

Agent 使用 Supabase CLI 的常见问题