{
  "schemaVersion": "bitshovel-editorial-review-v1",
  "id": "reader-service-8-20260906",
  "signalId": "feed-story-supabase-com-blog-enterprise-managed-auth-for-the-su-c74e1df9ad4b1af3",
  "originalUrl": "https://supabase.com/blog/enterprise-managed-auth-for-the-supabase-mcp-server",
  "kind": "evidence-review",
  "reviewedAt": "2026-09-06T03:48:28.498Z",
  "before": {
    "id": "feed-story-supabase-com-blog-enterprise-managed-auth-for-the-su-c74e1df9ad4b1af3",
    "state": "new",
    "lane": "workflow",
    "publishedAt": "2026-08-24T07:00:00.000Z",
    "observedAt": "2026-09-05T10:03:05.417Z",
    "originalUrl": "https://supabase.com/blog/enterprise-managed-auth-for-the-supabase-mcp-server",
    "relatedSources": [
      {
        "label": {
          "zh": "Supabase Blog 频道",
          "en": "Supabase Blog feed"
        },
        "url": "https://supabase.com/blog"
      }
    ],
    "source": {
      "zh": "Supabase Blog 一手发布",
      "en": "Supabase Blog first-party post"
    },
    "title": {
      "zh": "Supabase MCP 集中授权已 GA：先核对套餐与身份条件",
      "en": "Supabase MCP managed authorization is GA: check plans and identity setup"
    },
    "summary": {
      "zh": "Supabase 8 月 24 日宣布 MCP 企业受管授权 GA：组织统一授权后，成员按已有权限通过 Claude 访问项目。公告中的 Claude/Okta 组合要求 Supabase Team 或 Enterprise、Okta SSO，以及 Claude Team 或 Enterprise。",
      "en": "Supabase’s August 24 announcement makes enterprise-managed MCP authorization generally available, letting members use Claude with existing project permissions after centralized approval. The announced Claude/Okta setup requires Supabase Team or Enterprise, Okta SSO, and Claude Team or Enterprise."
    },
    "why": {
      "zh": "已满足条件的小团队，可先由组织所有者核对 MCP 客户端授权和角色，再用一个小范围项目测试成员接入与撤权流程。这样能判断集中管理是否减少逐人授权工作；本次没有实际部署验证。",
      "en": "Eligible teams can have an organization owner verify client authorization and roles, then test member access and revocation on a limited project. This checks whether centralized management reduces per-person setup; no deployment was tested here."
    },
    "caveat": {
      "zh": "当前文档还要求身份提供商能签发 ID-JAG，并明确授权 MCP 客户端；仅配置 SSO 不够。原文未列总费用，SCIM 仍在路线图；这些是官方配置说明，不能证明所有客户端都可用或带来实测安全、效率收益。",
      "en": "Current docs also require an ID-JAG-capable identity provider and explicit client authorization; SSO alone is insufficient. Total cost is unspecified and SCIM remains on the roadmap. These official descriptions do not prove universal client support or measured security and productivity gains."
    },
    "timeline": [
      {
        "date": {
          "zh": "9 月 5 日",
          "en": "Sep 5"
        },
        "kind": "record-added",
        "datetime": "2026-09-05T10:03:05.417Z",
        "summary": {
          "zh": "进入 BitShovel 雷达：Supabase Blog 一手发布（收录时各源可见 20 条）。",
          "en": "Entered the BitShovel radar: first-party on Supabase Blog (20 entries visible at collection)."
        },
        "source": {
          "zh": "Supabase Blog 快照",
          "en": "Supabase Blog snapshot"
        }
      }
    ],
    "followTarget": {
      "id": "page:supabase-com-blog-enterprise-managed-auth-for-the-su-c74e1df9ad4b1af3",
      "label": {
        "zh": "Supabase MCP Server 的企业受管授权",
        "en": "Enterprise-managed auth for the Supabase MCP server"
      },
      "scope": {
        "zh": "原文页面的后续实质变化：内容修订、数据更新或官方回应",
        "en": "Material follow-up changes on the original page: revisions, data updates, or an official response"
      },
      "url": "https://supabase.com/blog/enterprise-managed-auth-for-the-supabase-mcp-server",
      "updateMode": "editorial-watch"
    },
    "ingestion": {
      "mode": "editorial",
      "adapter": "syndication-corroborated",
      "evidenceClass": "official-statement",
      "editorialReadiness": "decision-brief"
    },
    "editorialReview": {
      "id": "r131-supabase-mcp-enterprise-auth-decision-20260905",
      "reviewedAt": "2026-09-05T14:39:14.930Z",
      "kind": "evidence-review",
      "note": {
        "zh": "已核对留存的官方正文，补充适用对象、实际变化、行动与限制，形成具体决策解读。发布日期与发现时钟分开保留；核验时间不作为产品新事件，未运行迁移、修复或集成测试。",
        "en": "Retained official pages were reviewed for audience, changes, actions and limits to form a decision brief. Publication and discovery clocks remain distinct; review time is not a new product event. No migration, repair or integration test was run."
      },
      "sources": [
        {
          "label": {
            "zh": "Supabase MCP 官方 GA 公告",
            "en": "Official Supabase MCP GA announcement"
          },
          "url": "https://supabase.com/blog/enterprise-managed-auth-for-the-supabase-mcp-server"
        },
        {
          "label": {
            "zh": "Supabase 企业 MCP 授权文档",
            "en": "Supabase enterprise MCP authorization documentation"
          },
          "url": "https://supabase.com/docs/guides/platform/sso/enterprise-mcp-authentication"
        },
        {
          "label": {
            "zh": "Claude 企业受管授权公告及 GA 补记",
            "en": "Claude enterprise-managed auth announcement and GA update"
          },
          "url": "https://claude.com/blog/enterprise-managed-auth"
        },
        {
          "label": {
            "zh": "保留的原始发布与发现记录",
            "en": "Retained publication and discovery entry"
          },
          "url": "https://supabase.com/blog/enterprise-managed-auth-for-the-supabase-mcp-server"
        }
      ],
      "sourceAssessments": [
        {
          "url": "https://supabase.com/blog/enterprise-managed-auth-for-the-supabase-mcp-server",
          "role": "direct-support",
          "scope": {
            "zh": "Supabase 的 GA 声明、成员角色和 Claude/Okta 组合门槛。",
            "en": "Supabase’s GA claim, member roles and Claude/Okta prerequisites."
          },
          "limitations": {
            "zh": "厂商声明，未独立部署测量；不证明首次支持。",
            "en": "Vendor description, not independent deployment evidence or proof of first support."
          },
          "evidenceUrls": [
            "https://supabase.com/blog/enterprise-managed-auth-for-the-supabase-mcp-server"
          ]
        },
        {
          "url": "https://supabase.com/docs/guides/platform/sso/enterprise-mcp-authentication",
          "role": "direct-support",
          "scope": {
            "zh": "本次可见的套餐、ID-JAG、组织所有者授权和令牌机制说明。",
            "en": "Currently documented plans, ID-JAG, owner authorization and token behavior."
          },
          "limitations": {
            "zh": "没有固定发布日，不能回填成 8 月 24 日已逐字存在的文档。",
            "en": "No pinned publication date; not proof of identical wording on August 24."
          },
          "evidenceUrls": [
            "https://supabase.com/docs/guides/platform/sso/enterprise-mcp-authentication"
          ]
        },
        {
          "url": "https://claude.com/blog/enterprise-managed-auth",
          "role": "background",
          "scope": {
            "zh": "Claude 侧已明确的 Supabase 集成和 6 月首发、8 月 GA 更新背景。",
            "en": "Claude-side Supabase integration and June publication/August GA-update context."
          },
          "limitations": {
            "zh": "仍有旧 beta 段落，GA 依据采用明确标注日期的顶部更新；不是独立效果核验。",
            "en": "An older beta paragraph remains; the dated top update supports GA. This is not independent outcome verification."
          },
          "evidenceUrls": [
            "https://claude.com/blog/enterprise-managed-auth"
          ]
        }
      ]
    }
  },
  "after": {
    "title": {
      "zh": "Supabase 可集中管理 Claude 的项目访问",
      "en": "Supabase adds centralized access management for Claude"
    },
    "summary": {
      "zh": "管理员统一授权后，成员可按自己已有的 Supabase 权限通过 Claude 访问项目。公告中的方案要求 Supabase 和 Claude 的 Team/Enterprise 套餐，并配置 Okta SSO。",
      "en": "After an admin approves the connection, employees can use Claude with their existing Supabase permissions. The announced setup requires Team or Enterprise plans for both products and Okta SSO."
    },
    "digest": {
      "zh": "已有企业身份系统的团队，可让 Claude 项目访问沿用成员的 Supabase 权限。",
      "en": "Teams with managed identity can let Claude project access follow employees’ existing Supabase permissions."
    },
    "why": {
      "zh": "适合已经使用 Claude、Supabase 和企业身份管理的团队。可以先用一个项目检查成员接入和撤权是否跟随现有角色，再决定是否扩大使用。",
      "en": "This is relevant to teams already using Claude, Supabase and managed identity. Start with one project and check whether onboarding and revoking access follow existing roles before expanding use."
    },
    "caveat": {
      "zh": "SSO 本身不足够：当前文档还要求身份提供商支持 ID-JAG，并显式授权客户端。公告方案有套餐与客户端条件；SCIM 仍属后续计划，本站未测试成本或管理效果。",
      "en": "SSO alone is insufficient: current docs also require an identity provider supporting ID-JAG and explicit client authorization. Plan and client requirements apply. SCIM remains planned, and we have not tested costs or management outcomes."
    }
  },
  "editorialReadiness": "decision-brief",
  "withdrawnSources": [],
  "withdrawnTimeline": [],
  "evidence": [
    {
      "type": "retained-official-page",
      "label": {
        "zh": "Supabase MCP 官方 GA 公告",
        "en": "Official Supabase MCP GA announcement"
      },
      "url": "https://supabase.com/blog/enterprise-managed-auth-for-the-supabase-mcp-server",
      "path": "app/_content/editorial-reviews/evidence/r131-supabase-mcp-enterprise-auth-page.json",
      "bytes": 1195,
      "sha256": "8ba575c8ca5a2f5421a39eff0f2a94f42ce1745107b7e07082b9dce9aa90db7c",
      "fetchedAt": "2026-09-05T11:07:11.863221Z"
    },
    {
      "type": "retained-official-page",
      "label": {
        "zh": "Supabase 企业 MCP 授权文档",
        "en": "Supabase enterprise MCP authorization documentation"
      },
      "url": "https://supabase.com/docs/guides/platform/sso/enterprise-mcp-authentication",
      "path": "app/_content/editorial-reviews/evidence/r131-supabase-mcp-auth-docs-page.json",
      "bytes": 1185,
      "sha256": "ef1c31719dc688a5a8224ec154111ee5628dce0e1502dded119cd0bbce7e1f76",
      "fetchedAt": "2026-09-05T11:09:52.175215Z"
    },
    {
      "type": "retained-official-page",
      "label": {
        "zh": "Claude 企业受管授权公告及 GA 补记",
        "en": "Claude enterprise-managed auth announcement and GA update"
      },
      "url": "https://claude.com/blog/enterprise-managed-auth",
      "path": "app/_content/editorial-reviews/evidence/r131-claude-enterprise-auth-context-page.json",
      "bytes": 1164,
      "sha256": "cf9b3de7d312fd803f6c9ff905a3c5c85d30df7a630289cd9c174e4cde956ada",
      "fetchedAt": "2026-09-05T11:12:30.447052Z"
    },
    {
      "type": "retained-feed-entry",
      "label": {
        "zh": "保留的原始发布与发现记录",
        "en": "Retained publication and discovery entry"
      },
      "url": "https://supabase.com/blog/enterprise-managed-auth-for-the-supabase-mcp-server",
      "fetchedAt": "2026-09-05T10:03:05.417Z",
      "path": "app/_content/editorial-reviews/evidence/r131-supabase-mcp-enterprise-auth-feed-entry.json",
      "bytes": 657,
      "sha256": "812a457990f4944059ac9df975c06ffd1dbcb8155d2334b04bac651eec934f2f",
      "retainedRecord": {
        "sourceSnapshot": "app/_content/source-observations/history/syndication-feeds.2026-09-05T10-03-05Z.snapshot.json",
        "sourceSnapshotSha256": "869b43001d3867238f47d14ab45c67974fa62093b6a78eb57344026054e59c00",
        "observedAt": "2026-09-05T10:03:05.417Z",
        "feedSourceKey": "feed:supabase-blog",
        "entry": {
          "id": "https://supabase.com/blog/enterprise-managed-auth-for-the-supabase-mcp-server",
          "title": "Enterprise-managed auth for the Supabase MCP server",
          "url": "https://supabase.com/blog/enterprise-managed-auth-for-the-supabase-mcp-server",
          "publishedAt": "2026-08-24T07:00:00.000Z",
          "updatedAt": null,
          "author": null
        }
      }
    }
  ],
  "sourceAssessments": [
    {
      "url": "https://supabase.com/blog/enterprise-managed-auth-for-the-supabase-mcp-server",
      "role": "direct-support",
      "scope": {
        "zh": "阅读 2026-08-24 官方 GA 公告及当前配置文档，区分公告中的 Claude/Okta/套餐组合与通用协议前提，核对沿用权限、ID-JAG、客户端授权和 SCIM 路线图。",
        "en": "Read the August 24 GA announcement and current setup docs, distinguishing the announced Claude/Okta/plan combination from general protocol requirements. Checked inherited permissions, ID-JAG, client authorization and the SCIM roadmap."
      },
      "limitations": {
        "zh": "未连接真实组织或测试授权、撤权、费用及节时；公开文档条件不能泛化为所有 MCP 客户端均可用。",
        "en": "No live organization was connected, and authorization, revocation, cost and time savings were not tested. Documented conditions do not imply support across all MCP clients."
      },
      "evidenceUrls": [
        "https://supabase.com/blog/enterprise-managed-auth-for-the-supabase-mcp-server",
        "https://supabase.com/docs/guides/platform/sso/enterprise-mcp-authentication",
        "https://claude.com/blog/enterprise-managed-auth"
      ]
    },
    {
      "url": "https://supabase.com/docs/guides/platform/sso/enterprise-mcp-authentication",
      "role": "direct-support",
      "scope": {
        "zh": "本次可见的套餐、ID-JAG、组织所有者授权和令牌机制说明。",
        "en": "Currently documented plans, ID-JAG, owner authorization and token behavior."
      },
      "limitations": {
        "zh": "没有固定发布日，不能回填成 8 月 24 日已逐字存在的文档。",
        "en": "No pinned publication date; not proof of identical wording on August 24."
      },
      "evidenceUrls": [
        "https://supabase.com/docs/guides/platform/sso/enterprise-mcp-authentication"
      ]
    },
    {
      "url": "https://claude.com/blog/enterprise-managed-auth",
      "role": "background",
      "scope": {
        "zh": "Claude 侧已明确的 Supabase 集成和 6 月首发、8 月 GA 更新背景。",
        "en": "Claude-side Supabase integration and June publication/August GA-update context."
      },
      "limitations": {
        "zh": "仍有旧 beta 段落，GA 依据采用明确标注日期的顶部更新；不是独立效果核验。",
        "en": "An older beta paragraph remains; the dated top update supports GA. This is not independent outcome verification."
      },
      "evidenceUrls": [
        "https://claude.com/blog/enterprise-managed-auth"
      ]
    }
  ],
  "note": {
    "zh": "根据官方正文补充用途、实际变化与使用条件；区分来源描述与尚未独立测试的效果。原发布日期和收录时间保留，编辑修订不作为新的产品发布。",
    "en": "Reviewed official materials to clarify purpose, changes and usage conditions, distinguishing source descriptions from untested results. Original publication and observation dates are retained; an editorial revision is not a new product release."
  },
  "integrity": "51651682d293c7a057267802cf66b6acc138895fba673108b815296e566d3a87"
}
