Supabase
- Pronunciation
- SOO-puh-bayss
In short
Supabase is an open-source backend platform built on PostgreSQL that gives an app a database, authentication, storage, real-time updates and instant APIs.
What is Supabase?
Supabase was founded in 2020. Every project is a real PostgreSQL database, with tables, SQL, joins, extensions and transactions, rather than a proprietary data model. On top of it Supabase adds the services an app needs: Auth for sign-in, Storage for files, Realtime for listening to database changes, and Edge Functions for server-side code.
The database is exposed through APIs generated automatically from the schema, so a front end can query tables directly with the Supabase client library: supabase.from("posts").select("*"). Access is controlled with PostgreSQL's row level security (RLS), policies written in SQL that decide which rows each signed-in user may read or change.
Because it is standard Postgres, data can be exported, queried with any SQL tool, connected to an ORM such as Prisma or Drizzle, and extended with extensions such as pgvector for AI embeddings. Supabase can be used as a hosted service or self-hosted, since the components are open source.
A common misconception is that the auto-generated API is safe by default. If row level security is not enabled and configured on a table, anyone with the public key may be able to read or modify it. Turning on RLS for every table exposed to clients and testing the policies is essential.
Key takeaways
- Supabase is an open-source backend platform built on PostgreSQL.
- It adds auth, storage, real-time updates and edge functions.
- APIs are generated automatically from the database schema.
- Row level security policies in SQL control access to each row.
- It is standard Postgres, so data and tools stay portable.
Example
import { createClient } from "@supabase/supabase-js";
const supabase = createClient("https://xyz.supabase.co", "public-anon-key");
// Each signed-in user only sees their own notes, thanks to the policy below
const { data, error } = await supabase
.from("notes")
.select("id, title, created_at")
.order("created_at", { ascending: false });
/* In SQL:
alter table notes enable row level security;
create policy "own notes" on notes
for select using (auth.uid() = user_id);
*/Readers ask
What is the difference between Supabase and Firebase?
Supabase is built on a relational PostgreSQL database with SQL and is open source. Firebase uses Google's NoSQL document databases and is proprietary. Both provide auth, storage and real-time features for apps.
Is Supabase just PostgreSQL?
At its core, yes: each project is a full Postgres database. Supabase adds managed services around it, such as authentication, storage, real-time subscriptions, generated APIs and a dashboard.
What is row level security?
A PostgreSQL feature that applies policies to every query, so a user can only read or change the rows the policy allows. Supabase relies on it to make direct database access from clients safe.
Often compared
See also
- PostgreSQLDatabases, p. 35PostgreSQL is a free, open-source relational database known for reliability, strict standards support and extensions, and widely used for web applications.
- FirebaseDatabases, p. 20Firebase is Google's platform that gives web and mobile apps a hosted database, authentication, storage, hosting and functions without managing a backend.
- Relational DatabaseDatabases, p. 38A relational database stores data in tables of rows and columns, links those tables through keys, and lets you query and combine the data with SQL.
- AuthenticationSecurity, p. 2Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- REST APIBackend & APIs, p. 38A REST API is a web API that exposes data as resources identified by URLs and lets clients read or change them using standard HTTP methods.
- SQLDatabases, p. 40SQL is the standard language for working with relational databases, used to create tables and to insert, query, update, and delete the data stored in them.
Spotted a mistake or something missing on this page?Suggest an edit