Powered by ORCA DEVS SURF

SERVERLESS / CUSTOMER OWNED
( ORCA SUPABASE CONNECTOR )
+
+

Let every customer connect the Supabase project they already own.

+
+

ORCA SUPABASE CONNECTOR

CUSTOMER OAUTH · GOVERNED SQL · MASKED PROXY

WEB APPLICATIONSLOCAL APPSDESKTOPCLI TOOLSSERVERLESS

One connector for the applications your customers already use.

ORCA gives each application a dedicated key, a customer-owned project connection, a governed SQL policy, a masked proxy endpoint, and observable receipts. The customer keeps their own Supabase authority; your app never receives their database password, OAuth token, project URL, or publishable key.

POWERED BY

A serverless foundation with visible authority at every step.

SSUPABASE
NNEON
NNEXT.JS
VVERCEL
PPOSTGRES
PPKCE
RREST
AAUTH
SSTORAGE
FFUNCTIONS
SSUPABASE
NNEON
NNEXT.JS
VVERCEL
PPOSTGRES
PPKCE
RREST
AAUTH
SSTORAGE
FFUNCTIONS

Open protocols for application builders. Strong boundaries for customer project credentials.

For web apps, return exactly where the customer expects.

Register an HTTPS callback URL and ORCA returns the approved browser with a connection ID after project selection. The application retrieves a one-time masked proxy configuration with its own ORCA key. Real Supabase configuration remains encrypted in Neon.

WEB APP MODE

HTTPS CALLBACK · PKCE · RESUME CONNECTION

EXACT RETURN URLCONNECTION IDONE-TIME PROXY KEY

LOCAL APP MODE

DESKTOP · CLI · KIOSK · NO RETURN URL

NO CALLBACKSTATUS POLLINGOS KEYSTORE READY

Open the customer browser. Let the local app keep polling.

Register a local application with no return URL. It opens the short-lived customer consent link in a browser, keeps the connection ID, and polls its own ORCA connection status with the application key. When the connection is active, it receives the masked proxy configuration one time.

Ask through policy. Observe through receipts.

ORCA permits one controlled statement at a time. It rejects chained statements, DDL, transactions, privileged commands, and writes unless an application key has been deliberately scoped. The activity ledger records outcomes, timing, and route class without retaining result rows.

POLICY + RECEIPTS

SELECT · WITH · EXPLAIN · MASKED PROXY

NO DDLNO CHAINSREAD FIRST

CONNECTION GUIDE / FIRST PRODUCT

CREATE THE APP.
OPEN THE PATH.

Start with your ORCA account, then register the application delivery mode that matches your product. The control plane makes the customer connection path visible without exposing their Supabase credentials.

OPEN ORCA ACCESS
01

CREATE THE ACCOUNT

Sign in to ORCA. Your account, applications, key hashes, connections, and receipts are stored in Neon.

02

REGISTER THE PRODUCT

Choose web mode for an HTTPS callback or local mode when your app has no return URL.

03

ISSUE A KEY

Create one application key. Save it when shown—the raw ORCA key appears only once.

04

START CUSTOMER CONSENT

Open the returned connection URL and let the customer select their own Supabase project.

ORCA SUPABASE CONNECTOR / CONTROL PLANE

OPEN THE
CONTROL PLANE

APPLICATIONS · CONNECTIONS · KEYS · QUERY CONSOLE · ACTIVITYCREATE ORCA ACCOUNT ↗
+

PRODUCT FLOW

CONNECTION
RECORD

01

FOUNDATION

ACCOUNT + APPLICATION

START HERECreate an ORCA account and register a web or local product.
02

CUSTOMER CONSENT

API KEY + CONNECTION

NEXTIssue an application key and open a customer-owned project connection.
03

SAFE CLIENT ACCESS

MASKED PROXY

NEXTRetrieve the ORCA proxy URL and one-time proxy key after approval.
04

GOVERNED OPERATIONS

QUERY + RECEIPTS

NEXTRun controlled SQL and review the live connection activity ledger.
OPEN PRODUCT WORKSPACE ↗