Platform overview
Tested with: Databasezy API v1 · zb CLI 0.1 · supabase-js 2
Every project on Databasezy has one HTTPS endpoint. Your application talks to it for sign-up and sign-in, for its tables over REST and GraphQL, for SQL over HTTPS on any database in the project and, as they ship, for files, functions and realtime messages. Requests carry a project key; the Supabase client libraries work against it unchanged.
The project endpoint
Section titled “The project endpoint”https://<ref>.us-east.databasezy.com:8443<ref> is the project’s reference: 20 lower-case letters, assigned when the project is created and never reused.
The portal shows the exact endpoint under Project settings, and the CLI prints it:
zb projects show # ref, endpoint, JWKS URL and primary database of the current project| Path | Service | Guide |
|---|---|---|
/auth/v1 | Auth: sign-up, sign-in, sessions, JWKS | Auth |
/rest/v1 | REST over the primary database (PostgREST) | Data API |
/graphql/v1 | GraphQL (pg_graphql) | Data API |
/query/v1/<instance> | SQL over HTTPS for any instance in the project | Data API |
/storage/v1 | Buckets and objects | Storage |
/functions/v1 | Functions | Functions |
/realtime/v1 | Realtime channels | Realtime |
Traffic is TLS only and served from the region that runs the project, next to its databases. Response bytes count toward your plan’s egress allowance.
Keys and roles
Section titled “Keys and roles”| Credential | Where it belongs | Acts as |
|---|---|---|
| Publishable key | Browsers and mobile apps | anon: only what your row-level security policies allow |
| A user’s session token | Sent by the client after sign-in | authenticated, with the user’s id in auth.uid() |
| Secret key | Servers, jobs, CI | service_role: bypasses row-level security |
Create and revoke keys in Project keys and JWKS.
The primary database
Section titled “The primary database”One Postgres or TimescaleDB instance per project can be marked as the primary database. Auth keeps its users
there (the auth schema), the Data API serves its tables, and storage keeps its object metadata there, so one set
of row-level security policies governs rows, users and files. Without a primary database the endpoint still answers
SQL over HTTPS for every instance.
Quickstart
Section titled “Quickstart”-
Create a project with a Postgres instance, in the portal or with the CLI:
shell zb projects create --name shopzb instances create --engine postgres --size s0 --region us-east --name shop-db --wait -
Open Project settings and choose
shop-dbas the primary database (or callPUT /v1/orgs/{org}/projects/<project-id>/primary-instance). -
Create a publishable key. It is shown once:
shell zb projects keys create --name web --kind publishable -
Turn on the Data API under Platform → Data API, then call your tables from the browser:
Terminal window curl "https://<ref>.us-east.databasezy.com:8443/rest/v1/todos?select=*" \-H "apikey: <publishable-key>" \-H "Authorization: Bearer <publishable-key>"import { createClient } from "@supabase/supabase-js";const supabase = createClient("https://<ref>.us-east.databasezy.com:8443", "<publishable-key>");const { data, error } = await supabase.from("todos").select("*");from supabase import create_clientsupabase = create_client("https://<ref>.us-east.databasezy.com:8443", "<publishable-key>")rows = supabase.table("todos").select("*").execute()// Cargo.toml: reqwest = { version = "0.12", features = ["json"] }, serde_json, tokiolet key = "<publishable-key>";let res = reqwest::Client::new().get("https://<ref>.us-east.databasezy.com:8443/rest/v1/todos?select=*").header("apikey", key).bearer_auth(key).send().await?.error_for_status()?;let json: serde_json::Value = res.json().await?;
Status of every capability
Section titled “Status of every capability”The same list drives the website, these docs and the pricing page; when something ships it moves to Live here.
| Service | Capability | Status |
|---|---|---|
| Project endpoint and keys | One HTTPS endpoint per project | Live |
| Project endpoint and keys | Publishable and secret project keys | Live |
| Project endpoint and keys | Per-project ES256 signing keys, JWKS and rotation | Live |
| Auth | Email and password sign-up and sign-in | Live |
| Auth | Magic links and email one-time codes | Live |
| Auth | Sessions with refresh-token rotation and reuse detection | Live |
| Auth | CAPTCHA with hCaptcha or Cloudflare Turnstile | Live |
| Auth | Password rules and leaked-password protection | Live |
| Auth | Rate limits and brute-force protection | Live |
| Auth | OAuth and social sign-in providers | Coming soon |
| Auth | Multi-factor authentication | Coming soon |
| Auth | SAML 2.0 single sign-on for your users | Coming soon |
| Auth | Third-party auth (Clerk, Auth0, Firebase, Cognito, WorkOS) | Coming soon |
| Auth | Anonymous sign-in and phone codes | Coming soon |
| Auth | User management in the portal | Coming soon |
| Auth | Import users from Supabase with their password hashes and ids | Coming soon |
| Auth | Server-side auth helpers (@supabase/ssr cookies, PKCE) | Coming soon |
| Auth | OAuth 2.1 / OpenID Connect provider: sign in with your app, MCP clients | Coming soon |
| Data API | REST over your tables (PostgREST) | Live |
| Data API | GraphQL (pg_graphql) | Live |
| Data API | SQL over HTTPS for every engine (/query/v1) | Live |
| Data API | TypeScript types for supabase-js (zb gen types) | Live |
| Storage | Buckets with row-level security and signed URLs | Coming soon |
| Storage | Resumable and multipart uploads | Coming soon |
| Storage | S3-compatible endpoint | Coming soon |
| Storage | Image transformations | Coming soon |
| Functions | TypeScript functions over HTTP, with secrets and logs | Coming soon |
| Functions | Cron, queue and database-change triggers | Coming soon |
| Realtime | Broadcast | Coming soon |
| Realtime | Presence | Coming soon |
| Realtime | Postgres changes filtered by row-level security | Coming soon |
| Apps and jobs | Always-on apps from your container image | Coming soon |
| Apps and jobs | One-off and cron jobs | Coming soon |
| Sandboxes | Ephemeral sandboxes for untrusted code | Coming soon |
| Database tools | Extensions manager | Live |
| Database tools | Cron (pg_cron) | Live |
| Database tools | Queues (pgmq) | Live |
| Database tools | Vector search and automatic embeddings | Coming soon |
| Database tools | Vault: encrypted secrets in your database | Coming soon |
| Database tools | Foreign data wrappers | Coming soon |
| Database tools | Table editor | Coming soon |
| Database tools | Row-level security policy and roles editor | Coming soon |
| Database tools | Security and performance advisors | Coming soon |
| Agent servers | A Kata VM per server, with Docker inside | Live |
| Agent servers | SSH through the bastion with your registered keys (VS Code, Cursor, Zed) | Live |
| Agent servers | Web terminal in the portal | Live |
| Agent servers | Stopping a server stops compute billing | Live |
| Agent servers | Coding agents and toolchains preinstalled | Live |
| Agent servers | Daily snapshots, restore and export | Coming soon |
| Agent servers | GitHub repositories cloned under ~/dev | Coming soon |
| Agent servers | Attach to a project to reach its databases privately | Coming soon |
| Agent servers | Secure placement on a HIPAA cell | Coming soon |