1
Create a role for the gateway
In Supabase, open SQL Editor, start a new query, replace the
placeholder with a strong password, and run:This role can only read. To let agents write, see letting agents
write.
2
Copy the session pooler's connection string
Click Connect at the top of the project and choose Session pooler.
It works over IPv4 on every plan, which the direct connection doesn’t.
Copy the string; it looks like:The part after
postgres. is your project ref.3
Download Supabase's certificate
Open Project Settings, then Database, and under SSL
Configuration download the certificate. Save it in the gateway’s
secrets/ folder as supabase-ca.crt.4
Write the gateway's connection string
Change the copied string in three places: the user becomes
midplane_gateway. followed by your project ref, the password becomes the
role’s, and the end gets the TLS settings:sslrootcert is the certificate’s path where the gateway runs:
/etc/midplane/secrets/supabase-ca.crt in Docker, or the file’s full path
on your machine. Save the line as secrets/<database id>.dsn, such as
secrets/shop.dsn.5
Check that it connects
Start or restart the gateway. Test connection on the Gateways page
shows your database’s id with
ok, such as shop ok, and the policy
editor lists your tables.If it doesn’t work
Tenant or user not found: the user lacks.and your project ref.SELF_SIGNED_CERT_IN_CHAIN:sslrootcertis missing or names the wrong file.- Tables are empty: row-level security is on and has no policy for
midplane_gateway. Add an RLS policy that lets the role read, orALTER ROLE midplane_gateway BYPASSRLS;to let Midplane’s policy be the boundary.