# Next.js boilerplate with Supabase

> Postgres with auth, storage and realtime attached, plus a local stack you can run from the CLI. Pick it when you want one vendor for the database and the services around it.

Managed Postgres with row level security, realtime and a local stack in Docker.

- **Category:** Database
- **Pricing:** Free: 2 active projects, 500 MB database each, paused after a week idle. Pro is $25/month per organisation with $10 of compute credit, 8 GB disk per project, 7 days of daily backups and no pausing. Extra projects add compute cost.
- **Best for:** Teams that want one Postgres provider to also cover auth, storage and realtime. Also teams who want to run the real stack locally, not against a shared dev database.
- **Requires:** orm
- **Conflicts with:** neon
- **Vendor docs:** https://supabase.com/docs

## Trade-offs

- A full Postgres, not a subset: extensions, triggers, functions and logical replication all work.
- Row level security is the security model. Going through the service role key everywhere throws away most of what you are paying for.
- The local CLI boots Postgres, PostgREST, GoTrue, Realtime and Storage in Docker, so the dev loop needs Docker running.
- Branching exists but is a paid feature and slower to spin up than a local reset. Most teams use local for the inner loop and branches for previews.
- Two connection strings: direct on port 5432 and the pooler on 6543. Pick the wrong one for a serverless runtime and you run out of connections in production.
- Auth, storage and realtime are optional. Using Supabase purely as Postgres is supported and common.

## Known fixes it ships

- [Server code should stop using the anon key, and must not reach for the service role instead](https://agenticboilerplate.com/cookbook/supabase/beyond-the-anon-key-on-the-server): The anon key is a public identifier, not a credential. Server work needs either the caller's JWT or a deliberate, audited service-role call. Here is how to tell which.
- [Supabase gives you three connection strings: pick the right one or production falls over](https://agenticboilerplate.com/cookbook/supabase/direct-vs-pooler-connection-strings): Direct on 5432, session pooler on 5432, transaction pooler on 6543. Which one serverless needs, why prepared statements break, and what to run migrations on.
- [Stopping Supabase generated types from drifting out of the schema](https://agenticboilerplate.com/cookbook/supabase/generated-types-drift): Generated database types are only true at the moment they were generated. Commit them, regenerate them in the same commit as the migration, and check them in verify.
- [Local Supabase or a hosted branch - pick per environment, not per team](https://agenticboilerplate.com/cookbook/supabase/local-dev-vs-supabase-branches): The CLI stack and Supabase branching solve different problems. Use local for the inner loop, a branch for preview deploys, and never share one dev project.
- [Row level security when an ORM is doing the querying](https://agenticboilerplate.com/cookbook/supabase/rls-with-an-orm-in-front): Your ORM connects as the postgres superuser, so RLS never runs. Here is how to keep policies meaningful without giving up typed queries.

## Generate it

[Build a repo with Supabase](https://agenticboilerplate.com/build?b=supabase)

---

Agentic Boilerplate: A Next.js repo your agent already knows. Free during launch, then $99 once.

- Site map for agents: https://agenticboilerplate.com/llms.txt
- Public API: https://agenticboilerplate.com/openapi.json
- Contact: agenticstudio@gmail.com
