Supabase (supabase.com) is an open-source backend-as-a-service (BaaS) platform that describes itself as a "Postgres development platform": every project gets a dedicated, full Postgres database, on top of which the platform auto-generates REST and GraphQL APIs and adds authentication, file storage, realtime subscriptions, edge functions, and pgvector-based vector search — a complete backend without writing server scaffolding. It rose to prominence in 2020 as "the open-source Firebase alternative"; the verifiable difference from Firebase is that the foundation is standard Postgres — your data is portable, self-hostable, and not locked into a vendor. Compared with running Postgres yourself, it packages the surrounding infrastructure as a managed service. Why it's listed: it is one of the largest and most actively maintained open-source backend projects (over 110k stars on the main GitHub repo as of 2026-09-19), it closed a 500MSeriesFata500M Series F at a10.5B valuation in June 2026, and it still ships under Apache-2.0 with a genuine self-hosting path.

At a Glance

  • URL: https://supabase.com
  • Type: Open-source backend-as-a-service (BaaS) / Postgres development platform; hosted cloud or Docker self-hosting
  • Pricing: Free tier at 0;Profrom0; Pro from25 per organization/month; Team from $599 per organization/month; Enterprise custom (as of 2026-09-19, see the official pricing page)
  • Sign-up: The hosted platform requires an account (the sign-in page offers email and SSO); self-hosted deployments need no Supabase account
  • License: The main supabase/supabase repository is Apache-2.0
  • Interface language: English only; no localized dashboard or docs observed (observation)

Background

According to press reports (Fortune), Supabase was founded in January 2020 by Paul Copplestone (CEO) and Ant Wilson (CTO), and joined Y Combinator's Summer 2020 batch (S20). In May 2020 the team changed the homepage tagline from "realtime Postgres" to "open-source Firebase alternative" and took off on Hacker News. Its funding cadence since then tracks the growth curve:

  • April 2025: 200MSeriesData200M Series D at a2B valuation (Fortune exclusive).
  • October 2025: 100MSeriesEata100M Series E at a5B pre-money valuation, led by Accel and Peak XV with Figma participating (official blog).
  • June 4, 2026: 500MSeriesFata500M Series F at a10B pre-money valuation ($10.5B post-money), led by Singapore sovereign wealth fund GIC, with a second investment from Stripe and new investors Georgian and Salesforce Ventures (official blog, CNBC).

On scale, the official company page claims more than 10 million registered developers; the GitHub API shows roughly 110k stars and 14k forks on the main repo with very active commits (as of 2026-09-19). The Series F announcement also disclosed that database launches on the platform grew 600% over the past year and that more than 60% of new databases are now created by AI coding tools. The company is fully remote, with employees in more than 50 countries.

Below is the homepage (2026-09-19): the tagline "Build in a weekend, scale to millions" sits above cards for the six core modules — Postgres database, authentication, edge functions, storage, realtime, and vector:

The Supabase homepage: the tagline "Build in a weekend, scale to millions" with cards for Postgres Database, Authentication, Edge Functions, Storage, Realtime, and Vector

Core Capabilities

Postgres database and auto-generated APIs. Each project is a dedicated, full Postgres instance with extensions, backups, and connection pooling; the official line is "100% portable, no vendor lock-in." Once you create tables, the platform derives a REST API via PostgREST and GraphQL queries via pg_graphql, and generates typed client SDKs (JavaScript/TypeScript, Dart/Flutter, Python, Swift, Kotlin, and more). The screenshot below shows the table editor on the official database product page:

Supabase's database product page: the tagline "Postgres without the hassle" above the Studio table editor with sample rows

Auth. Built-in email/password, magic links/OTP, social OAuth, and mobile logins; basic MFA, leaked-password protection (paid tiers), custom OAuth/OIDC providers, and SAML 2.0 single sign-on (from the Pro tier, 50 MAUs included, then metered).

Storage. Object storage for large files, integrated with Postgres Row Level Security (RLS) policies; paid tiers add image transformations and a Smart CDN.

Realtime. WebSocket-based Postgres change subscriptions, channel broadcast, and presence; the free tier includes 200 concurrent connections and 2 million messages per month.

Edge Functions. Server-side functions on the Deno runtime, deployed globally for custom server logic; the free tier includes 500,000 invocations per month.

Vector and AI tooling. Store and query embeddings with pgvector; semantic, keyword, and hybrid search; integrations with OpenAI, Hugging Face, LangChain, and others (official AI docs).

Dashboard and developer workflow. The Supabase Studio web console offers table editing, a SQL editor, and logs; the CLI spins up a full local development stack; paid tiers support database branching (billed per branch-hour); since August 2026, Pipelines — a managed CDC service streaming Postgres changes to BigQuery — is in public alpha, and a one-click Grafana Cloud integration is available on every plan including Free (August 2026 developer update).

Open source and self-hosting. The main repository is Apache-2.0, and the official Docker self-hosting guide documents a single-project deployment that collects no telemetry — but it lacks managed-platform features such as branching, point-in-time recovery, advanced metrics, ETL, and the platform management API; operations and high availability are entirely your responsibility, with community support only. The company is also advancing two lower-level open-source projects: Multigres (Postgres high availability and horizontal scaling; v0.1 alpha released June 2026, explicitly not production-ready) and OrioleDB (targeting production readiness within 2026, per the same announcement).

Pricing and Accounts

Below is the official pricing page as of 2026-09-19:

Supabase's pricing page: Free at <span class="katex"><span class="katex-mathml"><math xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mn>0</mn><mo separator="true">,</mo><mi>P</mi><mi>r</mi><mi>o</mi><mi>f</mi><mi>r</mi><mi>o</mi><mi>m</mi></mrow><annotation encoding="application/x-tex">0, Pro from</annotation></semantics></math></span><span class="katex-html" aria-hidden="true"><span class="katex-base"><span class="katex-strut" style="height:0.8889em;vertical-align:-0.1944em;"></span><span class="mord">0</span><span class="mpunct">,</span><span class="mspace" style="margin-right:0.1667em;"></span><span class="mord mathnormal" style="margin-right:0.1389em;">P</span><span class="mord mathnormal" style="margin-right:0.0278em;">r</span><span class="mord mathnormal">o</span><span class="mord mathnormal" style="margin-right:0.1076em;">f</span><span class="mord mathnormal" style="margin-right:0.0278em;">r</span><span class="mord mathnormal">o</span><span class="mord mathnormal">m</span></span></span></span>25/month, Team from $599/month, Enterprise custom

Key points of the four plans (official pricing page, as of 2026-09-19):

  • Free ($0): 500 MB database (shared CPU + 500 MB RAM), 50,000 monthly active users (MAUs), 5 GB egress, 1 GB file storage, 500,000 edge function invocations per month; projects are paused after one week of inactivity; community support only.
  • Pro (from 25perorganization/month,firstprojectincluded;additionalprojectsfrom25 per organization/month, first project included; additional projects from10/month): 8 GB disk (then 0.125/GB),100,000MAUs(then0.125/GB), 100,000 MAUs (then0.00325/MAU), 250 GB egress (then $0.09/GB), 100 GB file storage, 7-day automatic backups, email support.
  • Team (from $599 per organization/month): 28-day log retention (7 days on Pro), 14-day daily backups, platform audit logs, dashboard SSO, read-only and project-scoped roles, SOC 2 and ISO 27001 compliance artifacts, HIPAA as a paid add-on.
  • Enterprise (custom): uptime SLAs, AWS PrivateLink, 24×7 support, custom security questionnaires, and more.

Note that billing combines an organization subscription with many metered items: point-in-time recovery costs 100/monthper7daysofretention,branchingisbilledat100/month per 7 days of retention, branching is billed at0.01344 per branch-hour, log drains start at $60/month, and storage, egress, MAUs, and function invocations are all metered beyond included quotas. For accounts, the hosted platform requires registration (the sign-in page offers email and SSO). In May 2026 the company announced ISO/IEC 27001:2022 certification for the platform (May 2026 developer update); SOC 2 reports are available on Team and above.

Who It's For

  • Indie developers and small teams who want to skip backend scaffolding and get "database + API + auth" immediately: create a table and you have REST/GraphQL APIs and typed SDKs; the free tier is enough for prototyping.
  • Applications that need full Postgres capabilities (SQL, extensions, transactions) rather than a proprietary data model: data can be exported and migrated, avoiding lock-in.
  • AI apps and semantic search: pgvector puts vector retrieval inside your operational database, so you don't maintain a separate vector store; the company's disclosure that over half of new databases are created by AI coding tools shows it has become a common default backend in AI-assisted workflows.
  • Realtime collaborative apps: chat, presence, and live dashboards can subscribe directly to database changes via Realtime.
  • Teams with data-sovereignty or compliance requirements: evaluate Docker self-hosting or the Enterprise plan (SLAs, PrivateLink, HIPAA).

Limitations

  • The free tier is tight and pauses: 500 MB database, 1 GB storage, and 5 GB egress are quickly exhausted by anything beyond small projects; projects are paused after one week of inactivity and need manual restoration, so it's a poor fit for unattended demo deployments.
  • Many metered dimensions, weak bill predictability: egress, MAUs, storage, function invocations, PITR, branching, log drains, and more stack up; a traffic spike can push the bill well past expectations, and most overage meters are only visible once you're on a paid plan.
  • Self-hosting is a reduced edition with full operational responsibility: it lacks PITR, branching, the platform management API, and other managed features (official self-hosting docs); high availability, backups, and hardening are all on you, with community support only — a noticeable gap from the managed cloud experience.
  • Security configuration is the user's responsibility: auto-generated APIs must be paired with correct Row Level Security policies, and misconfiguration directly exposes data; only since May 2026 has "new tables are not exposed to the Data API by default" been the default for new projects (official notice), so older projects still need auditing.
  • English-only interface: the dashboard, docs, and emails are English-only, with no official localization observed (observation).
  • Some foundations are still maturing: Multigres, which carries the horizontal-scaling vision, only shipped v0.1 alpha in June 2026 and is explicitly "not production-ready"; very large Postgres workloads still need hand-rolled sharding or patience.

Alternatives

  • Firebase: Google's app development platform and Supabase's original reference point; NoSQL data model, closed-source hosted service, a more mature ecosystem but weaker data portability.
  • Neon: a serverless Postgres provider focused on scale-to-zero compute and branching; database only, without the BaaS modules like auth and storage.
  • Appwrite: another open-source BaaS with database, auth, storage, and functions; not tied to Postgres, with a smaller community than Supabase.

References