supabase
Supabase — Postgres with RLS as the auth layer
Supabase is a managed Postgres database wrapped in thin SDKs, a PostgREST data API, Auth, Storage, Realtime, and Deno Edge Functions. The one sentence that explains every footgun below:
Your authorization lives in the database (Row Level Security), not in your app code.
The browser holds a key that can hit your database directly. That is safe only because RLS gates every row. Get that wrong and you either leak everything or see nothing. Everything in this skill is downstream of that fact. You can write SQL already — what you need is Supabase's specific abstractions and where the trust boundary sits.
Use the current packages: @supabase/supabase-js v2 (v1 is security-fixes only) and
@supabase/ssr for server frameworks (it replaced the deprecated auth-helpers).