Data API Live
An API for your tables, without writing one
Turn on the Data API and your project serves REST (PostgREST) and GraphQL (pg_graphql) for the schemas you choose, plus SQL over HTTPS for every database in the project, whatever its engine. Requests run as the caller's role, so row-level security decides what each caller sees.
How it works
Data API, step by step
- Step 01
Choose a primary database
A Postgres or TimescaleDB instance in the project serves REST and GraphQL. Every other instance answers SQL over HTTPS.
- Step 02
Pick schemas and a row limit
Enable the Data API in the portal or with one API call, choose the exposed schemas and cap the rows a request may return.
- Step 03
Call it with a project key
A publishable key in browsers (role anon), a user's session token after sign-in, or a secret key on servers (role service_role).
- Step 04
Generate types
zb gen types writes the TypeScript Database type supabase-js uses, from the schemas you expose.
What you get
-
REST with filters and embedding
Select, filter, order, paginate and embed related tables over HTTP, with inserts, upserts and remote procedure calls.
Live -
GraphQL
pg_graphql reflects your schema into a GraphQL API at /graphql/v1, with the same roles and policies as REST.
Live -
SQL over HTTPS, any engine
Send a query to /query/v1/<instance> with a secret key: Postgres, MySQL, MongoDB, ClickHouse and every other engine in the project.
Live -
TypeScript types
Row, Insert and Update types for tables and views, plus functions and enums, generated from the live schema.
Live -
Row-level security everywhere
Tokens are verified at the edge and again by Postgres, which applies your policies to every request.
Live -
Per-key rate limits
Each project key gets a requests-per-second budget from your plan: 20 on Free, 100 on Solo, 500 on Team and 2,000 on Enterprise.
Live
Live today and coming next
Every part of this service and where it stands. The list changes as each piece ships, and the changelog announces it.
- REST over your tables (PostgREST) Live
- GraphQL (pg_graphql) Live
- SQL over HTTPS for every engine (/query/v1) Live
- TypeScript types for supabase-js (zb gen types) Live
Live: available on the platform today. Coming soon: being built now; prices and plan limits are already published. See every service on the platform overview.
Try it
Read rows with supabase-js, or with curl and a publishable key.
import { createClient } from "@supabase/supabase-js";
// Your project's endpoint and publishable key, from Project settings in the portal.
const supabase = createClient("https://<ref>.us-east.databasezy.com:8443", "<publishable-key>");
const { data, error } = await supabase
.from("todos")
.select("id, title, done")
.order("id");# REST, as the anon role (row-level security applies)
curl "https://<ref>.us-east.databasezy.com:8443/rest/v1/todos?select=id,title&done=eq.false" \
-H "apikey: <publishable-key>" \
-H "Authorization: Bearer <publishable-key>"
# SQL over HTTPS on any instance in the project (secret key, servers only)
curl -X POST "https://<ref>.us-east.databasezy.com:8443/query/v1/inst_01jb2m4n8r6xv3t8r5k6p0c2wd" \
-H "apikey: <secret-key>" \
-H "Authorization: Bearer <secret-key>" \
-H "Content-Type: application/json" \
-d '{"sql":"select count(*) from orders"}'Plan availability
Generated from the same plan catalogue that billing and the API use.
- Included
Free
$0 /mo5 keys per project, 20 requests per second per key
- Included
Solo
$25 /mo20 keys per project, 100 requests per second per key
- Included
Team
$599 /mo50 keys per project, 500 requests per second per key
- Included
Enterprise
CustomUnlimited keys per project, 2,000 requests per second per key
There is no per-request charge. Response bytes count toward your plan's egress allowance, like any other traffic.
Questions
Which databases serve REST and GraphQL?
The project's primary database, a Postgres or TimescaleDB instance. Every instance in the project, whatever its engine, answers SQL over HTTPS at /query/v1.
Is a publishable key safe in a browser?
Yes. It acts as the anon role, so it can only do what your row-level security policies allow, and it can never reach SQL over HTTPS. Secret keys act as service_role, bypass policies and belong on servers only.
Can I limit what the API exposes?
Choose the schemas to expose and a maximum number of rows per request. System and platform schemas such as auth and storage are never exposed.
Does a sleeping free-tier database answer?
Yes. The first request wakes it and is held until the database is ready.
Related features
- Live
Auth
Sign-up, sign-in and sessions for your app's users, stored in your own Postgres.
Learn more about Auth - Live
Database tools
Extensions, cron and queues for your Postgres from the portal, with vector search, vault and wrappers next.
Learn more about Database tools -
API and MCP
A REST API with an OpenAPI 3.1 document, signed webhooks, an MCP server for AI assistants and llms.txt.
Learn more about API and MCP
Start today
Create your first database
A free instance, no card. Upgrade when you outgrow it; nothing converts silently.