PostgREST
PostgREST is an open source web server that turns a PostgreSQL database directly into a RESTful API — a self-hosted Firebase and AWS AppSync alternative that skips the hand-written backend and uses your schema and database roles as the source of truth.
What is PostgREST?
PostgREST is a standalone web server that turns an existing PostgreSQL database directly into a RESTful API. It reads your tables, views, and functions and exposes them as HTTP endpoints automatically — no hand-written controllers, no ORM. Your database schema and its roles become the API’s structure and its permissions.
What is PostgREST best for?
PostgREST is best for teams that already treat Postgres as the center of their system and want a fast, thin API over it without maintaining a backend codebase. It suits database-first developers comfortable with SQL, roles, and row-level security who would rather define logic in the database than duplicate it in application code.
What can PostgREST do?
- Generate a full CRUD REST API from any PostgreSQL schema, with no code to write
- Filter, sort, paginate, and join related tables through URL query parameters
- Expose PostgreSQL functions as RPC endpoints for custom logic written in SQL or PL/pgSQL
- Authenticate with JWTs that map to native Postgres roles, enforcing access with row-level security
- Serialize JSON inside the database and stream it over the binary protocol with connection pooling for subsecond responses
- Serve a self-documenting OpenAPI description of the generated API
Where does PostgREST fall short?
- No multi-request transactions. Each HTTP request runs in its own transaction; PostgREST deliberately doesn’t support transactions that span several requests, so client-orchestrated multi-step writes aren’t a fit and would require a fundamentally different architecture.
- You must be fluent in Postgres. Permissions, validation, and business logic live in SQL, roles, and row-level security. That’s powerful, but if your team isn’t comfortable owning schema design and RLS policies, the learning curve is real.
- It’s one focused component, not a whole backend. PostgREST does REST-over-Postgres and nothing else — no bundled auth server, file storage, or GraphQL. You assemble those separately (or reach for a fuller platform), and it typically sits behind Nginx for TLS and caching.
Is PostgREST free?
Yes — PostgREST is fully free and open source under the MIT license, with no paid tier or open-core restrictions. You self-host it and pay only for the server and PostgreSQL database it runs on. Because it’s a single lightweight binary (or Docker image), the operational footprint is small.
What does PostgREST replace?
PostgREST is a self-hosted alternative to managed backend services like Firebase and AWS AppSync. Instead of a proprietary cloud database with per-read pricing, you point PostgREST at your own Postgres instance and get an instant API you fully own — no vendor lock-in and no metered request billing.
FAQ
Is PostgREST open source? Yes. PostgREST is released under the MIT license — one of the most permissive open source licenses — so you can self-host, modify, and use it commercially without restriction.
Can I self-host PostgREST for free? Yes. The software is free; you only pay for the server and PostgreSQL database it connects to. It ships as a single binary and an official Docker image, so setup is lightweight.
Is PostgREST a good Firebase alternative? For database-first teams, yes — you keep full control of your data in Postgres and avoid per-read pricing. But PostgREST only provides the API layer, so you pair it with your own auth and storage, or use a fuller platform like Supabase (which is built on PostgREST) if you want auth, storage, and a dashboard bundled in.
What do I need to run PostgREST? A PostgreSQL database and the PostgREST binary or Docker container. You define your API through the database schema and roles, and usually run it behind a reverse proxy like Nginx for TLS and caching.