Codex logoCoding agent·OpenAI

Codex + Powabase

One prompt writes your app and the Powabase backend it runs on.

Codex runs in a sandbox with file and shell access, so it can do the whole job from the command line. With the skill installed, the same prompt that writes your app also sets up the backend in your Powabase project and builds against the REST API.

Rather have it built? Powabase engineers build MVPs free for annual Scale and Enterprise plans.

Quick start

Three steps and Codex is building on Powabase.

  1. 1

    Install the Powabase skill

    Run it once in your project. From then on the agent knows the Powabase API and how to call it.

    Terminal
    npx skills add powabase-ai/agent-skills
  2. 2

    Launch Codex

    Open Codex in your repo.

    Terminal
    codex
  3. 3

    Describe the app

    Tell Codex what to build. It sets up the schema, auth, retrieval and agents, and returns a live API. Borrow one of the examples below if you want a head start.

Example apps

Real apps, each from one prompt. Copy any of them and give it to Codex.

RAG support chatbot

Ingest our product docs, help center, and resolved tickets into a knowledge base, embedding on upload. Expose a support agent that answers with inline citations, streams over SSE, and hands off to a human when confidence is low. Add email and Google sign-in, isolate every conversation per organization with row-level security, and ship it as an embeddable chat widget.

Internal knowledge assistant

Index our wikis, runbooks, and exported threads into a knowledge base, chunking and embedding on upload. Expose an agent that answers with citations and respects per-department access, keep it fresh with scheduled re-indexing of changed sources, and add SSO sign-in plus an analytics view of unanswered questions.

AI help desk

Model tickets, organizations, and agents with row-level security, and auto-triage incoming tickets with an agent that predicts category and priority and drafts a reply from the knowledge base. Escalate low-confidence cases, run SLA timers as scheduled jobs, add email auth, and provide a live queue dashboard.

Sales CRM

Model companies, contacts, deals, and activities in Postgres with row-level security per team and roles for reps and managers. Build a pipeline board with stage tracking, an activity timeline, and semantic search across notes, plus a dashboard of weighted pipeline and win rate. Wire OAuth sign-in and an audit log of every change.

News monitoring app

Pull RSS feeds and news APIs on a schedule, deduplicate and embed each article, and run an agent that clusters related stories, summarizes them, and tags entities and sentiment. Let users define watchlists and alert rules, isolate data per workspace, and deliver a realtime feed plus a daily email digest via a cron job.

Invoice & receipt automation

Accept PDF and image uploads to storage, then extract vendor, line items, totals, and dates with an extraction agent and write validated records to Postgres, routing low-confidence fields to human review. Add approval workflows, per-team access control, exports to accounting formats, and a searchable archive.

Where Codex keeps your keys

Codex doesn't store app secrets. It decides which of your environment variables reach the commands it runs through shell_environment_policy in ~/.codex/config.toml, so keep BASE_URL and API_KEY in your shell or in a gitignored .env your server code loads. The Service Role key stays in server code, and anything for the browser uses the Anon key. If you tighten that policy, remember that ignore_default_excludes = false drops every variable whose name contains KEY, SECRET, or TOKEN, API_KEY included.

Codex docs

Connect over MCP

Config lives at ~/.codex/config.toml (or .codex/config.toml in a trusted project) (TOML file).

TOML file
[mcp_servers.powabase]
url = "https://mcp.powabase.ai/mcp"

Then run codex mcp login powabase to finish the OAuth sign-in in your browser. You can also add the server from the terminal with codex mcp add powabase --url https://mcp.powabase.ai/mcp. The Codex CLI, the IDE extension, and the ChatGPT desktop app share this config.

Append ?read_only=true to the MCP URL and the server exposes only the tools that don't write. We use it for sessions that should inspect a project and never mutate it.

Codex MCP docs

Codex example

app/powabase.py
# What Codex writes for a Python backend: run a Powabase agent server-side.
import os
import requests

BASE_URL = os.environ["BASE_URL"]
API_KEY = os.environ["API_KEY"]  # Service Role (Secret) Key
HEADERS = {"apikey": API_KEY, "Authorization": f"Bearer {API_KEY}"}


def ask_agent(agent_id: str, message: str, session_id: str | None = None) -> dict:
    body = {"message": message}
    if session_id:
        body["session_id"] = session_id  # continue a multi-turn conversation
    res = requests.post(
        f"{BASE_URL}/api/agents/{agent_id}/run", headers=HEADERS, json=body, timeout=60
    )
    res.raise_for_status()
    return res.json()

POST /api/agents/{id}/run returns the whole reply as JSON in one call, with no tool use. When the agent needs its tools, Codex should call /run/stream and read the server-sent events instead.

Connecting to Powabase from any tool

Mechanics that don’t change from tool to tool.

Anon (Publishable) Key
Client-side
Respects Row Level Security, so it's safe to ship to a browser.
Service Role (Secret) Key
Server-side only
Bypasses RLS. Never put it in anything that ships to a browser.
Keys & RLS docs ↗
  • Every call to /api/* or /rest/v1/* needs two headers, apikey and Authorization: Bearer, both set to the same key. Sending only one is the most common cause of a 401.

    Docs
  • The Database URL from the Connect modal is PgBouncer in transaction mode, not a direct Postgres connection. Disable prepared statements in your driver, or you'll hit prepared statement "..." does not exist. No LISTEN/NOTIFY and no session-level SET across statements. Use Realtime for change notifications; SET LOCAL inside a transaction otherwise. The username and database in the URL are both your project ref, not postgres.

    Docs
  • @supabase/supabase-js mostly works for the BaaS surface (PostgREST, Auth, Storage, Realtime) when you point it at your project URL with the Anon key. It doesn't cover the /api/* AI surface (agents, knowledge bases, orchestrations), which you call over plain REST. There's no /graphql/v1 route: point any GraphQL client at POST /rest/v1/rpc/graphql instead.

    Docs

Common errors

Calls to your project URL fail while Codex runs the code
Cause: Codex's default workspace-write sandbox runs with network access turned off, so commands it runs can't reach *.p.powabase.ai until you allow it.
Fix: Approve the network request when Codex asks, or opt in for the workspace with network_access = true under [sandbox_workspace_write] in config.toml.
KeyError: 'API_KEY' when Codex runs your script, even though it's set in your shell
Cause: shell_environment_policy filtered it out. With ignore_default_excludes = false, Codex removes names containing KEY, SECRET, or TOKEN; inherit = "none" starts from an empty environment.
Fix: Keep ignore_default_excludes at its default (true), keep the default inherit setting, and exclude only the variables you actually want hidden.
401 Unauthorized
Cause: Only one of the apikey / Authorization headers was sent.
Fix: Send both, set to the same key. Docs
prepared statement "..." does not exist
Cause: PgBouncer's transaction-mode pooler moved you to a different server connection.
Fix: Disable prepared statements in your driver's config. Docs
A query that should return rows comes back empty, or a write is silently rejected
Cause: Row Level Security on your own tables. New public tables ship with RLS off, but once you add policies they gate every request.
Fix: Check the policy's USING/WITH CHECK clause and confirm which role (anon, authenticated, service_role) you actually authenticated as. Docs
The Service Role key turns up in a browser bundle or other client-visible code
Cause: It was used somewhere that ships to the client instead of staying server-side.
Fix: Move the call server-side; use the Anon key with RLS for anything client-visible. If it shipped, rotate it in Studio. Docs

FAQ

Add a [mcp_servers.powabase] table to ~/.codex/config.toml with url = "https://mcp.powabase.ai/mcp", then run codex mcp login powabase to sign in. codex mcp add powabase --url https://mcp.powabase.ai/mcp writes the same entry for you.

Yes. The CLI, the IDE extension, and the ChatGPT desktop app all read the same config.toml, so Powabase shows up in each after you add it once.

Yes. Put the [mcp_servers.powabase] table in .codex/config.toml inside the project instead of your home directory. Codex only reads project-level config in projects you've marked as trusted.

Yes, once network access is allowed. The default sandbox keeps it off, so Codex asks before a command goes to the internet. Approve it per request or turn it on for the workspace in config.toml.