Supabase
Why Supabase
Supabase is an open-source backend platform centred on a managed PostgreSQL database bundled with authentication, auto-generated REST and GraphQL APIs, realtime subscriptions, file storage, and edge functions. Designed for technical founders and developers who want a full backend without assembling separate services, it is available as a hosted cloud service or self-hostable Docker stack. Row-level security handles authorisation directly in the database.
What it does
Supabase is an open-source backend platform built on Postgres. Every project is a full Postgres database. Around it you get auto-generated REST and GraphQL APIs, authentication, file storage, realtime subscriptions, edge functions, scheduled jobs and vector search. You can use the hosted service or run it yourself.
Why you would need it
Every app needs the same plumbing before it does anything useful: a database, logins, file uploads, an API and a way to push live updates. Assembling that from separate services costs weeks and leaves you with five bills and five sets of docs. If you pick a hidden document store to save time, you may regret it when the data needs joins and reports.
Supabase gives you that plumbing on day one. The data sits in a real relational database you can query, migrate and move.
Where it fits
It is the backend of your product. Your front end, built with something like Next.js on Vercel, talks to it through the generated API or the client libraries. Stripe webhooks can land in its edge functions. Your analytics, workflows and AI features can read from the same database. It replaces a self-built API server plus separate auth and storage services. It competes with Firebase and with managed Postgres hosts such as Neon.
What stands out
- Real Postgres, so indexes, joins, migrations and extensions carry straight over.
- Row Level Security, which puts authorisation in the database next to the data.
- Realtime features for database changes, broadcast and presence.
- An official MCP server, a Management API and a CLI for local development.
My take
I'd pick it when you build a product on a relational model and want to move fast without giving up SQL. The bundle removes a lot of early work, and the open-source base means you can leave if you must.
What I'd watch is Row Level Security. It is a good model, but a wrong policy is a security problem, not a cosmetic one, so it needs care and tests. Leaning on functions, realtime and the generated client ties more of your app to Supabase conventions, even though the database itself stays portable. And the breadth means a learning curve before it feels easy.
Verdict
Pick it when you are a technical team that wants a proper SQL foundation with auth, storage and realtime included. Skip it when nobody on the team wants to think about SQL and access policies, or when you want a backend that hides the database completely.
Notes
Your note
Before you choose
Security is your job
Row Level Security keeps authorisation close to the data, but you write and test the policies. A missing policy can expose rows. Use the built-in advisors, test policies with real roles, and review them whenever a table changes.
Read moreShow less
Free plan limits
There is a free plan, which is good for prototypes. It has small storage and egress limits, a cap on active projects and pauses a project after a week of inactivity. Do not run a production app on it. Paid usage is billed on top of the plan, so watch egress, storage and compute as you grow.
Platform conventions create some lock-in
The database is portable Postgres, but your auth setup, edge functions, realtime channels and generated client are Supabase-specific. If you want an easy exit, keep business logic in plain SQL and keep an eye on how much you build in functions.
Alternatives to compare
Firebase is the document-store route with deep Google integration. Neon is serverless Postgres without the bundled auth and storage. If you want to avoid managing a backend altogether, a no-code tool such as Airtable is a different category but worth a look for internal apps.