# Supabase

Probo reads your Supabase organization's members through the Supabase Management API so you can review who has access.

:::caution
Use a Supabase **personal access token** (`sbp_…`) created on your account's **Access Tokens** page. Give it **Organization** resource access that includes the organization you want to review. A token left on the default **Project** resource access cannot read organization members. Project API keys do not work either. Publishable keys (`sb_publishable_…`), secret keys (`sb_secret_…`) and the legacy `anon` and `service_role` JWTs authenticate requests to a single project, but the organization members endpoint is on the Management API at `api.supabase.com`, which accepts only a personal access token or an OAuth2 token.
:::

## Prerequisites

- Probo organization administrator access
- A Supabase account with an organization role in the organization you want to review. Every organization role (**Owner**, **Administrator**, **Developer** and **Read-Only**) can list organization members. An account with access to specific projects only cannot select the organization for an **Organization** token. A token never has more access than the account that created it
- The **Organization Slug** of the organization Probo should review, which the Connect dialog asks for alongside the token. Supabase puts it in the dashboard URL while the organization is open: `supabase.com/dashboard/org/<organization-slug>`

## Collected Fields

| Probo field | Supabase field                                           | Notes                                                                                                                                                                                                                                               |
| ----------- | -------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Name        | `user_name`                                              | The member's Supabase user name. There is no fallback, so a member returned without one is listed with an empty name                                                                                                                                |
| Email       | `email`                                                  |                                                                                                                                                                                                                                                     |
| Role        | `role_name`                                              | The members endpoint returns one role name per member. Supabase's organization roles are `Owner`, `Administrator`, `Developer` and `Read-Only`. Probo trims surrounding whitespace, and a member returned without a role name is listed without one |
| Admin       | `role_name`                                              | Flagged as an administrator when `role_name` is `Owner` or `Administrator`, and not for `Developer` or `Read-Only`                                                                                                                                  |
| Status      |  |                                                                                                                                                                                                                                                     |
| MFA         | `mfa_enabled`                                            | Enabled when the flag is true, disabled otherwise. Supabase returns the flag for every member                                                                                                                                                       |
| Last login  |  |                                                                                                                                                                                                                                                     |
| External ID | `user_id`                                                | Stable identifier used to track the account across reviews                                                                                                                                                                                          |
| Created at  |  |                                                                                                                                                                                                                                                     |

## Step 1: Create a Personal Access Token

![The Generate token dialog in Supabase with Organization resource access selected](/docs/access-review/supabase-create-api-key.webp)

1. In the [Supabase dashboard](https://supabase.com/dashboard/account/tokens), go to **Account Settings** > **Access Tokens** and click **Generate new token**.
2. Enter a **Name** (e.g. `Probo Access Review`) and set **Expires in**. The dialog defaults to 7 days, so pick **90 days** or a **Custom** date that covers your review cycle.
3. Under **Resource access**, select **Organization** instead of the default **Project**, then choose the organization Probo should review in **Select organizations**.
4. Under **Permissions**, open **Account and organization** and set **Organization Members** to **Read**. Probo reads nothing else, so leave the other permissions at **None**.
5. Click **Review access**, then **Create token**. Copy the token (`sbp_…`) and store it securely. Supabase shows it once and you cannot retrieve it afterwards.

## Step 2: Connect in Probo

1. In Probo, go to **Access Review** > **Connections**.
2. Find **Supabase**, click **API Key**, paste the token, enter your **Organization Slug**, and click **Connect**.

When you click **Connect**, Probo uses the token to request that organization's members from Supabase. If Supabase has no organization with that slug, the dialog shows an error under **Organization Slug**. If it accepts the token but refuses to list that organization's members, the error appears under **API Key**. In both cases Probo does not save the connection. After you connect, Probo names the source after your organization slug and pulls its members into your campaigns.

## Troubleshooting

- **Token rejected.** The Connect dialog only accepts a key that starts with `sbp_`, so a project API key is refused before it reaches Supabase. An expired or deleted personal access token is not caught when you connect: the source then shows **Supabase credentials are invalid**. Confirm the token is still listed under **Account Settings** > **Access Tokens**.
- **"This access token cannot read the members of this organization."** Shown under **API Key**. The token has the default **Project** resource access, is scoped to other organizations, or belongs to an account that is not a member of this organization. Generate a token with **Organization** resource access that includes the organization and **Organization Members** set to **Read**.
- **"Supabase has no organization with this slug."** Open the organization in the Supabase dashboard and copy the **Organization Slug** from the URL: `supabase.com/dashboard/org/<organization-slug>`.
- **Syncs worked and then stopped.** The token has expired, or the account that created it has left the organization. A token has only its owner's access, so it stops reading the organization once that person leaves. The console cannot replace the token on an existing source. Generate a new token, **Delete** the source in **Connections**, and connect Supabase again with the new token. Campaigns that already include the deleted source stop fetching it, so start a new campaign to review it again.
- **Using a legacy token.** A legacy token has full access to your account and shows a **LEGACY** badge on the **Access Tokens** page. Tokens created before Supabase introduced scoped tokens are legacy tokens, and so are tokens made with **Create legacy token**. A legacy token works, but it grants far more access than Probo needs. Prefer a token scoped as described in Step 1.
