Supabase compatibility
Tested with: supabase-js 2 · PostgreSQL 17 · Databasezy API v1
Databasezy’s project platform follows Supabase’s HTTP APIs, database layout and roles, so applications written for Supabase move over with a new URL and new keys. This page lists what matches and what differs.
What matches
Section titled “What matches”- Paths:
/auth/v1,/rest/v1,/graphql/v1,/storage/v1,/functions/v1and/realtime/v1on one endpoint per project. - Keys on the wire: the key goes in the
apikeyheader andAuthorization: Bearer, as the Supabase clients send it. - Roles:
anon,authenticatedandservice_roleexist in the primary database with the same meaning, plus theauthenticatorrole PostgREST connects as. - The auth schema:
auth.users,auth.identities,auth.sessions,auth.refresh_tokens,auth.mfa_factorsand the other Supabase auth tables, with the helper functionsauth.uid(),auth.jwt(),auth.role()andauth.email(). Row-level security policies written for Supabase run unchanged. - JWT claims:
sub,role,aud,email,app_metadata,user_metadata,aalandsession_id. - PostgREST and pg_graphql: the same engines Supabase runs, so query syntax, embedding,
rpcand GraphQL collections behave the same.
What differs
Section titled “What differs”| Topic | Supabase | Databasezy |
|---|---|---|
| Endpoint | https://<ref>.supabase.co | https://<ref>.<region>.databasezy.com:8443, shown under Project settings |
| Keys | anon and service_role JWTs, or sb_publishable_ / sb_secret_ keys | Opaque publishable (zbp_) and secret (zbs_) keys. Do not decode them: they are not JWTs |
| Token signing | Shared HS256 secret on older projects, asymmetric keys on newer ones | ES256 per project, private key never leaves the region. There is no shared JWT secret: verify tokens with the JWKS |
| Primary database | Every project is one Postgres database | A project can hold several instances of any engine; one Postgres or TimescaleDB instance is the primary for auth, the Data API and storage |
| SQL over HTTP | Not part of the public project API | /query/v1/<instance> with a secret key, for every engine in the project |
| Dashboard | Supabase Studio | The Databasezy portal, CLI (zb) and REST API |
| Platform schemas | auth, storage, realtime, graphql, vault, extensions, … | auth and storage live in your primary database; the others appear as the matching services ship |
Client calls
Section titled “Client calls”| Client call | Path | Status |
|---|---|---|
auth.signUp , signInWithPassword , signInWithOtp , verifyOtp , resetPasswordForEmail , updateUser | /auth/v1 | Live |
refreshSession , getUser , signOut | /auth/v1 | Live |
auth.signInWithOAuth | /auth/v1 | Coming soon |
auth.mfa.* | /auth/v1 | Coming soon |
auth.signInWithSSO | /auth/v1 | Coming soon |
auth.signInAnonymously | /auth/v1 | Coming soon |
from(table).select / insert / update / upsert / delete , rpc | /rest/v1 | Live |
GraphQL clients | /graphql/v1 | Live |
storage.from(bucket).* | /storage/v1 | Coming soon |
functions.invoke | /functions/v1 | Coming soon |
channel(...) broadcast | /realtime/v1 | Coming soon |
channel(...) presence | /realtime/v1 | Coming soon |
channel(...) postgres_changes | /realtime/v1 | Coming soon |
Status of each service
Section titled “Status of each service”| Service | Capability | Status |
|---|---|---|
| Auth | Email and password sign-up and sign-in | Live |
| Auth | Magic links and email one-time codes | Live |
| Auth | Sessions with refresh-token rotation and reuse detection | Live |
| Auth | CAPTCHA with hCaptcha or Cloudflare Turnstile | Live |
| Auth | Password rules and leaked-password protection | Live |
| Auth | Rate limits and brute-force protection | Live |
| Auth | OAuth and social sign-in providers | Coming soon |
| Auth | Multi-factor authentication | Coming soon |
| Auth | SAML 2.0 single sign-on for your users | Coming soon |
| Auth | Third-party auth (Clerk, Auth0, Firebase, Cognito, WorkOS) | Coming soon |
| Auth | Anonymous sign-in and phone codes | Coming soon |
| Auth | User management in the portal | Coming soon |
| Auth | Import users from Supabase with their password hashes and ids | Coming soon |
| Auth | Server-side auth helpers (@supabase/ssr cookies, PKCE) | Coming soon |
| Auth | OAuth 2.1 / OpenID Connect provider: sign in with your app, MCP clients | Coming soon |
| Data API | REST over your tables (PostgREST) | Live |
| Data API | GraphQL (pg_graphql) | Live |
| Data API | SQL over HTTPS for every engine (/query/v1) | Live |
| Data API | TypeScript types for supabase-js (zb gen types) | Live |
| Storage | Buckets with row-level security and signed URLs | Coming soon |
| Storage | Resumable and multipart uploads | Coming soon |
| Storage | S3-compatible endpoint | Coming soon |
| Storage | Image transformations | Coming soon |
| Functions | TypeScript functions over HTTP, with secrets and logs | Coming soon |
| Functions | Cron, queue and database-change triggers | Coming soon |
| Realtime | Broadcast | Coming soon |
| Realtime | Presence | Coming soon |
| Realtime | Postgres changes filtered by row-level security | Coming soon |
| Database tools | Extensions manager | Live |
| Database tools | Cron (pg_cron) | Live |
| Database tools | Queues (pgmq) | Live |
| Database tools | Vector search and automatic embeddings | Coming soon |
| Database tools | Vault: encrypted secrets in your database | Coming soon |
| Database tools | Foreign data wrappers | Coming soon |
| Database tools | Table editor | Coming soon |
| Database tools | Row-level security policy and roles editor | Coming soon |
| Database tools | Security and performance advisors | Coming soon |
Migrating
Section titled “Migrating”Move from Supabase walks through the database, policies, users and client code.