| Authentication |
| Authentication methods | Hosted password, passwordless, social, and SSO flows Email/password, email magic links, Google, Microsoft, Apple, and Facebook are built in. Business and Enterprise plans add SSO. | Broad password, passwordless, phone, social, and SSO support Supports email or phone credentials, magic links and OTPs, anonymous users, many social and custom OAuth/OIDC providers, and usage-priced SAML on paid plans. Applications integrate the flows. |
| MFA and passkeys | Hosted TOTP, recovery, trusted-device, and passkey flows Enrollment, challenge, recovery codes, trusted devices, administrator MFA reset, and user-managed WebAuthn credentials are part of the hosted journey. | Plan, add-on, or setup dependent MFA APIs and experimental passkeys TOTP is included and phone MFA is a paid add-on. The application must build enrollment, challenge, factor management, and enforcement. Passkey support is experimental and requires explicit client opt-in. |
| Sessions and revocation | Hosted session controls and API revocation choices Users can inspect and revoke browser and OAuth sessions from the hosted portal. APIs can reject revoked tokens on their next introspection check; locally validated JWTs remain valid until expiry. | Available JWT and rotating refresh-token sessions Pro adds session timeouts and single-session controls. Sign-out removes refresh state, but an issued access JWT remains valid until its expiry unless the API checks session state. |
| Authorization |
| OAuth/OIDC and API protection | Ready OAuth/OIDC flows for users, APIs, and services Includes hosted authorization, Authorization Code with PKCE, refresh tokens, Client Credentials, JWT/JWKS validation, introspection, revocation, APIs, audiences, and scopes. | Plan, add-on, or setup dependent Beta OAuth 2.1/OIDC server with RLS integration Supports Authorization Code with PKCE and refresh tokens, discovery, UserInfo, and JWKS. Client Credentials is not supported; the developer must build login handoff and consent UI. |
| Roles and permissions | Low-code roles, permissions, and organizations Manage roles, direct and inherited permissions, OAuth scopes, and token claims in the identity console. Business adds organizations and multi-tenancy. | Plan, add-on, or setup dependent Build the model with Postgres RLS and custom claims Supabase documents SQL role and permission tables, a Custom Access Token Hook, and RLS policies. It is flexible, but teams design, code, test, and administer the tenant and permission model. |
| Branding |
| User self-service | Complete hosted profile and security portal Users manage profile data, credentials, linked identities, passkeys, sessions, account deletion, and a basic profile export in a branded hosted experience. | Plan, add-on, or setup dependent APIs, not a hosted account portal APIs cover profile updates, identity linking, MFA, passkeys, and OAuth grants. The application builds and maintains the profile, security, session, consent, and account-deletion experience. |
| White-label branding | White-label hosted journey on every plan Theme controls, assets, custom text and links, seven languages, and advanced per-page HTML/CSS are available on all plans across login and profile surfaces. | Available Customizable code blocks for basic Next.js auth screens Supabase UI offers copied-into-your-app password and social-auth blocks for Next.js. Teams own the code and still build the wider account, MFA, passkey, consent, and administration journey. Email branding removal starts on Pro. |
| Custom domains | Included on every plan Customers configure a custom identity domain through a simple Customer Portal wizard on Startup, Business, and Enterprise. | Plan, add-on, or setup dependent $10 monthly project add-on Available on paid plans at $10 per domain per month per project. A project can use one CNAME-based custom domain; DNS and activation changes remain part of setup. |
| Transactional email | Email templates and delivery included Seventeen editable email templates, preview, testing, and SMTP, Postmark, SendGrid, or Amazon SES delivery are managed alongside authentication. | Plan, add-on, or setup dependent Custom templates with customer-supplied production delivery Custom SMTP and a Send Email Hook are supported. The default sender is testing-only, limited to authorized addresses and currently two messages per hour. |
| Pricing |
| Pricing model | Predictable identity plans with published allowances Startup is $50/€45 monthly with 100,000 MAU, 10,000 M2M tokens, and 1,000,000 introspections. Business is $250/€225 with 500,000 MAU, 100,000 M2M tokens, and 5,000,000 introspections. Annual billing lowers the monthly rate. | Available Project subscription plus usage and add-ons Free includes 50,000 MAU. Pro and Team include 100,000, then charge $0.00325 per MAU. Compute, egress, SSO, custom domains, and phone MFA can add cost. |
| Developer experience |
| Product focus and ideal customer | Complete customer identity platform Guardhouse delivers hosted customer pages, administration, authorization, email templates and delivery, API protection, and machine access in one product. | Auth service inside a backend platform Supabase Auth can stand alone, but its main advantage is integration with a project's Postgres database, generated APIs, Storage, Realtime, and Functions. The application still owns the end-user journey. |
| User administration | Purpose-built customer administration The console and management API cover search, create, invite, update, block, reset, access assignment, anonymization, and deletion without building an admin application. | Available Project dashboard plus server-side Admin APIs Project operators can view, invite, delete, and export users in the dashboard; Admin APIs cover programmatic management. A delegated customer-admin experience requires application UI and a trusted backend. |
| Webhooks | Available User-created and user-updated webhooks Includes user lifecycle events, signed delivery, endpoint controls, secret rotation, retry settings, and delivery history. | Plan, add-on, or setup dependent Auth-flow hooks at selected execution points HTTP or Postgres hooks can run before user creation, token issuance, email/SMS sending, and selected verification attempts; some hooks require Team or Enterprise. |
| SDKs and frameworks | Available .NET and JavaScript SDKs, with selected beta SDKs Includes .NET/ASP.NET Core and React support. Node.js, React Native, and Python SDKs are beta; Python includes FastAPI and Flask helpers. | Broad official and community client ecosystem Official libraries cover JavaScript/TypeScript, Dart/Flutter, Swift, and Python; other languages are community-maintained. Supabase UI adds Next.js auth blocks, while the SSR package remains beta. |
| Migration assistance | Migration assistance and bulk import across plans Guardhouse can support discovery, field and permission mapping, bulk user import, validation, and cutover. Scope and responsibilities are agreed for the source system and rollout. | Available Documentation and plan-based support Supabase publishes migration guides and lets project owners export users from Postgres. The published Free, Pro, and Team plans do not list hands-on Auth migration. |
| Support and ecosystem | Available Direct product support with migration help Startup includes standard email support and Business adds priority support. Enterprise support, account management, and any response commitments are tailored to the customer agreement. Migration assistance is available with agreed scope. | Large ecosystem with plan-based managed support Free is community-supported, Pro adds email support, Team adds priority support and SLAs, and Enterprise lists dedicated and 24/7 support. Self-hosting is community-supported. |
| M2M and AI |
| M2M authentication | First-class OAuth for services and APIs Client Credentials issues service tokens for configured API resources, audiences, and scopes, with introspection where current revocation status matters. | Limited Backend secret keys, not an OAuth Client Credentials grant Secret project keys support servers and jobs but bypass RLS. Supabase OAuth 2.1 explicitly does not support the client_credentials grant. |
| AI agents and MCP servers | Dedicated agent and MCP resource types Guardhouse protects agent and MCP resources with Client Credentials, scopes, JWT validation, and optional introspection. | Plan, add-on, or setup dependent Beta user-delegated OAuth for MCP Supports discovery, dynamic client registration, user consent, refresh tokens, and RLS. The developer supplies the MCP server and authorization interface. |
| Deployment |
| Cloud regions | Available Managed cloud in the USA and EU Choose a primary Guardhouse Cloud region in the USA or EU. Enterprise can be customer-operated or operated by LegioSoft, with a hosting model tailored to customer requirements. | One primary region from a broad AWS catalog Each project uses one primary region. Supabase lists three general choices and 17 specific AWS regions across the Americas, Europe, and APAC. |
| Self-hosting and deployment ownership | Enterprise deployment choice Enterprise can be customer-operated as a Docker deployment or operated by LegioSoft. The hosting model and responsibilities are tailored to customer requirements; SSO, directory sync, SCIM, and BYOK are also available. | Docker self-hosting for the wider Supabase stack The operator owns provisioning, hardening, upgrades, Postgres maintenance, high availability, backups, monitoring, and uptime. Self-host support is community-based. |