Friction

Supabase

supabase.com · Backend platform

Open-source Postgres backend with auth, storage and realtime APIs.

54 items · 51 source threads · 2 source types · updated 2026-07

Compare

Pain points 36

ItemAreaSeveritySupportLast seen
Making views respect row level security takes real heroics

Row level security is insecure by default and it is easy to write a policy that looks valid but does not work. Views in particular are hard to get to respect it.

Affects: Developer building a front-end-only app on Supabase

Permissions & securityCauses churn3 sources2024-04

“And for views, you have to do some real heroics to get them to respect RBS”

“I guess my main concern is that it's hard to setup RLS correctly using SQL”

Local API gateway and Postgres logs fail with 502

Local development logging returns 502 errors even after updating, resetting Docker images and db reset, and the user feels local dev experience is neglected.

Affects: Local development users

Reliability & bugsCauses churn2 sources2024-05

“It is very frustrating that the supabase team is not working to improve the local development experience”

“Supabase Studio for local development flow is not reliable at all”

Self-hosting docs lack guidance for changing passwords

Changing the Postgres password in .env breaks docker compose startup and the docs do not say the volume must be wiped, which cost hours to find.

Affects: Self-hosters using Docker

DocumentationCauses churn2 sources2024-04

“there is no mention of fixing that or any passwd changing guidelines”

“no clear instructions on how to get the database working with initialization or migrations”

Self-hosted dashboard file uploads stall at 0 percent

Manual uploads to a bucket from the self-hosted dashboard hang at 0% across computers and file types.

Affects: Self-hosters using Docker

Self-hosting & upgradesBlocks work2 sources2025-11

“However, large files that require resumable/multipart uploads always generate URLs pointing to http://myhost:8000/storage/v1//upload/resumable/dHJhaW5p..., ignoring the external port configuration”

“the progress gets stuck at 0% and the upload never seems to commence”

getUserByCookie fails in Next.js middleware

The server-side cookie user lookup does not work in Next.js middleware because it hits an XMLHttpRequest error, and the message is unclear.

Affects: Next.js developers

API & developer experienceBlocks work2 sources2024-05

“[AuthSessionMissingError: Auth session missing!]”

“`supabase.auth.api.getUserByCookie()` doesn't work in Next.JS server-side environment (`_middleware.ts`)”

Prisma cannot connect to Supabase database

Affects: Developers using Prisma

IntegrationsBlocks work2 sources2024-03
redirectTo ignored in Google sign-in

Affects: Developers using OAuth sign-in

Reliability & bugsBlocks work2 sources2021-06
Production user finds Supabase buggy and poorly tested

Affects: Production Supabase customer

Reliability & bugsCauses churn1 source2025-04
Enabling email auth caused rate limits on phone OTP traffic

Affects: Apps using SMS OTP

Reliability & bugsCauses churn1 source2022-12
Self-hosting dashboard stuck connecting after 12 hours of effort

Affects: First-time self-hosters

Self-hosting & upgradesCauses churn1 source2022-11
SQL editor caused data loss

Affects: Developers using the dashboard SQL editor

Reliability & bugsCauses churn1 source2022-05
React Native queries return nothing in release builds

Affects: React Native and Expo developers

MobileCauses churn1 source2021-05
Supabase MCP OAuth fails in Cursor with unrecognized client_id

Affects: Cursor users of Supabase MCP

IntegrationsBlocks work1 source2026-03
pgvector indexing needs many resources when adding rows

Affects: Teams indexing large document collections for AI

PerformanceBlocks work1 source2025-08
Project stuck in Pausing state for over a week

Affects: Developers pausing projects

Reliability & bugsBlocks work1 source2025-04
Functions deploy cannot resolve Deno workspace packages

Affects: Edge Functions developers using Deno workspaces

API & developer experienceBlocks work1 source2025-04
Custom SMTP with Office 365 or Outlook times out

Affects: Teams using Office 365 mail for auth emails

IntegrationsBlocks work1 source2025-03
No documentation for Google sign-in in Chrome extensions

Affects: Chrome extension developers

DocumentationBlocks work1 source2024-10
Studio impersonation ignores custom access token hook

Affects: Teams using auth hooks with RLS

Permissions & securityBlocks work1 source2024-07
Poor communication of auth-helpers to ssr migration and deprecation

Affects: Developers using SvelteKit with Supabase auth

DocumentationBlocks work1 source2024-04
SvelteKit docs and examples are incomplete and lead to deprecated repos

Affects: SvelteKit developers

DocumentationBlocks work1 source2024-04
PostgREST API judged too basic compared to writing SQL

Affects: Developer building a front-end-only app

API & developer experienceBlocks work1 source2024-04
Auth function error messages are not documented

Affects: Developers handling auth errors in supabase-js

DocumentationBlocks work1 source2024-03
Fetch to Supabase APIs fails in Safari with access control errors

Affects: Apps with Safari users

Reliability & bugsBlocks work1 source2024-02
CLI started requiring Docker to deploy edge functions

Affects: Developers deploying edge functions from CI or machines without Docker

API & developer experienceBlocks work1 source2023-12
SQL editor crashes the page on any incorrect query

Affects: Dashboard SQL editor users

Reliability & bugsBlocks work1 source2023-11
Magic link emails quarantined by Outlook

Affects: Apps with business Outlook users

Reliability & bugsBlocks work1 source2023-06
Log search capped at 100 results with no load more

Affects: Users diagnosing issues from logs

Reporting & analyticsBlocks work1 source2023-04
SIGNED_IN auth event fires on every tab refocus

Affects: Web app developers using supabase-js

Reliability & bugsBlocks work1 source2022-06
Vercel preview deployments need manual redirect URL additions

Affects: Teams using preview deployments

IntegrationsBlocks work1 source2022-01
Twitter OAuth signup fails for accounts without an email

Affects: Apps using Twitter login without needing email

IntegrationsBlocks work1 source2021-08
Table editor cannot create foreign key relationships

Affects: Table editor users

UI & usabilityBlocks work1 source2021-01
Server framework docs still use getUser instead of getClaims

Affects: Developers using SSR frameworks

DocumentationAnnoyance1 source2025-10
Local studio SQL query name cannot be edited

Affects: Local development users

UI & usabilityAnnoyance1 source2023-10
Dashboard is slow and renders incorrectly

Affects: Dashboard users

PerformanceAnnoyance1 source2022-05
Self-hosting story seems deprioritized
Self-hosting & upgradesAnnoyance1 source2022-05

Top 5 shown with evidence. The rest are listed by title; open any item for its evidence.

Feature requests 9

ItemAreaSeveritySupportLast seen
Wants better authorization tooling pushed through external coding platforms

A security researcher says authorization improvements would help a lot, especially if they can be enforced or surfaced through third-party AI coding platforms that integrate with Supabase.

Affects: Vibe-coded app builders

Permissions & securityBlocks work1 source2026-01

“any improvement in authz will be very helpful, especially if it can be pushed via external coding platforms”

Wants automatic resource scaling instead of manual plan switching

The user wants compute resources to scale up and down automatically rather than monitoring usage and moving to the next plan.

Affects: Teams indexing large document collections for AI

Pricing & plansBlocks work1 source2025-08

“wish the resources scale up/down automatically. Instead of having to monitor and switch to the next plan”

Custom domains for API and auth to avoid phishing-looking URLs

Google sign-in shows a random supabase.co subdomain that looks like phishing, costing conversion. The user wants custom domain aliases for the project URL.

Affects: Teams shipping consumer apps with social login

CustomizationBlocks work1 source2022-02

“I'd love to be able to set a custom domain alias for my supabase project url”

Wants a pricing tier between free and 25 dollars

The 25 dollar plan is too much for early startups and the free quota is not enough. They request a cheaper tier, also easing the 2 org by 2 project limit.

Affects: Startups and hobbyists

Pricing & plansBlocks work1 source2022-01

“Please add a new pricing tier for 10$”

Server-side API to verify access tokens and get the user

The user building a Node API server wants a firebase-admin-like way to verify an access token and get the current user in middleware.

Affects: Node.js backend developers

API & developer experienceBlocks work1 source2021-01

“Add functionality to verify the access token and get a user on the server-side”

Wants self-hosted auth in front of Postgres without being tied to Supabase

Affects: Developers wanting self-hosted auth

Self-hosting & upgradesAnnoyance1 source2024-08
Wants built-in integrations with CDNs, transactional email and domain registrars
IntegrationsAnnoyance1 source2024-04
Wants TypeScript-defined schema with generated migrations

Affects: Developers managing schema and RLS

API & developer experienceAnnoyance1 source2023-05
Allow newlines in SMS OTP template for WebOTP

Affects: PWA developers using SMS OTP

CustomizationAnnoyance1 source2021-09

Top 5 shown with evidence. The rest are listed by title; open any item for its evidence.

Workarounds 5

ItemAreaSeveritySupportLast seen
Uses Supabase only as hosted Postgres reached by own backend

To avoid RLS risk, the user stopped using the auto API and uses Supabase just as a managed Postgres that only their backend connects to.

Affects: Developers concerned about public table access

Permissions & securityBlocks work1 source2024-01

“I now just use Supabase to host a normal Postgres that only my backend connects to”

Local signup fails on null provider_id; constraint dropped as workaround

Email signup in local development errors because provider_id is null in identities. The user drops the not-null constraint as a workaround.

Affects: Local development users

Reliability & bugsBlocks work1 source2023-12

“As of today, whenever I try to sign up I see this error in my local development environment:”

redirectTo not working across auth methods, useEffect used instead

redirectTo has no effect for email/password, Google or GitHub sign-in. The user redirects manually in a useEffect hook, which they find not ideal.

Affects: Developers using supabase-js auth

Reliability & bugsBlocks work1 source2022-02

“As the title suggests, redirectTo is not working for any of my auth methods”

Realtime stopped with FOR ALL TABLES publication on PG12

Database-wide realtime publications broke after the row-level security update on PG12. The workaround is to enable tables individually.

Affects: Realtime users on PG12

Reliability & bugsBlocks work1 source2021-12

“Disable the `FULL` publication (red) and enable each table individually (green)”

Manual migrations and type generation slow development; MCP used to avoid them

Pushing migrations and generating types by hand adds a lot of time to development. The user relies on the Supabase MCP server to keep database changes fluid.

Affects: Developers building apps with AI coding tools

API & developer experienceAnnoyance1 source2025-11

“Trying to push migrations and generate types manually beforehand add so much time”

Switching reasons 4

ItemAreaSeveritySupportLast seen
Managed Postgres became costly coupled dependency after scale, migrated to Aurora/RDS

A solo-founder style user says Neon and Supabase became a tightly coupled dependency whose growing cost defeated the savings, so the team migrated to Aurora or RDS.

Affects: Bootstrapped founders and growing startups

Pricing & plansCauses churn1 source2026-07

“they ended up becoming a tightly coupled annoying dependency after scale that defeated the cost savings as they grew in costs”

Planning to leave Supabase for custom-built backend pieces

The user was already planning to leave, finding the Postgres-layer approach (PostgREST, realtime, JWT auth) more annoying than useful and preferring to build the pieces themselves.

Affects: Production Supabase customer

OtherCauses churn1 source2025-04

“I was already planning to leave them”

May develop on production or leave because local environment is unstable

Because the local development environment is unstable, the user says they will either develop directly on production or look for another solution.

Affects: Teams developing locally

Reliability & bugsCauses churn1 source2023-11

“I'll need to either develop directly on production or look for a different solution”

Cancelled Logflare/Supabase Logs after too many issues for low-volume retention

A user wanting high retention of low-volume logs found Logflare geared to graphs rather than diagnosis and cancelled a paid plan, moving to LogTail.

Affects: Small apps needing long log retention

Reporting & analyticsCauses churn1 source2023-04

“I ran into too many issues and had to cancel my subscription:”