Skip to content
Review · PostgreSQL in the cloud

Supabase Review 2026: Postgres, Auth, Pricing & Limits

Supabase is a backend platform built around a full PostgreSQL database per project, with Auth, Storage, Realtime, Edge Functions and an auto-generated API on top. This review covers what the documentation says about each piece, the free tier and its pausing rules, how the bill is built, and where the limits are.

Facts checked 8 October 2026 against the providers' official documentation and pricing pages. Next review due January 2027. Cloud services, regions and prices change often; confirm on the provider's site before you buy.
Short answer
  • Every Supabase project is a dedicated, full PostgreSQL instance, not a Postgres-like abstraction, so SQL, extensions and standard tools work.
  • Around the database you get Auth (users stored in your Postgres), Row Level Security, file Storage, Realtime, Edge Functions and a REST API generated from your schema.
  • The free tier allows 2 active projects with a 500 MB database each, and free projects pause after a week of inactivity.
  • Paid plans charge a monthly organisation fee plus always-on compute per project, billed hourly; point-in-time recovery is an extra add-on.
  • It is open source (Apache-2.0) and can be self-hosted with Docker, which gives an exit route that most hosted backends lack.
How we know: Research-based: features, plan limits and prices were checked against the Supabase documentation, the Supabase pricing page and the Supabase GitHub repository on 8 October 2026. We have not run Supabase projects for this review, so no performance or latency claims are made.

What Supabase is

Supabase describes each project as a full Postgres database, not a Postgres abstraction, and its compute documentation states that every project on the platform comes with its own dedicated Postgres instance. That database is the foundation for everything else Supabase sells: authentication, file storage, realtime messaging, serverless functions and APIs. If you only want a hosted PostgreSQL database, Supabase can be used that way too; you connect with any Postgres client or ORM and ignore the rest.

The difference from a plain managed database such as RDS is that the backend pieces are integrated with the database. Auth stores its users in your Postgres database, and the REST API respects Row Level Security policies tied to the signed-in user, so many apps can read and write data from the browser without writing a server.

The platform: Postgres, Auth, Storage and Realtime

Postgres database and APIs

Supabase provides a RESTful API using PostgREST, generated automatically from your database schema. Extensions such as pgvector (for embeddings and similarity search) can be enabled per project. Read Replicas are additional databases kept in sync with the primary, optionally in other regions. Each project is deployed to one primary region, which also decides where its data is stored.

Auth and Row Level Security

Supabase Auth supports passwords, magic links, one-time passwords, social login with providers such as Google, GitHub and Apple, and SAML single sign-on on higher plans. It issues JSON Web Tokens, and because user data lives in a special schema in your own database, you can join it to your tables and write Row Level Security policies that restrict each user to their own rows.

Storage, Realtime and Edge Functions

Storage handles files with access rules that can reuse the same policies. Realtime offers Broadcast (low-latency messages between clients), Presence and Postgres Changes, which streams database changes to subscribed clients. Edge Functions are server-side TypeScript functions for webhooks and third-party integrations. Branching creates preview environments from Git, but new branches start without production data unless you seed them or choose to include data.

Supabase free tier limits and pausing

The free plan is enough for a prototype, a learning project or a hackathon, but its two rules matter. Only 2 projects can be active at once, and free projects are paused after 1 week of inactivity. A paused project can be restored from the dashboard within a 1-year window; paid projects are never paused. There are no automatic backups on Free, and Supabase recommends that free projects export their data regularly with the CLI db dump command.

Supabase Free plan limits (pricing page and docs, October 2026)
LimitFree plan
Active projects2
Database size500 MB per project
ComputeNano: shared CPU, up to 0.5 GB RAM
Auth50,000 monthly active users
File storage and egress1 GB storage; 5 GB egress plus 5 GB cached egress
Backups and PITRNot included
InactivityPaused after 1 week

Limits and trade-offs

Compute is always on. Unlike serverless Postgres, a paid Supabase project runs continuously and is billed per hour of compute whether or not it is busy. Each additional project adds its own compute cost, so a staging copy of every project roughly doubles that line.

Disk can go read-only. Disk grows automatically on paid plans, but only a limited number of times in 24 hours; the documentation warns that a project reaching 95% disk use with no resize quota left enters read-only mode.

Networking. Direct database connections use IPv6 unless you buy the IPv4 add-on; IPv4-only networks connect through the shared pooler instead. Serverless and edge functions are told to use the pooler in transaction mode.

Backups cost extra for fine-grained recovery. Pro includes 7 days of daily backups. Point-in-time recovery is a paid add-on that also requires at least the Small compute size.

Platform coupling. The database is portable, but Auth, Storage policies, Realtime and Edge Functions are Supabase-specific. Self-hosting reduces that risk: the code is Apache-2.0 and Supabase recommends Docker for self-hosting, though you then own security, upgrades and backups yourself.

Who should use Supabase, and who should not

A good fit: web and mobile apps that need users, files and live updates without building a backend; teams who want SQL and relational data rather than a document store; and products that want a credible self-hosting fallback.

Probably not the right fit: databases that sit idle most of the time (scale-to-zero billing such as Neon's can cost less), estates with many small databases, organisations committed to AWS, Azure or Google Cloud networking and IAM, and workloads that only need a database and would pay for platform features they never use.

For a head-to-head on the most common alternative, see Supabase vs Neon and our Neon review. Other comparisons: Supabase vs Firebase and Supabase vs AWS RDS, plus our list of Supabase alternatives.

Pricing

Prices from the provider's official pricing pages, checked 8 October 2026, region All Supabase regions (the pricing page lists one rate per plan and compute size), in USD, excluding tax. List prices only; discounts, commitments and your actual usage change the bill.

A Supabase bill has three parts: the organisation's plan, compute for each project (billed hourly), and usage beyond the plan's quotas. Paid plans include 10 USD a month of compute credits, which covers one Micro project.

Supabase list prices from the pricing page and compute documentation
ItemPrice
Free plan0 USD per month (2 active projects, Nano compute)
Pro planFrom 25 USD per month, includes 10 USD compute credits
Team planFrom 599 USD per month
EnterpriseCustom pricing (contact sales)
Micro compute (1 GB RAM, shared)0.01344 USD per hour, about 10 USD per month
Small compute (2 GB RAM, shared)0.0206 USD per hour, about 15 USD per month
Medium compute (4 GB RAM, shared)0.0822 USD per hour, about 60 USD per month
Disk beyond 8 GB per project (Pro)0.125 USD per GB
Egress beyond 250 GB (Pro)0.09 USD per GB
Monthly active users beyond 100,000 (Pro)0.00325 USD per MAU
Point-in-time recovery, 7 days0.137 USD per hour, about 100 USD per month

One production project on Pro with Micro compute

  • One project running all month (730 hours)
  • Within Pro quotas: 8 GB disk, 250 GB egress, 100,000 MAUs
  • No add-ons
ItemBasisEstimated per month
Pro planMonthly fee25.00 USD
Micro compute730 hours x 0.01344 USD = 9.81 USD, covered by the 10 USD credit0.00 USD
Estimated totalabout 25.00 USD per month

Pro with Small compute and a 20 GB database

  • One project on Small compute, 730 hours
  • 20 GB disk, so 12 GB above the 8 GB included
  • Other usage within quotas
ItemBasisEstimated per month
Pro planMonthly fee25.00 USD
Small compute730 hours x 0.0206 USD = 15.04 USD, minus 10 USD credit5.04 USD
Extra disk12 GB x 0.125 USD1.50 USD
Estimated totalabout 31.54 USD per month

Adding 7-day point-in-time recovery

  • The project above (PITR requires at least Small compute)
  • 7-day recovery retention
ItemBasisEstimated per month
Project aboveFrom the previous example31.54 USD
PITR, 7 days730 hours x 0.137 USD100.01 USD
Estimated totalabout 131.55 USD per month

Worked examples are estimates calculated from the list prices above; they are not quotes or measured bills.

Frequently asked questions

Is Supabase a NoSQL database?

No. Supabase is built on PostgreSQL, a relational SQL database. It can store and query unstructured data in json and jsonb columns, so document-style data is possible, but queries, constraints and joins are standard SQL.

Is Supabase free?

There is a free plan with 2 active projects, a 500 MB database each and 50,000 monthly active users. Free projects pause after a week of inactivity and have no automatic backups, so it suits prototypes rather than production.

Can I self-host Supabase?

Yes. The code is Apache-2.0 licensed and Supabase documents self-hosting with Docker Compose as the recommended route. You become responsible for servers, security patches, upgrades and backups.

Can I use Supabase only as a PostgreSQL host?

Yes. Each project exposes a normal Postgres connection string for psql, pgAdmin, DBeaver or any ORM. You still pay the plan and compute prices, which include the platform services whether or not you use them.

Does a Supabase project scale to zero?

No. Paid projects run continuously and are billed per hour of compute. Only free projects are paused, after a week of inactivity, and they must be restored before use.

Sources

Checked 8 October 2026.

How we research cloud database guides: our editorial method. CodeWithSQL earns nothing from the providers mentioned.

Choosing where to run your database?

Start with the section overview, or compare providers side by side.