Field-by-field comparison

Compare the evidence before choosing an MCP.

Each signal stays separate, missing facts remain visible, and the column order follows your selection.

MCPs in this comparison

Uncheck an MCP to remove it. Comparing two or three keeps each signal in its own row.

Open canonical comparison link

Comparable alternatives

Shown only when capability or industry context overlaps.

Side-by-side MCP evidence comparison
Evidence fieldQdrant MCPWatchlist candidateSupabase MCPMCP100 Selected
Task fit
Best for
  • Store and retrieve semantic memories and code context in Qdrant.
  • Teams already using Qdrant that can test with non-sensitive data and least privilege.
  • Inspecting one Supabase project's schema, logs, advisors, and docs
  • Development environments using project-scoped read-only access
  • Teams that understand database and deployment consequences
Not ideal for
  • Users who need an MCP100-selected recommendation today
  • Unattended production workflows before permissions and failure behavior are reviewed
  • Production database administration by an unattended agent
  • Users needing only public Supabase documentation
  • Organizations unable to grant Supabase OAuth access to an MCP client
Avoid when
  • The connected data or account cannot be safely exposed to the selected AI client
  • You cannot verify least-privilege access and review write-capable tool calls
  • The server would be left organization-wide rather than project-scoped
  • Write-capable SQL, migrations, functions, branches, or storage changes cannot be human-approved
  • Production secrets or customer records could be returned to the model
Provenance
Provenance details

First-party MCP

Qdrant · Publisher source ↗

First-party MCP

Supabase · Publisher source ↗

Maintenance
Maintenance details

Repo: Aug 14, 2026

Package: Dec 10, 2025

Repo: Aug 14, 2026

Package: Not documented

Popularity evidence
GitHub stars

1,501

GitHub stars · checked 2026-08-14T18:46:26.000Z

2,863

GitHub stars · checked 2026-08-14T18:46:26.000Z

30-day package downloads

1,512,245

30-day package downloads · checked 2026-07-29T17:30:00.000Z

No reliable download data
External adoption evidence
  • npm: package downloads: 1,512,245Exact attributable signal.npm: package downloads · Admission snapshot · checked 2026-07-29T17:30:00.000ZEvidence source ↗
  • github: repository stars: 1,501Exact attributable signal.github: repository stars · Admission snapshot · checked 2026-08-14T18:46:26.000ZEvidence source ↗
  • github: repository stars: 2,863Exact attributable signal.github: repository stars · Admission snapshot · checked 2026-08-14T18:46:26.000ZEvidence source ↗
Client coverage
Client coverage details
Claude CodeLocal stdio
Claude DesktopLocal stdio
CodexLocal stdio
VS CodeLocal stdio
CursorLocal stdio
OpenCodeLocal stdio
Claude CodeStreamable HTTP
Claude DesktopStreamable HTTP
CodexStreamable HTTP
VS CodeStreamable HTTP
CursorStreamable HTTP
OpenCodeStreamable HTTP
Client coverage noteLocal stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server.
Access and data
AuthenticationAuthentication follows the publisher's documented endpoint or local-server configuration. OAuth scopes, API-key handling, and revocation behavior remain review items.Hosted MCP uses browser OAuth and grants organization access to the MCP client. Project scope, read-only mode, and feature groups are encoded in URL query parameters.
CostNo MCP100 cost conclusion is published yet. The publisher's account plan, API usage, infrastructure, or per-action charges may apply.The MCP server is open source; normal Supabase plan, database, branch, Edge Function, storage, and usage charges apply. Branching and some storage operations require a paid plan.
PermissionsExact permissions and the read/write boundary have not yet completed MCP100 independent review; consult the linked publisher sources and use the narrowest available scope.Without project_ref the hosted server can access all projects in the authorized organization. With project_ref it is limited to one project. read_only=true uses a read-only Postgres user for SQL and disables listed mutation tools. Feature groups can further narrow exposed tools.
Data handlingPublisher-accessible account or application data may be returned to the MCP client and its selected model. Retention and subprocess behavior require candidate-specific review.Enabled tools may return schemas, table data from executed queries, logs, security/performance advisors, project metadata, publishable keys, types, and Edge Function source. Hosted mode sends tool requests through Supabase's MCP service.
Limitations
Tradeoffs
  • First-party provenance and a clear task improve confidence, but do not replace an independent permissions and usability review.
  • Client transport compatibility does not prove that authentication, scopes, failure handling, and every tool behave safely.
  • Project scoping removes account-level tools but materially reduces blast radius.
  • Read-only mode disables mutations but also removes migration, deployment, branch, and storage configuration workflows.
  • Branching and some storage capabilities require paid plans; the server is pre-1.0 and may change.
Risk contextUse a test workspace or non-production account, least privilege, read-only controls where available, explicit approval for mutations, and credential revocation after evaluation.Unscoped or write-enabled access can affect every project in an organization, execute SQL, apply migrations, deploy functions, or manage branches. Always set project_ref and read_only=true first, minimize feature groups, and avoid production data.
Evidence date
Editorial review2026-07-242026-07-24
Candidate evidence2026-08-14T18:46:26.000Z2026-08-14T18:46:26.000Z

Popularity, maintenance, fit, permissions, and client support are independent evidence fields.

Read the evidence method →