| Layer | Product | Role |
|---|---|---|
| L4 | Blekline | Mask, enforce tool policy, audit |
| L2 | Supabase pgvector | Framework / retrieval |
Wiring
- Add
@blekline/mcp-serveror@blekline/clientto your agent pipeline - Pattern: mcp-proxy policy on vector query tools
- Route tool calls through
@blekline/mcp-proxywhen agents invoke external tools
Flow: Agent → L4 Blekline → L2 Supabase pgvector → models / vector stores.
Security
- Tool-arg governance — Block PII in embedding queries via MCP tool policy.
- Tenant isolation — You manage Supabase pgvector credentials; Blekline does not store them.
See Supabase pgvector documentation.
Next steps: Frameworks hub · MCP proxy · TypeScript SDK · Open workspace