Run better-supabase in production with confidence
The library is MIT licensed. For teams that want a direct line to the maintainers, we offer support, reviews and migration help.
Posture
Secure by default, boring on purpose
The properties security and platform teams ask about first.
RLS stays in chargedefineSupabase holds no secrets. Every request connects with the caller’s client, so Postgres policies decide what each user sees.No service in the data pathEverything runs in your code against your Supabase project, hosted or self-hosted. Nothing phones home.Doctor in CIRLS, index, drift, auth-config and env-file checks plus the Supabase Advisors, reported as SARIF or GitHub annotations.A small supply chainThe core depends only on the Supabase packages and Standard Schema. Advisor lints are fetched at a pinned commit and checked against a SHA-256.Stability you can plan aroundSemver, an export snapshot reviewed on every change, versioned plugin contracts and a documented deprecation policy.Standards, pinnedRFC 9457 problem details, OpenTelemetry, CloudEvents, Standard Webhooks and OpenAPI, with draft specs pinned in code.
Work with us
How we can help
Support
A direct line to the maintainers for your team, with priority on issues that block you.
Architecture reviews
RLS policies, auth flows, caching and schema design reviewed against how better-supabase runs them.
Migrations
Move an existing supabase-js codebase to typed repositories incrementally, one table at a time.
Talk to the maintainers
Tell us about your stack, your Supabase setup and what you need.
hello@scaledock.com