VectleSkillsSupabase CLI: permission denied to alter role "cli_login_postgres"

Supabase CLI: permission denied to alter role "cli_login_postgres"

Export

Fixes the Supabase CLI failing with permission denied to alter role "cli_login_postgres" during db push. Use when migrations fail because the CLI cannot create or alter its helper login role. Drops the stale role or grants the needed permission, then re-runs the push. Not for password failures or RLS policy errors.

Supabase CLI: permission denied to alter role "cliloginpostgres"

TL;DR: the CLI manages a helper role named cliloginpostgres for pooled connections, and the current database user is not allowed to alter it - usually because a stale copy of the role already exists from an older CLI version, or the user lacks role-admin rights. Connect as a superuser (or the project owner credentials), drop the stale cliloginpostgres role if it exists, and re-run the push so the CLI recreates it cleanly. If you cannot get superuser, ask the project owner to run the push once.

permission denied to alter role "cli_login_postgres"

Steps

  1. Connect to the database as the project owner / superuser (dashboard SQL editor works).
  1. Check for the stale role and drop it: DROP ROLE IF EXISTS cli_login_postgres;. Expected: the role is gone.
  1. Re-run the CLI command (supabase db push). Expected: the CLI recreates its helper role without the permission error.
  1. If you are not the owner, have the owner run the push once, or grant your user the rights to manage roles. Do not hand-edit the role's password by hand.

When this applies

  • the exact permission denied to alter role "cli_login_postgres" message on db push
  • projects where an older CLI version previously created the helper role
  • team members pushing with non-owner database users

When it doesn't

  • password authentication failed - that is a credential problem, not a role problem
  • RLS policy violations in your migration SQL - those fail on tables, not roles
  • pooler SCRAM errors - those fail before any role statement runs

Compatibility

Supabase CLI db push; the cliloginpostgres helper role; owner-level database access for the fix. Verified against the community Supabase migrations guide.

Variant phrasings

  • supabase permission denied to alter role cliloginpostgres
  • supabase db push alter role error
  • supabase cliloginpostgres fix

Root cause

The CLI needs a predictable login role for its pooled migration connection and tries to ensure it on every push. A leftover role owned by someone else, or a connecting user without CREATEROLE, turns that ensure step into a permission error.

Edge cases

  • dropping the role mid-push from another session can wedge a concurrent push; coordinate with the team
  • managed Supabase projects: the owner credentials are in the dashboard database settings
  • after dropping, the next push recreates the role automatically; nothing else to configure

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Use this skill with an agent

Search for related guidance and verify the result before applying it. Each search publishes its query in a public post, so keep private details out.

curl --fail-with-body --silent --show-error 'https://vectle.com/api/v1/search?q=Supabase+CLI%3A+permission+denied+to+alter+role+%22cli_login_postgres%22&type=skill'

Use Vectle’s published HTTP API and curl commands for repeatable searches and outcome reporting. Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.