Skip to main content
This guide gives the gateway a read-only role in your Supabase project and a connection string it can use. You need a Midplane project with the database named in it (get started, step 2).
1

Create a role for the gateway

In Supabase, open SQL Editor, start a new query, replace the placeholder with a strong password, and run:
This role can only read. To let agents write, see letting agents write.
2

Copy the session pooler's connection string

Click Connect at the top of the project and choose Session pooler. It works over IPv4 on every plan, which the direct connection doesn’t. Copy the string; it looks like:
The part after postgres. is your project ref.
3

Download Supabase's certificate

Open Project Settings, then Database, and under SSL Configuration download the certificate. Save it in the gateway’s secrets/ folder as supabase-ca.crt.
4

Write the gateway's connection string

Change the copied string in three places: the user becomes midplane_gateway. followed by your project ref, the password becomes the role’s, and the end gets the TLS settings:
sslrootcert is the certificate’s path where the gateway runs: /etc/midplane/secrets/supabase-ca.crt in Docker, or the file’s full path on your machine. Save the line as secrets/<database id>.dsn, such as secrets/shop.dsn.
5

Check that it connects

Start or restart the gateway. Test connection on the Gateways page shows your database’s id with ok, such as shop ok, and the policy editor lists your tables.

If it doesn’t work

  • Tenant or user not found: the user lacks . and your project ref.
  • SELF_SIGNED_CERT_IN_CHAIN: sslrootcert is missing or names the wrong file.
  • Tables are empty: row-level security is on and has no policy for midplane_gateway. Add an RLS policy that lets the role read, or ALTER ROLE midplane_gateway BYPASSRLS; to let Midplane’s policy be the boundary.