Platform
Everything your app needs around its database
Every project gets one HTTPS endpoint for auth, data APIs, storage, functions and realtime, authenticated with project keys and compatible with the Supabase client libraries. Your users and files stay in your own Postgres, in your region.
import { createClient } from "@supabase/supabase-js";
// Your project's endpoint and publishable key (Project settings in the portal).
const supabase = createClient("https://<ref>.us-east.databasezy.com:8443", "<publishable-key>");
// Sign a user up, then read the rows your policies allow.
await supabase.auth.signUp({ email: "[email protected]", password: "a-long-password" });
const { data: todos } = await supabase.from("todos").select("id, title, done");# The same endpoint answers plain HTTP
curl "https://<ref>.us-east.databasezy.com:8443/rest/v1/todos?select=id,title" \
-H "apikey: <publishable-key>" \
-H "Authorization: Bearer <publishable-key>"Services
Each service shows where it stands today. Coming soon means it is being built now, with prices and plan limits already published.
-
Project endpoint and keys
LiveOne HTTPS endpoint per project, publishable and secret keys, and per-project signing keys with a public JWKS.
Read the docs about Project endpoint and keys (documentation site) -
Auth
LiveSign-up, sign-in and sessions for your app's users, stored in your own Postgres so row-level security can use them.
/auth/v1Learn more about Auth -
Data API
LiveREST and GraphQL over your Postgres tables, plus SQL over HTTPS for every engine in the project.
/rest/v1Learn more about Data API -
Storage
Coming soonBuckets for files and images with signed URLs, resumable uploads, an S3-compatible endpoint and image transforms.
/storage/v1Learn more about Storage -
Functions
Coming soonTypeScript functions at the project endpoint, triggered by HTTP, cron, queues or database changes.
/functions/v1Learn more about Functions -
Realtime
Coming soonBroadcast, presence and Postgres changes over WebSockets, filtered by row-level security.
/realtime/v1Learn more about Realtime -
Apps and jobs
Coming soonAlways-on containers next to your databases, with releases, rollback, scale to zero and cron jobs.
Learn more about Apps and jobs -
Sandboxes
Coming soonShort-lived isolated runtimes for untrusted code such as AI agents, billed per second.
Learn more about Sandboxes -
Database tools
LiveExtensions, cron, queues, vector search, vault and foreign data wrappers for your Postgres, managed from the portal and API.
Learn more about Database tools -
Agent servers
LiveCloud development machines for you and your coding agents, with SSH, a web terminal and hourly billing that stops when they stop.
Learn more about Agent servers
Status of every capability
The same list drives these pages, the docs and the pricing page. When something ships, it moves to Live here and in the changelog.
Project endpoint and keys Live
- One HTTPS endpoint per project Live
- Publishable and secret project keys Live
- Per-project ES256 signing keys, JWKS and rotation Live
Auth Live
- Email and password sign-up and sign-in Live
- Magic links and email one-time codes Live
- Sessions with refresh-token rotation and reuse detection Live
- CAPTCHA with hCaptcha or Cloudflare Turnstile Live
- Password rules and leaked-password protection Live
- Rate limits and brute-force protection Live
- OAuth and social sign-in providers Coming soon
- Multi-factor authentication Coming soon
- SAML 2.0 single sign-on for your users Coming soon
- Third-party auth (Clerk, Auth0, Firebase, Cognito, WorkOS) Coming soon
- Anonymous sign-in and phone codes Coming soon
- User management in the portal Coming soon
- Import users from Supabase with their password hashes and ids Coming soon
- Server-side auth helpers (@supabase/ssr cookies, PKCE) Coming soon
- OAuth 2.1 / OpenID Connect provider: sign in with your app, MCP clients Coming soon
Data API Live
- REST over your tables (PostgREST) Live
- GraphQL (pg_graphql) Live
- SQL over HTTPS for every engine (/query/v1) Live
- TypeScript types for supabase-js (zb gen types) Live
Storage Coming soon
- Buckets with row-level security and signed URLs Coming soon
- Resumable and multipart uploads Coming soon
- S3-compatible endpoint Coming soon
- Image transformations Coming soon
Functions Coming soon
- TypeScript functions over HTTP, with secrets and logs Coming soon
- Cron, queue and database-change triggers Coming soon
Realtime Coming soon
- Broadcast Coming soon
- Presence Coming soon
- Postgres changes filtered by row-level security Coming soon
Apps and jobs Coming soon
- Always-on apps from your container image Coming soon
- One-off and cron jobs Coming soon
Sandboxes Coming soon
- Ephemeral sandboxes for untrusted code Coming soon
Database tools Live
- Extensions manager Live
- Cron (pg_cron) Live
- Queues (pgmq) Live
- Vector search and automatic embeddings Coming soon
- Vault: encrypted secrets in your database Coming soon
- Foreign data wrappers Coming soon
- Table editor Coming soon
- Row-level security policy and roles editor Coming soon
- Security and performance advisors Coming soon
Agent servers Live
- A Kata VM per server, with Docker inside Live
- SSH through the bastion with your registered keys (VS Code, Cursor, Zed) Live
- Web terminal in the portal Live
- Stopping a server stops compute billing Live
- Coding agents and toolchains preinstalled Live
- Daily snapshots, restore and export Coming soon
- GitHub repositories cloned under ~/dev Coming soon
- Attach to a project to reach its databases privately Coming soon
- Secure placement on a HIPAA cell Coming soon
Live: available today. Beta: usable, may still change, no SLA yet. Coming soon: being built now.
How the platform is built
-
Your data stays in your database
Users, file metadata and policies live in your project's Postgres, in your region, under your backups. The control plane keeps settings and secret references only.
-
One endpoint, one set of keys
Every service answers under the project endpoint. A publishable key is safe in browsers; secret keys stay on servers; sessions are JWTs signed with your project's own key.
-
Policies enforced by Postgres
Row-level security decides what each caller sees in the Data API today, and in storage and realtime as they ship. Policies are never re-implemented in application code.
-
Metered like everything else
Each plan includes allowances; above them you pay published prices, inside the same spend cap, budgets and invoices as your databases.
Pricing, agent servers and comparisons
-
Platform pricing
Free includes 10,000 monthly active users and small allowances for every service; above them auth is $0.003 per MAU.
See prices and allowances -
Agent servers
LiveCloud machines for you and your coding agents, from $12 a month, billed by the hour and nothing for compute while stopped. On Solo, Team and Enterprise.
Learn more about agent servers -
Compared with Supabase and Layerbase
What we match, where we go further and where another option may fit you better, side by side.
See the comparison
Start today
Start a project
A free Postgres instance with Auth and the Data API on its endpoint, no card. Upgrade when you need more.