Skip to content

Rank #1 of 4 in Backend as a Service

Supabase logo

Supabase

Open SourceYC S20

Supabase Inc.

109.1k15.8k/yrnpm 20.1M/wk +315npm/wk -4.9M

Access

Install

npmnpm install @supabase/supabase-js
brewbrew install supabase/tap/supabase

Compare head-to-head

Alternatives to Supabase

Showcase

Supabase homepage screenshot
homepage · captured Sep 2026 · view live ↗
Supabase docs screenshot
docs · captured Sep 2026 · view live ↗

Try itExperimental

See what an agent can do with Supabase before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; the live MCP handshake runs real requests from our edge, right now — including, where the server allows it, one real read-only tool call (bring your own key for auth-gated servers); sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).

$mcp-probe → https://mcp.supabase.com/mcplive — run just now from our edge
$ press ▶ run to send one JSON-RPC initialize from our edge
real JSON-RPC against the vendor’s documented MCP endpoint — read-only, nothing is written

Verified integrations

Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.

By theme — the product's score on each story themeBy theme

Agenticness — how well agents can access and operate the productAgenticnessevidence →

How well agents can access and operate the product

49.2/100

Ai vector — stories about ai vector in this arenaAi vectorevidence →

Stories about ai vector in this arena

60.0/100

Auth — stories about auth in this arenaAuthevidence →

Stories about auth in this arena

55.2/100

Automation depth — how much of the product can run unattendedAutomation depthevidence →

How much of the product can run unattended

11.3/100

Database realtime — database and realtime features — queries, subscriptions, live syncDatabase realtimeevidence →

Database and realtime features — queries, subscriptions, live sync

50.8/100

Functions — stories about functions in this arenaFunctionsevidence →

Stories about functions in this arena

55.2/100

Local dev — stories about local dev in this arenaLocal devevidence →

Stories about local dev in this arena

42.5/100

Openness — open source, data portability, and self-hosting storiesOpennessevidence →

Open source, data portability, and self-hosting stories

58.4/100

Privacy posture — data-handling and privacy storiesPrivacy postureevidence →

Data-handling and privacy stories

10.0/100

Schema migrations — stories about schema migrations in this arenaSchema migrationsevidence →

Stories about schema migrations in this arena

40.3/100

Security rules — stories about security rules in this arenaSecurity rulesevidence →

Stories about security rules in this arena

25.2/100

Storage — stories about storage in this arenaStorageevidence →

Stories about storage in this arena

52.5/100

Story verdicts — every judged story with its evidenceStory verdicts

?

Sorted by importance (agentic first) (high → low) · 51/51 stories · click a row’s chevron for the rationale and evidence

Connect an agent via an official MCP server G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full9/10T

Drive the product through a documented public API G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full8/10T

Delegate tasks to a built-in AI assistant inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness3noneuntestednone yet

Plug MCP servers into this product so it can use their tools G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/auntestednone yet

Download a machine-readable API spec (OpenAPI or equivalent) G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Point an agent at llms.txt or agent-oriented docs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Run the product headlessly / in CI for automation G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Use an official CLI G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Operate the product with natural-language commands G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10T

Build against official SDKs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial6/10T

Get AI-generated insights and suggestions from my data inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial5/10T

Explore an interactive API reference with runnable examples G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial4/10T

Issue scoped/least-privilege API credentials for an agent G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2disputed4/10D

Rely on versioned APIs with a documented deprecation policy G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Set up automations that run autonomously in the background G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Subscribe to events via webhooks G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Test against a sandbox environment without touching production data G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness1full8/10T

Provision a managed database and read/write it from client and server SDKs C

Database

developerDatabase realtime — database and realtime features — queries, subscriptions, live syncDatabase realtime3full9/10T

Self-host the core product G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3full9/10T

Subscribe to live data changes so my UI updates in real time without polling C

Realtime

developerDatabase realtime — database and realtime features — queries, subscriptions, live syncDatabase realtime3full9/10X

Add email/password and social OAuth sign-in with the platform SDK in minutes C

Authentication

developerAuth — stories about auth in this arenaAuth3full8/10X

Deploy server-side functions invoked by HTTP or SDK calls without managing servers C

developerFunctions — stories about functions in this arenaFunctions3full8/10C

Store embeddings and run vector similarity search for AI features C

Vector

developerAi vector — stories about ai vector in this arenaAi vector3full8/10C

Have an agent stand up a new backend — schema, auth, and policies — headlessly from the CLI in a script C

Ai provisioning

ai-native userLocal dev — stories about local dev in this arenaLocal dev3full7/10T

Let an agent create and test schema changes in an isolated branch or preview environment before production C

Ai migrations

ai-native userSchema migrations — stories about schema migrations in this arenaSchema migrations3partial7/10T

Restrict data access per user with row-level security policies or security rules C

Access control

developerSecurity rules — stories about security rules in this arenaSecurity rules3partial7/10X

Upload and serve user files with access rules and CDN-backed delivery C

Files

developerStorage — stories about storage in this arenaStorage3full7/10X

Export all of my data in open formats and leave G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3partial5/10X

Run the whole backend stack locally with an emulator or CLI before deploying C

Local

developerLocal dev — stories about local dev in this arenaLocal dev3disputed5/10D

Define rules that trigger actions automatically on events G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth3partial4/10C

Manage schema changes as version-controlled migrations applied via the CLI or CI C

Migrations

developerSchema migrations — stories about schema migrations in this arenaSchema migrations3disputed4/10D

Prevent my data from being used to train AI models G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture3n/auntestednone yet

Generate typed client code (e.g. TypeScript types) from my schema automatically C

Type safety

developerSchema migrations — stories about schema migrations in this arenaSchema migrations2full8/10C

Do everything through the API that I can do in the UI G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2partial7/10T

Read the product's source under an open license G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2full7/10C

Express relational queries with joins, constraints, and transactions C

Database

developerDatabase realtime — database and realtime features — queries, subscriptions, live syncDatabase realtime2partial6/10X

Ask an AI assistant in the dashboard to write queries, debug errors, and explain my backend C

Ai assist

ai-native userAi vector — stories about ai vector in this arenaAi vector2partial5/10T

Choose where my data is stored (region/residency) G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2partial5/10C

Connect to the underlying database with standard clients and ORMs via a connection string C

Database

developerDatabase realtime — database and realtime features — queries, subscriptions, live syncDatabase realtime2partial5/10X

Require MFA and enterprise SSO (SAML/OIDC) for my application users G

Authentication

platform-engineerAuth — stories about auth in this arenaAuth2partial3/10C

Run functions automatically in response to database or auth events C

developerFunctions — stories about functions in this arenaFunctions2partial3/10C

Build offline-capable clients whose local writes sync automatically on reconnect C

Realtime

developerDatabase realtime — database and realtime features — queries, subscriptions, live syncDatabase realtime2none0/10

Rely on automated backups and point-in-time recovery for my data C

Data protection

platform-engineerSecurity rules — stories about security rules in this arenaSecurity rules2none0/10

Control data retention and deletion G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Opt out of telemetry and usage tracking G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Perform bulk operations across many items at once G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2noneuntestednone yet

Run full-text search over my data without wiring up an external search service C

Search

developerDatabase realtime — database and realtime features — queries, subscriptions, live syncDatabase realtime2noneuntestednone yet

Schedule recurring jobs or workflows G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2noneuntestednone yet

Track user presence and broadcast ephemeral state between connected clients C

Realtime

developerDatabase realtime — database and realtime features — queries, subscriptions, live syncDatabase realtime1full9/10X

Version, review, and roll back my automations G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth1partial3/10C

Serve resized or transformed images from storage without running my own image pipeline C

Files

developerStorage — stories about storage in this arenaStorage1none0/10

Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 27 stories with headroom

What would move Supabase’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.

  1. Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product

    nonemoves Built-in AIimpact 45

    All evidence describes Supabase's MCP server, which lets *external* AI assistants (Cursor, Claude, etc.) connect to and query a Supabase project — this is the client-connectivity story, not a built-in assistant living inside Supabase's own product/dashboard.

  2. Agenticness — how well agents can access and operate the productSet up automations that run autonomously in the background

    nonemoves Built-in AIimpact 30

    The evidence pack covers Edge Functions, Realtime, RLS, and MCP/CLI tooling, but contains no mention of scheduled jobs, cron triggers, database webhooks, or any mechanism for autonomous background automations that an AI-native user could set up and let run unattended.

  3. Agenticness — how well agents can access and operate the productSubscribe to events via webhooks

    nonemoves agent-readyimpact 30

    Missing: any documentation of Database Webhooks or HTTP callback subscription mechanism.

  4. Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy

    nonemoves API qualityimpact 30

    The evidence pack has no mention of API versioning schemes or a documented deprecation policy for Supabase's REST/GraphQL/Auth/Storage APIs; there's an OpenAPI spec probe but nothing about version lifecycle or deprecation commitments.

  5. Security rules — stories about security rules in this arenaRely on automated backups and point-in-time recovery for my data

    nonemoves PA Scoreimpact 20

    The evidence pack contains no vendor-tier documentation describing automated backups or point-in-time recovery (PITR) features; the only related evidence is a community report (supabase-comm-9) describing nightly pg_dump backups causing write-contention problems and the team merely 'investigating' moving customers to PITR.

  6. Automation depth — how much of the product can run unattendedPerform bulk operations across many items at once

    nonemoves PA Scoreimpact 20

    The evidence pack documents Supabase's REST API generation, RLS, realtime, storage, and CLI/MCP tooling, but nothing explicitly addresses bulk/batch operations (e.g., batch insert/update/delete across many rows or items) via the API, CLI, or MCP server.

  7. Automation depth — how much of the product can run unattendedSchedule recurring jobs or workflows

    nonemoves PA Scoreimpact 20

    The evidence pack covers Supabase's database, auth, storage, realtime, edge functions, CLI, and MCP integration, but contains no mention of a scheduling feature (e.g., pg_cron, scheduled Edge Functions, or workflow orchestration) for recurring jobs.

  8. Database realtime — database and realtime features — queries, subscriptions, live syncRun full-text search over my data without wiring up an external search service

    nonemoves PA Scoreimpact 20

    The evidence pack covers Supabase's database, realtime, auth, storage, vector/AI, and CLI/MCP capabilities extensively, but nowhere mentions Postgres full-text search (tsvector, GIN indexes, or a dedicated search feature).

Showing the top 8 of 27 — every none/partial verdict in the story verdicts table is headroom.

Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.

Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map7 surfaces · 37 covered stories

Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.

docs36 stories

Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence

11 of 16 testable claims verified · 1 contradictedintegrity 56/100

20 distinct capability claims found in Supabase’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.

11

Verified

4

Unverified

1

Contradicted

19

Undersold

Verified (13)
Unverified (5)
Contradicted (2)
Undersold (19)
Claims outside our story set (4)

Real capability claims found in Supabase’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.

  • Compute can scale up to 64 cores and 256 GB RAM

    source ↗
  • Auto-generated GraphQL API available alongside REST

    source ↗
  • Dashboard lets you manage your app without leaving it

    source ↗
  • Project stack lets you add Auth, Data APIs, Edge Functions, Realtime, Storage, and Vector embeddings on top of Postgres

    source ↗
Suggest a story for these →

Business model

open-sourcefree-tiersubscription-flatusage-based

Open-source and free to self-host; hosted Free tier, Pro from $25/mo per organization plus usage-based compute, storage, and bandwidth, Team and Enterprise above.

pricing ↗

Score trend

How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.

PA Score40 (Sep 4 '26)45 (Sep 4 '26)
Agent-ready54 (Sep 4 '26)64 (Sep 4 '26)

Try Experimental

Run it in the microterminal →

Recorded agent sessions — and a live MCP handshake where the vendor ships one.

Flag

⚑ Flag a verdict

Think a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.

Badge

Embed this product's score badge →

Hotlinked SVG — always shows the live current score.

For agents

Data

⚿ auth1 auth-gated probe

Agent surface uptime MCP 100% · llms.txt 100% · openapi.json 100% (30d, checked every 6h since Sep 8 '26)