Replit logoVibe-coding platform·Replit

Replit + Powabase

Build and host on Replit. Keep data, auth and agents on Powabase.

Replit's Agent writes and hosts full-stack apps from the browser. Give it your project URL and Service Role key, or install the skill in the Repl's shell, and it builds straight against your Powabase backend.

Rather have it built? Powabase engineers build MVPs free for annual Scale and Enterprise plans.

Quick start

Three steps and Replit is building on Powabase.

  1. 1

    Create a Powabase project

    Create a project at app.powabase.ai and open the Connect dialog (top-left in Studio). Copy the Project URL and the Service Role (Secret) Key. The Service Role key reaches everything: the agent and AI endpoints, plus full database access. Keep it on the server and never put it in the browser.

    The Powabase Connect dialog showing the Project URL, Anon key, Service Role key, JWT secret, and Database URL
    The Connect dialog in Powabase Studio.
  2. 2

    Add them as Repl Secrets

    Put the Project URL and Service Role key in your Repl's Secrets so the Agent can reach Powabase. The key stays server-side; don't reference it from client code.

    Replit Secrets
    BASE_URL=<Project URL>
    API_KEY=<Service Role (Secret) Key>
  3. 3

    Brief the Agent

    Tell the Agent what to build on the Powabase REST API. Each example below is sized for a real product.

Example apps

Real apps, each from one prompt. Copy any of them and give it to Replit.

RAG support chatbot

Ingest our product docs, help center, and resolved tickets into a knowledge base, embedding on upload. Expose a support agent that answers with inline citations, streams over SSE, and hands off to a human when confidence is low. Add email and Google sign-in, isolate every conversation per organization with row-level security, and ship it as an embeddable chat widget.

Internal knowledge assistant

Index our wikis, runbooks, and exported threads into a knowledge base, chunking and embedding on upload. Expose an agent that answers with citations and respects per-department access, keep it fresh with scheduled re-indexing of changed sources, and add SSO sign-in plus an analytics view of unanswered questions.

AI help desk

Model tickets, organizations, and agents with row-level security, and auto-triage incoming tickets with an agent that predicts category and priority and drafts a reply from the knowledge base. Escalate low-confidence cases, run SLA timers as scheduled jobs, add email auth, and provide a live queue dashboard.

Sales CRM

Model companies, contacts, deals, and activities in Postgres with row-level security per team and roles for reps and managers. Build a pipeline board with stage tracking, an activity timeline, and semantic search across notes, plus a dashboard of weighted pipeline and win rate. Wire OAuth sign-in and an audit log of every change.

News monitoring app

Pull RSS feeds and news APIs on a schedule, deduplicate and embed each article, and run an agent that clusters related stories, summarizes them, and tags entities and sentiment. Let users define watchlists and alert rules, isolate data per workspace, and deliver a realtime feed plus a daily email digest via a cron job.

Invoice & receipt automation

Accept PDF and image uploads to storage, then extract vendor, line items, totals, and dates with an extraction agent and write validated records to Postgres, routing low-confidence fields to human review. Add approval workflows, per-team access control, exports to accounting formats, and a searchable archive.

Where Replit keeps your keys

Replit keeps keys in the Secrets pane, encrypted with AES-256 at rest, and exposes each one to your app as an environment variable: process.env.API_KEY in Node, os.getenv("API_KEY") in Python. Put BASE_URL and the Service Role key under App Secrets so they belong to this app only; Account Secrets are for values you want to link across several apps. Someone who remixes your app without being a collaborator sees the secret names but not the values. Only server code should read the Service Role key.

Replit docs

Connect over MCP

Add it from replit.com/integrations → MCP Servers for Replit Agent (GUI form).

GUI form
1. Open replit.com/integrations and scroll to MCP Servers for Replit Agent.
2. Click + Add MCP server.
3. Display name: Powabase
4. URL: https://mcp.powabase.ai/mcp
5. Click Test & save, then sign in to Powabase when Replit asks.

Replit walks you through the OAuth sign-in during Test & save, so you don't need custom headers. Once saved, the connection shows under MCP Servers with its status, and the Agent can call Powabase's tools while it builds.

Append ?read_only=true to the MCP URL and the server exposes only the tools that don't write. We use it for sessions that should inspect a project and never mutate it.

Replit MCP docs

Replit example

server.js (Express)
// A route the Agent writes. The browser calls /api/search, never Powabase.
app.use(express.json()); // needed for req.body
app.post("/api/search", async (req, res) => {
  const key = process.env.API_KEY; // Secret: Service Role (Secret) Key
  const url = `${process.env.BASE_URL}/api/knowledge-bases/${process.env.KB_ID}/search`;
  const r = await fetch(url, {
    method: "POST",
    headers: {
      apikey: key,
      Authorization: `Bearer ${key}`,
      "Content-Type": "application/json",
    },
    body: JSON.stringify({ query: req.body.query, top_k: 5 }),
  });
  if (!r.ok) return res.status(r.status).json({ error: "search failed" });
  const { results } = await r.json();
  res.json(results);
});

KB_ID is a third App Secret holding your knowledge base's ID. The same route works in any Replit deployment that runs a server. Before this goes live, check the caller is a signed-in user so strangers can't spend your key.

Connecting to Powabase from any tool

Mechanics that don’t change from tool to tool.

Anon (Publishable) Key
Client-side
Respects Row Level Security, so it's safe to ship to a browser.
Service Role (Secret) Key
Server-side only
Bypasses RLS. Never put it in anything that ships to a browser.
Keys & RLS docs ↗
  • Every call to /api/* or /rest/v1/* needs two headers, apikey and Authorization: Bearer, both set to the same key. Sending only one is the most common cause of a 401.

    Docs
  • The Database URL from the Connect modal is PgBouncer in transaction mode, not a direct Postgres connection. Disable prepared statements in your driver, or you'll hit prepared statement "..." does not exist. No LISTEN/NOTIFY and no session-level SET across statements. Use Realtime for change notifications; SET LOCAL inside a transaction otherwise. The username and database in the URL are both your project ref, not postgres.

    Docs
  • @supabase/supabase-js mostly works for the BaaS surface (PostgREST, Auth, Storage, Realtime) when you point it at your project URL with the Anon key. It doesn't cover the /api/* AI surface (agents, knowledge bases, orchestrations), which you call over plain REST. There's no /graphql/v1 route: point any GraphQL client at POST /rest/v1/rpc/graphql instead.

    Docs

Common errors

Your Secrets are undefined after you publish
Cause: The app was published as a Static Deployment, which is the one deployment type that doesn't get Secrets.
Fix: Publish with a deployment type that runs your server, and keep the Powabase calls in that server code.
The app saves data, but none of it appears in Powabase
Cause: The Agent added Replit's own database, which creates a DATABASE_URL secret, and the generated code writes there.
Fix: Tell the Agent to use Powabase for data. If you connect over Postgres, store the Powabase Database URL under its own name, such as POWABASE_DATABASE_URL, so the two never collide.
401 Unauthorized
Cause: Only one of the apikey / Authorization headers was sent.
Fix: Send both, set to the same key. Docs
prepared statement "..." does not exist
Cause: PgBouncer's transaction-mode pooler moved you to a different server connection.
Fix: Disable prepared statements in your driver's config. Docs
A query that should return rows comes back empty, or a write is silently rejected
Cause: Row Level Security on your own tables. New public tables ship with RLS off, but once you add policies they gate every request.
Fix: Check the policy's USING/WITH CHECK clause and confirm which role (anon, authenticated, service_role) you actually authenticated as. Docs
The Service Role key turns up in a browser bundle or other client-visible code
Cause: It was used somewhere that ships to the client instead of staying server-side.
Fix: Move the call server-side; use the Anon key with RLS for anything client-visible. If it shipped, rotate it in Studio. Docs

FAQ

In the Secrets pane, on the App Secrets tab. Add BASE_URL and API_KEY there and read them with process.env or os.getenv in server code. Don't paste the key into a file, and don't read it from anything that runs in the browser.

Yes. Replit Agent connects to remote MCP servers from replit.com/integrations. Pick one from the pre-listed catalog, or click + Add MCP server and paste a URL like https://mcp.powabase.ai/mcp; Replit handles the OAuth sign-in during Test & save.

Not if they aren't collaborators: a non-owner who remixes your app sees secret names but not values. Collaborators you invite to a Multiplayer session can see the values, so only invite people you'd trust with the Service Role key.

If the app only needs to store rows, Replit's built-in database is the shortest path. Use Powabase when the app also needs knowledge bases, retrieval, agents, or workflows next to its Postgres data, or when you want a backend that isn't tied to the tool that wrote the frontend.