Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | Neon MCPWatchlist candidate | Supabase MCPMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | First-party MCP Neon · Publisher source ↗ | First-party MCP Supabase · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Aug 13, 2026 Package: Sep 16, 2025 | Repo: Aug 14, 2026 Package: Not documented |
| Popularity evidence | ||
| GitHub stars | 624 GitHub stars · checked 2026-08-14T18:46:26.000Z | 2,863 GitHub stars · checked 2026-08-14T18:46:26.000Z |
| 30-day package downloads | 6,433 30-day package downloads · checked 2026-07-29T17:30:00.000Z | No reliable download data |
| External adoption evidence |
|
|
| Client coverage | ||
| Client coverage details | Claude Code✓ Streamable HTTP Claude Desktop✓ Streamable HTTP Codex✓ Streamable HTTP VS Code✓ Streamable HTTP Cursor✓ Streamable HTTP OpenCode✓ Streamable HTTP | Claude Code✓ Streamable HTTP Claude Desktop✓ Streamable HTTP Codex✓ Streamable HTTP VS Code✓ Streamable HTTP Cursor✓ Streamable HTTP OpenCode✓ Streamable HTTP |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | Authentication follows the publisher's documented endpoint or local-server configuration. OAuth scopes, API-key handling, and revocation behavior remain review items. | Hosted MCP uses browser OAuth and grants organization access to the MCP client. Project scope, read-only mode, and feature groups are encoded in URL query parameters. |
| Cost | No MCP100 cost conclusion is published yet. The publisher's account plan, API usage, infrastructure, or per-action charges may apply. | The MCP server is open source; normal Supabase plan, database, branch, Edge Function, storage, and usage charges apply. Branching and some storage operations require a paid plan. |
| Permissions | Exact permissions and the read/write boundary have not yet completed MCP100 independent review; consult the linked publisher sources and use the narrowest available scope. | Without project_ref the hosted server can access all projects in the authorized organization. With project_ref it is limited to one project. read_only=true uses a read-only Postgres user for SQL and disables listed mutation tools. Feature groups can further narrow exposed tools. |
| Data handling | Publisher-accessible account or application data may be returned to the MCP client and its selected model. Retention and subprocess behavior require candidate-specific review. | Enabled tools may return schemas, table data from executed queries, logs, security/performance advisors, project metadata, publishable keys, types, and Edge Function source. Hosted mode sends tool requests through Supabase's MCP service. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | Use a test workspace or non-production account, least privilege, read-only controls where available, explicit approval for mutations, and credential revocation after evaluation. | Unscoped or write-enabled access can affect every project in an organization, execute SQL, apply migrations, deploy functions, or manage branches. Always set project_ref and read_only=true first, minimize feature groups, and avoid production data. |
| Evidence date | ||
| Editorial review | 2026-07-24 | 2026-07-24 |
| Candidate evidence | 2026-08-14T18:46:26.000Z | 2026-08-14T18:46:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →