Supabase
supabase.com · Backend platform
Open-source Postgres backend with auth, storage and realtime APIs.
54 items · 51 source threads · 2 source types · updated 2026-07
No items match these filters.
Pain points 36
| Item | Area | Severity | Support | Last seen |
|---|---|---|---|---|
| Making views respect row level security takes real heroics Row level security is insecure by default and it is easy to write a policy that looks valid but does not work. Views in particular are hard to get to respect it. Affects: Developer building a front-end-only app on Supabase |
Permissions & security | Causes churn | 3 sources | 2024-04 |
| ||||
| Local API gateway and Postgres logs fail with 502 Local development logging returns 502 errors even after updating, resetting Docker images and db reset, and the user feels local dev experience is neglected. Affects: Local development users |
Reliability & bugs | Causes churn | 2 sources | 2024-05 |
| ||||
| Self-hosting docs lack guidance for changing passwords Changing the Postgres password in .env breaks docker compose startup and the docs do not say the volume must be wiped, which cost hours to find. Affects: Self-hosters using Docker |
Documentation | Causes churn | 2 sources | 2024-04 |
| ||||
| Self-hosted dashboard file uploads stall at 0 percent Manual uploads to a bucket from the self-hosted dashboard hang at 0% across computers and file types. Affects: Self-hosters using Docker |
Self-hosting & upgrades | Blocks work | 2 sources | 2025-11 |
| ||||
| getUserByCookie fails in Next.js middleware The server-side cookie user lookup does not work in Next.js middleware because it hits an XMLHttpRequest error, and the message is unclear. Affects: Next.js developers |
API & developer experience | Blocks work | 2 sources | 2024-05 |
| ||||
| Prisma cannot connect to Supabase database Affects: Developers using Prisma |
Integrations | Blocks work | 2 sources | 2024-03 |
| redirectTo ignored in Google sign-in Affects: Developers using OAuth sign-in |
Reliability & bugs | Blocks work | 2 sources | 2021-06 |
| Production user finds Supabase buggy and poorly tested Affects: Production Supabase customer |
Reliability & bugs | Causes churn | 1 source | 2025-04 |
| Enabling email auth caused rate limits on phone OTP traffic Affects: Apps using SMS OTP |
Reliability & bugs | Causes churn | 1 source | 2022-12 |
| Self-hosting dashboard stuck connecting after 12 hours of effort Affects: First-time self-hosters |
Self-hosting & upgrades | Causes churn | 1 source | 2022-11 |
| SQL editor caused data loss Affects: Developers using the dashboard SQL editor |
Reliability & bugs | Causes churn | 1 source | 2022-05 |
| React Native queries return nothing in release builds Affects: React Native and Expo developers |
Mobile | Causes churn | 1 source | 2021-05 |
| Supabase MCP OAuth fails in Cursor with unrecognized client_id Affects: Cursor users of Supabase MCP |
Integrations | Blocks work | 1 source | 2026-03 |
| pgvector indexing needs many resources when adding rows Affects: Teams indexing large document collections for AI |
Performance | Blocks work | 1 source | 2025-08 |
| Project stuck in Pausing state for over a week Affects: Developers pausing projects |
Reliability & bugs | Blocks work | 1 source | 2025-04 |
| Functions deploy cannot resolve Deno workspace packages Affects: Edge Functions developers using Deno workspaces |
API & developer experience | Blocks work | 1 source | 2025-04 |
| Custom SMTP with Office 365 or Outlook times out Affects: Teams using Office 365 mail for auth emails |
Integrations | Blocks work | 1 source | 2025-03 |
| No documentation for Google sign-in in Chrome extensions Affects: Chrome extension developers |
Documentation | Blocks work | 1 source | 2024-10 |
| Studio impersonation ignores custom access token hook Affects: Teams using auth hooks with RLS |
Permissions & security | Blocks work | 1 source | 2024-07 |
| Poor communication of auth-helpers to ssr migration and deprecation Affects: Developers using SvelteKit with Supabase auth |
Documentation | Blocks work | 1 source | 2024-04 |
| SvelteKit docs and examples are incomplete and lead to deprecated repos Affects: SvelteKit developers |
Documentation | Blocks work | 1 source | 2024-04 |
| PostgREST API judged too basic compared to writing SQL Affects: Developer building a front-end-only app |
API & developer experience | Blocks work | 1 source | 2024-04 |
| Auth function error messages are not documented Affects: Developers handling auth errors in supabase-js |
Documentation | Blocks work | 1 source | 2024-03 |
| Fetch to Supabase APIs fails in Safari with access control errors Affects: Apps with Safari users |
Reliability & bugs | Blocks work | 1 source | 2024-02 |
| CLI started requiring Docker to deploy edge functions Affects: Developers deploying edge functions from CI or machines without Docker |
API & developer experience | Blocks work | 1 source | 2023-12 |
| SQL editor crashes the page on any incorrect query Affects: Dashboard SQL editor users |
Reliability & bugs | Blocks work | 1 source | 2023-11 |
| Magic link emails quarantined by Outlook Affects: Apps with business Outlook users |
Reliability & bugs | Blocks work | 1 source | 2023-06 |
| Log search capped at 100 results with no load more Affects: Users diagnosing issues from logs |
Reporting & analytics | Blocks work | 1 source | 2023-04 |
| SIGNED_IN auth event fires on every tab refocus Affects: Web app developers using supabase-js |
Reliability & bugs | Blocks work | 1 source | 2022-06 |
| Vercel preview deployments need manual redirect URL additions Affects: Teams using preview deployments |
Integrations | Blocks work | 1 source | 2022-01 |
| Twitter OAuth signup fails for accounts without an email Affects: Apps using Twitter login without needing email |
Integrations | Blocks work | 1 source | 2021-08 |
| Table editor cannot create foreign key relationships Affects: Table editor users |
UI & usability | Blocks work | 1 source | 2021-01 |
| Server framework docs still use getUser instead of getClaims Affects: Developers using SSR frameworks |
Documentation | Annoyance | 1 source | 2025-10 |
| Local studio SQL query name cannot be edited Affects: Local development users |
UI & usability | Annoyance | 1 source | 2023-10 |
| Dashboard is slow and renders incorrectly Affects: Dashboard users |
Performance | Annoyance | 1 source | 2022-05 |
| Self-hosting story seems deprioritized | Self-hosting & upgrades | Annoyance | 1 source | 2022-05 |
Top 5 shown with evidence. The rest are listed by title; open any item for its evidence.
Feature requests 9
| Item | Area | Severity | Support | Last seen |
|---|---|---|---|---|
| Wants better authorization tooling pushed through external coding platforms A security researcher says authorization improvements would help a lot, especially if they can be enforced or surfaced through third-party AI coding platforms that integrate with Supabase. Affects: Vibe-coded app builders |
Permissions & security | Blocks work | 1 source | 2026-01 |
| ||||
| Wants automatic resource scaling instead of manual plan switching The user wants compute resources to scale up and down automatically rather than monitoring usage and moving to the next plan. Affects: Teams indexing large document collections for AI |
Pricing & plans | Blocks work | 1 source | 2025-08 |
| ||||
| Custom domains for API and auth to avoid phishing-looking URLs Google sign-in shows a random supabase.co subdomain that looks like phishing, costing conversion. The user wants custom domain aliases for the project URL. Affects: Teams shipping consumer apps with social login |
Customization | Blocks work | 1 source | 2022-02 |
| ||||
| Wants a pricing tier between free and 25 dollars The 25 dollar plan is too much for early startups and the free quota is not enough. They request a cheaper tier, also easing the 2 org by 2 project limit. Affects: Startups and hobbyists |
Pricing & plans | Blocks work | 1 source | 2022-01 |
| ||||
| Server-side API to verify access tokens and get the user The user building a Node API server wants a firebase-admin-like way to verify an access token and get the current user in middleware. Affects: Node.js backend developers |
API & developer experience | Blocks work | 1 source | 2021-01 |
| ||||
| Wants self-hosted auth in front of Postgres without being tied to Supabase Affects: Developers wanting self-hosted auth |
Self-hosting & upgrades | Annoyance | 1 source | 2024-08 |
| Wants built-in integrations with CDNs, transactional email and domain registrars | Integrations | Annoyance | 1 source | 2024-04 |
| Wants TypeScript-defined schema with generated migrations Affects: Developers managing schema and RLS |
API & developer experience | Annoyance | 1 source | 2023-05 |
| Allow newlines in SMS OTP template for WebOTP Affects: PWA developers using SMS OTP |
Customization | Annoyance | 1 source | 2021-09 |
Top 5 shown with evidence. The rest are listed by title; open any item for its evidence.
Workarounds 5
| Item | Area | Severity | Support | Last seen |
|---|---|---|---|---|
| Uses Supabase only as hosted Postgres reached by own backend To avoid RLS risk, the user stopped using the auto API and uses Supabase just as a managed Postgres that only their backend connects to. Affects: Developers concerned about public table access |
Permissions & security | Blocks work | 1 source | 2024-01 |
| ||||
| Local signup fails on null provider_id; constraint dropped as workaround Email signup in local development errors because provider_id is null in identities. The user drops the not-null constraint as a workaround. Affects: Local development users |
Reliability & bugs | Blocks work | 1 source | 2023-12 |
| ||||
| redirectTo not working across auth methods, useEffect used instead redirectTo has no effect for email/password, Google or GitHub sign-in. The user redirects manually in a useEffect hook, which they find not ideal. Affects: Developers using supabase-js auth |
Reliability & bugs | Blocks work | 1 source | 2022-02 |
| ||||
| Realtime stopped with FOR ALL TABLES publication on PG12 Database-wide realtime publications broke after the row-level security update on PG12. The workaround is to enable tables individually. Affects: Realtime users on PG12 |
Reliability & bugs | Blocks work | 1 source | 2021-12 |
| ||||
| Manual migrations and type generation slow development; MCP used to avoid them Pushing migrations and generating types by hand adds a lot of time to development. The user relies on the Supabase MCP server to keep database changes fluid. Affects: Developers building apps with AI coding tools |
API & developer experience | Annoyance | 1 source | 2025-11 |
| ||||
Switching reasons 4
| Item | Area | Severity | Support | Last seen |
|---|---|---|---|---|
| Managed Postgres became costly coupled dependency after scale, migrated to Aurora/RDS A solo-founder style user says Neon and Supabase became a tightly coupled dependency whose growing cost defeated the savings, so the team migrated to Aurora or RDS. Affects: Bootstrapped founders and growing startups |
Pricing & plans | Causes churn | 1 source | 2026-07 |
| ||||
| Planning to leave Supabase for custom-built backend pieces The user was already planning to leave, finding the Postgres-layer approach (PostgREST, realtime, JWT auth) more annoying than useful and preferring to build the pieces themselves. Affects: Production Supabase customer |
Other | Causes churn | 1 source | 2025-04 |
| ||||
| May develop on production or leave because local environment is unstable Because the local development environment is unstable, the user says they will either develop directly on production or look for another solution. Affects: Teams developing locally |
Reliability & bugs | Causes churn | 1 source | 2023-11 |
| ||||
| Cancelled Logflare/Supabase Logs after too many issues for low-volume retention A user wanting high retention of low-volume logs found Logflare geared to graphs rather than diagnosis and cancelled a paid plan, moving to LogTail. Affects: Small apps needing long log retention |
Reporting & analytics | Causes churn | 1 source | 2023-04 |
| ||||