supabase mcp unrecognized client_id on first connect
Fixes unrecognized client_id specifically in Supabase MCP client setups. Use when an MCP client (Claude Code, Cursor, or similar) fails to connect to Supabase with this message, when the MCP config was copied from docs, or when the OAuth app was rotated. Not for stdio transport errors, for missing MCP servers, or for RLS denials.
TL;DR
Your MCP client's Supabase config carries a client id that Supabase doesnt recognize, usually copied from a doc example or left over from a deleted OAuth app. Open the Supabase dashboard, create (or re-create) the integration to get a live client id, paste it into the MCP config exactly, and restart the client.
supabase mcp {"message":"unrecognized client_id"}Use this when
- An MCP client fails to start the Supabase connection with unrecognized client_id
- The MCP config was hand-written or copied from a blog post
- The Supabase project was recreated or the integration revoked
Not for this skill when
- The MCP server process itself wont launch (thats a transport or install problem)
- Queries through MCP get RLS denials (thats policy, not identity)
- The error is about an API key rather than a client id
Steps
- Find the MCP config file and read the Supabase entry:
cat ~/.config/claude/mcp.json || find ~ -name "*mcp*.json" -not -path "*/node_modules/*" | head -5Expected output: the config path and the client id value inside. Note it down for comparison.
- In the Supabase dashboard, open your project and re-create the integration to mint a fresh client id:
Dashboard: Project Settings \u2192 Integrations \u2192 add the MCP / OAuth integration againExpected output: a new client id string. Doc examples and old screenshots show ids that were never valid for your project.
- Replace the client id in the MCP config, being careful with JSON quoting:
{
"mcpServers": {
"supabase": {
"client_id": "PASTE_FRESH_VALUE_HERE"
}
}
}Expected output: valid JSON with the fresh value. Validate with python -m json.tool on the file; one stray comma breaks the whole client.
- Fully quit and relaunch the MCP client (not just the chat window):
# quit the app completely, then reopen itExpected output: the Supabase MCP tools appear and the error is gone. MCP clients read config at startup, so a running client keeps using the old id.
Variant phrasing
same error but only in one IDE
Each IDE keeps its own MCP config. Fixing Claude Code's file doesnt fix Cursor's; update each one.
Why it happens
MCP clients authenticate to Supabase through OAuth, and OAuth identifies the client app by id. Supabase rejects ids it never issued or that belonged to deleted integrations. Because MCP config is just JSON in a dotfile, stale ids survive project recreations and dashboard cleanups, and the client keeps presenting the dead id on every connect.
Edge cases
- If the dashboard integration shows as active, the config id is stale or mistyped; copy from the dashboard, dont retype.
- Some setups need both a client id and a redirect URI registered; a missing redirect registration can surface as the same unrecognized message.
- Team members sharing one config file will all break when the id rotates; each person should use their own integration.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst3uXOEwehzwmdBv84NZ0Vg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.