Hasura
Hasura is an open source engine that generates a realtime GraphQL and REST API over your existing databases — a self-hosted AWS AppSync and Firebase alternative that gives you a secure, composable API with fine-grained access control instead of a hand-written backend.
What is Hasura?
Hasura is an open source engine that connects to your existing databases and instantly generates a realtime GraphQL and REST API over them, complete with fine-grained access control and event-driven webhooks. It reads your schema and exposes a single, composable API endpoint — no resolver code to write by hand.
What is Hasura best for?
Hasura is best for teams that already have a database (or several) and want a secure, production-ready API in front of it without building a backend. It fits GraphQL-first frontends, mobile apps that need realtime subscriptions, and projects that want to federate Postgres, MongoDB, and other sources behind one endpoint with permissions baked in.
What can Hasura do?
- Auto-generate GraphQL queries, mutations, and realtime subscriptions from your database schema.
- Serve the same data as REST endpoints alongside GraphQL.
- Enforce role-based, fine-grained authorization down to the row and column, tied to your auth provider (JWT, webhook, or session variables).
- Fire event triggers and webhooks on database inserts, updates, and deletes.
- Federate multiple data sources — Postgres, MongoDB, ClickHouse, MS SQL Server, plus REST/GraphQL remote schemas — behind one API.
- Extend to any data source with custom connectors written in TypeScript, Python, or Go.
Where does Hasura fall short?
Several production-grade features are gated behind the paid Enterprise Edition and Hasura Cloud rather than the free Community Edition — API rate limiting, query depth and cost limits, disabling GraphQL introspection, response caching, read replicas, and Prometheus metrics all sit on the paid side, so a self-hosted CE deployment needs its own protections in front of it.
Hasura also spans two generations. The stable v2 engine is written in Haskell; the newer v3 / DDN (Data Delivery Network) engine is a Rust rewrite with a different, project-based workflow and metadata format. v3 is the direction Hasura is investing in but is younger and less battle-tested than v2, and moving between them is a migration, not a version bump — worth checking which one your tutorials and connectors target before you commit.
Is Hasura free?
Yes — the core GraphQL Engine (Community Edition) is open source under the Apache-2.0 license and free to self-host at any scale. Paid tiers add managed hosting and enterprise features: Hasura DDN Cloud has a free plan, with Base starting at $5 per active model per month and Advanced at $30 per active model per month, plus a separately licensed Enterprise Edition for self-hosters who need caching, rate limiting, and observability.
What does Hasura replace?
Hasura stands in for managed GraphQL and API backends. It’s a self-hosted AWS AppSync alternative — you get a managed-style API over your own database without per-request AWS billing or lock-in — and a Firebase alternative for teams that want realtime data and access control over their own Postgres instead of Google’s proprietary datastore. Unlike PostgREST, which turns Postgres into a REST API, Hasura leads with GraphQL and multi-database federation; tools like Nhost actually bundle the Hasura engine into a fuller Firebase-style backend.
FAQ
Is Hasura open source? Yes. The core GraphQL Engine is licensed under Apache-2.0, for both the stable v2 (Haskell) and the newer v3 (Rust) editions. Some advanced features are reserved for the separately licensed Enterprise Edition and Hasura Cloud.
Can I self-host Hasura for free? Yes. The Community Edition runs as a Docker container (or on Kubernetes) against your own database at no cost. You supply the database, hosting, and — since rate limiting and caching are enterprise features — your own API protections.
Is Hasura a good AWS AppSync or Firebase alternative? For teams that want an instant API over a database they control, yes. It gives you GraphQL, realtime subscriptions, and fine-grained permissions without vendor lock-in or per-request pricing, though you take on the hosting and hardening that a managed service handles for you.
What do I need to run Hasura? A supported database (Postgres is the most common), Docker or Kubernetes to run the engine, and an auth mechanism (JWT or webhook) to drive its permission rules. It’s stateless, so it scales horizontally behind a load balancer.