Supabase
Connect
Connect Supabase from the terminal. Pass --help for the flags Supabase accepts, plus --no-browser for headless environments.
polylane cloud connect --provider supabaseOAuth authorization, or a personal access token from your Supabase account settings.
Supabase connects via OAuth: click Connect with Supabase, authorize read access on Supabase choosing the organization to connect, and you're redirected back with syncing already started. Tokens are encrypted before they are stored, and the agent never sees them.
Personal access token alternative
If you prefer a long-lived credential, connect with a personal access token instead:
- Open Supabase, go to Account → Access Tokens.
- Click Generate new token and copy the token (it starts with
sbp_). - Paste the token into Polylane. If your account can access more than one organization, also provide the organization slug to connect.
- Polylane validates the token and starts syncing.
Each connection covers a single Supabase organization. Polylane discovers its projects with their edge functions, database branches, and storage buckets, including status, region, and compute size.
Troubleshooting
"Invalid access token" error
- Check that the token has not been revoked in Supabase's account settings.
- Personal access tokens act with your account's permissions; make sure your account can access the organization.
"Multiple Supabase organizations are reachable" error
- The credentials can reach more than one organization, so name the one to connect.
- Connecting via OAuth in the console, pick the organization when prompted after authorizing.
- Connecting via the API, set the
organizationfield to the organization slug.
Missing resources
- Supabase can take a few minutes to sync everything.
- Paused (inactive) projects are listed, but their edge functions, branches, and buckets are only synced while the project is active.
- Trigger a manual Sync from the account header to refresh.
Disconnecting
Disconnect the account in Polylane, then revoke the access token from your Supabase account settings.
Connect Supabase from a CI job or any other environment without a browser.
Connecting Supabase needs no browser: the same endpoint the console calls fits in a CI job. One authenticated POST creates the connection and starts the first sync.
Prerequisites
- A Polylane API key with the
cloud_accounts:writeandcloud_accounts:readscopes. See API keys and OAuth. - Your workspace ID, which starts with
ws_. Read it fromGET /v1/workspaceswith the same key. - A Supabase personal access token (starts with
sbp_) from Account → Access Tokens. The console's OAuth flow needs a browser; access tokens do not.
Create the connection
curl -X POST https://api.polylane.com/v1/cloud_accounts \
-H "x-api-key: $POLYLANE_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"provider": "supabase",
"workspaceId": "ws_0abc123",
"token": "sbp_...",
"organization": "my-org-slug"
}'
One call connects one Supabase organization.
organizationmay be omitted only when the token reaches exactly one organization; otherwise the call fails with a400that lists the reachable organization slugs.
The response lists what was connected, with the first sync already running. Trimmed to the two fields the rest of the flow reads:
{
"success": true,
"result": {
"provider": "supabase",
"accounts": [{ "id": "acc_34gky74ibc92h8t2efn8csrh", "status": "syncing" }],
"failures": []
}
}
An account that is already connected lands in failures instead of accounts, so repeating the call never duplicates a connection.
Wait for the first sync
Poll each returned account by its id until status reaches ready (new on registration, syncing while resources stream in):
until [ "$(curl -s "https://api.polylane.com/v1/cloud_accounts/$WORKSPACE_ID/$ACCOUNT_ID" \
-H "x-api-key: $POLYLANE_API_KEY" | jq -r '.result.status')" = "ready" ]; do
sleep 15
done
Give the loop a deadline so a failed connect fails the job instead of hanging it. Once the account is ready, its resources are in the topology and Polylane has started its first check.
Disconnect from the API
Deleting the connection stops every sync and check and deletes the credentials Polylane held. The call needs the cloud_accounts:delete scope:
curl -X DELETE "https://api.polylane.com/v1/cloud_accounts/$WORKSPACE_ID/$ACCOUNT_ID" \
-H "x-api-key: $POLYLANE_API_KEY"
Then revoke the Supabase credential on the provider side, as described under Disconnect below.
Disconnect
Disconnecting stops every sync and check and deletes the credentials Polylane held. Polylane removes what Supabase's API lets it remove. The following stays until you remove it yourself:
- OAuth grant
polylane cloud disconnect <id>Tools
4Operations agents can perform in threads.
Supported resources
13Resource types that show up in your infrastructure graph.