Skip to content
Databasezy

Data API Live

An API for your tables, without writing one

Turn on the Data API and your project serves REST (PostgREST) and GraphQL (pg_graphql) for the schemas you choose, plus SQL over HTTPS for every database in the project, whatever its engine. Requests run as the caller's role, so row-level security decides what each caller sees.

Data API, step by step

  1. Step 01

    Choose a primary database

    A Postgres or TimescaleDB instance in the project serves REST and GraphQL. Every other instance answers SQL over HTTPS.

  2. Step 02

    Pick schemas and a row limit

    Enable the Data API in the portal or with one API call, choose the exposed schemas and cap the rows a request may return.

  3. Step 03

    Call it with a project key

    A publishable key in browsers (role anon), a user's session token after sign-in, or a secret key on servers (role service_role).

  4. Step 04

    Generate types

    zb gen types writes the TypeScript Database type supabase-js uses, from the schemas you expose.

What you get

  • REST with filters and embedding

    Select, filter, order, paginate and embed related tables over HTTP, with inserts, upserts and remote procedure calls.

    Live
  • GraphQL

    pg_graphql reflects your schema into a GraphQL API at /graphql/v1, with the same roles and policies as REST.

    Live
  • SQL over HTTPS, any engine

    Send a query to /query/v1/<instance> with a secret key: Postgres, MySQL, MongoDB, ClickHouse and every other engine in the project.

    Live
  • TypeScript types

    Row, Insert and Update types for tables and views, plus functions and enums, generated from the live schema.

    Live
  • Row-level security everywhere

    Tokens are verified at the edge and again by Postgres, which applies your policies to every request.

    Live
  • Per-key rate limits

    Each project key gets a requests-per-second budget from your plan: 20 on Free, 100 on Solo, 500 on Team and 2,000 on Enterprise.

    Live

Live today and coming next

Every part of this service and where it stands. The list changes as each piece ships, and the changelog announces it.

  • REST over your tables (PostgREST) Live
  • GraphQL (pg_graphql) Live
  • SQL over HTTPS for every engine (/query/v1) Live
  • TypeScript types for supabase-js (zb gen types) Live

Live: available on the platform today. Coming soon: being built now; prices and plan limits are already published. See every service on the platform overview.

Try it

Read rows with supabase-js, or with curl and a publishable key.

supabase-js
import { createClient } from "@supabase/supabase-js";

// Your project's endpoint and publishable key, from Project settings in the portal.
const supabase = createClient("https://<ref>.us-east.databasezy.com:8443", "<publishable-key>");

const { data, error } = await supabase
  .from("todos")
  .select("id, title, done")
  .order("id");
curl
# REST, as the anon role (row-level security applies)
curl "https://<ref>.us-east.databasezy.com:8443/rest/v1/todos?select=id,title&done=eq.false" \
  -H "apikey: <publishable-key>" \
  -H "Authorization: Bearer <publishable-key>"

# SQL over HTTPS on any instance in the project (secret key, servers only)
curl -X POST "https://<ref>.us-east.databasezy.com:8443/query/v1/inst_01jb2m4n8r6xv3t8r5k6p0c2wd" \
  -H "apikey: <secret-key>" \
  -H "Authorization: Bearer <secret-key>" \
  -H "Content-Type: application/json" \
  -d '{"sql":"select count(*) from orders"}'

Plan availability

Generated from the same plan catalogue that billing and the API use.

  • Free

    $0 /mo
    Included

    5 keys per project, 20 requests per second per key

  • Solo

    $25 /mo
    Included

    20 keys per project, 100 requests per second per key

  • Team

    $599 /mo
    Included

    50 keys per project, 500 requests per second per key

  • Enterprise

    Custom
    Included

    Unlimited keys per project, 2,000 requests per second per key

There is no per-request charge. Response bytes count toward your plan's egress allowance, like any other traffic.

Compare every plan on the pricing page

Questions

Which databases serve REST and GraphQL?

The project's primary database, a Postgres or TimescaleDB instance. Every instance in the project, whatever its engine, answers SQL over HTTPS at /query/v1.

Is a publishable key safe in a browser?

Yes. It acts as the anon role, so it can only do what your row-level security policies allow, and it can never reach SQL over HTTPS. Secret keys act as service_role, bypass policies and belong on servers only.

Can I limit what the API exposes?

Choose the schemas to expose and a maximum number of rows per request. System and platform schemas such as auth and storage are never exposed.

Does a sleeping free-tier database answer?

Yes. The first request wakes it and is held until the database is ready.

Create your first database

A free instance, no card. Upgrade when you outgrow it; nothing converts silently.