RowAttest
Runs an eight-stage isolation test against your staging Supabase and issues a signed attestation.
Should I use this
Quality & Safety
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"rowattest": {
"url": "https://app.rowattest.com/mcp"
}
}
}Remote endpoints
https://app.rowattest.com/mcpstreamable-httpWhat it can do
Tool inventory
Tools (6)
🟢list_projects
Lists the Supabase projects connected to this account with id, name, connection state and whether each is ready to run. Call this first to get a project_id.
Input Schema
{
"type": "object",
"properties": {},
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢run_review(project_id)
Starts an authorization test run on a connected project and returns the run_id and status. If the project already has a run waiting to start, returns that run instead of starting another. Runs that do not fail count against the monthly allowance.
Input Schema
{
"type": "object",
"properties": {
"project_id": {
"type": "string"
}
},
"required": [
"project_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢get_run_status(run_id)
Returns a run's status (queued, running, complete or failed), its current stage, timestamps and, when a signed report exists, its verify_url.
Input Schema
{
"type": "object",
"properties": {
"run_id": {
"type": "string"
}
},
"required": [
"run_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢wait_for_run(run_id, timeout_seconds)
Waits up to timeout_seconds (1 to 60) for a run to finish, then returns the same information as get_run_status. Call it again while the status is still queued or running.
Input Schema
{
"type": "object",
"properties": {
"run_id": {
"type": "string"
},
"timeout_seconds": {
"type": "number"
}
},
"required": [
"run_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢get_findings(run_id)
Returns the cells that did not pass in a complete run that has a signed report — verdict, surface, operation, boundary, identity, layer outcomes and notes — plus tenancy flags and blocking findings. For a complete run with no signed report, while one can still be bought on the run page, it returns the run's unverified result instead: the verdict, surface, operation and principal of each cell that did not pass, the run page's finding lines, the counts, the coverage lines and the access model summary. The list of cells is empty when every tested cell passed. Contains no fix suggestions: the engine records only what it observed.
Input Schema
{
"type": "object",
"properties": {
"run_id": {
"type": "string"
}
},
"required": [
"run_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}🟢get_report(run_id)
Returns the full signed report of a complete run as the exact stored JSON, with its verify_url and report_sha256 (sha256 of the canonical signed bytes, the fingerprint shown on the verify page). Use get_findings for the compact view.
Input Schema
{
"type": "object",
"properties": {
"run_id": {
"type": "string"
}
},
"required": [
"run_id"
],
"$schema": "https://json-schema.org/draft/2020-12/schema"
}Community
Evidence