ionic-supabase
Wire Supabase Auth and Postgres database into an Ionic Capacitor app via the @supabase/supabase-js client. Trigger when adding Supabase Auth (email, magic link, Google, Apple), Postgres queries, realtime subscriptions, or storage to an Ionic app.
Works with
---
name: ionic-supabase
description: Wire Supabase Auth and Postgres database into an Ionic Capacitor app via the @supabase/supabase-js client. Trigger when adding Supabase Auth (email, magic link, Google, Apple), Postgres queries, realtime subscriptions, or storage to an Ionic app.
license: MIT
---
# Supabase
Open-source Firebase alternative: Postgres + GoTrue auth + Realtime + Storage. Same shape as `ionic-firebase` but Postgres-flavored — pick this when your team prefers SQL, RLS, or self-hosting.
## When to consult
- **Project setup + client init**: [setup.md](references/setup.md)
- **Auth** (email, magic link, OAuth, native Apple/Google): [auth.md](references/auth.md)
- **Database** (queries, RLS, realtime): [database.md](references/database.md)
- **Per-framework integration**: [framework-snippets.md](references/framework-snippets.md)
## Hard rules
- ✅ The **anon key** is publishable — safe to ship in the bundle. Row Level Security (RLS) does the gating.
- ✅ The **service role key** is a secret — NEVER ship it; server-side only.
- ✅ **Enable RLS on every table** that holds user data. Without RLS, anon-key clients can read/write everything.
- ✅ Native OAuth (Google / Apple) on mobile uses `signInWithOAuth({ skipBrowserRedirect: true })` + your app's deep-link scheme. The default web flow doesn't return cleanly to a native app.
- ❌ Don't store JWTs in `localStorage` if you can avoid it — use `@capacitor/preferences` via the Supabase storage adapter (see setup.md).
## Library
```bash
npm install @supabase/supabase-js
```
No native plugin required — the JS client works in WKWebView / Android WebView and uses HTTPS only.More Database skills
supabase-postgres-best-practices
supabase/agent-skills
Postgres best practices maintained by Supabase, for Postgres running anywhere. Load this skill BEFORE writing or changing anything that lives in a Postgres database: creating or altering tables and columns (including choosing column types), schema design, migrations and declarative schema files, RLS policies and the tests that verify them, indexes, triggers, database functions, queues and scheduled jobs (pg_cron, pgmq), vector/semantic search (pgvector), and restoring dumps (pg_restore) or importing data. Also load it when diagnosing slow queries, high CPU, timeouts, EXPLAIN plans, connection exhaustion, locking, bloat, or rows visible to the wrong user or tenant. This is not just a performance guide — schema, migration, security, and SQL authoring tasks need these rules too, even for a one-column change or a single query.
prisma-database-setup
prisma/skills
Guides for configuring Prisma with different database providers (PostgreSQL, MySQL, SQLite, MongoDB, etc.). Use when setting up a new project, changing databases, or troubleshooting connection issues. Triggers on "configure postgres", "connect to mysql", "setup mongodb", "sqlite setup".
prisma-postgres
prisma/skills
Prisma Postgres setup and operations guidance across Console, create-db CLI, Management API, and Management API SDK. Use when creating Prisma Postgres databases, working in Prisma Console, provisioning with create-db/create-pg/create-postgres, or integrating programmatic provisioning with service tokens or OAuth.

