Lovable logoVibe-coding platform·Lovable

Lovable + Powabase

Lovable makes the app. Powabase makes it real.

Describe an app and Lovable builds the UI for you. Connect a Powabase project and that UI talks to a real backend over the REST API for sign-in, tables, file storage and search.

Rather have it built? Powabase engineers build MVPs free for annual Scale and Enterprise plans.

Quick start

Three steps and Lovable is building on Powabase.

  1. 1

    Create a Powabase project

    Create a project at app.powabase.ai and open the Connect dialog (top-left in Studio). Copy the Project URL and the Service Role (Secret) Key. The Service Role key reaches everything: the agent and AI endpoints, plus full database access. Keep it on the server and never put it in the browser.

    The Powabase Connect dialog showing the Project URL, Anon key, Service Role key, JWT secret, and Database URL
    The Connect dialog in Powabase Studio.
  2. 2

    Add the keys in Lovable

    Add the Project URL and Service Role key to Lovable's server-side environment. Ship the Anon (publishable) key to the browser, never the Service Role key.

    Environment
    BASE_URL=<Project URL>
    API_KEY=<Service Role (Secret) Key>
  3. 3

    Describe the app

    Describe what you want. Lovable builds the UI and calls Powabase for data and sign-in. Start from an example below.

Example apps

Real apps, each from one prompt. Copy any of them and give it to Lovable.

RAG support chatbot

Ingest our product docs, help center, and resolved tickets into a knowledge base, embedding on upload. Expose a support agent that answers with inline citations, streams over SSE, and hands off to a human when confidence is low. Add email and Google sign-in, isolate every conversation per organization with row-level security, and ship it as an embeddable chat widget.

Internal knowledge assistant

Index our wikis, runbooks, and exported threads into a knowledge base, chunking and embedding on upload. Expose an agent that answers with citations and respects per-department access, keep it fresh with scheduled re-indexing of changed sources, and add SSO sign-in plus an analytics view of unanswered questions.

AI help desk

Model tickets, organizations, and agents with row-level security, and auto-triage incoming tickets with an agent that predicts category and priority and drafts a reply from the knowledge base. Escalate low-confidence cases, run SLA timers as scheduled jobs, add email auth, and provide a live queue dashboard.

Sales CRM

Model companies, contacts, deals, and activities in Postgres with row-level security per team and roles for reps and managers. Build a pipeline board with stage tracking, an activity timeline, and semantic search across notes, plus a dashboard of weighted pipeline and win rate. Wire OAuth sign-in and an audit log of every change.

News monitoring app

Pull RSS feeds and news APIs on a schedule, deduplicate and embed each article, and run an agent that clusters related stories, summarizes them, and tags entities and sentiment. Let users define watchlists and alert rules, isolate data per workspace, and deliver a realtime feed plus a daily email digest via a cron job.

Invoice & receipt automation

Accept PDF and image uploads to storage, then extract vendor, line items, totals, and dates with an extraction agent and write validated records to Postgres, routing low-confidence fields to human review. Add approval workflows, per-team access control, exports to accounting formats, and a searchable archive.

Lovable's Connect Supabase flow is not the way to connect Powabase. It links a Supabase organization that you authorize on supabase.com and then lists the projects in that organization, so a Powabase project never appears there. Leave that button alone: store BASE_URL and the Service Role key in Secrets, and let Lovable write server-side code that calls the Powabase API.

Lovable docs

Where Lovable keeps your keys

Lovable keeps backend keys in Secrets (More → Cloud → Secrets). They're encrypted, write-only, and injected into your server-side code at runtime: an Edge Function in older React + Vite apps, a server function in newer TanStack Start apps. BASE_URL and the Service Role key go there. Anything prefixed VITE_ lives in the project's .env instead, which Lovable commits to the repo and bundles into the browser, so the Anon key is the only Powabase key that can go there.

Lovable docs

Connect over MCP

Add it from Connectors → + → MCP server (GUI form).

GUI form
1. Open Connectors, click + at the top right of the catalog, and choose MCP server.
2. Server name: Powabase
3. Server URL: https://mcp.powabase.ai/mcp
4. Authentication: OAuth (the default)
5. Click Add & authorize and sign in to Powabase.

This is a chat connector, available on every Lovable plan. Lovable can read your Powabase project as context while you build, and the connection is personal to you. It is never part of your published app, which still reaches Powabase through Secrets and server-side code.

Append ?read_only=true to the MCP URL and the server exposes only the tools that don't write. We use it for sessions that should inspect a project and never mutate it.

Lovable MCP docs

Lovable example

Edge Function (Deno)
// The browser calls this function; only the function talks to Powabase.
const cors = {
  "Access-Control-Allow-Origin": "*",
  "Access-Control-Allow-Headers": "authorization, x-client-info, apikey, content-type",
};

Deno.serve(async (req) => {
  if (req.method === "OPTIONS") return new Response(null, { headers: cors });
  const { query } = await req.json();
  const key = Deno.env.get("API_KEY")!; // Secret: Service Role (Secret) Key
  const url = `${Deno.env.get("BASE_URL")}/api/knowledge-bases/${Deno.env.get("KB_ID")}/search`;
  const res = await fetch(url, {
    method: "POST",
    headers: { apikey: key, Authorization: `Bearer ${key}`, "Content-Type": "application/json" },
    body: JSON.stringify({ query, top_k: 5, retrieval_method: "hybrid" }),
  });
  const headers = { ...cors, "Content-Type": "application/json" };
  return new Response(await res.text(), { status: res.status, headers });
});

KB_ID is a third Secret holding your knowledge base's ID. Newer TanStack Start apps get a server function instead of an Edge Function; the fetch inside is the same. Before this goes live, have it check the signed-in user so strangers can't run searches on your key.

Connecting to Powabase from any tool

Mechanics that don’t change from tool to tool.

Anon (Publishable) Key
Client-side
Respects Row Level Security, so it's safe to ship to a browser.
Service Role (Secret) Key
Server-side only
Bypasses RLS. Never put it in anything that ships to a browser.
Keys & RLS docs ↗
  • Every call to /api/* or /rest/v1/* needs two headers, apikey and Authorization: Bearer, both set to the same key. Sending only one is the most common cause of a 401.

    Docs
  • The Database URL from the Connect modal is PgBouncer in transaction mode, not a direct Postgres connection. Disable prepared statements in your driver, or you'll hit prepared statement "..." does not exist. No LISTEN/NOTIFY and no session-level SET across statements. Use Realtime for change notifications; SET LOCAL inside a transaction otherwise. The username and database in the URL are both your project ref, not postgres.

    Docs
  • @supabase/supabase-js mostly works for the BaaS surface (PostgREST, Auth, Storage, Realtime) when you point it at your project URL with the Anon key. It doesn't cover the /api/* AI surface (agents, knowledge bases, orchestrations), which you call over plain REST. There's no /graphql/v1 route: point any GraphQL client at POST /rest/v1/rpc/graphql instead.

    Docs

Common errors

Lovable won't save a secret named SUPABASE_URL or SUPABASE_SERVICE_ROLE_KEY
Cause: The SUPABASE_ and LOVABLE_ prefixes are reserved for Lovable's own backend.
Fix: Name them BASE_URL and API_KEY, as in the quick start, and read those names in your server code.
The Service Role key turns up in your repo and in the browser bundle
Cause: It was saved as a VITE_ variable in .env. Lovable refuses VITE_ names in Secrets, commits .env to the repo, and bundles VITE_ values into client code.
Fix: Remove it from .env, add it to Secrets under a name without the VITE_ prefix, and read it only in server-side code. If it shipped, rotate it in Studio.
Calls to Powabase fail in a remixed project
Cause: Secrets you add by hand aren't copied when a project is remixed.
Fix: Add BASE_URL and API_KEY again under More → Cloud → Secrets in the remix.
401 Unauthorized
Cause: Only one of the apikey / Authorization headers was sent.
Fix: Send both, set to the same key. Docs
prepared statement "..." does not exist
Cause: PgBouncer's transaction-mode pooler moved you to a different server connection.
Fix: Disable prepared statements in your driver's config. Docs
A query that should return rows comes back empty, or a write is silently rejected
Cause: Row Level Security on your own tables. New public tables ship with RLS off, but once you add policies they gate every request.
Fix: Check the policy's USING/WITH CHECK clause and confirm which role (anon, authenticated, service_role) you actually authenticated as. Docs

FAQ

Yes. Lovable can integrate any API that's reachable from the internet. For Powabase, store the Project URL and Service Role key as Secrets and ask Lovable to call the Powabase API from server-side code, giving it the endpoints you need.

In Secrets, under More → Cloud → Secrets, or through the secure form Lovable shows when a feature asks for a key. Don't paste it into the chat or into .env; .env is for VITE_ values that ship to the browser.

Only in older React + Vite projects, where Secrets and Edge Functions live in Cloud. Newer TanStack Start apps, created from May 13, 2026 (June 22, 2026 on Enterprise), store secrets and run server functions without enabling Cloud.

Yes. Add https://mcp.powabase.ai/mcp as a custom MCP server under Connectors, with OAuth. It works in the project chat on all plans, but it's personal to you and never part of the published app.