Provision and operate Supabase Postgres for this project — creating the project, picking the right connection string for each job, local CLI workflow, migrations, generated types, RLS policies, and…

UnlicenseAuto-check passedDatabases

Install Supabase DB

skills CLI
$ npx skills add textura-agency/next16-claude-starter --skill supabase-db -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install textura-agency/next16-claude-starter supabase-db --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/textura-agency/next16-claude-starter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/supabase-db .claude/skills/supabase-db && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supabase-db
GitHub stars
133
Token cost
~1.4k tokens
SKILL.md length
553 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
Unlicense

At a glance

Provision and operate Supabase Postgres for this project — creating the project, picking the right connection string for each job, local CLI workflow, migrations, generated types, RLS policies, and…

  • Works in 7 steps: Connection strings — pick per job, not… → Keys — use the new ones → Local workflow → …
  • The user asks to set up the database
  • SKILL.md covers 1. Connection strings — pick…, 2. Keys — use the new ones, 3. Local workflow and 4. RLS — the default, not the…, plus 3 more sections
  • Calls supabase and brew; needs NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY

What it does

Supabase DB is an agent skill from textura-agency/next16-claude-starter. Provision and operate Supabase Postgres for this project — creating the project, picking the right connection string for each job, local CLI workflow, migrations, generated types, RLS policies, and storage buckets. Use when the user asks to "set up the database", "add Supabase", "write a migration", "add RLS", "connect Payload to Supabase", or hits pooler/prepared-statement errors.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Databases. It works with Supabase and PostgreSQL. The repository describes itself as: AI-first Next.js 16 starter for animation-heavy sites, wired with an Obsidian vault & Claude Code hooks. The licence is Unlicense.

When your agent uses it

  • The user asks to set up the database
  • Write a migration
  • Connect Payload to Supabase
  • Hits pooler/prepared-statement errors

Example prompts

  • “set up the database”
  • “add Supabase”
  • “write a migration”
  • “/supabase-db”

Requirements

  • Node.js
  • Docker
  • A credential in NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Connection strings — pick per job, not per project
  2. Keys — use the new ones
  3. Local workflow
  4. RLS — the default, not the afterthought
  5. Storage
  6. Verify before reporting done
  7. Update the vault

What it can do on your machine

Read from SKILL.md and the folder at commit 6c6edf9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • supabase
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use supabase, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Supabase DB loads about 1.4k tokens when it runs. Until then it costs about 99 tokens; SKILL.md has 553 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~99
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from textura-agency/next16-claude-starter at commit 6c6edf9, republished under its Unlicense licence (© textura-agency). 553 words, ~1,359 tokens.

Download SKILL.mdSave it as .claude/skills/supabase-db/SKILL.md (or your agent's skills folder).
name
supabase-db
description
Provision and operate Supabase Postgres for this project — creating the project, picking the right connection string for each job, local CLI workflow, migrations, generated types, RLS policies, and storage buckets. Use when the user asks to "set up the database", "add Supabase", "write a migration", "add RLS", "connect Payload to Supabase", or hits pooler/prepared-statement errors.

Supabase Postgres

Supabase is the database for this project. In a Payload build it is Payload's Postgres; in a bespoke build it is queried directly. Either way the connection rules below are what break first.

Verified 2026-08 against @supabase/supabase-js 2.112, @supabase/ssr 0.12.

1. Connection strings — pick per job, not per project

Supabase hands you several strings. They are not interchangeable.

JobConnectionPortWhy
App runtime on serverless / Fluid ComputeSupavisor transaction6543many short-lived connections
Migrations, payload migrate, psql, pg_dumpDirect5432needs session state + DDL
Long-lived Node server, IPv4-only networkSupavisor session5432pooled but session-safe

Two traps:

  • Transaction mode (6543) does not support prepared statements. Symptoms: prepared statement "s0" already exists, or intermittent failures under load. Disable prepared statements in the client for that URL.
  • Direct connections are IPv6 by default. On an IPv4-only network (many CI runners) they fail to resolve — use the session pooler, or add the IPv4 add-on.

Store both: DATABASE_URL (6543, runtime) and DATABASE_URL_DIRECT (5432, migrations). Wire both into src/env.ts as server-only zod-validated vars.

2. Keys — use the new ones

Legacy anon / service_role JWTs are being retired (end of 2026). Use:

  • Publishable sb_publishable_… → NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY. Browser-safe only because RLS is enforced. It is not a secret, but it is also not protection.
  • Secret sb_secret_… → server-only, via getServerEnv(). Bypasses RLS entirely. Never NEXT_PUBLIC_, never import into a client component, never log it. Supabase now 401s a secret key sent from a browser user-agent, but do not rely on that as your control.

3. Local workflow

bash
brew install supabase/tap/supabase        # or npx supabase
supabase init                             # creates supabase/
supabase link --project-ref <ref>
supabase start                            # local Postgres + Studio in Docker
supabase db pull                          # snapshot remote schema into a migration
supabase migration new <name>             # hand-written SQL migration
supabase db push                          # apply migrations to the linked project
supabase gen types typescript --linked > src/types/database.ts

Never point local dev at the production database. A schema push — Payload's or the CLI's — will rewrite it. Use a separate project or a Supabase branch.

If Payload owns the schema, Payload owns migrations (payload generate:migrations) and the Supabase CLI is only used for things outside Payload's tables: RLS on your own tables, extensions, functions, storage policies. Do not let both tools generate migrations for the same tables.

Show full SKILL.md (235 more words)Show less

4. RLS — the default, not the afterthought

Every table holding user or tenant data gets RLS enabled plus at least one policy. A table with RLS enabled and no policy denies everything; a table without RLS is readable by anyone holding the publishable key.

sql
alter table public.submissions enable row level security;

create policy "insert own submissions"
  on public.submissions for insert to authenticated
  with check ((select auth.uid()) = user_id);

create policy "read own submissions"
  on public.submissions for select to authenticated
  using ((select auth.uid()) = user_id);
  • Wrap auth.uid() in (select …) so Postgres caches it per statement instead of per row — the single biggest RLS performance win on large tables.
  • Index every column a policy filters on (user_id, tenant_id).
  • Always name the role (to authenticated) — an unqualified policy also applies to anon.
  • Payload's own tables should not get RLS policies. Payload connects as the database owner and enforces its own access control; adding RLS there breaks the admin panel in confusing ways.

5. Storage

Buckets are private by default — keep it that way for anything user-supplied. For Payload media, use the S3-compatible endpoint with forcePathStyle: true (see the payload-cms skill). For direct use, prefer signed URLs over public buckets, and write storage policies the same way as table policies.

6. Verify before reporting done

  • Both connection strings tested — runtime query on 6543, a migration on 5432.
  • select * from pg_policies where schemaname = 'public'; — every user-data table appears, with the intended roles.
  • Types regenerated and committed if the schema changed.
  • No secret key anywhere in client-reachable code: grep -rn "sb_secret" src/ returns nothing outside src/env.ts usage.
  • .env.example updated; src/env.ts zod schema updated.

7. Update the vault

obsidian/backend/database-supabase.md, obsidian/architecture/environment-variables.md, obsidian/architecture/tech-stack.md, obsidian/meta/changelog.md.

© textura-agency, Unlicense. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/supabase-db of textura-agency/next16-claude-starter.

Open the folder on GitHubat commit 6c6edf9

Compare with similar skills

Supabase DB next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supabase DB compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supabase DB this skilltextura-agency/next16-claude-starter133—~1.4kAutomated safety check: PassUnlicense
Supabase Postgres Best Practicessupabase/agent-skills2.7k24 repos~808Automated safety check: PassMIT
Clickhouse Logs Queriessupabase/supabase111k—~2.4kAutomated safety check: PassApache-2.0
Safe SQL Executionsupabase/supabase111k—~4.2kAutomated safety check: PassApache-2.0
Add Backendahpxex/open-dashboard146—~3.6kAutomated safety check: PassMIT
Take Doc Screenshotspgplex/pgconsole155—~841Automated safety check: PassApache-2.0

Similar skills

  • Official

    Gives the agent Postgres rules to consult before writing or changing tables, queries, indexes, RLS policies or migrations, and when diagnosing slow queries.

    2.7k GitHub starsUsed in 24 repos~808 tokens
    DatabasesAuto-check passed
  • Clickhouse Logs Queries

    supabase/supabase

    Official

    Write, review, and migrate Supabase logs queries against the ClickHouse-backed logs table (the logs.all.otel analytics endpoint).

    111k GitHub stars~2.4k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Safe SQL Execution

    supabase/supabase

    Official

    A skill your agent uses whenever code will build, return, fetch, or execute SQL that runs against a user's real Postgres database — even when the request reads like an ordinary feature or bug fix…

    111k GitHub stars~4.2k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Add Backend

    ahpxex/open-dashboard

    Everything about the data layer — pick one of six ready-to-run backend templates (TanStack Start + Drizzle + better-auth, Hono + Drizzle + better-auth, Hono + Prisma + better-auth, Hono + Drizzle +…

    146 GitHub stars~3.6k tokensUpdated 3 mo ago
    DatabasesAuto-check passed
  • Take Doc Screenshots

    pgplex/pgconsole

    Take screenshots of the running pgconsole app for documentation.

    155 GitHub stars~841 tokensUpdated 1 mo ago
    DatabasesAuto-check passed
  • Srtd Dev

    t1mmen/srtd

    Expert knowledge for developing the SRTD codebase itself. An agent skill from t1mmen/srtd.

    105 GitHub stars~2.3k tokensUpdated 1 mo ago
    DatabasesAuto-check passed

More from textura-agency/next16-claude-starter

All 16 skills in this repo
  • Mobile Device QA

    textura-agency/next16-claude-starter

    Make a site behave on real phones — the defects no Lighthouse run or headless scroll test sees, learned from site owners reviewing production sites on an iPhone.

    135 GitHub stars~5k tokensUpdated yesterday
    Auto-check: notes
  • Optimize Load

    textura-agency/next16-claude-starter

    Get a page into Lighthouse's green zone on desktop and mobile, for people AND for the robot form crawlers get — build it, audit all four categories (Performance, Accessibility, Best Practices, SEO)…

    135 GitHub stars~4.6k tokensUpdated yesterday
    Auto-check: notes
  • Optimize Performance

    textura-agency/next16-claude-starter

    Make a page in this starter actually smooth — build it, scroll it in real Chrome on PC and on an emulated phone, fix what the measurement blames, re-measure to prove it.

    135 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes
  • Payload Admin

    textura-agency/next16-claude-starter

    Make a Payload admin feel like part of the site and explain itself — the skin re-tinted from the site's own tokens (calm, light, no added motion), the site's wordmark and favicon, a dashboard…

    135 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Payload Cms

    textura-agency/next16-claude-starter

    Put a Payload CMS admin on a site built from this starter — every visible string and content photo editable, derived from the site's own content objects with the code's copy as the fallback, a…

    135 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes
  • Aeo Visibility

    textura-agency/next16-claude-starter

    Answer Engine Optimisation — make the site citable by ChatGPT, Claude, Perplexity, Gemini and AI Overviews.

    135 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check: notes

Categories

Questions about Supabase DB

What does Supabase DB do?

Provision and operate Supabase Postgres for this project — creating the project, picking the right connection string for each job, local CLI workflow, migrations, generated types, RLS policies, and…. Supabase DB is an agent skill from textura-agency/next16-claude-starter. Provision and operate Supabase Postgres for this project — creating the project, picking the right connection string for each job, local CLI workflow, migrations, generated types, RLS policies, and storage buckets.

When should I use Supabase DB?

Supabase DB fits situations like: the user asks to set up the database; write a migration; connect Payload to Supabase; hits pooler/prepared-statement errors.

How do I install Supabase DB in Claude Code?

Run `npx skills add textura-agency/next16-claude-starter --skill supabase-db -a claude-code`. Or copy the skill folder (.claude/skills/supabase-db in textura-agency/next16-claude-starter) into .claude/skills/supabase-db in your project. Claude Code loads it when a task matches its description.

How do I install Supabase DB in Codex?

Run `npx skills add textura-agency/next16-claude-starter --skill supabase-db -a codex`. Or copy the skill folder (.claude/skills/supabase-db in textura-agency/next16-claude-starter) into .agents/skills/supabase-db in your project. Codex loads it when a task matches its description.

Can I use Supabase DB in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add textura-agency/next16-claude-starter --skill supabase-db -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supabase-db, .gemini/skills/supabase-db, .github/skills/supabase-db and .opencode/skills/supabase-db in your project.

What does Supabase DB need to run?

Going by SKILL.md and its folder, Supabase DB needs the command-line tools its instructions call (supabase and brew) and credentials named NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY. Our summary lists: Node.js; Docker; A credential in NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY.

Does Supabase DB access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Supabase DB safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Supabase DB use?

Supabase DB is published under the Unlicense licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supabase DB use?

About 1.4k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Supabase DB?

Skills that share tags, products or a category with Supabase DB: Supabase Postgres Best Practices (supabase/agent-skills, 2.7k stars), Clickhouse Logs Queries (supabase/supabase, 111k stars), Safe SQL Execution (supabase/supabase, 111k stars) and Add Backend (ahpxex/open-dashboard, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supabase DB?

textura-agency (a GitHub organization) maintains it in textura-agency/next16-claude-starter, which has 133 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 7, 2026.

Source: textura-agency/next16-claude-starter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.