Overview
Supabase composes Postgres, GoTrue auth, Realtime and Storage behind one API — a strong default for B2B apps.
Components
- Postgres — primary datastore with RLS.
- Auth — JWT sessions, row-level policies.
- Realtime — presence and broadcast channels.
- Storage — file buckets with access policies.
RLS
policy
alter table invoices enable row level security;
create policy t on invoices
using (tenant_id = current_setting('app.tenant_id')::uuid);Set the tenant id from a verified session on every connection.