No email required
Sample evaluation report
This is the whole artifact, not a preview of one. The export contains exactly this, as Markdown and CSV.
An evaluation of Supabase, Notion, Linear across 18 criteria, with the source URL and verification date behind every value. Undocumented criteria appear as their own rows and are collected at the end as a vendor questionnaire. Data collected .
| Criterion | Supabase | Notion | Linear |
|---|---|---|---|
| Access and authentication | |||
| Authentication required | Yes We checked checkedPOST initialize without credentials -> HTTP 401 Unauthenticated connection attempt — https://mcp.supabase.com/mcp | Yes We checked checkedPOST initialize without credentials -> HTTP 401 Unauthenticated connection attempt — https://mcp.notion.com/mcp | Yes We checked checkedPOST initialize without credentials -> HTTP 401 Unauthenticated connection attempt — https://mcp.linear.app/mcp |
| OAuth 2.1 authorization | Yes We checked checkedhttps://mcp.supabase.com/.well-known/oauth-protected-resource/mcp -> 200 OAuth discovery metadata — https://mcp.supabase.com/mcp | Yes We checked checkedhttps://mcp.notion.com/.well-known/oauth-protected-resource/mcp -> 200 OAuth discovery metadata — https://mcp.notion.com/mcp | Yes We checked checkedhttps://mcp.linear.app/.well-known/oauth-protected-resource/mcp -> 200 OAuth discovery metadata — https://mcp.linear.app/mcp |
| Dynamic client registration | Yes We checked checked"registration_endpoint": "https://api.supabase.com/platform/oauth/apps/register" Authorization server metadata — https://mcp.supabase.com/mcp | Yes We checked checked"registration_endpoint": "https://mcp.notion.com/register" Authorization server metadata — https://mcp.notion.com/mcp | Yes We checked checked"registration_endpoint": "https://mcp.linear.app/register" Authorization server metadata — https://mcp.linear.app/mcp |
| Documented scopes | Yes organizations:read, projects:read, projects:write, database:write, database:read, analytics:read, secrets:read, edge_functions:read, edge_functions:write, environment:read, environment:write, storage:read, storage:write We checked checked"scopes_supported": ["organizations:read","projects:read","projects:write","database:write","database:read","analytics:read","secrets:read","edge_functions:read","edge_functions:write","environment:read","environment:write","storage:read","storage:write"] Protected Resource Metadata — https://mcp.supabase.com/mcp | Yes default We checked checked"scopes_supported": ["default"] Protected Resource Metadata — https://mcp.notion.com/mcp | Yes read, write We checked checked"scopes_supported": ["read","write"] Protected Resource Metadata — https://mcp.linear.app/mcp |
| Read and write are separate scopes | Yes We checked checkedscopes_supported enumerates both read and write: ["organizations:read","projects:read","projects:write","database:write","database:read","analytics:read","secrets:read","edge_functions:read","edge_functions:write","environment:read","environment:write","storage:read","storage:write"] Protected Resource Metadata — https://mcp.supabase.com/mcp | No We checked checkedscopes_supported is ["default"] -- no separate read-only scope is offered Protected Resource Metadata — https://mcp.notion.com/mcp | Yes We checked checkedscopes_supported enumerates both read and write: ["read","write"] Protected Resource Metadata — https://mcp.linear.app/mcp |
| Deployment and transport | |||
| Streamable HTTP transport | Yes Registry checked"type": "streamable-http", "url": "https://mcp.supabase.com/mcp" | Yes Registry checked"type": "streamable-http", "url": "https://mcp.notion.com/mcp" | Yes Registry checked"type": "streamable-http", "url": "https://mcp.linear.app/mcp" |
| SSE transport | No Registry checkedno sse remote declared | Yes Registry checked"type": "sse", "url": "https://mcp.notion.com/sse" | No Registry checkedno sse remote declared |
| Vendor-hosted endpoint | Yes Registry checked1 remote endpoint(s) declared | Yes Registry checked2 remote endpoint(s) declared | Yes Registry checked1 remote endpoint(s) declared |
| Self-hostable package | Yes Registry checkednpm:@supabase/mcp-server-supabase | No Registry checkedno installable package declared | No Registry checkedno installable package declared |
| Supply chain | |||
| Public source repository | Yes Registry checkedhttps://github.com/supabase/mcp | No Registry checkedno repository declared in the registry record | No Registry checkedno repository declared in the registry record |
| Open-source license | Not checked | Not checked | |
| Repository actively maintained | Yes Vendor checkedlast push 0 days ago GitHub repository — https://github.com/supabase/mcp | Not checked | Not checked |
| Package deprecated | Not checked | Not checked | Not checked |
| Secret inputs marked as secret | Yes Registry checked1 credential input(s), all marked isSecret | Not checked | Not checked |
| Documented controls | |||
| Audit logging documented | Not documented | Not documented | Not documented |
| Access controls documented | Not documented | Not documented | Not documented |
| Data residency documented | Not documented | Not documented | Not documented |
| Data retention documented | Not documented | Not documented | Not documented |
Open questions for these vendors
The export turns every undocumented criterion into this list. Undocumented means unanswered, not absent.
Supabase
5 undocumented
- Package deprecated
- Audit logging documented
- Access controls documented
- Data residency documented
- Data retention documented
Notion
8 undocumented
- Open-source license
- Repository actively maintained
- Package deprecated
- Secret inputs marked as secret
- Audit logging documented
- Access controls documented
Linear
8 undocumented
- Open-source license
- Repository actively maintained
- Package deprecated
- Secret inputs marked as secret
- Audit logging documented
- Access controls documented