Supabase Self-Hosted: The Open-Source Firebase Alternative
What This Article Covers
- What Supabase is: Postgres + Auth + Realtime + Storage as a complete backend.
- Self-hosting with Docker and how it differs from the cloud version.
- Why pgvector makes Supabase a vector database candidate for RAG.
- REST-API (PostgREST), Auth, and Realtime in practice.
- When to choose Supabase vs. plain Postgres vs. Firebase.
Introduction
Supabase is the leading open-source alternative to Firebase: you get a Postgres database with REST-API, authentication (email, OAuth, magic links), realtime subscriptions via WebSocket, file storage, and edge functions, all from a single stack, entirely open source.
For AI projects, Supabase is doubly compelling. Postgres includes pgvector, turning Supabase into a vector database for embeddings and RAG without needing a separate system.
Typical Use Cases
- AI app backend: web app with Supabase auth + Postgres + pgvector for RAG.
- Chatbot persistence: conversations, user profiles, and document indexes in one database.
- Realtime dashboards: live updates for monitoring or AI generations.
- Multi-user services: auth + row-level security ensures clean tenant isolation.
- Form backends: NocoDB alternative with real programmability.
Installation: Docker
Supabase self-hosted is a multi-container stack (Postgres, PostgREST, GoTrue Auth, Realtime, Storage, Studio UI):
git clone --depth 1 https://github.com/supabase/supabase.git
cd supabase/docker
cp .env.example .env
# Edit .env: POSTGRES_PASSWORD, JWT_SECRET, ANON_KEY, SERVICE_ROLE_KEY, Site-URL
docker compose up -d
Key .env variables:
POSTGRES_PASSWORD=secret
JWT_SECRET=long-random-key
ANON_KEY=jwt-with-anon-role # Generate using JWT_SECRET
SERVICE_ROLE_KEY=jwt-with-service-role # Admin key, never expose to frontend!
SITE_URL=https://app.yourdomain.com
API_EXTERNAL_URL=https://api.yourdomain.com
Generate the keys using supabase gen or JWT tools. ANON_KEY is public (protected by RLS) while SERVICE_ROLE_KEY is admin-only and must remain secret.
Studio UI runs at http://localhost:8000: database management, auth, API docs.
Core Features
Automatic REST-API (PostgREST)
Every table immediately gets a REST-API:
# Table "documents" → automatically:
curl "https://api.yourdomain.com/rest/v1/documents?select=*" \
-H "apikey: ANON_KEY" \
-H "Authorization: Bearer USER_JWT"
No backend code needed; CRUD is out of the box.
Auth (GoTrue)
Email/password, magic links, OAuth (Google, GitHub), JWT tokens, and ready-made UI components for React/Next.js.
Realtime
WebSocket subscriptions to database changes: “new row in table X” pushes live to the frontend.
Storage
S3-compatible file storage with bucket rules and access-controlled RLS.
pgvector: Supabase as a Vector Database for AI
The killer feature for AI: the Postgres extension pgvector stores embeddings directly in Supabase:
-- In the Supabase SQL console:
create extension if not exists vector;
create table documents (
id bigint primary key generated always as identity,
content text,
embedding vector(1024) -- bge-m3 uses 1024 dimensions
);
-- Similarity search
create function match_documents(query_embedding vector(1024), match_count int)
returns table (id bigint, content text, similarity float)
language sql as $$
select id, content, 1 - (embedding <=> query_embedding) as similarity
from documents
order by embedding <=> query_embedding
limit match_count;
$$;
# From your app, embedding from Ollama, search in Supabase:
emb = ollama_client.embeddings(model="bge-m3", prompt=query)["embedding"]
result = supabase.rpc("match_documents", {
"query_embedding": emb,
"match_count": 5
}).execute()
context = "\n".join(r["content"] for r in result.data)
This means you don’t need a separate Qdrant or Chroma setup. Supabase combines database and vector search in one. For very large datasets (over 1 million vectors), dedicated Qdrant is faster, but pgvector handles most projects just fine.
Row-Level Security (RLS)
The most important security feature: rules directly in Postgres. “Users see only their own data”:
alter table documents enable row level security;
create policy "own docs" on documents
for all using (auth.uid() = user_id);
This makes the REST-API safe and multi-tenant-capable without custom backend logic.
Self-Hosted vs. Supabase Cloud
| Aspect | Self-hosted | Supabase Cloud |
|---|---|---|
| Data ownership | ✅ Your server | US/EU cloud |
| Setup | Docker stack, ~7 containers | 5 minutes sign-up |
| Cost | Server only | Free tier, then $25+ |
| Maintenance | You handle it (updates, backups) | Managed |
| Features | Full core | Some features cloud-only |
Security
- SERVICE_ROLE_KEY secret: has admin privileges, bypasses RLS, never expose to frontend.
- ANON_KEY + RLS: the public key is safe because RLS controls visibility.
- HTTPS: API endpoint behind a reverse proxy with TLS.
- Backups: regular Postgres dumps; see Backup.
- JWT_SECRET: strong and secret; used to sign all auth tokens.
Supabase vs. Alternatives
| Tool | Strength | Weakness |
|---|---|---|
| Supabase | Complete backend (DB + Auth + Realtime + Storage), pgvector | multi-container stack, complex |
| Firebase | Managed, mature | Google Cloud, proprietary, expensive |
| NocoDB | No-code UI, simple | Less programmable |
| Bare Postgres | lean, full control | No auth/REST/realtime out of the box |
| Pocketbase | Single binary, lightweight | SQLite, less powerful |
Further Reading
- IRC-Coding.de: in-depth programming tutorials on Postgres, REST, auth, WebSocket.
- Lokales RAG: embeddings and vector search in detail.
- Qdrant: dedicated vector database.
- NocoDB: no-code alternative.
- Docker: deployment fundamentals.
Key Takeaways
- Supabase is Postgres + Auth + Realtime + Storage + REST-API as an open-source backend.
- pgvector makes it a vector database for RAG; no separate system needed.
- Self-hosted is a ~7-container stack: more setup, but full control.
- RLS (row-level security) provides a secure multi-tenant API without backend code.
- For AI apps, it’s the best all-in-one foundation: auth + database + vector search in one.
FAQ
Can Supabase really do vector search?
Is self-hosting complicated?
Supabase or NocoDB?
Authentication without custom code?
Why Supabase for AI?
Limitations of self-hosted?
Sources and Further Reading
- Supabase: GitHub.
- Supabase Self-Hosting: documentation.
- pgvector: vector extension.
- IRC-Coding.de: programming tutorials.


