Claude Code logoCoding agent·Anthropic

Claude Code + Powabase

Tell Claude Code what to build. It sets up the backend in your Powabase project and writes the code against it.

Claude Code already lives in your terminal and editor. Create a project in Studio, add the Powabase skill, and Claude can work in that project directly. It designs the schema, loads a knowledge base, connects agents, and hands back a working REST API. You describe the app; Claude does the wiring.

Rather have it built? Powabase engineers build MVPs free for annual Scale and Enterprise plans.

Quick start

Three steps and Claude Code is building on Powabase.

  1. 1

    Install the Powabase skill

    Run it once in your project. From then on the agent knows the Powabase API and how to call it.

    Terminal
    npx skills add powabase-ai/agent-skills
  2. 2

    Open your project in Claude Code

    Open Claude in the repo you're working in. It picks up the skill on its own.

    Terminal
    claude
  3. 3

    Describe the app

    Say what you want built: the data, who can see what, any agents. Claude wires it up and hands you a REST API. The examples below are a good place to start.

Example apps

Real apps, each from one prompt. Copy any of them and give it to Claude Code.

RAG support chatbot

Ingest our product docs, help center, and resolved tickets into a knowledge base, embedding on upload. Expose a support agent that answers with inline citations, streams over SSE, and hands off to a human when confidence is low. Add email and Google sign-in, isolate every conversation per organization with row-level security, and ship it as an embeddable chat widget.

Internal knowledge assistant

Index our wikis, runbooks, and exported threads into a knowledge base, chunking and embedding on upload. Expose an agent that answers with citations and respects per-department access, keep it fresh with scheduled re-indexing of changed sources, and add SSO sign-in plus an analytics view of unanswered questions.

AI help desk

Model tickets, organizations, and agents with row-level security, and auto-triage incoming tickets with an agent that predicts category and priority and drafts a reply from the knowledge base. Escalate low-confidence cases, run SLA timers as scheduled jobs, add email auth, and provide a live queue dashboard.

Sales CRM

Model companies, contacts, deals, and activities in Postgres with row-level security per team and roles for reps and managers. Build a pipeline board with stage tracking, an activity timeline, and semantic search across notes, plus a dashboard of weighted pipeline and win rate. Wire OAuth sign-in and an audit log of every change.

News monitoring app

Pull RSS feeds and news APIs on a schedule, deduplicate and embed each article, and run an agent that clusters related stories, summarizes them, and tags entities and sentiment. Let users define watchlists and alert rules, isolate data per workspace, and deliver a realtime feed plus a daily email digest via a cron job.

Invoice & receipt automation

Accept PDF and image uploads to storage, then extract vendor, line items, totals, and dates with an extraction agent and write validated records to Postgres, routing low-confidence fields to human review. Add approval workflows, per-team access control, exports to accounting formats, and a searchable archive.

Where Claude Code keeps your keys

Claude Code has no secrets store of its own. The key lives wherever your app reads it, usually a gitignored .env that your server code loads as BASE_URL and API_KEY. The Service Role key belongs only in server-side files; anything Claude writes for the browser should use the Anon key. If you'd rather Claude never open that file, add Read(./.env) to the deny list in your Claude Code settings: your app still loads it at runtime, Claude just can't read it.

Claude Code docs

Connect over MCP

Config lives at ~/.claude.json (local scope) or .mcp.json with --scope project (JSON, written by the CLI).

Terminal
claude mcp add --transport http powabase https://mcp.powabase.ai/mcp

Then run /mcp inside Claude Code and finish the sign-in in your browser, or run claude mcp login powabase. The command writes to local scope, which is private to you in this project. Add --scope project to write .mcp.json instead and share the server with your team through git; each person signs in once.

Append ?read_only=true to the MCP URL and the server exposes only the tools that don't write. We use it for sessions that should inspect a project and never mutate it.

Claude Code MCP docs

Claude Code example

lib/powabase.ts
// Server-only helper: the key comes from the environment, never the browser.
const BASE_URL = process.env.BASE_URL!;
const API_KEY = process.env.API_KEY!; // Service Role (Secret) Key

export async function searchDocs(kbId: string, query: string) {
  const res = await fetch(`${BASE_URL}/api/knowledge-bases/${kbId}/search`, {
    method: "POST",
    headers: {
      apikey: API_KEY,
      Authorization: `Bearer ${API_KEY}`,
      "Content-Type": "application/json",
    },
    body: JSON.stringify({ query, top_k: 5, retrieval_method: "hybrid" }),
  });
  if (!res.ok) throw new Error(`Powabase search failed: ${res.status}`);
  const { results } = await res.json();
  return results; // [{ score, text, ... }]
}

This is the shape Claude writes once the skill is installed: a server-side helper that searches a knowledge base with hybrid retrieval. Your route handlers call it; nothing in the browser sees the key.

Connecting to Powabase from any tool

Mechanics that don’t change from tool to tool.

Anon (Publishable) Key
Client-side
Respects Row Level Security, so it's safe to ship to a browser.
Service Role (Secret) Key
Server-side only
Bypasses RLS. Never put it in anything that ships to a browser.
Keys & RLS docs ↗
  • Every call to /api/* or /rest/v1/* needs two headers, apikey and Authorization: Bearer, both set to the same key. Sending only one is the most common cause of a 401.

    Docs
  • The Database URL from the Connect modal is PgBouncer in transaction mode, not a direct Postgres connection. Disable prepared statements in your driver, or you'll hit prepared statement "..." does not exist. No LISTEN/NOTIFY and no session-level SET across statements. Use Realtime for change notifications; SET LOCAL inside a transaction otherwise. The username and database in the URL are both your project ref, not postgres.

    Docs
  • @supabase/supabase-js mostly works for the BaaS surface (PostgREST, Auth, Storage, Realtime) when you point it at your project URL with the Anon key. It doesn't cover the /api/* AI surface (agents, knowledge bases, orchestrations), which you call over plain REST. There's no /graphql/v1 route: point any GraphQL client at POST /rest/v1/rpc/graphql instead.

    Docs

Common errors

Powabase is listed in /mcp, but Claude can't use any of its tools
Cause: The server was added, but the OAuth sign-in never finished, so Claude Code has no token for it.
Fix: Run /mcp, select powabase, and complete the browser sign-in. From a terminal, claude mcp login powabase does the same.
A teammate opens the repo and Claude Code has no Powabase server
Cause: claude mcp add writes to local scope unless told otherwise, and local scope is private to you.
Fix: Add it again with --scope project so it lands in .mcp.json, commit that file, and have each person sign in once.
401 Unauthorized
Cause: Only one of the apikey / Authorization headers was sent.
Fix: Send both, set to the same key. Docs
prepared statement "..." does not exist
Cause: PgBouncer's transaction-mode pooler moved you to a different server connection.
Fix: Disable prepared statements in your driver's config. Docs
A query that should return rows comes back empty, or a write is silently rejected
Cause: Row Level Security on your own tables. New public tables ship with RLS off, but once you add policies they gate every request.
Fix: Check the policy's USING/WITH CHECK clause and confirm which role (anon, authenticated, service_role) you actually authenticated as. Docs
The Service Role key turns up in a browser bundle or other client-visible code
Cause: It was used somewhere that ships to the client instead of staying server-side.
Fix: Move the call server-side; use the Anon key with RLS for anything client-visible. If it shipped, rotate it in Studio. Docs

FAQ

Yes. Run claude mcp add --transport http powabase https://mcp.powabase.ai/mcp, then /mcp to sign in. Claude gets dozens of tools: SQL, auth users, storage, knowledge bases and sources, agents, orchestrations, workflows, docs search, and listing, pausing, or resuming your projects.

Use both, because they do different jobs. The skill teaches Claude the REST API, so the code it writes calls Powabase correctly when your app runs. The MCP server lets Claude act on a live project during the session, like running SQL, checking what a knowledge base returns, or starting an agent run. The code you ship talks to the REST API either way.

No. The MCP server signs you in with OAuth in the browser, so no key goes into ~/.claude.json or .mcp.json. The Service Role key is only for the server code Claude writes for your app.

Not over MCP. The server can list, inspect, pause, and resume projects you already have, but you create projects in Studio at app.powabase.ai. Create one there, then point Claude at it.

By default in ~/.claude.json under the current project's path, visible only to you. With --scope project it goes in .mcp.json at the repo root, which you can commit; with --scope user it applies to all your projects. The file holds the server URL, and each person signs in separately.