An open-source backend platform built on Postgres that bundles database, auth, storage, edge functions, realtime, and vector search into one integrated project.
Software capabilities Authentication, Security & Compliance Anonymous Sign-ins Creates temporary anonymous user sessions that can later be converted into permanent accounts. Auth Hooks Customizes authentication flows by invoking a Postgres function or Edge Function at points such as JWT issuance or custom SMS/email sending. Auth Rate Limits Applies token-bucket rate limits to Auth endpoints, with configurable limits for email and SMS sends, sign-ins, verification, token grants, MFA, anonymous and Web3 sign-ins. CAPTCHA Protection Adds hCaptcha or Cloudflare Turnstile bot protection to authentication endpoints. Custom OAuth Scopes Requests additional OAuth scopes from social providers to access extra user permissions. Custom OIDC/OAuth Provider Admin Lets project admins create, update, list, and delete custom OIDC/OAuth identity providers for sign-in via a server-side admin API. Custom SMTP Sends authentication emails through a customer-configured SMTP server. Customizable Auth Email Templates Customizes the content and branding of authentication emails such as confirmation and password reset. Data API Security Controls Provides grants, dedicated API schemas, pre-request checks, and the option to disable the Data API entirely to control what the auto-generated REST/GraphQL surface exposes. Email/Password Auth Provides email and password signup with confirmation, password reset, and email-change flows. Enterprise-Managed Authentication for MCP Lets an organization's identity provider authorize MCP clients for the whole organization using an ID-JAG token exchange, so members reach the Supabase MCP Server through existing SSO without a per-user OAuth consent prompt. HIPAA Compliant Projects Offers a HIPAA-eligible project configuration, available as a paid add-on, for handling protected health information. Identity Linking Links multiple authentication identities such as social and email logins to a single user account. JWT Signing Keys & API Keys Signs and verifies session JWTs with asymmetric public/private key pairs and issues publishable and secret API keys in place of the legacy anon and service_role keys, which are being deprecated by the end of 2026. Leaked Password Protection Blocks sign-ups and password changes that use credentials found in the HaveIBeenPwned breach database. Magic Link Auth Authenticates users passwordlessly through a one-time sign-in link sent by email. Multi-Factor Authentication Adds TOTP-based and phone-based multi-factor authentication, enforceable through Row Level Security policies using JWT authenticator-assurance-level claims; phone challenges can be delivered via SMS or WhatsApp. Network Restrictions & SSL Enforcement Restricts which IP ranges can connect to a project's database and enforces SSL for all Postgres client connections. OAuth 2.1 Authorization Server Lets a Supabase project act as an OAuth 2.1 authorization server, driving user consent and authorization for third-party client applications; signed-in users can list and revoke grants they've issued to third-party clients. Phone / OTP Auth Authenticates users via SMS one-time passwords through a configured phone provider such as Twilio. PrivateLink Connects to a project's Postgres database over AWS PrivateLink so traffic never traverses the public internet. Regional Data Residency Provisions a project in one of 16+ regions so user and database data reside in a chosen geographic location. Row Level Security Enforces row-level authorization policies written in SQL that apply consistently across the Data API, Realtime subscriptions, and direct Postgres connections. Server-Side Auth Helpers Provides server-side rendering auth helpers for Next.js, SvelteKit, Remix, TanStack Start, and other frameworks. Session Controls Configures session controls including single session per user, session timeouts, and refresh token rotation. SOC 2 / ISO 27001 Compliance Maintains SOC 2 Type 2 and ISO 27001 certification covering the security of the hosted platform. Social Login Provides one-click OAuth sign-in with 20+ social identity providers including Google, GitHub, Apple, and Azure. SSO with SAML 2.0 Lets application users authenticate through an enterprise identity provider using the SAML 2.0 protocol. Studio Single Sign-On Lets an organization's team members log in to the Supabase dashboard through their own SSO identity provider. Temporary Access (JIT Database Access) Lets authorized project users connect to Postgres and Supavisor using their Personal Access Token or dashboard session token as the password for an authorized Postgres role, with expiry and IP restrictions managed via dashboard or Management API. Third-Party Auth Accepts JWTs issued by an external auth provider, such as Clerk, for Postgres Row Level Security authorization without migrating users into Supabase Auth. User Management Views, creates, edits, and deletes application users from the Supabase dashboard. Vault Stores and encrypts secrets and sensitive column data inside Postgres using the pgsodium-backed Vault extension. Web3 Wallet Auth Authenticates users by verifying signed messages from Ethereum and Solana wallets.
Postgres Database & Developer Tooling Branching GitHub Integration Connects branching to GitHub so preview branches are created and updated per pull request. Configuration as Code Declares project configuration in a config.toml file applied through the CLI. Database Branching Creates isolated preview branches of the database, which start without default privileges on the public schema until migrations grant them. Database Configuration Exposes Postgres configuration parameters for tuning a project's database from the dashboard. Database Functions Creates and manages PL/pgSQL and SQL stored functions that run inside Postgres. Database Indexes Creates and manages Postgres indexes, including advisor-suggested ones, from the dashboard or SQL. Database Linter Lints the database schema for security and performance issues with the built-in linter. Database Migrations Versions schema changes as SQL migration files applied and tracked through the CLI. Database Roles & Grants Manages Postgres roles, privileges, and grants for database-level access control. Database Testing (pgTAP) Runs database unit tests written with the pgTAP extension through the CLI. Database Triggers Runs database functions automatically in response to table INSERT, UPDATE, or DELETE events. Local Development Stack Runs the full Supabase stack locally in Docker through the CLI for offline development. Multigres High Availability Runs a project's Postgres as a multi-node cluster with automatic failover, unchanged connection strings, and consensus-backed durability via the Multigres integration (public alpha). OrioleDB Storage Engine Offers OrioleDB as an alternative Postgres storage engine with automatic memory tuning by compute size, configurable compression settings, and experimental support for non-B-tree indexes. Postgres Database Provisions each project a dedicated, portable PostgreSQL database that can be connected to directly with any Postgres client. Postgres Extensions Enables 40+ Postgres extensions such as pgvector, PostGIS, and pg_cron with a single click from the dashboard or SQL. Postgres Version Upgrades Upgrades a project to a newer Postgres major version using pg_upgrade, currently targeting Postgres 15.19 and 17.11, with documented reindexing steps for ltree and btree_gist indexes affected by the upgrade. Publications Manages Postgres logical replication publications that expose table changes to Realtime and pipelines. Schema Visualizer Renders an entity-relationship diagram of the database schema in the dashboard. Seed Data Seeds a local or branch database from SQL seed files on reset. SQL Editor Provides an in-dashboard editor to write, run, and save SQL queries with autocomplete and syntax highlighting. SQL Snippets Saves, organizes, and shares SQL queries as reusable snippets within a project. Supabase CLI Provides a command-line tool for local development, database migrations, type generation, and deploying projects, functions, and configuration. Supabase Studio Provides a web dashboard with table and SQL editors, database and policy management, and API docs, deployable standalone for local development and self-hosting. Supabase UI Library Ships shadcn-installable UI blocks — password and social auth, OAuth 2.1 consent, file dropzone uploads, current-user avatar, realtime chat/cursor/avatar-stack/collaborative Monaco and flow editors, a Supabase client, TanStack DB bindings, and a Platform Kit embeddable project manager — for React, Next.js, Nuxt, Vue, React Router, and TanStack Start. Table Editor Provides a spreadsheet-like interface in Studio for viewing and editing table rows, relationships, and JSON columns. Terraform Provider Manages Supabase projects, branches, settings, API keys, edge functions, secrets and third-party auth through the Supabase Terraform provider. TypeScript Type Generation Generates TypeScript types from the database schema using the CLI.
Data APIs, Edge Functions & Platform Auto-generated API Docs Auto-generates browsable API documentation for the project's tables and RPC functions in the dashboard. Auto-generated GraphQL API Auto-generates a GraphQL API from the database schema using the pg_graphql Postgres extension, resolved entirely inside the database. Auto-generated REST API Auto-generates a RESTful CRUD API from the database schema via the PostgREST server, with no backend code required; can omit null-valued fields from responses via the nulls=stripped Accept header variant (PostgREST 11.2+). Client Libraries Provides official client SDKs for JavaScript, Flutter/Dart, Swift, Kotlin, Python, and C# covering auth, database, storage, realtime, and functions. Custom Domains Serves a project's APIs from a customer-owned domain instead of the default supabase.co subdomain. Edge Function Background Tasks & WebSockets Runs background tasks beyond the request lifecycle and hosts WebSocket servers inside Edge Functions. Edge Function Regional Invocation Pins Edge Function execution to a region near the database to reduce database latency. Edge Function Secrets Stores and injects environment variables and secrets into Edge Functions at runtime. Edge Function Static File Hosting Bundles and serves static assets alongside Edge Functions. Edge Functions Runs globally distributed TypeScript/Deno serverless functions with Node.js and npm compatibility, integrated with the rest of the platform; client library invocations support aborting an in-flight request via an abort signal, and the @supabase/server package can wrap a handler as an RFC 9728 OAuth protected resource. Edge Functions Dashboard Editor Creates, edits, tests, and deploys Edge Functions directly from the dashboard. Edge Functions Node & npm Compatibility Runs Edge Functions with Node.js APIs and 2M+ npm modules via npm and node specifiers. GraphiQL Explorer Provides an in-dashboard GraphiQL IDE for exploring and running GraphQL queries against the project. Management API Manages organizations, projects, branches, Edge Functions, log drains, and configuration programmatically over a REST API. OAuth Apps Lets developers build third-party applications that access Supabase organizations through OAuth 2.0 authorization. Storage S3 Compatibility Exposes Storage through a standard S3 API compatible with existing S3 tools and SDKs. Stripe Projects provisioning Provisions a Supabase project with Postgres, Auth, Storage, Edge Functions and Realtime from a single Stripe CLI command and writes the credentials to a local .env file. Vanity Subdomains Assigns a chosen subdomain on Supabase's own domain instead of a randomly generated project reference.
Organizations, Access & Billing Access Roles Grants scoped personal access token permissions across resource groups including API keys and secrets, JWT secrets, compute workers, advisors and branches. Billing & Invoices Provides billing history, invoices, and payment method management for an organization. Compute Credits Applies monthly compute credits on paid plans to offset compute costs. Cost Control / Spend Cap Caps usage-based charges with a spend cap that prevents scaling beyond included quota when enabled. Organizations & Projects Groups projects under organizations for shared billing, membership, and configuration. Plan Management Manages Free, Pro, Team, and Enterprise plan subscriptions for an organization. Platform Audit Logs Records an auditable history of account- and project-level actions taken on the platform, available on Team and Enterprise plans. Project Pause & Restore Automatically pauses inactive Free-tier projects after a warning period and lets owners restore a paused project's data and configuration from Studio within a fixed window after pausing, currently one year. Project Transfer Transfers a project from one organization to another. Read-Only & Scoped Access Grants project-scoped and read-only dashboard access roles on higher tiers. Team Member Management Invites, manages, and removes members within an organization. Usage-Based Billing Meters and bills usage for compute, storage, egress, and monthly active users beyond plan quotas.
Logs, Reports & Observability Analytics Buckets Stores large datasets in columnar Parquet format on Apache Iceberg tables inside Storage, queryable via SQL from Postgres or any Iceberg-compatible engine. Client-Side Tracing (JS SDK) Propagates W3C Trace Context headers from the Supabase JS SDK to API Gateway and Edge Function logs so client spans correlate with server-side logs; opt-in via tracePropagation, requires @supabase/supabase-js 2.106.0+. Grafana Cloud Integration Connects a Supabase project to Grafana Cloud in one click from the dashboard, provisioning authentication, metric scraping, and a pre-built dashboard tracking 200+ metrics. Log Drains Exports project logs to third-party observability and log-analysis destinations, including Custom Endpoint, OpenTelemetry (OTLP), Datadog, Loki, Amazon S3, Sentry, Axiom, Last9, and Syslog. Logs & Log Explorer Provides SQL-queryable log exploration across API, Postgres, Auth, Storage, and Edge Function logs, running on ClickHouse (migrated from BigQuery) with regex-based filtering and a full field reference. Metrics Endpoint Exposes a Prometheus-compatible Metrics API endpoint (public beta) surfacing about 200 Postgres performance and health series, scrapable via the Datadog Agent or Prometheus remote write; not available on self-hosted projects. Project Reports Displays prebuilt usage and performance reports for the database, API, auth, and storage. Query Performance Insights Surfaces slow and frequent queries using pg_stat_statements data in the dashboard. Security & Performance Advisors Runs automated Security Advisor and Performance Advisor checks that flag misconfigurations and slow queries.
Backups, Recovery & Data Movement Automatic Backups Takes scheduled daily backups of the project database with a plan-based retention window. Backup Downloads Downloads logical database backups on demand. CSV Import Imports data into tables from CSV and spreadsheet files through the dashboard. Foreign Data Wrappers (Wrappers) Queries 30+ external systems — including Stripe, Snowflake, MongoDB, MySQL, MSSQL, Redis, BigQuery, ClickHouse, DynamoDB, Airtable, Firebase, Shopify, Slack, HubSpot, Notion, Auth0, Apache Iceberg, and any OpenAPI 3.0+ REST API — directly from Postgres using SQL, without duplicating the data. Migration Tooling Migrates data into Supabase from Firebase, Auth0, Postgres, MySQL, and other sources with guided tooling. Physical Backups Takes WAL-based physical backups for large databases, enabling faster restores than logical backups. Pipelines Streams change-data-capture from Postgres tables to supported analytical destinations in near real time, with a dashboard-shown cost and volume estimate before a pipeline's initial sync begins. Point in Time Recovery Restores a project's database to any point in time, down to the second, as a paid add-on.
Object Storage & Media Image Transformations Resizes, crops, and converts image format on the fly using URL parameters when serving files from Storage. Resumable Uploads Uploads large files in resumable chunks using the open TUS protocol, continuing after connection interruptions. Standard Uploads Uploads files through a standard multipart upload API up to the plan's file size limit. Storage Access Policies Controls access to storage objects with Postgres Row Level Security policies on the storage schema. Storage Bucket Lifecycle Policies Manages S3-style lifecycle policies on storage buckets, expiring noncurrent object versions via getBucketLifecycle, updateBucketLifecycle and deleteBucketLifecycle. Storage Buckets Stores and serves files and media through object storage buckets with Postgres-based row level security policies; client libraries support streaming file downloads and cursor-based paginated listing. Storage CDN Caches and serves Storage assets from a global edge network, with a Smart CDN variant that auto-revalidates on change; supports on-demand cache purging for a whole bucket or a single object, including purging only transformed image variants. Storage File Browser Provides drag-and-drop uploads, file browsing, folder management, and multi-select operations in the dashboard.
Vector, Embeddings & Search Automatic Embeddings Generates and refreshes vector embeddings automatically via triggers, a message queue, and a scheduled worker whenever source rows change. Full-Text Search Searches table content using native Postgres full-text search, with multilingual support available through the PGroonga extension. Hybrid Search Combines full-text keyword search and pgvector semantic search to rank results in a single query. In-Function Embedding Generation Generates embeddings from open-source models such as gte-small directly inside Edge Functions. vecs Python Client Provides the vecs Python client for creating vector collections, upserting embeddings, and querying them. Vector Buckets Stores and queries vector embeddings in vector buckets, with hosted queries accepting topK up to 10,000 and paginated results and local pgvector-backed queries capped at 100. Vector Metadata Filtering Filters vector similarity queries by any column or JSONB metadata to combine semantic and structured search. Vector Search (pgvector) Stores and queries vector embeddings alongside relational data in Postgres using the pgvector extension with HNSW and IVFFlat indexes.
AI Assistant & MCP AI Schema & Query Generation Generates database schemas, SQL queries, and Row Level Security policies from natural-language prompts in Studio. Custom MCP Servers Build and deploy custom MCP servers on Edge Functions with Supabase Auth as the OAuth 2.1 authorization server, so every tool call runs as the signed-in user under RLS. Headless App Block (UI Library) Installs a TanStack Start starter in which an AI agent is the primary interface, backed by an MCP server Edge Function and RLS-scoped task data. MCP Server Block (UI Library) Ships a shadcn-installable block that runs a user-scoped MCP server as a Supabase Edge Function, authenticating callers via forwarded product session tokens or OAuth 2.1 access tokens so embedded agents and external MCP clients get RLS-scoped tool access to the developer's own product. Studio AI Assistant Provides an AI assistant inside Supabase Studio that helps write SQL, RLS policies, and diagnose database and performance issues. Supabase Agent Skills Publishes packaged instructions for AI coding agents covering core Supabase usage and Postgres performance best practices, installable via the `npx skills add supabase/agent-skills` CLI. Supabase MCP Server Connects AI assistants and coding agents to a Supabase project through the Model Context Protocol, with documented setup for Cursor IDE and the Cursor CLI.
Realtime Broadcast from Database Triggers Realtime broadcast messages directly from Postgres using database functions and triggers. Broadcast Replay Replays recent broadcast messages on private channels using a since timestamp and optional limit, with messages retained for at least 72 hours. Realtime Authorization Enforces Row Level Security policies on Realtime channels to control who can send and receive messages. Realtime Broadcast Sends arbitrary low-latency messages between clients subscribed to the same channel without persisting them to the database. Realtime Connection Health Exposes a heartbeat status stream reporting whether the Realtime client's connection is healthy, acknowledged, or timed out. Realtime Postgres Changes Streams Postgres INSERT, UPDATE and DELETE events to subscribed clients with schema/table/event filters, column selection, and server-side filter operators including negation and AND composition. Realtime Presence Synchronizes shared online-state, such as who is connected or typing, across clients subscribed to a channel.
Compute, Scaling & Delivery Advanced Disk Configuration Configures high-performance disk with adjustable size, IOPS, and throughput up to 60 TB. Compute Add-ons Scales project compute from Micro to 16XL and larger instances, billed hourly with autoscaling options. Connection Pooling (Supavisor) Pools client connections through Supavisor for transaction and session pooling at scale. Dedicated IPv4 Address Assigns a project a dedicated IPv4 address as a paid add-on. Read Replicas Deploys read-only Postgres replicas across regions to isolate analytical workloads and reduce read latency for geographically distributed users.
Cron, Queues & Automation Cron Schedules recurring SQL statements, database functions, Edge Functions, or HTTP webhooks using cron syntax via the pg_cron extension. Database Webhooks Triggers HTTP requests to external services or Edge Functions when rows are inserted, updated, or deleted, using the pg_net extension. Queues Provides durable, exactly-once message queues backed by the pgmq Postgres extension for asynchronous task processing.