Skip to content
BotServBotServ
SupabaseFirebase AlternativePostgresBackendSelf-HostingOpen Sourcepgvector

Supabase Self-Hosted: Open-Source Firebase Alternative

Self-host Supabase with Postgres, Auth, Realtime, and Storage. Docker setup, pgvector for AI, and API usage guide.

S

schutzgeist

4 min read
Supabase Self-Hosted: Open-Source Firebase Alternative

Supabase Self-Hosted: The Open-Source Firebase Alternative

What This Article Covers

  • What Supabase is: Postgres + Auth + Realtime + Storage as a complete backend.
  • Self-hosting with Docker and how it differs from the cloud version.
  • Why pgvector makes Supabase a vector database candidate for RAG.
  • REST-API (PostgREST), Auth, and Realtime in practice.
  • When to choose Supabase vs. plain Postgres vs. Firebase.

Introduction

Supabase is the leading open-source alternative to Firebase: you get a Postgres database with REST-API, authentication (email, OAuth, magic links), realtime subscriptions via WebSocket, file storage, and edge functions, all from a single stack, entirely open source.

For AI projects, Supabase is doubly compelling. Postgres includes pgvector, turning Supabase into a vector database for embeddings and RAG without needing a separate system.

Typical Use Cases

  • AI app backend: web app with Supabase auth + Postgres + pgvector for RAG.
  • Chatbot persistence: conversations, user profiles, and document indexes in one database.
  • Realtime dashboards: live updates for monitoring or AI generations.
  • Multi-user services: auth + row-level security ensures clean tenant isolation.
  • Form backends: NocoDB alternative with real programmability.

Installation: Docker

Supabase self-hosted is a multi-container stack (Postgres, PostgREST, GoTrue Auth, Realtime, Storage, Studio UI):

git clone --depth 1 https://github.com/supabase/supabase.git
cd supabase/docker
cp .env.example .env
# Edit .env: POSTGRES_PASSWORD, JWT_SECRET, ANON_KEY, SERVICE_ROLE_KEY, Site-URL
docker compose up -d

Key .env variables:

POSTGRES_PASSWORD=secret
JWT_SECRET=long-random-key
ANON_KEY=jwt-with-anon-role          # Generate using JWT_SECRET
SERVICE_ROLE_KEY=jwt-with-service-role  # Admin key, never expose to frontend!
SITE_URL=https://app.yourdomain.com
API_EXTERNAL_URL=https://api.yourdomain.com

Generate the keys using supabase gen or JWT tools. ANON_KEY is public (protected by RLS) while SERVICE_ROLE_KEY is admin-only and must remain secret.

Studio UI runs at http://localhost:8000: database management, auth, API docs.

Core Features

Automatic REST-API (PostgREST)

Every table immediately gets a REST-API:

# Table "documents" → automatically:
curl "https://api.yourdomain.com/rest/v1/documents?select=*" \
  -H "apikey: ANON_KEY" \
  -H "Authorization: Bearer USER_JWT"

No backend code needed; CRUD is out of the box.

Auth (GoTrue)

Email/password, magic links, OAuth (Google, GitHub), JWT tokens, and ready-made UI components for React/Next.js.

Realtime

WebSocket subscriptions to database changes: “new row in table X” pushes live to the frontend.

Storage

S3-compatible file storage with bucket rules and access-controlled RLS.

pgvector: Supabase as a Vector Database for AI

The killer feature for AI: the Postgres extension pgvector stores embeddings directly in Supabase:

-- In the Supabase SQL console:
create extension if not exists vector;

create table documents (
  id bigint primary key generated always as identity,
  content text,
  embedding vector(1024)          -- bge-m3 uses 1024 dimensions
);

-- Similarity search
create function match_documents(query_embedding vector(1024), match_count int)
returns table (id bigint, content text, similarity float)
language sql as $$
  select id, content, 1 - (embedding <=> query_embedding) as similarity
  from documents
  order by embedding <=> query_embedding
  limit match_count;
$$;
# From your app, embedding from Ollama, search in Supabase:
emb = ollama_client.embeddings(model="bge-m3", prompt=query)["embedding"]
result = supabase.rpc("match_documents", {
    "query_embedding": emb,
    "match_count": 5
}).execute()
context = "\n".join(r["content"] for r in result.data)

This means you don’t need a separate Qdrant or Chroma setup. Supabase combines database and vector search in one. For very large datasets (over 1 million vectors), dedicated Qdrant is faster, but pgvector handles most projects just fine.

Row-Level Security (RLS)

The most important security feature: rules directly in Postgres. “Users see only their own data”:

alter table documents enable row level security;

create policy "own docs" on documents
  for all using (auth.uid() = user_id);

This makes the REST-API safe and multi-tenant-capable without custom backend logic.

Self-Hosted vs. Supabase Cloud

AspectSelf-hostedSupabase Cloud
Data ownership✅ Your serverUS/EU cloud
SetupDocker stack, ~7 containers5 minutes sign-up
CostServer onlyFree tier, then $25+
MaintenanceYou handle it (updates, backups)Managed
FeaturesFull coreSome features cloud-only

Security

  • SERVICE_ROLE_KEY secret: has admin privileges, bypasses RLS, never expose to frontend.
  • ANON_KEY + RLS: the public key is safe because RLS controls visibility.
  • HTTPS: API endpoint behind a reverse proxy with TLS.
  • Backups: regular Postgres dumps; see Backup.
  • JWT_SECRET: strong and secret; used to sign all auth tokens.

Supabase vs. Alternatives

ToolStrengthWeakness
SupabaseComplete backend (DB + Auth + Realtime + Storage), pgvectormulti-container stack, complex
FirebaseManaged, matureGoogle Cloud, proprietary, expensive
NocoDBNo-code UI, simpleLess programmable
Bare Postgreslean, full controlNo auth/REST/realtime out of the box
PocketbaseSingle binary, lightweightSQLite, less powerful

Further Reading

  • IRC-Coding.de: in-depth programming tutorials on Postgres, REST, auth, WebSocket.
  • Lokales RAG: embeddings and vector search in detail.
  • Qdrant: dedicated vector database.
  • NocoDB: no-code alternative.
  • Docker: deployment fundamentals.

Key Takeaways

  • Supabase is Postgres + Auth + Realtime + Storage + REST-API as an open-source backend.
  • pgvector makes it a vector database for RAG; no separate system needed.
  • Self-hosted is a ~7-container stack: more setup, but full control.
  • RLS (row-level security) provides a secure multi-tenant API without backend code.
  • For AI apps, it’s the best all-in-one foundation: auth + database + vector search in one.

FAQ

Can Supabase really do vector search?

Yes. The pgvector extension stores embeddings in Postgres and searches by cosine or L2 distance. It handles up to about 1 million vectors; beyond that, dedicated systems like Qdrant or Weaviate are faster.

Is self-hosting complicated?

More involved than a single container. Postgres, PostgREST, GoTrue, Realtime, Storage, Studio amount to about 7 services. The official Docker Compose helps, but it’s a proper stack, not one-click.

Supabase or NocoDB?

Supabase is a programmable backend with auth, realtime, pgvector, and RLS. NocoDB is a no-code table UI. For applications: Supabase. For data management without code: NocoDB.

Authentication without custom code?

Yes. GoTrue handles email/password, magic links, and OAuth (Google, GitHub). Frontend SDKs for React, Vue, etc. are ready to use. No custom auth code needed.

Why Supabase for AI?

Because you get auth, document database, vector search (pgvector), and API all in one stack. Chatbot backends, RAG systems, and multi-user AI apps all run on one foundation.

Limitations of self-hosted?

Edge Functions (Deno) and some monitoring features are cloud-exclusive or harder to deploy. The core (database, auth, REST, realtime, storage, pgvector) is fully available.

Sources and Further Reading

Back to Blog
Share:

Related Posts