How it works
Point PostgREST at a database and every table, view and function becomes an endpoint: a request such as GET /orders?status=eq.paid returns JSON. It passes the caller's role to PostgreSQL, so permissions come from database roles and row level security rather than from code in the API.
Supabase uses PostgREST for its automatic API, which is why its client library can query tables directly. The flip side is that a table without proper policies can be read by anyone holding the public key.
PostgREST pricing
Related terms
More in Databases and storage
Talking to a database