Skip to content
Agentic Workflowdocs
v0.8.2Install free

use the app / connections

Connect Supabase

Use your project's anon public key, and let Row Level Security decide what a workflow may read and write.

≈ 3 min Extension Bearer Token
  • A Supabase project, with Row Level Security (RLS) policies for the tables you use.
  • The AWFlow browser extension. These steps run in the extension (the web app hands them to it).

This is the only method AWFlow accepts. The secret service_role key is refused because it bypasses RLS.

  1. Copy the key. In Supabase, open Project Settings › API and copy the key labelled anon public. Also note the Project URL (https://<project>.supabase.co).

  2. Save it in AWFlow. Open Credentials and click Add Credential (or + Add Credential in a node’s Credential field), then fill the New Credential form. In the browser side panel the form comes in two steps: tap Supabase in the list, then fill the rest.

    The New Credential dialog with Supabase picked under Integration App / Service: Name and Description fields, a Bearer Token field (no Auth Type menu: the app sets it), a note that the secret is saved locally and encrypted in this browser, and the Cancel and Create Credential buttons. The New Credential dialog with Supabase picked under Integration App / Service: Name and Description fields, a Bearer Token field (no Auth Type menu: the app sets it), a note that the secret is saved locally and encrypted in this browser, and the Cancel and Create Credential buttons.

    Numbered areas in the screenshot: 1. Integration App / Service: Supabase; 2. Name; 3. Bearer Token; 4. Where the secret is stored (here, locally in this browser); 5. Create Credential.

  3. Allow the access with RLS policies on each table, for example a policy that lets the anon role insert into prices.

  4. In the node, pick the credential and paste the Project URL.

  • “This is a Supabase service_role key, which bypasses Row Level Security…”. Replace it with the anon key.
  • “401 … the request was blocked” (or 403). No RLS policy allows this operation for anon. Add one on the table.
  • Select returns an empty list. RLS hides the rows from anon, or the filter matches nothing (use eq.42, not 42).
  • The run is blocked in the web app. Supabase runs through the browser extension. Install the extension and allow Supabase for this workflow when asked, or run the workflow from the extension. See Extension-only integrations in the web app.
Ask Aria