Skip to main content
New in version 2.13.0 This guide shows you how to secure your FastMCP server using Supabase Auth. This integration uses the Remote OAuth pattern, where Supabase handles user authentication and your FastMCP server validates the tokens.

Configuration

Prerequisites

Before you begin, you will need:
  1. A Supabase Account with a project or a self-hosted Supabase Auth instance
  2. Your FastMCP server’s URL (can be localhost for development, e.g., http://localhost:8000)

Step 1: Get Supabase Project URL

In your Supabase Dashboard:
  1. Go to Project Settings
  2. Copy your Project URL (e.g., https://abc123.supabase.co)

Step 2: FastMCP Configuration

Create your FastMCP server using the SupabaseProvider:
server.py

Testing

Running the Server

Start your FastMCP server with HTTP transport to enable OAuth flows:
Your server is now running and protected by Supabase authentication.

Testing with a Client

Create a test client that authenticates with your Supabase-protected server:
client.py
When you run the client for the first time:
  1. Your browser will open to Supabase’s authorization page
  2. After you authorize, you’ll be redirected back
  3. The client receives the token and can make authenticated requests

Environment Variables

For production deployments, use environment variables instead of hardcoding credentials.

Provider Selection

Setting this environment variable allows the Supabase provider to be used automatically without explicitly instantiating it in code.

FASTMCP_SERVER_AUTH
default:"Not set"
Set to fastmcp.server.auth.providers.supabase.SupabaseProvider to use Supabase authentication.

Supabase-Specific Configuration

These environment variables provide default values for the Supabase provider, whether it’s instantiated manually or configured via FASTMCP_SERVER_AUTH.

FASTMCP_SERVER_AUTH_SUPABASE_PROJECT_URL
required
Your Supabase project URL (e.g., https://abc123.supabase.co)
FASTMCP_SERVER_AUTH_SUPABASE_BASE_URL
required
Public URL of your FastMCP server (e.g., https://your-server.com or http://localhost:8000 for development)
FASTMCP_SERVER_AUTH_SUPABASE_AUTH_ROUTE
default:"/auth/v1"
Your Supabase auth route (e.g., /auth/v1)
FASTMCP_SERVER_AUTH_SUPABASE_REQUIRED_SCOPES
default:"[]"
Comma-, space-, or JSON-separated list of required OAuth scopes (e.g., openid email or ["openid", "email"])
Example .env file:
With environment variables set, your server code simplifies to:
server.py