Supabase Development and Debugging
supabase/agent-skills
General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.
Implement Supabase database webhooks, pgnet async HTTP, LISTEN/NOTIFY, and Edge Function event handlers with signature verification.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-webhooks-events -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-webhooks-events --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/supabase-webhooks-events .claude/skills/supabase-webhooks-events && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "supabase-webhooks-events" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-webhooks-events into .claude/skills/supabase-webhooks-events/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-webhooks-events", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-webhooks-eventsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-webhooks-events -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-webhooks-events --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/.curated/supabase-webhooks-events .agents/skills/supabase-webhooks-events && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "supabase-webhooks-events" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-webhooks-events into .agents/skills/supabase-webhooks-events/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-webhooks-events", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-webhooks-events -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-webhooks-events --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/.curated/supabase-webhooks-events .cursor/skills/supabase-webhooks-events && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "supabase-webhooks-events" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-webhooks-events into .cursor/skills/supabase-webhooks-events/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-webhooks-events", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path skills/.curated/supabase-webhooks-events--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-webhooks-events -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-webhooks-events --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/.curated/supabase-webhooks-events .gemini/skills/supabase-webhooks-events && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "supabase-webhooks-events" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-webhooks-events into .gemini/skills/supabase-webhooks-events/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-webhooks-events", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-webhooks-eventsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-webhooks-events -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/.curated/supabase-webhooks-events .github/skills/supabase-webhooks-events && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "supabase-webhooks-events" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-webhooks-events into .github/skills/supabase-webhooks-events/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-webhooks-events", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-webhooks-events -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-webhooks-events --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/.curated/supabase-webhooks-events .opencode/skills/supabase-webhooks-events && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "supabase-webhooks-events" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-webhooks-events into .opencode/skills/supabase-webhooks-events/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-webhooks-events", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
supabase-webhooks-eventsImplement Supabase database webhooks, pgnet async HTTP, LISTEN/NOTIFY, and Edge Function event handlers with signature verification.
Supabase Webhooks Events is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement Supabase database webhooks, pgnet async HTTP, LISTEN/NOTIFY, and Edge Function event handlers with signature verification. Use when setting up database webhooks for INSERT/UPDATE/DELETE events, sending HTTP requests from PostgreSQL triggers, handling Realtime postgreschanges as an event source, or building event-driven architectures. Trigger with phrases like "supabase webhook", "database events", "pgnet trigger", "supabase LISTEN NOTIFY", "webhook signature verify", "supabase event-driven"…
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/database-webhooks.md`, `references/edge-function-receivers.md` and `references/errors.md`). Compatibility notes: Designed for Claude Code
It sits in Backend & APIs, covering Webhooks and Event-driven systems. It works with Supabase and PostgreSQL. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
WriteBash(supabase:*)Bash(curl:*)Bash(psql:*)From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
supabaseFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
supabase.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
WEBHOOK_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code
From compatibility in the SKILL.md frontmatter.
Supabase Webhooks Events loads about 2.2k tokens when it runs, and up to ~8.6k if it reads all its reference files. Until then it costs about 142 tokens; SKILL.md has 665 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 665 words, ~2,195 tokens.
.claude/skills/supabase-webhooks-events/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.Supabase offers four complementary event mechanisms: Database Webhooks (trigger-based HTTP calls via pg_net), supabase_functions.http_request() (call Edge Functions from triggers), Postgres LISTEN/NOTIFY (lightweight pub/sub), and Realtime postgres_changes (client-side event subscriptions). This skill covers all four patterns with production-ready code including signature verification, idempotency, and retry handling.
supabase CLI installedpg_net extension enabled: Dashboard > Database > Extensions > search "pg_net" > Enable@supabase/supabase-js v2+ installed for client-side patternsBoth directions of a webhook are authenticated:
Authorization: Bearer <service_role_key> header. Store the key in a Postgres setting (app.settings.service_role_key) or Supabase Vault — never inline it in a committed migration.WEBHOOK_SECRET (read from Deno.env) using a constant-time comparison, and reject mismatches with 401. See signature-verification.md.Pick the mechanism that fits the consumer: pg_net triggers for server-side HTTP fan-out, Edge Function receivers for signed processing, LISTEN/NOTIFY for in-database pub/sub, and Realtime for client UI. Write each SQL trigger to a supabase/migrations/ file and each handler to supabase/functions/<name>/index.ts, then apply and deploy with the supabase CLI.
pg_net and Trigger FunctionsEnable pg_net, then write a trigger function that POSTs the changed row to an Edge Function. Attach it AFTER INSERT/UPDATE/DELETE. Full trigger set (conditional status-change trigger, the supabase_functions.http_request() built-in helper, and net._http_response inspection queries) is in database-webhooks.md.
CREATE EXTENSION IF NOT EXISTS pg_net WITH SCHEMA extensions;
CREATE OR REPLACE FUNCTION public.notify_order_created()
RETURNS trigger AS $$
BEGIN
PERFORM net.http_post(
url := 'https://<project-ref>.supabase.co/functions/v1/on-order-created',
headers := jsonb_build_object('Content-Type', 'application/json'),
body := jsonb_build_object('type', TG_OP, 'record', row_to_json(NEW)::jsonb)
);
RETURN NEW;
END;
$$ LANGUAGE plpgsql SECURITY DEFINER;
CREATE TRIGGER on_order_created
AFTER INSERT ON public.orders
FOR EACH ROW EXECUTE FUNCTION public.notify_order_created();Write an Edge Function that reads the raw body, verifies the HMAC signature, parses the typed payload, and routes by event type. Guard against duplicate delivery with a processed_events idempotency table. The complete receiver, the idempotent-handler variant, and the idempotency table DDL are in edge-function-receivers.md.
// supabase/functions/on-order-created/index.ts
serve(async (req) => {
const rawBody = await req.text();
const secret = Deno.env.get("WEBHOOK_SECRET");
if (secret) {
const sig = req.headers.get("x-webhook-signature") ?? "";
if (!(await verifySignature(rawBody, sig, secret)))
return new Response(JSON.stringify({ error: "Invalid signature" }), { status: 401 });
}
const payload = JSON.parse(rawBody); // { type, table, record, old_record }
// route by payload.type: INSERT | UPDATE | DELETE
return new Response(JSON.stringify({ received: true }));
});Use pg_notify from a trigger for lightweight, non-persistent pub/sub consumed by a backend LISTEN; use Realtime postgres_changes for client-side UI subscriptions (keep NOTIFY payloads to IDs — they truncate past 8000 bytes). The backend listener, the full Realtime subscription with event routing, and the combined event-driven architecture diagram are in listen-notify-realtime.md.
const channel = supabase
.channel("orders-events")
.on("postgres_changes",
{ event: "*", schema: "public", table: "orders" },
(payload) => console.log(payload.eventType, payload.new))
.subscribe();These patterns produce:
pg_net on row changes| Error | Cause | Fix |
|---|---|---|
pg_net returns 404 | Edge Function not deployed or wrong URL | Run supabase functions deploy <name> and verify the URL matches |
| Webhook not firing | Trigger not attached or table not in publication | Check SELECT * FROM pg_trigger WHERE tgrelid = 'orders'::regclass; |
| Duplicate events processed | No idempotency layer | Add processed_events table with unique event_id constraint |
| Realtime not receiving | Table not added to Realtime publication | Dashboard > Database > Replication > enable the table |
net._http_response shows 401 | Invalid or missing auth header | Verify service_role_key is set in app.settings or vault |
| NOTIFY payload truncated | Payload exceeds 8000 bytes | Send only IDs in NOTIFY, fetch full record in the listener |
| Auth hook errors | Function raises exception | Check Dashboard > Logs > Auth; ensure function returns valid JSONB |
| Trigger silently fails | SECURITY DEFINER without search_path | Add SET search_path = public, extensions; to function |
pg_net trigger set: conditional status-change trigger, the supabase_functions.http_request() helper, and net._http_response inspection queries.LISTEN client, full Realtime subscription, and the combined event-driven architecture diagram.channel().on() APIFor performance optimization of triggers and queries, see supabase-performance-tuning. For production hardening including RLS policies on webhook-accessed tables, see supabase-security-basics.
© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (references) in skills/.curated/supabase-webhooks-events of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit cfae287
Supabase Webhooks Events next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Supabase Webhooks Events this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~2.2k | Automated safety check: Pass | MIT | |
| Supabase Development and Debuggingsupabase/agent-skills | 2.7k | 3 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Stripe Projectsfossasia/eventyay | 1.7k | 5 repos | ~2k | Automated safety check: Notes | Apache-2.0 | |
| Supabasecurvenote/curvenote | 170 | 5 repos | ~2.2k | Automated safety check: Pass | Custom licence | |
| Golivemikehasa/golive-skill | 1.3k | — | ~13k | Automated safety check: Notes | MIT | |
| Windmill Trigger Type Checklistwindmill-labs/windmill | 18k | — | ~4.7k | Automated safety check: Pass | Custom licence |
supabase/agent-skills
General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.
fossasia/eventyay
A skill your agent uses when the user wants to provision infrastructure or third-party services using Stripe Projects.
curvenote/curvenote
A skill your agent uses when doing ANY task involving Supabase.
mikehasa/golive-skill
Take an agent-written app from repo to live production on the user's OWN accounts, with providers they choose (hosting, database, auth, payments, email, domain/DNS).
windmill-labs/windmill
Checklist of every backend, frontend, CLI and capture change needed to add a new TriggerCrud-based trigger type, such as Azure, GCP or Kafka, to Windmill.
OtterMind/Nubase
A skill your agent uses when the user mentions Nubase broadly, wants a backend for an AI-generated app, or needs to deploy/publish generated code online — across Database, Auth, Storage, Assets…
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Works with
Categories
Implement Supabase database webhooks, pgnet async HTTP, LISTEN/NOTIFY, and Edge Function event handlers with signature verification. Supabase Webhooks Events is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement Supabase database webhooks, pgnet async HTTP, LISTEN/NOTIFY, and Edge Function event handlers with signature verification.
Supabase Webhooks Events fits situations like: setting up database webhooks for INSERT/UPDATE/DELETE events; sending HTTP requests from PostgreSQL triggers; handling Realtime postgreschanges as an event source; building event-driven architectures.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-webhooks-events -a claude-code`. Or copy the skill folder (skills/.curated/supabase-webhooks-events in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/supabase-webhooks-events in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-webhooks-events -a codex`. Or copy the skill folder (skills/.curated/supabase-webhooks-events in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/supabase-webhooks-events in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-webhooks-events -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supabase-webhooks-events, .gemini/skills/supabase-webhooks-events, .github/skills/supabase-webhooks-events and .opencode/skills/supabase-webhooks-events in your project.
Going by SKILL.md and its folder, Supabase Webhooks Events needs the command-line tools its instructions call (supabase) and credentials named WEBHOOK_SECRET. Our summary lists: Node.js; A credential in WEBHOOK_SECRET. Its frontmatter pre-approves these tools: Write, Bash(supabase:*), Bash(curl:*), Bash(psql:*). Compatibility (from SKILL.md): Designed for Claude Code.
SKILL.md names 1 domain. As links in the text: supabase.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Supabase Webhooks Events is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Supabase Webhooks Events: Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Stripe Projects (fossasia/eventyay, 1.7k stars), Supabase (curvenote/curvenote, 170 stars) and Golive (mikehasa/golive-skill, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.