Open Authorization Integration Addendum
An addendum to the Master Partner Program Agreement governing OAuth integrations.
Version 1 — August 6, 2026
This Open Authorization Integration Addendum (this "Addendum") contains terms and conditions that govern your participation in Supabase's OAuth Partner Program (the "Program") and is a contract between Supabase and Partner. This Addendum is subject to Supabase's standard Master Partner Program Agreement, currently available on Supabase's website at https://supabase.com/legal/partner-resources/master-partner-program-agreement unless otherwise agreed by the Parties in writing ("MPPA"). Capitalized terms not otherwise defined in this Addendum will have the respective meanings assigned to them in the MPPA.
This Addendum becomes binding and effective on Partner upon signature of a Program Authorization granting Partner the right to participate in the Program.
1. Background.#
Supabase provides access to the Services to existing and prospective End-Customers who may benefit from the availability of an open authorization integration of Partner's software, mobile applications or other technology-based resources (the "Partner's Platform") with the Services (such open authorization integrations to be referred to herein as the "OAuth Integration"). Supabase and/or Partner may develop a given OAuth Integration (the Party or Parties responsible for the development of a given OAuth Integration, the "Developing Party(ies)"), and the Developing Party desires to offer such OAuth Integration to the existing and prospective End-Customers of Supabase, however offered, including whether via Partner's websites, or any marketplace functionality Partner makes available or within Partner's Platform itself ("Partner's Marketplace"). Partner shall provide no other services relevant to the Services to End-Customers except as expressly authorized by, and in accordance with, the Agreement.
2. Publication of OAuth Integration.#
The Developing Party(ies) may only publish, release, or otherwise share or make available OAuth Integration with End-Customers via the Partner's Marketplace, that have received final approval in writing (email sufficient) from Supabase ("Publication"). Such written approval shall not be unreasonably withheld by Supabase. The Parties shall reasonably collaborate to achieve Publication approval, and Supabase shall determine the qualification of an OAuth Integration for Publication pursuant to the terms of this Addendum and Partner's compliance with the Agreement. If the Developing Party is Supabase, or partially Supabase, then upon approval for Publication of an OAuth Integration, Supabase grants to Partner a non-exclusive, revocable (solely as set forth in this Addendum), worldwide, non-transferable (except in compliance with Section 20 of the MPPA), non-sublicensable, fully paid-up, royalty-free license solely to (a) host, link to, reproduce, publicly perform, publicly display, test, distribute, make available, and use the OAuth Integration, in each case for the purposes of making the OAuth Integration available through the Partner's Marketplace to End-Customers pursuant to this Addendum; and (b) reproduce, perform, display, use and access the OAuth Integration for administration and demonstration purposes in connection with the operation and marketing of the Partner's Marketplace.
3. Development of OAuth Integrations.#
3.1 Collaboration.#
The Parties may work collaboratively to determine the exact features and functionalities of the OAuth Integration. Throughout the development of the OAuth Integration, the Developing Party shall consult with the other Party and act reasonably in light of the other Party's advice, both in the Developing Party's use of the Services or Partner's Platform, as applicable, and otherwise. Accordingly, the Party that is not the Developing Party with respect to a given OAuth Integration (the "Non-Developing Party") shall (i) provide reasonable technical documentation and support to assist the Developing Party in the successful completion and implementation of the OAuth Integration; and (ii) monitor the availability of its Services or Partner's Platform, as applicable, and work with the Developing Party to resolve technical issues and errors relevant thereto that may arise from time to time.
3.2 Developing Party Obligations.#
The Developing Party shall ensure that the OAuth Integration: (i) utilizes Supabase's Management API as outlined in Supabase's User Guide, in particular at https://supabase.com/docs/reference/api/introduction ("Management API"); (ii) set the user-agent header to "[Partner name]" in all requests made to the Management API; (iii) implement and maintain appropriate technical and organizational security measures consistent with industry standards to protect against unauthorized access, loss, or misuse of the Services.
4. Maintenance of OAuth Integration.#
4.1 Marketing and Promotion.#
Each Party shall collaborate with the other Party to assist the other Party in the incorporation of references to the OAuth Integration in its marketing materials, including as may be specifically described in a Program Authorization. Each Party shall only publicize the OAuth Integration's availability on its own websites and marketing efforts in accordance with the other Party's Branding Guidelines.
4.2 Continuing Support.#
Partner shall: (i) update the OAuth Integration as necessary to accommodate for updates and modifications to the Services and/or Partner's Platform, as applicable; (ii) be fully responsible for the OAuth Integrations' upkeep and availability, including by ensuring the OAuth Integration remains active and functional in all respects throughout the period of its Publication; (iii) provide any and all required and requested support to End-Customers who utilize the OAuth Integration; and (iv) provide a single point of contact to resolve technical issues that arise from the OAuth Integration in a timely manner.
5. Access and Use of the Services and Partner's Platform.#
Subject to the Service Terms or the EULA, as applicable, and except as otherwise expressly provided in the Agreement, the Non-Developing Party grants the Developing Party the right to access and use the Services or Partner's Platform (as applicable), solely to assist in the Developing Party's development and maintenance of the OAuth Integration. This right terminates upon termination of this Addendum, and the Developing Party's rights and remedies with respect to its use of the Services or Partner's Platform (as applicable), shall at all times be governed by the Service Terms or the EULA, as applicable. The Developing Party is not itself granted a subscription or license to the Services or Partner's Platform (as applicable) for its own internal use, nor is it granted any right to resell or grant third parties the right to use the Services or Partner's Platform (as applicable) under this Addendum; any such rights would be subject to a separate agreement between the Parties.
6. Partner Responsibilities and Restrictions; Suspension.#
6.1 Partner Responsibilities.#
(a) General.#
As between the Parties, Partner shall be solely responsible for: (i) obtaining authorizations from joint customers of Supabase and Partner as may be necessary to push and/or pull data of such joint customers through the OAuth Integration; (ii) using commercially reasonable efforts to prevent the introduction of Harmful Code to: (a) any joint customers' systems, platforms, services, software, devices, sites and/or networks; or (b) the Services; (iii) compliance with Applicable Law, including Applicable Data Protection Laws in the development, maintenance, and use of the OAuth Integration; (iv) implementing and maintaining appropriate technical and organizational security measures consistent with industry standards as applicable to the development and maintenance of the OAuth Integration; (v) notifying Supabase in writing within forty-eight (48) hours of any breach of security leading to the unauthorized access to or use of data flowing through the OAuth Integration ("Security Incident"); and (vi) the security, integrity, and legality of Partner's Platform. Partner shall make no representations or warranties with respect to the Services or Supabase's associated support offerings to its customers or prospects and shall maintain adequate insurance coverage and minimum coverage limits for its business as required by any Applicable Law. Partner's lack of or insufficiency of insurance coverage shall not limit any liability Partner may have under this Addendum. For purposes of this clause, "Harmful Code" means code, files, scripts, agents or programs intended to do harm, including any code containing viruses, Trojan horses, worms or like destructive code, code that self-replicates or code that contains a "timeout" feature to prevent access and use at some future date. In addition, Partner shall grant to each End-Customer the rights necessary for operation of the OAuth Integration, under the separate end user license agreement that will govern the End Customer's rights to the OAuth Integration (the "EULA"). Partner acknowledges and agrees that the applicable EULA for each OAuth Integration is solely between Partner and the End-Customer. Supabase shall neither be party to, nor have any liability whatsoever, under any EULA or privacy policy between Partner and any End-Customer.
(b) Customer User Monitoring Obligation.#
To the extent relevant to the specific OAuth Integration, Partner shall promptly (and in no event later than twenty-four (24) hours) terminate, disable, or otherwise deactivate any OAuth Integration use by a Customer User that Partner suspends, blocks, terminates, or otherwise restricts due to suspected or actual abuse, fraud, violation of applicable law, or breach of Partner's EULA. To the extent Partner is technically unable to directly terminate or deactivate such Customer User, Partner shall notify Supabase within twenty-four (24) hours and provide sufficient identifiers (including project IDs or other mutually agreed identifiers) to enable Supabase to take action. Partner shall implement and maintain an automated mechanism (including API-based signaling or other technical integrations specified by Supabase) to (i) effectuate such deactivation and (ii) where applicable, transmit notices to Supabase in real time or near real time. Supabase reserves the right, but not the obligation, to independently suspend, throttle, restrict, or permanently disable any such Customer User, or associated resources at any time to mitigate security, operational, or financial risk. "Customer User" means an individual employee, agent or contractor of an End-Customer for whom access has been granted to the Services.
(c) Security.#
In furtherance of Partner's Section 6.1(a)(iv) obligation, Partner shall be solely responsible for the proper integration with, and configuration of the Services with the OAuth Integration, including ensuring that the Services are appropriately configured for use by End-Customers and their Customer Users, pursuant to Supabase's shared responsibility model (found at https://supabase.com/docs/guides/deployment/shared-responsibility-model). Partner shall take all reasonable steps to ensure that any integrations, access controls, environment variables, and data retention or exposure settings are secure and aligned with Supabase's documentation, recommendations, and best practices. Partner is required to use Supabase's Security Advisor feature and either directly act on all security alerts, or alternatively, notify End-Customers' Customer Users, on at least a weekly basis, of any outstanding security alerts to maintain the security of Customer Accounts. Supabase shall not be liable for any security incidents, data breaches, or system misuse resulting from Partner's misconfiguration, negligence, or failure to follow Supabase guidance. Supabase reserves the right to conduct a security review or technical audit, either directly or through third-party assessment, and/or suspend or restrict Partner's access to the Services in the event of a Security Incident, or if it reasonably determines that Partner's use or configuration poses a material security or operational risk to Supabase's infrastructure, systems, or other customers. Supabase shall cooperate in good faith by providing reasonable cooperation in the investigation, mitigation, remediation, and any required disclosure of such incidents, including providing access to relevant personnel, logs, and system information upon request.
6.2 Partner Restrictions.#
Partner shall not, shall not attempt, or assist or permit any third party to: (i) access any endpoints of the Services other than those endpoints that Supabase has agreed that Partner may access in writing, even if the Partner has technical access to additional endpoints; (ii) use or access the Services in a manner that exceeds any express request volume provided by Supabase (or otherwise, a reasonable request volume), and as may be adjusted from time to time; (iii) intentionally submit queries to the Services (whether demo or demo environment) which fail to contain all required parameters; (iv) use or access the Services beyond the minimum extent reasonably necessary to develop and manage the OAuth Integration; (v) push or pull any data which it does not own into or from the Services that it has not been explicitly authorized by the data owner to share with Supabase; (vi) bypass the security or authentication protocols of the Services; (vii) intentionally interfere with or disrupt: (a) any features or functionalities that are embedded in or included with the Services, (b) Supabase's monitoring of the Services, or (c) the servers or networks providing or hosting the Services; (viii) use the Services, any data obtained through the Services, or any OAuth Integration: (a) in any manner or for any purpose that violates any Applicable Law or any right of any person or entity, including but not limited to Intellectual Property Rights, rights of privacy, and rights of personality, (b) in a false or misleading manner, or in any manner inconsistent with this Addendum or the Service Terms, or (c) in a way that may be offensive, profane, obscene, libelous to Supabase, Supabase's End-Customers or prospects; or (ix) create new Organizations on behalf of any End-Customer or Customer User; End-Customers and Customer Users must create their own Organizations directly within the Services, and once created, the End-Customer or Customer User may opt into the OAuth Integration to authorize Partner's access to that Organization.
6.3 Data Processing.#
(a) Artificial Intelligence.#
If any OAuth Integration uses or incorporates any AI, such use must be fully disclosed to End-Customers in advance, including in Partner's EULA as legally required, and Partner's development and use of AI must comply with all relevant Applicable Laws. Any use or incorporation of AI without such disclosure, or otherwise in violation of this Section, shall be considered a material breach of this Addendum. Partner shall (i) reasonably test the use or incorporation of AI with various inputs to ensure that outputs do not violate this Addendum; (ii) have a mechanism for End-Customers to report feedback to Partner related to errors, bugs, improper, or undesired outputs; (iii) inform End-Customers of the appropriate use cases, best practices, and limitations of the AI used or incorporated in an OAuth Integration; and (iv) not use Supabase's End-Customer's data or source code to train or fine tune Partner's or any third party's AI models. "AI" means generative artificial intelligence that is designed to take input and generate output of any kind, including but not limited to images, video, music, speech, text, software code, and product designs.
(b) Personal Data Protection.#
Any Personal Data processed in connection with this Addendum shall be handled as follows:
(i) Roles. Except where the Parties expressly agree otherwise in a Program Authorization, each Party acts as an independent controller (or equivalent role under Applicable Data Protection Laws) with respect to Personal Data it collects, receives, or determines the purposes and means of processing for in connection with the OAuth Integration; neither Party processes Personal Data on behalf of the other except as expressly designated in writing.
(ii) Compliance. Each Party shall comply with all Applicable Data Protection Laws in its processing of Personal Data, including obtaining and maintaining all notices, consents, and lawful bases required for the disclosures and processing contemplated by the OAuth Integration.
(iii) Security. Partner shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure, consistent with the standard set forth in Section 6.1(a)(iv).
(iv) International Transfers. To the extent the OAuth Integration involves a transfer of Personal Data across jurisdictions, the transferring Party shall ensure a valid transfer mechanism is in place (such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful mechanism), and the Parties shall reasonably cooperate to execute any additional documentation required under Applicable Data Protection Laws.
(v) Incidents. Partner shall notify Supabase of any Security Incident in accordance with Section 6.1(a)(v) and shall reasonably cooperate with Supabase in connection with the investigation, remediation, and notification of any such incident.
(vi) Data Subject Rights and Regulator Inquiries. Each Party shall, at its own cost, reasonably cooperate with the other in responding to any verified data subject request or competent supervisory authority inquiry to the extent such request or inquiry relates to Personal Data processed in connection with the OAuth Integration.
(vii) Sub-processors. To the extent Partner engages any third party to process Personal Data received from or through the Services in connection with the OAuth Integration, Partner shall impose on such third party, data protection obligations no less protective than those set forth in this Section 6.3(b) and shall remain liable for the acts and omissions of such third parties.
(viii) Return or Deletion. Upon expiration or termination of this Addendum, or upon Supabase's written request, Partner shall, at Supabase's option, return or securely delete Personal Data received from or through the Services, except to the extent retention is required by Applicable Law or for the establishment, exercise, or defense of legal claims. The Parties agree that this Section 6.3(b) constitutes the data protection terms governing Personal Data processed under this Addendum, and no separate data processing agreement shall be required unless and until the Parties' processing activities materially change such that one is required by Applicable Data Protection Law.
6.4 Developer Credentials.#
Solely to the extent the Non-Developing Party issues the Developing Party any developer credentials (such as tokens or electronic keys) with respect to the Services or to Partner's Platform, as applicable ("Developer Credentials"), the Developing Party shall: (i) solely use the Developer Credentials to access the Services or Partner's Platform; (ii) not misrepresent or mask its identity when utilizing the Services or Partner's Platform; and (iii) hold such Developer Credentials in confidence and not share with, or transfer the Developer Credentials to, any third party without the Non-Developing Party's prior written consent (which can be revoked at any time). The Non-Developing Party hereby reserves the right to update the Non-Developing Party's Developer Credentials from time to time and the Developing Party shall be obligated to use the new Developer Credentials and shall no longer access the Services or Partner's Platform using any deprecated Developer Credentials.
6.5 Suspension and Revocation.#
The Non-Developing Party reserves the right to suspend or discontinue the Developing Party's access to all or any portion of the Services or Partner's Platform (as applicable). Notwithstanding the foregoing, in the event that Supabase reasonably determines that Partner's access to the Services, or its OAuth Integration, poses a security or privacy risk to Supabase or any other party and that risk cannot be cured by Partner in a reasonable amount of time, then Supabase may, at its sole discretion, immediately suspend or discontinue the Partner's access to all or any portion of the Services and/or request the removal of the OAuth Integration from the Partner's Marketplace, with or without prior notice to the Partner. Any exercise of this right by Supabase shall result in no liability or remedy owed to Partner unless otherwise separately agreed by the Parties in writing.
7. Intellectual Property.#
7.1 Supabase IP Rights.#
Nothing in this Addendum shall be construed to grant the Partner any ownership right in the Services, any derivative works of the Services, or the related Intellectual Property Rights.
7.2 Partner IP Rights.#
Supabase acknowledges and agrees that as between Supabase and Partner, the Partner owns all right, title and interest in and to the Intellectual Property Rights in and to the Partner's Platform and, except as expressly stated otherwise in this Addendum, the OAuth Integration. This includes any associated services, documentation, prototypes, models, computer source code, source files, and any other computer files and materials (regardless of form or format) that Partner creates in connection with the OAuth Integration. For clarity, nothing in this Addendum, or the Agreement shall be construed to grant Supabase any ownership right in the Partner's Platform or its related Intellectual Property Rights. Notwithstanding the foregoing, upon final approval of the OAuth Integration by Supabase, Partner hereby authorizes Supabase to market, promote, and subject to Publication, the OAuth Integration as Supabase deems appropriate.
7.3 No Jointly Developed or Held Intellectual Property; No Implied Rights.#
The Parties understand that they do not anticipate jointly developing any intellectual property under this Addendum, and to the extent they do, the Parties will handle ownership and licensing of such intellectual property in good faith and as mutually agreed upon in a separate written agreement. Additionally, as of the Effective Date of the Agreement, no intellectual property is held between the Parties. Subject to the limited licenses expressly provided in this Agreement, nothing in this Agreement (including this Addendum) transfers or assigns to a Party any of the other Party's Intellectual Property Rights in its Marks, technology, or otherwise, and no rights are implied.
8. Representations and Warranties.#
In addition to the representations and warranties provided by the Parties in the MPPA, Partner further represents and warrants that: (a) Partner's OAuth Integration complies with all Applicable Data Protection Laws and Applicable Law relevant to consumer protection; (b) Partner has obtained all End-Customer and Customer User consents required for the Processing of data as relevant to its OAuth Integration; and (c) Partner will not use the OAuth Integration for any unlawful purpose.
9. Applicability of MPPA.#
This Addendum is subject to the terms and conditions of the MPPA. Without limiting the foregoing, and for clarity of the Parties: (i) Partner's obligations under the MPPA with respect to its conduct and its compliance with Applicable Laws, including those relating to Personal Data, anti-bribery and anti-corruption, and export controls and trade sanctions, extend to this Addendum; (ii) except as otherwise expressly provided in this Addendum, Partner's remedies with respect to its participation in the Program, and use of the Services, shall be solely as provided in the MPPA and this Addendum; and (iii) Sections 6, 7, 11, 12, and 19 through 24 of the MPPA shall, in addition to the remainder of the MPPA, apply to this Addendum. For clarity, no End-Customer or Customer User shall be deemed a third-party beneficiary of this Addendum, or the Agreement.
10. Term and Termination.#
10.1 Term.#
Notwithstanding any contrary provision in the MPPA, the term of this Addendum will continue through the expiration or earlier termination of the MPPA, or the end of the Publication of the OAuth Integration, whichever is earlier ("Addendum Term").
10.2 Termination Rights.#
In addition to the termination rights of the Parties expressly provided in the MPPA, either Party may terminate this Addendum and the availability of any OAuth Integration, effective on written notice to the other Party, if the other Party materially breaches this Addendum, and such breach (if capable of cure) remains uncured thirty (30) days after the non-breaching Party provides the breaching Party with written notice of such breach. Additionally, Supabase may terminate this Addendum and the approval of Publication of any OAuth Integration for convenience upon ninety (90) days prior written notice to Partner.
10.3 Effects of Termination.#
Upon expiration or earlier termination of this Addendum: (a) all rights granted to Partner with respect to the Services will terminate effective as of the effective date of termination; and (b) in the event of Supabase's termination pursuant to the last sentence of Section 10.2 of this Addendum, Partner shall continue to comply with Section 4 of this Addendum through expiration or termination of Publication.
10.4 Survival.#
In addition to Section 10.3, the following provisions of this Addendum shall survive any expiration or termination of this Addendum: Section 1, Section 6.2 (Partner Restrictions, to the extent of Partner's continuing use, if any, of data or materials obtained under this Addendum), Section 7 (Intellectual Property), Section 9 (Applicability of MPPA), Section 10.3 (Effects of Termination), this Section 10.4 (Survival), Section 11 (Indemnification), Section 12 (Limitations of Liability), and Section 13 (Miscellaneous). In addition, any right or obligation of the Parties under this Addendum that, by its nature, is intended to survive termination or expiration (including any accrued payment obligations and any claims arising from acts or omissions occurring prior to termination or expiration) shall so survive.
11. Indemnification.#
In addition to the obligations of the Parties in the MPPA, and subject to the indemnification procedures described in the MPPA:
11.1 Partner Indemnification.#
Partner agrees to defend, indemnify and hold harmless Supabase and Supabase Indemnitees, from and against any and all Losses arising out of or related to any Third-Party Claim alleging: (i) Partner's violation of Section 6.2 of this Addendum; or (ii) Partner, the OAuth Integration, or Partner's Platform's infringement of a third party's Intellectual Property Rights.
12. Limitations of Liability.#
Solely with respect to the Parties' obligations under this Addendum, and to the fullest extent permitted by Applicable Law, except as otherwise expressly provided in this Section 12, in no event shall: (a) either Party, its Affiliates or their employees, agents, contractors, officers or directors be liable for any indirect, punitive, incidental, special, consequential or exemplary damages, including without limitation damages for business interruption, loss of profits, goodwill, use, data or other intangible losses arising out of or relating to this Addendum; or (b) either Party's cumulative and aggregate liability under this Addendum exceed fifty thousand United States Dollars (USD $50,000.00). The foregoing liability cap shall not apply to liabilities arising under this Addendum due to: (i) either Party's gross negligence, willful misconduct, or fraudulent misrepresentation; or (ii) either Party's indemnification obligations. Notwithstanding the foregoing, and solely to the extent permitted by Applicable Law, the aggregate liability of either Party for all claims arising under clauses (i) and (ii) above shall not exceed three hundred thousand United States Dollars (USD $300,000.00).
13. Miscellaneous.#
The MPPA and this Addendum are the complete and exclusive statement of the agreement between the Parties with respect to the OAuth Integration that Partner makes available. Any terms and conditions of any other instrument issued by Partner or any End-Customer in connection with the OAuth Integration which are in addition to, inconsistent with or different from the terms and conditions of the MPPA and this Addendum shall be of no force or effect. In the event any provision of this Addendum is deemed to conflict with a provision of the MPPA, the applicable provision of this Addendum shall control. Supabase may change this Addendum from time to time at its discretion. The date on which the Addendum was last modified will be updated at the top of this Addendum. Amendments to this Addendum will only take effect on Partner, on the renewal of this Addendum only when the Parties enter into a subsequent Program Authorization.