Skip to content

Products

Compliance Officer Service Expert-led compliance, end to end Compliance Portal Share security documents securely Employee Portal Your whole team’s compliance, in one portal Access Review Monitor user access across all your systems AI Agents Run compliance from the tools you use Cookie Banner Consent that follows every visitor's law Device Agent Continuous security posture for every device Open-source platform Deploy Probo on your own infrastructure

Resources

Probo stories How teams get compliant with Probo Blog Ideas and guidance from the Probo team Guides & tools Practical compliance guides and free tools Love from Customers What customers say about working with Probo Changelog Latest product updates Download Get the Device Agent

Company

About The people and vision powering Probo Careers Join the team building Probo Brand assets Official logos and visual resources Security Review our security and compliance posture
Overview Understand Probo and its core concepts Product Explore Probo's GRC capabilities Developers Explore GraphQL, CLI, MCP, n8n, and webhooks Deployment Probo Cloud, self-hosting, and configuration

Explore

GitHub Explore our open-source compliance tools

Supabase

Connect Supabase as an access review source using a personal access token so Probo can list the members of your Supabase organization.

View as Markdown

Probo reads your Supabase organization’s members through the Supabase Management API so you can review who has access.

  • Probo organization administrator access
  • A Supabase account with an organization role in the organization you want to review. Every organization role (Owner, Administrator, Developer and Read-Only) can list organization members. An account with access to specific projects only cannot select the organization for an Organization token. A token never has more access than the account that created it
  • The Organization Slug of the organization Probo should review, which the Connect dialog asks for alongside the token. Supabase puts it in the dashboard URL while the organization is open: supabase.com/dashboard/org/<organization-slug>
Probo fieldSupabase fieldNotes
Nameuser_nameThe member’s Supabase user name. There is no fallback, so a member returned without one is listed with an empty name
Emailemail
Rolerole_nameThe members endpoint returns one role name per member. Supabase’s organization roles are Owner, Administrator, Developer and Read-Only. Probo trims surrounding whitespace, and a member returned without a role name is listed without one
Adminrole_nameFlagged as an administrator when role_name is Owner or Administrator, and not for Developer or Read-Only
StatusNot supported
MFAmfa_enabledEnabled when the flag is true, disabled otherwise. Supabase returns the flag for every member
Last loginNot supported
External IDuser_idStable identifier used to track the account across reviews
Created atNot supported

The Generate token dialog in Supabase with Organization resource access selected

  1. In the Supabase dashboard, go to Account Settings > Access Tokens and click Generate new token.
  2. Enter a Name (e.g. Probo Access Review) and set Expires in. The dialog defaults to 7 days, so pick 90 days or a Custom date that covers your review cycle.
  3. Under Resource access, select Organization instead of the default Project, then choose the organization Probo should review in Select organizations.
  4. Under Permissions, open Account and organization and set Organization Members to Read. Probo reads nothing else, so leave the other permissions at None.
  5. Click Review access, then Create token. Copy the token (sbp_…) and store it securely. Supabase shows it once and you cannot retrieve it afterwards.
  1. In Probo, go to Access Review > Connections.
  2. Find Supabase, click API Key, paste the token, enter your Organization Slug, and click Connect.

When you click Connect, Probo uses the token to request that organization’s members from Supabase. If Supabase has no organization with that slug, the dialog shows an error under Organization Slug. If it accepts the token but refuses to list that organization’s members, the error appears under API Key. In both cases Probo does not save the connection. After you connect, Probo names the source after your organization slug and pulls its members into your campaigns.

  • Token rejected. The Connect dialog only accepts a key that starts with sbp_, so a project API key is refused before it reaches Supabase. An expired or deleted personal access token is not caught when you connect: the source then shows Supabase credentials are invalid. Confirm the token is still listed under Account Settings > Access Tokens.
  • “This access token cannot read the members of this organization.” Shown under API Key. The token has the default Project resource access, is scoped to other organizations, or belongs to an account that is not a member of this organization. Generate a token with Organization resource access that includes the organization and Organization Members set to Read.
  • “Supabase has no organization with this slug.” Open the organization in the Supabase dashboard and copy the Organization Slug from the URL: supabase.com/dashboard/org/<organization-slug>.
  • Syncs worked and then stopped. The token has expired, or the account that created it has left the organization. A token has only its owner’s access, so it stops reading the organization once that person leaves. The console cannot replace the token on an existing source. Generate a new token, Delete the source in Connections, and connect Supabase again with the new token. Campaigns that already include the deleted source stop fetching it, so start a new campaign to review it again.
  • Using a legacy token. A legacy token has full access to your account and shows a LEGACY badge on the Access Tokens page. Tokens created before Supabase introduced scoped tokens are legacy tokens, and so are tokens made with Create legacy token. A legacy token works, but it grants far more access than Probo needs. Prefer a token scoped as described in Step 1.