Skip to main content

Supabase

Pronunciation
SOO-puh-bayss
Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/supabase

In short

Supabase is an open-source backend platform built on PostgreSQL that gives an app a database, authentication, storage, real-time updates and instant APIs.

What is Supabase?

Supabase was founded in 2020. Every project is a real PostgreSQL database, with tables, SQL, joins, extensions and transactions, rather than a proprietary data model. On top of it Supabase adds the services an app needs: Auth for sign-in, Storage for files, Realtime for listening to database changes, and Edge Functions for server-side code.

The database is exposed through APIs generated automatically from the schema, so a front end can query tables directly with the Supabase client library: supabase.from("posts").select("*"). Access is controlled with PostgreSQL's row level security (RLS), policies written in SQL that decide which rows each signed-in user may read or change.

Because it is standard Postgres, data can be exported, queried with any SQL tool, connected to an ORM such as Prisma or Drizzle, and extended with extensions such as pgvector for AI embeddings. Supabase can be used as a hosted service or self-hosted, since the components are open source.

A common misconception is that the auto-generated API is safe by default. If row level security is not enabled and configured on a table, anyone with the public key may be able to read or modify it. Turning on RLS for every table exposed to clients and testing the policies is essential.

Key takeaways

  • Supabase is an open-source backend platform built on PostgreSQL.
  • It adds auth, storage, real-time updates and edge functions.
  • APIs are generated automatically from the database schema.
  • Row level security policies in SQL control access to each row.
  • It is standard Postgres, so data and tools stay portable.

Example

Querying data with the Supabase client and an RLS policyjavascript
import { createClient } from "@supabase/supabase-js";

const supabase = createClient("https://xyz.supabase.co", "public-anon-key");

// Each signed-in user only sees their own notes, thanks to the policy below
const { data, error } = await supabase
  .from("notes")
  .select("id, title, created_at")
  .order("created_at", { ascending: false });

/* In SQL:
alter table notes enable row level security;
create policy "own notes" on notes
  for select using (auth.uid() = user_id);
*/

Readers ask

What is the difference between Supabase and Firebase?

Supabase is built on a relational PostgreSQL database with SQL and is open source. Firebase uses Google's NoSQL document databases and is proprietary. Both provide auth, storage and real-time features for apps.

Is Supabase just PostgreSQL?

At its core, yes: each project is a full Postgres database. Supabase adds managed services around it, such as authentication, storage, real-time subscriptions, generated APIs and a dashboard.

What is row level security?

A PostgreSQL feature that applies policies to every query, so a user can only read or change the rows the policy allows. Supabase relies on it to make direct database access from clients safe.

Often compared

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings