ShipTiffin vs Supabase
A self-hosted Supabase alternative
For people with many small projects, each needing a database, sign-in and file storage.
Updated
In short
ShipTiffin gives every project its own Postgres 18 database, sign-in, S3-compatible file storage and a KV store, next to its apps, on one server in your own Hetzner account. It costs $19 a month however many projects you run, and nothing pauses for inactivity.
Supabase has more: realtime, edge functions, APIs generated from your schema and a large ecosystem. On its cloud, each Pro project adds its own compute cost, and free projects pause after a week without activity.
The real differences
| ShipTiffin | Supabase | |
|---|---|---|
| Where it runs | One server in your own Hetzner account. | Supabase's cloud. It can also be self-hosted with Docker. |
| Price | $19 a month per box ($12 for the first 100 customers), plus the server at Hetzner’s price. No per-project fee. | Free for 2 active projects. Pro from $25 a month, with $10 of compute credit; each more project adds its own compute, from $10 a month. |
| Quiet projects | Never paused. A production app sleeps only if you ask it to; its data stays up. | Free projects are paused after 1 week of inactivity. Paid projects are not. |
| Database | Postgres 18 per project, with pgvector and pg_cron, and a copy-on-write branch for every preview. | Postgres per project, with pgvector and REST and GraphQL APIs generated from your schema. |
| Sign-in | Better Auth: email and password, magic links, one-time codes, passkeys, two-step sign-in, organizations. Google is tested; GitHub, Apple and 9 more are wired up. | Email and password, magic links, phone codes and social logins, with access control through Row Level Security. |
| Files | S3-compatible buckets, uploads straight from the browser, image resizing. | Object storage with a CDN and image transformations. |
| KV store | Valkey per project, with an Upstash-compatible REST endpoint | Not among its products |
| Realtime | No realtime service; a job’s progress can stream to the browser | Database changes, presence and messages over WebSockets |
| Server code | Your apps on the box (Next.js, Hono, FastAPI and more), plus queues, crons and durable workflows. | Edge Functions: serverless TypeScript deployed globally. |
| App hosting | Included | Host your apps elsewhere |
| Restore to a moment | Included: Postgres to any second of the last 7 days (every project on the box together). | An add-on: about $100 a month per project for 7 days. |
| Reaching the database | Only from apps on the box, or from your computer through an SSH tunnel on a box you set up yourself. | From anywhere, including the browser through its client libraries and APIs. |
| Licence | AGPL-3.0 (the SDK is Apache-2.0) | Apache-2.0 |
What 1, 5 and 20 projects cost
Each project with its own database. A month in US dollars before tax. The ShipTiffin column also hosts the apps.
| Supabase Pro | ShipTiffin | |
|---|---|---|
| 1 project | $25: the first Micro project is covered by the credit | about $29: ShipTiffin $19, Hetzner CX23 (2 vCPU, 4 GB) about $10 |
| 5 projects | $65: $25, plus $10 for each of 4 more Micro projects | about $32: ShipTiffin $19, Hetzner CX33 (4 vCPU, 8 GB) about $13 |
| 20 projects | $215: $25, plus $10 for each of 19 more Micro projects | about $41: ShipTiffin $19, Hetzner CX43 (8 vCPU, 16 GB) about $22 |
| Restore to a moment, 7 days | About $100 a month for each project that has it | Included |
| Billed on top | Usage past each quota: more than 100,000 monthly active users, 8 GB of disk per project, 250 GB of egress. | Nothing from us. Hetzner includes 20 TB of traffic a month in Europe (at least 1 TB in the US) and charges past that. |
What ShipTiffin doesn't have
If your app depends on one of these, stay on Supabase or plan the work to replace it.
Realtime
No database change feeds, presence or broadcast channels. The box can stream a job's or workflow's progress to the page; for anything else, run a WebSocket server as one of your apps.APIs generated from your schema
No REST or GraphQL layer over the database. Your app's server code queries Postgres with DATABASE_URL, the way a Next.js route handler or server action already does.Client libraries in the browser
Supabase’s client calls are not understood here. Sign-in has its own SDK, files speak the S3 API, and data goes through your app. Sign-in in your app.A database reachable from anywhere
Postgres and KV answer only apps on the box for now; a public address per project is planned. Databases from outside the box.Phone sign-in and every provider tested
No SMS codes. Google is tested end to end; the other providers are wired up but not tested yet. Sign-in limits.Many servers and regions
Everything runs on one server in one place. A hardware fault means downtime until it is back, and a point-in-time restore takes every project back together.
Which one fits
ShipTiffin is the better fit when
- you have many small projects and a per-project bill;
- you want the apps and their backend on one server you own;
- your projects go quiet for weeks and must not pause;
- your app talks to its data from server code;
- you want restore to a moment without paying for it per project.
Supabase is the better fit when
- you use realtime, edge functions or the generated APIs;
- your frontend talks to the database from the browser;
- you want a managed database with no server of your own at all;
- you need several regions, or room to grow past one server;
- you want a large ecosystem of guides, integrations and AI app builders.
Moving from Supabase
It is a code change, not a settings change: plan it one project at a time.
Bring the data
Every project already has its own Postgres; add extensions such as pgvector intiffin.config.ts. On a box you set up withtiffin up,tiffin db tunnellets you load apg_dumpfrom your computer. A managed box closes SSH after setup, so the tunnel doesn’t reach it. From your computer.Swap the client calls
Replace Supabase client queries with your own server code using DATABASE_URL, and keep row-level security where you rely on it.Set up sign-in
Addservices: { auth: {} }and use@shiptiffin/sdk/auth. Users live in the project’s own database. There is no importer for Supabase Auth users, so plan how existing users sign in again. Sign-in.Copy the files
Buckets speak the S3 API ats3.<your domain>, so an S3 tool or SDK can copy files across. Apps getS3_*variables without setup. Files.
Questions
Why not self-host Supabase?
You can: it is open source. Supabase’s Docker guide asks for at least 4 GB of memory and 2 cores, runs about a dozen services, and leaves secrets, HTTPS, email and updates to you (self-hosting docs, read 10 October 2026). ShipTiffin runs the database, sign-in, files and KV next to your apps, with updates and off-server backups done for you.
Does the database pause when nobody uses it?
No. Postgres stays up. A production app sleeps only if you set sleepAfter, and wakes on the next request; previews sleep after 15 idle minutes. Sleep and wake.
Can one project use up the server?
Give it a limit and it can’t. A project’s limit holds its apps, its share of Postgres, its KV memory and its builds; a storage limit caps its database and files together. Sharing the box.
Is row-level security available?
Yes, it is plain Postgres. The box also adds a helper that keys row-level security on the signed-in user’s organization. Postgres.
How do backups compare?
Every box backs up daily and every 6 hours, and Postgres can go back to any second of the last 7 days. On a managed box the backups are copied off the server every 6 hours, encrypted with a key only you hold, and kept 30 days. A restore to a moment takes every project back together. Backups.
Put your next project on your own box.
Setup takes about five minutes in your own Hetzner account. 14-day money-back.