Skip to content

Enable the Supabase OAuth server and confirm the connector can discover it #223

Description

@HMarzban

Problem

docs.plus has no way for a person to connect it to Claude or ChatGPT. The blocker looked like a missing credential system. It is not.

Supabase already ships an OAuth 2.1 authorization server. The switch is in this repository at packages/supabase/config.toml:357-363, and it is off:

[auth.oauth_server]
enabled = false
authorization_url_path = "/oauth/consent"
allow_dynamic_registration = false

Even with the server disabled, GET /auth/v1/.well-known/openid-configuration already returns 200 and advertises /auth/v1/oauth/authorize, /auth/v1/oauth/token, authorization_code, refresh_token, and PKCE (code_challenge_methods_supported: ["S256","plain"]).

Two fields are missing, and both are configuration. registration_endpoint is absent, because allow_dynamic_registration = false. client_id_metadata_document_supported is absent. Claude needs one of those two.

What to do

In the production Supabase dashboard:

  1. Enable the OAuth server.
  2. Enable dynamic client registration.
  3. Set site_url to the docs.plus origin.

Then re-probe. This is a configuration change and a measurement. Write no code.

Acceptance

  • GET /.well-known/oauth-authorization-server/auth/v1 returns 200, not {"code":404,"error_code":"feature_disabled"}.
  • GET /auth/v1/.well-known/openid-configuration now includes registration_endpoint.
  • The result is recorded on this issue, pass or fail.
  • The issue records which of the two Claude accepts: registration_endpoint, or client_id_metadata_document_supported.

Notes

This is the cheapest go or no-go decision in the connector work. It takes hours, not days. If either probe fails, every task below it changes shape, so nothing else starts until this is answered.

Supabase supports five fixed scopes: openid, profile, email, phone, offline_access. Custom scopes do not exist, and OAuth scopes do not control access to database tables. Scoping belongs to Row Level Security and to which tools the connector chooses to expose.

Do not build a credential table. A pasted API key is org-shared, and it is immutable after a connector is added. Claude's own documentation says to use OAuth when each person signs in as themselves.

Activity

  1. HMarzban commented on Sep 23, 2026

    @HMarzban
    CollaboratorAuthor

    Probed locally on 2026-09-22 with the OAuth server and dynamic registration on
    (packages/supabase/config.toml, commit 1b109b553).

    • GET /auth/v1/.well-known/openid-configuration returns 200 and now lists
      registration_endpoint (/auth/v1/oauth/clients/register).
    • GET /.well-known/oauth-authorization-server/auth/v1 is a 404 on the local stack, because
      of how the local gateway routes it. Hosts fall back to the OpenID document, so this is not a
      blocker. The real gate is registration_endpoint.
    • Claude accepts both paths. It uses CIMD only when the server advertises
      client_id_metadata_document_supported. Supabase does not support CIMD, so Claude and ChatGPT
      both use dynamic registration here.
    • Production still needs the dashboard toggle. supabase config push does not sync
      [auth.oauth_server].
  2. HMarzban commented on Sep 29, 2026

    @HMarzban
    CollaboratorAuthor

    Re-probed production on 2026-09-29. /.well-known/oauth-authorization-server/auth/v1, /auth/v1/.well-known/openid-configuration and /auth/v1/.well-known/oauth-authorization-server all return 200 and list registration_endpoint (/auth/v1/oauth/clients/register). Claude and ChatGPT both connect through dynamic client registration, since Supabase has no CIMD. Local config is in 1b109b553. The connector has been live since 2026-09-28.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions