◎ Discry Score
supabase.com
infrastructure · API
A
0 / 100
DISCOVERY0
COMPREHENSION0
Category leader: 98 (A)
Discry your API →
INFRASTRUCTURE · RANK #5 OF 68

Supabase is Agent-Ready to agents.

Discry independently scored how well an AI agent can discover and understand the Supabase API from what’s public — not whether it’s usable. Below: every signal we checked, what’s costing the score, and what to change.

Discry your API — freeView the docs ↗

SCORED UNDER RUBRIC 1.2 · A full re-launch under Discry Score 2.5 — a new behavioral instrument, not comparable to these scores — is in progress.

Discovery

45% of score · 95/100
OpenAPI specA machine-readable OpenAPI/Swagger spec agents can parse.Pass
llms.txtAn llms.txt index that points agents to the docs that matter.Pass
llms.txt qualityThe llms.txt is focused, current, and well under the size budget.Pass
llms-full.txtA full-text bundle agents can load in one request.Pass
AGENTS.mdAn AGENTS.md that tells coding agents how to build on the API.Pass
.well-known/mcp.jsonA discoverable MCP manifest at a well-known path.Fail
MCP registryThe API is listed in a public MCP registry.Pass
robots.txt AI directivesrobots.txt allows (or explicitly guides) AI crawlers.Pass
SitemapA sitemap so agents can enumerate the docs surface.Pass

Comprehension

55% of score · 96/100
Task-oriented descriptionsEndpoints described by what they accomplish, not just their shape.Pass
Realistic examplesRunnable, real-world request/response examples.Pass
Multi-step workflowsDocs that chain calls into complete jobs an agent can follow.Pass
Error-recovery guidanceDocumented failure modes and how to recover from them.Partial
Answer-first formatThe answer leads; preamble does not bury it.Pass
Capability boundariesClear limits — what the API can and cannot do.Pass
Naming consistencyConsistent, predictable naming across endpoints.Pass
Heading hierarchyClean heading structure agents can navigate.Pass
Markdown docsDocs available as clean markdown, not JS-rendered HTML only.Pass
Token efficiencyDocs are concise enough to fit an agent context window.Pass

What we found

  • Supabase is the highest-scoring API under v1.1 methodology: llms.txt is API-focused and right-sized, llms-full.txt (8.7MB) is comprehensive, AGENTS.md exists across multiple repos, and multi-step workflow guides cover auth setup through production deployment
  • The robots.txt uses the Content-Signal header with ai-train=yes and ai-input=yes — one of the most explicitly agent-friendly signals in the dataset
  • Error recovery guidance is the only comprehension check not at full marks — error codes are documented but specific recovery steps (what to DO when a rate limit or auth error occurs) are limited compared to the best-in-class examples
  • Discovery is strong (88/100) with the only gap being .well-known/mcp.json — despite official MCP servers listed on Glama, Smithery, and PulseMCP
  • The llms.txt provides structured progressive disclosure in under 2,000 tokens linking to per-SDK references in 7 languages — a model for token-efficient agent consumption

What to change

Prioritized by impact on discoverability. You (or your docs platform) deploy these — Discry never touches your API.

  1. 01Add .well-known/mcp.json at supabase.com with tool declarations for the official Supabase MCP server — the only discovery signal missing
  2. 02Add explicit error recovery guidance for common scenarios: what to do on rate limit (429), auth failure (401), RLS permission denied, and connection timeout
  3. 03Document idempotency key support for write operations to enable safe agent retries
  4. 04Consolidate the multiple OpenAPI specs (Management API, Storage, Auth) into a single discoverable index

Execution coverage · INFORMATIONAL, UNSCORED

Whether an agent can actually complete a call and recover from errors is the deeper Audit layer — documented here, but not part of the Discry Score.

api_keyoauth2jwt Error format documented Rate limits documented Pagination documented Idempotency documented

API key auth via publishable/secret keys (Bearer token), OAuth2 for social login providers, JWT-based sessions. JSON error responses. Detailed auth rate limit tables with per-endpoint limits. Cursor-based pagination. No idempotency key support documented.

See your own Discry Score.

Drop your API docs URL. See what an agent sees — in 60 seconds, free.

Discry your API — free