Blog

Insights

What Is Supabase? Features & Pricing (2026)

What is Supabase? An open-source backend built on Postgres with auth, storage, and realtime. See how it compares to Firebase and what it costs in 2026.

Writer

Nafis Amiri

Co-Founder of CatDoes

Minimalist presentation slide with the text ‘What Is Supabase: A Developer’s Guide to the Open Source Backend’ centered on a white background, with ‘Supabase’ in bold and a subtle grid floor perspective at the bottom.

Supabase is an open-source backend platform built on PostgreSQL. It gives you a database, user logins, file storage, auto-generated APIs, and serverless functions from a single dashboard. You get a real backend without running servers yourself.

The project looks very different than it did a year ago. In June 2026 Supabase raised $500 million and said that nearly 10 million developers now build on it. More than 60% of new databases on the platform are created by an AI tool rather than a person typing in a dashboard.

This guide explains what Supabase does, what it costs in 2026, how it compares to Firebase, and when it is the right choice for your project.

Table of Contents

  • Key Takeaways

  • What Is Supabase?

  • Is Supabase a Database or a Backend?

  • The Core Supabase Features

  • Supabase as AI and Agent Infrastructure

  • Supabase vs. Firebase: A Head-to-Head Comparison

  • Supabase Pricing in 2026

  • When to Choose Supabase for Your Project

  • Getting Started with Your First Supabase Project

  • Supabase Pros and Cons

  • Frequently Asked Questions About Supabase

Key Takeaways

  • Supabase is a Backend-as-a-Service built on Postgres, an open-source relational SQL database.

  • The core services are Database, Auth, Storage, Edge Functions, and Realtime. Newer additions include Cron, Queues, Branching, and an MCP server for AI agents.

  • The free plan covers 2 active projects, a 500 MB database, 1 GB of file storage, and 50,000 monthly active users. Free projects pause after one week of inactivity.

  • Paid plans start at $25 per month for Pro and $599 per month for Team.

  • The main difference from Firebase is SQL instead of a document store, plus the option to self-host the whole stack.

  • Supabase raised a $500 million Series F in June 2026 at a $10 billion pre-money valuation, led by GIC.

What Is Supabase?

Supabase is a hosted backend that bundles a Postgres database with the services most apps need around it. You create a project, and within a couple of minutes you have a database, a REST API, a realtime socket, an auth system, and a file store that all talk to each other.

It is often called an open-source Firebase alternative. That is a fair shorthand, but it undersells the difference. Firebase is built on a NoSQL document store. Supabase is built on Postgres, which means you get tables, joins, constraints, and plain SQL.

Every Supabase project is a real Postgres database. You can connect to it with any standard Postgres client, run your own migrations, and take the data with you if you leave.

Supabase homepage in 2026 showing the open-source Postgres backend platform.

Who Supabase Is For

Supabase fits solo developers and small teams who want to ship an app without hiring a backend engineer. It also fits larger teams who like Postgres and want managed infrastructure around it.

It is a weaker fit if your app needs heavy custom server logic, long-running jobs, or a data model that does not suit a relational database.

How Supabase Grew

Supabase started in 2020 as a small open-source project. By June 2026 it had raised a $500 million Series F led by GIC at a $10 billion pre-money valuation. In its funding announcement, the company said database launches had grown 600% over the prior year.

Is Supabase a Database or a Backend?

Both, and the distinction matters when you are picking tools. At the center is a Postgres database. Around it sit the services that turn that database into a working backend.

Supabase reads your database schema and generates a REST API for it automatically. Add a table, and the endpoints to read and write it exist straight away. There is no controller or route file to maintain.

Security is handled in the database itself through Row Level Security. You write policies as SQL rules, and they apply no matter how the data is accessed. A rule that says a user can only read their own orders holds for the REST API, the realtime stream, and a direct SQL connection alike.

This is the standard shape of a Backend-as-a-Service: the vendor runs the servers, and you work at the level of data and rules instead of processes and deploys.

The Core Supabase Features

Supabase ships as a set of services that share one project, one auth system, and one set of permissions. Here is what each one does.

Diagram showing Supabase as a central platform connecting to database, authentication, and storage services.

The Postgres Database

Each project runs a dedicated Postgres instance. You get SQL, joins, foreign keys, triggers, views, and functions. Extensions are available too, including pgvector for storing embeddings and PostGIS for location data.

Supabase Studio gives you a spreadsheet-style table editor and a SQL editor in the browser. You can also connect with psql, Prisma, Drizzle, or any other Postgres tool.

Authentication

Auth handles sign-up, login, and sessions. It supports email and password, magic links, phone one-time codes, and social logins through providers such as Google, GitHub, and Apple. Single sign-on through SAML is available on higher plans.

Users live in a table inside your own database, so you can join user records against your application data directly in SQL.

Storage

Storage holds files such as images, video, and documents. It uses the same permission system as the database, so you write access rules in SQL rather than in a separate console.

A rule like "only the user who uploaded this file may delete it" is written once and enforced everywhere.

Edge Functions and Realtime

Edge Functions run TypeScript on demand, close to your users. They now support regional invocation, so you can pin a function to the region where your database lives and cut round-trip time. They also support persistent storage for temporary files.

Realtime pushes database changes to connected clients over websockets. It powers live dashboards, chat, presence indicators, and collaborative editing.

What Shipped After the Core Five

The five services above are the classic Supabase stack, but the platform has grown well past them. Several of these are worth knowing about before you assume something is missing.

Service

What it does

Cron

Runs scheduled jobs directly in Postgres, with no external scheduler.

Queues

A durable message queue for background work.

Branching

Spins up a throwaway copy of your database per Git branch for testing.

Read Replicas

Adds read-only copies of your database in other regions.

Vector Buckets

Stores and searches embeddings for semantic search and RAG.

Automatic Embeddings

Generates and refreshes embeddings as your rows change.

Analytics Buckets

Columnar storage in Apache Iceberg format for analytics workloads.

Foreign Data Wrappers

Queries outside sources such as Stripe or BigQuery as if they were tables.

Supavisor

A connection pooler that keeps serverless clients from exhausting connections.

MCP Server

Lets AI coding agents inspect and change a project directly.

Supabase features page listing the full product set including Cron, Queues, and Branching.

Supabase as AI and Agent Infrastructure

This is the biggest change to Supabase since 2025, and most guides still leave it out. Supabase is no longer used mainly by people clicking through a dashboard. It is used by AI agents building apps on someone's behalf.

In its funding announcement, Supabase said more than 60% of new databases on the platform are launched by some kind of AI tool. The company pointed to Claude Code and Codex as drivers of that growth since January 2026.

Isometric illustration of an AI agent automatically provisioning a cloud database with auth and storage.

The Supabase MCP Server

The Model Context Protocol server is the piece that makes this work. It gives an AI assistant a set of tools for working with a Supabase project: list tables, run a migration, query data, read logs, generate types, deploy an Edge Function.

Instead of pasting connection strings and schema dumps into a chat window, the agent queries the project directly. You can connect the MCP server to Claude, Cursor, VS Code, and other clients.

If you give an agent write access, scope it carefully. Read-only mode and project scoping exist for a reason, and a development project is a safer target than production.

Supabase MCP server documentation showing how AI agents connect to a project.

Building AI Features on Supabase

Supabase is also a place to build AI features, not just a thing AI builds on. The pgvector extension turns your database into a vector store, so you can run semantic search next to your normal tables in one query.

Automatic Embeddings keeps those vectors current as rows change, which removes the usual background job for re-indexing content. There is also an AI Assistant inside Studio that writes SQL, explains errors, and suggests policies.

If you are building with AI tools rather than by hand, it helps to understand the role backend services play in AI and no-code apps before you pick one.

Supabase vs. Firebase: A Head-to-Head Comparison

Firebase is the tool people compare Supabase against most often. They solve the same problem, but the foundations are different, and that difference shapes everything else.

Side-by-side view of two tablets displaying a comparison of Supabase versus Firebase.


Supabase

Firebase

Database

PostgreSQL (relational, SQL)

Firestore (NoSQL document store)

Queries

Full SQL with joins and aggregates

Document lookups; joins done in app code

Source

Open source, Apache 2.0

Closed source, Google-owned

Self-hosting

Yes, full stack via Docker

No

Permissions

Row Level Security in SQL

Firebase Security Rules

Pricing model

Flat plan plus usage

Pay per read, write, and delete

Vector search

Built in via pgvector

Through an extension or an outside service

Mobile SDKs

Good, but younger

Very mature, deep Google integration

Why the Database Choice Matters

With Firestore, a report that spans users, orders, and products means several reads and some code to stitch them together. With Postgres it is one query with joins.

The billing model differs in the same way. Firestore charges per document operation, so a screen that reads a lot of small documents can get expensive in a way that is hard to predict. Supabase charges for storage, bandwidth, and compute, which is easier to model ahead of time.

Where Firebase Still Wins

Firebase has been around longer and its mobile SDKs show it. Crashlytics, Cloud Messaging, Remote Config, and A/B testing are mature and tightly linked. If you are building a mobile-first app and want that toolkit, Firebase is still a reasonable pick.

Supabase Pricing in 2026

Supabase pricing has two parts: a plan fee, and usage above what the plan includes. Here is what each tier covers as of September 2026.

Supabase pricing page showing the Free, Pro, Team, and Enterprise plans.


Free

Pro

Team

Enterprise

Price

$0

From $25/mo

From $599/mo

Custom

Database size

500 MB

8 GB, then $0.125/GB

8 GB, then $0.125/GB

Custom

File storage

1 GB

100 GB, then $0.0213/GB

100 GB, then $0.0213/GB

Custom

Egress

5 GB

250 GB, then $0.09/GB

250 GB, then $0.09/GB

Custom

Monthly active users

50,000

100,000, then $0.00325 each

100,000, then $0.00325 each

Custom

Edge Function calls

500,000

2M, then $2 per million

2M, then $2 per million

Custom

Realtime connections

200 peak

500, then $10 per 1,000

500, then $10 per 1,000

Custom

Projects

2 active

Unlimited, from $10/mo each

Unlimited, from $10/mo each

Custom

Backups

None

Daily, kept 7 days

Daily, kept 14 days

Custom retention

Log retention

1 day

7 days

28 days

90 days

Compliance

None

None

SOC 2, ISO 27001, HIPAA add-on

Plus SLAs and PrivateLink

The Free Plan Limits That Actually Bite

The free plan is genuinely useful, but two limits catch people out. You can only have two active projects at once. And a free project pauses after one week with no activity, so a side project you check on monthly will be asleep when you return. You can restore it from the dashboard.

The free plan also has no backups, runs on shared compute with 500 MB of RAM, and keeps logs for one day. That is fine for prototypes and demos. It is not fine for anything with real users.

What Pro Actually Costs

Pro starts at $25 per month and includes $10 in compute credits, which covers one Micro instance. Each extra project adds compute cost on top, starting at $10 per month. A single production app on a small instance typically lands near the base price. Bandwidth is the line item most likely to surprise you if you serve large media files.

The Team plan at $599 per month has the same technical limits as Pro. You pay for SOC 2 and ISO 27001 reports, single sign-on, longer backups, and a HIPAA add-on. Check the official pricing page before you budget, since usage rates change.

When to Choose Supabase for Your Project

Supabase is a strong default for most apps that need a database and user accounts. It is a particularly good match in a few cases.

  • Apps with related data. Anything with users, teams, projects, orders, or permissions benefits from real joins and foreign keys.

  • Realtime products. Chat, live dashboards, collaborative editors, and multiplayer features work without extra infrastructure.

  • SaaS with tenants. Row Level Security maps cleanly onto keeping one customer's data away from another's.

  • AI apps. pgvector means your embeddings live next to your application data instead of in a separate service.

  • Teams that already know SQL. There is no new query language to learn.

When to Look Elsewhere

Supabase is not the answer to everything. If your workload is mostly long-running background processing, Edge Functions will feel constraining. If you need a schema that changes shape constantly, a document store may suit you better.

And if you need very specific database tuning, extensions outside the supported set, or deployment in a region Supabase does not serve, running your own Postgres is still an option worth pricing out.

Getting Started with Your First Supabase Project

Setting up a project takes a few minutes. Here is the path from nothing to a working backend.

A person typing on a laptop, creating a new project in Supabase Studio for quick setup.
  1. Sign up and create a project. Pick a region close to your users and save the database password somewhere safe.

  2. Create your first table in the Studio table editor, or write the SQL yourself in the SQL editor.

  3. Turn on Row Level Security for the table and add a policy. Supabase blocks access by default until you do.

  4. Copy your project URL and publishable API key from the project settings.

  5. Install the client library for your framework and make your first query.

A Note on the New API Keys

Supabase has moved to a new key format. You will see keys that start with sb_publishable_ for client-side use and sb_secret_ for server-side use. These replace the older anon and service_role keys.

The rule has not changed: publishable keys can ship in your frontend, secret keys never can. A secret key bypasses Row Level Security entirely.

Designing the Schema

The part that takes real thought is the data model, not the setup. Getting tables and relationships right early saves painful migrations later. If you are new to this, our guide on how to create a database from idea to live app walks through the process.

Supabase Pros and Cons

What Works Well

  • Real Postgres. Decades of tooling, documentation, and hiring pool come with it.

  • No lock-in. The stack is open source, so you can export your data or move to your own servers.

  • Fast setup. A usable backend in minutes, with APIs generated from your schema.

  • Predictable bills. Charges track storage, bandwidth, and compute rather than individual reads.

  • One permission model. Row Level Security covers the API, realtime, and direct SQL at once.

What to Watch

  • You need some SQL. Basic queries are easy, but Row Level Security policies take real understanding.

  • Edge Functions have limits. They are not built for long jobs or heavy computation.

  • Mobile SDKs are younger than Firebase's, with a smaller pool of examples to copy.

  • Self-hosting is work. The option exists, but running it means managing upgrades, backups, and scaling yourself.

If the last point interests you, we have a walkthrough on setting up a self-hosted Supabase instance.

Most teams should start on the hosted version. Self-host later if compliance or cost makes it worth the operational load.

Skipping the Setup Entirely

Picking a backend, wiring up auth, and writing security policies is real work before you have shipped anything. If you would rather describe the app you want and have the database, auth, and storage configured for you, that is what CatDoes does. It builds and deploys the app, and the backend comes with it.

Frequently Asked Questions About Supabase

Short answers to the questions that come up most often about Supabase.

Is Supabase completely free to use?

Supabase has a free plan that does not expire, but it is not unlimited. It covers two active projects, a 500 MB database, 1 GB of file storage, 5 GB of egress, and 50,000 monthly active users. Free projects pause after one week of inactivity. The code is also open source, so self-hosting is free apart from your own server costs.

Is Supabase SQL or NoSQL?

Supabase is SQL. It runs PostgreSQL, a relational database with tables, columns, and foreign keys. You can still store unstructured data in JSONB columns when you need flexibility, which covers most cases people reach for NoSQL to solve.

Is Supabase a BaaS?

Yes. Supabase is a Backend-as-a-Service. It provides a hosted database, authentication, storage, serverless functions, and auto-generated APIs, so you do not have to build or run a backend server yourself.

Does Supabase use Postgres?

Yes. Every Supabase project is a dedicated PostgreSQL database. You can connect to it with any standard Postgres client or ORM, and you can export the data at any time.

Do I need to know SQL to use Supabase?

Not to start. The Studio table editor works like a spreadsheet, and the client libraries let you read and write data in JavaScript, Python, or Dart. You will want basic SQL once you write Row Level Security policies, since those are SQL expressions.

How secure is Supabase?

Security rests on Postgres Row Level Security, which enforces access rules in the database rather than in application code. Supabase holds SOC 2 Type II and ISO 27001 certifications, with HIPAA available as a paid add-on on the Team plan. The most common real-world mistake is leaving Row Level Security off on a table, or exposing a secret key in frontend code.

What are the main alternatives to Supabase?

Firebase is the closest direct comparison. Other options include Appwrite, which is also open source, Neon and PlanetScale for managed Postgres and MySQL without the extra services, and AWS Amplify for teams already inside the AWS ecosystem. Running your own Postgres with a framework like Django or Rails is still viable too.

Can you self-host Supabase?

Yes. The whole stack is open source under the Apache 2.0 license and ships as Docker containers. Self-hosting removes vendor dependence and can cut costs at scale, but you take on upgrades, backups, monitoring, and scaling yourself.

Writer

Nafis Amiri

Co-Founder of CatDoes