# AX Check: supabase.com
Checked 2026-09-27.

Supabase quickstart works end-to-end, pricing stated upfront.
All 23 checklist items passed: docs, install commands, and API keys are explicit, and pricing tiers (Free $0, Pro $25/mo, Team $599/mo) are readable without login.

## Onboarding needs a login

## Coding sessions
All three independent sessions (DeepSeek V4.1 Flash, Kimi K3, Qwen 3.8 Max) completed the task and correctly reported Supabase's Free, Pro, and Team pricing tiers with specific dollar amounts and usage assumptions, all sourced directly from the public pricing page with no login wall encountered.

### DeepSeek V4.1 Flash
[View public run](https://agents.withgauge.com/p/runs/336e6923-afb8-469c-8c32-ba1e709c00fc) · [Read transcript](https://www.ax-check.com/supabase.com/sessions/deepseek.json)
Final output gives a pricing table (Free $0, Pro from $25/mo, Team from $599/mo, Enterprise custom) sourced from supabase.com/pricing (seq 60-61) with explicit assumptions like MAU/disk/egress tiers, compute-instance sizes, and add-on costs (PITR, log drains, custom domains, phone MFA).
#### End-to-end onboarding
- **Onboarding needs a login**: Agent never obtained Supabase credentials on its own. It explicitly checked for a Supabase CLI and any SUPABASE_* environment variables, found none, and could not create a hosted project or an API key without human help. It built a script and ran it only against dummy/missing values, producing a deliberate 'BLOCKED' exit and a generic fetch failure with fake credentials -- neither is an authenticated operation against the real product. The session ends with the agent asking the user to supply a URL and anon key.
  Event 4:

  ```text
  which supabase 2>&1; supabase --version 2>&1; echo "--- env supabase ---"; env | grep -i supabase 2>&1
  ```
  Event 57:

  ```text
  BLOCKED: set SUPABASE_URL and SUPABASE_ANON_KEY (from your hosted project settings).
  exit=2
  --- with dummy creds (expect a real API error, not a crash) ---
  insert failed: TypeError: fetch failed
  exit=1
  ```
  Event 63:

  ```text
  I cannot create or read your hosted project without a `SUPABASE_URL` + `SUPABASE_ANON_KEY` (for app calls), or a personal access token (for the Management API). I don't have any, so I can't do a real end-to-end run.
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No self-service way to get a Supabase project or API key**: The environment has no Supabase CLI and no SUPABASE_* environment variables, so the agent had no path to provision a project or obtain an anon/service key without a human. This is a missing-credentials limitation of the test environment/product signup flow, not a bug in the SDK itself -- Supabase requires dashboard signup for project creation. The agent correctly stopped short of guessing at billing/provisioning actions rather than erroring out destructively.
  Event 4:

  ```text
  env | grep -i supabase 2>&1
  ```
  Event 63:

  ```text
  I'm blocked on credentials. I cannot create or read your hosted project without a `SUPABASE_URL` + `SUPABASE_ANON_KEY`
  ```

#### Suggested Changes
- **Offer a scriptable/CLI-free way to provision a throwaway project and key**: During the session, obtaining a Supabase URL and anon key required dashboard access with no non-interactive alternative available in the sandbox (no CLI installed, no env vars, no token). If a lightweight, non-interactive project-creation path (e.g., a documented Management API token flow reachable via curl) were surfaced directly in the pricing/quickstart page the agent already fetched, an agent could self-serve a sandbox project and complete a real end-to-end run instead of stopping at the credential wall observed at seq 63.
  Event 63:

  ```text
  or a personal access token (for the Management API). I don't have any, so I can't do a real end-to-end run.
  ```

### Kimi K3
[View public run](https://agents.withgauge.com/p/runs/9da56484-903f-452a-87f3-0b9eb3490fb3) · [Read transcript](https://www.ax-check.com/supabase.com/sessions/kimi.json)
Final output gives Free/Pro/Team tier pricing and names assumptions — 'for a simple example, the Free tier is comfortably enough' and flags usage-based overages (compute size, storage/bandwidth) as the cost dial.
#### End-to-end onboarding
- **Onboarding needs a login**: Agent found no Supabase credentials in the sandbox environment or home directory, confirmed the Management API rejects unauthenticated requests (401), and correctly identified that Supabase account creation requires GitHub OAuth or email verification in a browser with no unattended signup path. It stopped and asked the human for a personal access token or project URL/anon key rather than fabricating success. No credentials were obtained and no authenticated product operation occurred.
  Event 10:

  ```text
  200
  401
  
  ```
  Event 14:

  ```text
  .
  ..
  .cache
  .gauge
  .pi
  .tmp
  repo
  done
  
  ```
  Event 16:

  ```text
  There are no Supabase credentials in this environment (`SUPABASE_ACCESS_TOKEN`, project URL, or anon key), the Management API at `api.supabase.com` correctly returns `401`, and there's no unattended signup — account creation needs GitHub OAuth or email verification in a browser.
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No Supabase account or API credentials available**: The sandbox had no SUPABASE_ACCESS_TOKEN, project URL, or anon key, and Supabase requires browser-based signup (GitHub OAuth or email verification) with no unattended path to create an account. This is a missing-credentials limitation of the test environment, not a product defect, since Supabase intentionally gates account creation behind normal auth.
  Event 10:

  ```text
  200
  401
  
  ```
  Event 16:

  ```text
  account creation needs GitHub OAuth or email verification in a browser
  ```

#### Suggested Changes
None identified in this transcript.

### Qwen 3.8 Max
[View public run](https://agents.withgauge.com/p/runs/453fb4e5-7516-478b-8dbc-112101855488) · [Read transcript](https://www.ax-check.com/supabase.com/sessions/qwen.json)
Final output gives Free/Pro/Team tiers with explicit named assumptions (project limits, DB size, egress, MAU, per-project vs per-org billing) and caveats it may change — check pricing page.
#### End-to-end onboarding
- **Onboarding needs a login**: The agent checked the sandbox environment for Supabase credentials and found none (only a pi gateway key was present). It confirmed network reachability to Supabase's API but got a 401 from the Management API, and had no self-service path to obtain a project URL/anon key or an access token. It built the demo code and schema, but explicitly stated it could not run it against a real hosted project and asked the human to supply either an anon key or a personal access token. No authenticated product operation against hosted Supabase was ever demonstrated.
  Event 4:

  ```text
  which node npm python3 psql curl 2>/dev/null; node -v 2>/dev/null; echo "---"; ls ~/.netrc ~/.config 2>/dev/null
  ```
  Event 10:

  ```text
  api.supabase.com:401
  ```
  Event 38:

  ```text
  I have no Supabase credentials in this environment.** `env` has only a pi gateway key, and `api.supabase.com/v1/projects` returns 401. So I could not run the demo against a real hosted project.
  ```
  Event 36:

  ```text
  ✗ insert: TypeError: fetch failed
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No Supabase credentials available in sandbox**: The environment only exposed a pi gateway API key; no Supabase project URL, anon key, or access token was present. This is a missing-credentials limitation of the test environment, not a product defect — Supabase requires normal signup/dashboard steps to get keys, which the agent correctly could not bypass. The agent tried a dummy key against a nonexistent project ref to confirm the failure mode, then stopped and asked the human for real credentials.
  Event 5:

  ```text
  PI_GATEWAY_API_KEY=<redacted>
  ```
  Event 10:

  ```text
  api.supabase.com:401
  ```
  Event 36:

  ```text
  ✗ insert: TypeError: fetch failed
  ```
  Event 38:

  ```text
  paste `SUPABASE_URL` + `SUPABASE_ANON_KEY` into `.env` and I'll run it and fix whatever comes back, or
  - also give me a `SUPABASE_ACCESS_TOKEN` (personal access token) and I can create the project, apply the schema, and run the demo end-to-end myself via the Management API.
  ```

#### Suggested Changes
- **Offer a scriptable/self-service credential path for sandboxed or CI-style agents**: The agent noted that Supabase secrets are dashboard-first, meaning any automated agent without a human in the loop cannot obtain a project URL, anon key, or personal access token to complete a hosted example. If Supabase wants to support this kind of automated onboarding, consider documenting or exposing a non-interactive way to provision a free project and retrieve keys (e.g., a documented CLI/API flow) and verify it by having an agent run `node demo.mjs` end-to-end without human-supplied secrets.
  Event 38:

  ```text
  secrets are dashboard-first, so unless you hand me a token I'm dependent on you for credential rotation
  ```
- **Document the free-tier inactivity pause behavior near connection-error troubleshooting**: The agent flagged that Free-tier projects pause after about a week of inactivity, producing a 'connection refused' style failure that looks like a code bug. Adding a note about this near common connection-error troubleshooting docs (or in the client library's error messages) would help developers distinguish a paused project from an actual bug.
  Event 38:

  ```text
  Free-tier inactivity pausing produces confusing "connection refused" failures days later that look like code bugs but aren't
  ```

### Task given to each agent
Help me build a simple example using Supabase. Tell me how pricing works, and briefly tell me whether this product will be easy for you to manage. Let me know if you get blocked. If this product has no developer workflow you can act on, say so plainly and stop. Stay light: use the hosted product through its SDK or API. Do not start local service stacks or wait for long-running commands; if the quickstart requires either, say so plainly and stop.

No product credentials were supplied and no purchases were authorized.

## Score: A · 100/100 (provisional)
Grades come from completed site checks. Coding sessions and skipped checks do not affect the score.

### Clarity
- **Pass** — Homepage answers Markdown requests

  ```text
  Homepage returned text/markdown with 200 when requested with Accept: text/markdown.
  ```

- **Pass** — llms.txt provides an actionable documentation index

  ```text
  llms.txt lists docs guides, SDK references, CLI, API and MCP links.
  ```

- **Pass** — llms.txt provides navigation guidance

  ```text
  llms.txt organizes links under Documentation, Pricing, and API/agent resources headings.
  ```

- **Pass** — llms.txt mentions offered API, MCP, and skills

  ```text
  llms.txt links Management API OpenAPI spec and Supabase MCP server endpoint.
  ```

- **Pass** — A compact guide representation exists

  ```text
  llms.txt and .md routes serve Supabase docs as Markdown, e.g. reactjs.md and generate-text-embeddings.md.
  ```

- **Pass** — A focused guide is directly retrievable

  ```text
  React quickstart .md returns a full 9-step guide with SQL, install and code.
  ```

- **Pass** — Equivalent instructions fit a token budget

  ```text
  React quickstart Markdown is 1770 tokens, well under the 8000-token budget.
  ```

- **Pass** — Product-docs links survive format changes

  ```text
  Markdown quickstart keeps docs links to Auth, Storage, RLS and API keys.
  ```

- **Pass** — The compact guide is independently actionable

  ```text
  React quickstart gives concrete steps: create project, SQL, install supabase-js, run app.
  ```

- **Pass** — Install and next-step links resolve

  ```text
  Sampled install and next-step links (docs, API, MCP, skills) fetched successfully.
  ```


### Onboarding
- **Pass** — Docs lead to a relevant quickstart

  ```text
  React quickstart gives concrete steps: create project, SQL, install supabase-js, query data.
  ```

- **Pass** — Installation commands are extractable

  ```text
  Install commands extractable: npm install @supabase/supabase-js and CLI installs across npm/brew/scoop.
  ```

- **Pass** — Code examples are available without interaction

  ```text
  Full code examples shown inline: SQL, client init, App.jsx, and Edge Function handler.
  ```

- **Pass** — Prerequisites and auth boundaries are explicit

  ```text
  Prerequisites (Node 20, Docker) and API key/URL setup with where to obtain them are explicit.
  ```


### Pricing
- **Pass** — Pricing is readable without interaction

  ```text
  Supabase pricing.md renders plan tiers, compute add-ons and feature tables as plain readable text.
  ```

- **Pass** — Prices are stated, not gated

  ```text
  Prices stated openly: Free $0, Pro $25/mo, Team $599/mo, plus per-unit rates.
  ```

- **Pass** — Pricing units and limits are explicit

  ```text
  Units and limits explicit: MAUs, GB egress, disk GB, compute sizes with RAM and connections.
  ```

- **Pass** — Agents identify pricing and its assumptions

  ```text
  3 of 3 sessions were judged on pricing; 0 fell short. DeepSeek V4.1 Flash: Final output gives a pricing table (Free $0, Pro from $25/mo, Team from $599/mo, Enterprise custom) sourced from supabase.com/pricing (seq 60-61) with explicit assumptions like MAU/disk/egress tiers, compute-instance sizes, and add-on costs (PITR, log drains, custom domains, phone MFA). Kimi K3: Final output gives Free/Pro/Team tier pricing and names assumptions — 'for a simple example, the Free tier is comfortably enough' and flags usage-based overages (compute size, storage/bandwidth) as the cost dial. Qwen 3.8 Max: Final output gives Free/Pro/Team tiers with explicit named assumptions (project limits, DB size, egress, MAU, per-project vs per-org billing) and caveats it may change — check pricing page. This behavioural item does not affect the fast grade.
  ```


### Activation
- **Pass** — An API reference or OpenAPI spec is reachable

  ```text
  llms.txt links a Management API OpenAPI spec; openapi.json returns OpenAPI 3.0 with 115 paths.
  ```

- **Pass** — An MCP server is documented and well-formed

  ```text
  MCP docs give hosted endpoint, per-client configs, tool groups, auth, and security guidance.
  ```

- **Pass** — A CLI install path is documented

  ```text
  CLI getting-started documents npm, Homebrew, Scoop, and Linux package installs plus npx usage.
  ```

- **Pass** — SDK packages resolve on their registries

  ```text
  Registry lookups for npm @supabase/supabase-js and supabase both returned HTTP 200.
  ```

- **Pass** — Agent skills are published

  ```text
  Agent Skills page documents install via npx skills add supabase/agent-skills and lists skills.
  ```



[Full report data](https://www.ax-check.com/supabase.com/report.json)
