Open Viro

    Supabase

    Connect Supabase and Viro can look inside one of your projects: its tables and columns, the rows in them, and Supabase's own security and performance warnings. Ask for a change, like a new table or a few rows, and Viro writes the SQL and shows it on a card. Nothing changes until you confirm.

    What can Viro do with Supabase?

    • List your tables with their columns, keys, and whether row-level security is on
    • Look up rows in your tables, such as counts, totals, or the latest entries
    • Show Supabase's security and performance warnings for the project
    • List the migrations that have run and the extensions that are installed
    • Generate TypeScript types from your database for your app's code
    • Create or change tables, columns, indexes, and row-level security policies, after you confirm
    • Add, change, or delete rows, after you confirm

    Viro can't:

    • See or change any project other than the one you choose
    • Undo a change once it has run
    • Delete a whole schema or database, or create and change database logins
    • Read or change Supabase's own sign-in, storage, and secrets tables
    • Deploy edge functions, manage storage or branches, or create, pause, and delete projects
    • Read your project's logs or API keys

    How do I connect Supabase?

    1. Open Customize > Connectors

      Select Customize in the sidebar, then Connectors.
    2. Open Supabase and select Connect to Viro

      Sign in to Supabase, choose the organization that holds your project, and select Authorize Viro AI. Back in Viro, pick the one project Viro may use and select Use this project.
    3. Check that it's connected

      Back in Viro, Supabase is listed under Yours.

    What can I ask?

    Once it's connected, just ask in any chat. For example:

    • "What tables are in my Supabase project?"
    • "How many rows are in my orders table?"
    • "Any security warnings for my Supabase project?"
    • "Add a table for blog posts with a title, a body, and a published date."
    • "Add a notes column to the orders table."
    • "Generate the TypeScript types for my Supabase project."

    Which project can Viro use?

    One. Supabase's sign-in covers every project in the organization you pick, so after you connect, Viro asks you to choose a single project. From then on Viro works inside that project only. It can't see or change any other project, including others in the same organization.

    The project is shown on the Supabase page in Customize > Connectors, by name and ID. Select Change there to pick a different one. Until a project is chosen, Viro can't look anything up.

    Supabase recommends connecting AI tools to a development project. If you connect a project your live app runs on, read each card carefully before you confirm it.

    Does Viro change anything without asking?

    No. When you ask for a change, Viro shows a card marked Needs your OK with the project's name and ID and the exact SQL it will run. Nothing happens in your project until you select the card's button:

    • Run migration for a change to the structure of your database, such as a new table, column, index, or policy. It's recorded in your project's migration history under the name on the card.
    • Run SQL for a change to rows: adding, changing, or deleting them.

    Select Edit to change the SQL or the migration's name first, or Cancel to drop it. What runs is what's on the card when you confirm. Afterward, the card shows Open in Supabase so you can check the result. Looking things up never needs a card, because lookups only read.

    What happens when a change would delete something?

    Viro asks twice. The card carries a warning that says what the SQL would do, and the first time you select its button nothing runs. The card turns red, asks Are you sure? Viro cannot undo this. and the button becomes Yes, run it. If you edit the SQL after that, Viro asks again. You'll see this for SQL that:

    • Deletes a table or a column, or empties a table
    • Deletes rows, or changes every row in a table because it has no WHERE
    • Removes a row-level security policy or turns row-level security off
    • Removes a function, trigger, index, view, or type, renames something, or changes a column's type
    • Sends data to another server, sets up a scheduled job, or runs a block of code

    What won't Viro run?

    A few changes are too large to make from a chat, so Viro refuses them even if you ask, and a card edited into one of them is refused too:

    • Deleting a whole schema or database, or creating and changing database logins
    • Dropping, emptying, or restructuring Supabase's own tables, such as the ones that hold your users' sign-ins and your stored files
    • SQL that reads files or runs programs on the database server

    You can still do these yourself in the Supabase dashboard.

    Can I undo a change?

    Not from Viro. A change runs on your project as soon as you confirm it, and Viro can't reverse it. Supabase's free plan keeps no automatic backups; its paid plans are backed up daily by Supabase. If the data matters, make sure you have a backup before you confirm a change that deletes.

    Will a new table work with my app right away?

    Viro turns on row-level security for the tables it creates. With row-level security on and no policy, your app can't read or write the table. Tell Viro who should be able to read and write, for example "signed-in users can read every post and edit only their own," and it puts the policies in the same change. If you haven't said, Viro tells you the table is locked and asks.

    What if the SQL fails?

    The card shows the database's own error, for example that a table already exists. Select Edit to fix the SQL and run it again, or tell Viro what the error says and ask for a corrected change.

    Why does Supabase's screen list more than this page does?

    Supabase's approval screen lists what the connection is allowed to do: your database, edge functions, secrets, and basic details of your organization and projects. Viro uses the database part only. It reads your tables, and it changes them only through a card you confirm. It doesn't deploy functions or read your API keys.

    How do I disconnect Supabase?

    In Customize > Connectors, open Supabase and select Disconnect. This deletes the connection Viro stored. Your past chats aren't deleted. Supabase may still list Viro AI as an authorized app for your organization. If you want it gone there too, remove it in your Supabase organization's settings.

    Is my Supabase data private?

    Viro reads your Supabase data only to answer what you ask. It's never used to train AI models, and Viro never sells your data. Rows in your tables can include your own users' names, email addresses, and other personal details.

    See all connectors.

    Frequently asked questions

    Can Viro change my Supabase database?

    Yes, with your OK each time. Viro writes the SQL and shows it on a card with the project's name. Nothing runs until you select Run migration or Run SQL, and it asks twice before anything that deletes.

    Which Supabase projects can Viro see?

    One. After you connect, you choose a single project, and Viro can't see or change any other, including others in the same organization.

    Can Viro undo a change it made in Supabase?

    No. A change runs on your project as soon as you confirm it. Supabase's free plan keeps no automatic backups, so check you have one before confirming a change that deletes.