The Connection URL field does not take a Supabase service_role API key.
Before you start
- A read-only Postgres connection URL for your Supabase project.
1. Create a read-only Postgres role
In the Supabase SQL editor, create a read-only role.
2. Grant access to selected data
Grant it access only to the schemas and tables Permute should query. Avoid service_role keys.
Permute asks for a read-only Postgres connection URL for live queries and schema discovery. Grant the role access only to the schemas and tables Permute should query. Use Postgres credentials, not a Supabase service_role API key.
Table and column names can remain visible during discovery even when the role cannot read their data. If a query is denied, check schema USAGE and table SELECT grants.
3. Add Supabase in Permute
In your workspace, open Connectors, select Add Connector, choose Supabase, and name the account.
Connection details
| Field or access | What to use |
|---|---|
| Connection URL | Copy a direct or pooled Postgres URL from the Supabase Connect panel. |
| Username and password | Use the read-only role in that connection mode’s username format. |
- Paste the read-only Postgres URL into Connection URL.
- Select Connect.
Copy a Postgres connection string
In the Supabase project dashboard, select Connect and copy a Postgres connection string. Use your read-only role in the username format for that connection mode, with its password. For the shared pooler, the username is <role>.<project-ref>.
If the password contains a reserved URL character, percent-encode it in the connection string.
4. Check the first result
- Choose a known table in a schema granted to the read-only role.
- Check that its schema is visible, then run a read-only query against it.
Available data
| Data group | What the setup screen covers |
|---|---|
| Schema discovery | See table and column definitions, including tables the role cannot query. |
| Live queries | Query tables the role may read. |
Check the endpoint and SSL
Supabase documents direct and pooler endpoints. Direct connections use IPv6 unless the project has the IPv4 add-on; the pooler can help IPv4-only clients. Supabase also documents SSL settings for Postgres connection strings.
If the URL cannot connect at all, check its host, port, network path, and SSL mode. If it connects but a query is denied, check the role’s schema and table permissions.
Troubleshooting
| Problem | What to check |
|---|---|
| Cannot connect | Check the endpoint, network path, username format, password encoding, and SSL mode. |
| A query is denied | Check the role’s schema USAGE and table SELECT grants. |