diff --git a/apps/reference/docs/about.md b/apps/reference/docs/about.md
deleted file mode 100644
index 5aebf386295..00000000000
--- a/apps/reference/docs/about.md
+++ /dev/null
@@ -1,9 +0,0 @@
----
-id: about
-title: Introduction
-description: 'What is Supabase?'
-slug: /
-hide_table_of_contents: true
----
-
-Guides here
diff --git a/apps/reference/docs/about.mdx b/apps/reference/docs/about.mdx
new file mode 100755
index 00000000000..13ed94d8911
--- /dev/null
+++ b/apps/reference/docs/about.mdx
@@ -0,0 +1,155 @@
+---
+id: about
+title: Introduction
+description: 'What is Supabase?'
+slug: /
+hide_table_of_contents: true
+---
+
+import ThemedImage from '@theme/ThemedImage'
+import AngularLogo from '@site/static/img/libraries/angular-icon.svg'
+import ExpoLogo from '@site/static/img/libraries/expo-icon.svg'
+import DartLogo from '@site/static/img/libraries/dart-icon.svg'
+import JavascriptLogo from '@site/static/img/libraries/javascript-icon.svg'
+import NextjsDarkLogo from '@site/static/img/libraries/nextjs-dark-icon.svg'
+import NextjsLightLogo from '@site/static/img/libraries/nextjs-light-icon.svg'
+import ReactLogo from '@site/static/img/libraries/react-icon.svg'
+import SolidJSLogo from '@site/static/img/libraries/solidjs-icon.svg'
+import RedwoodJsLogo from '@site/static/img/libraries/redwoodjs-icon.svg'
+import SvelteLogo from '@site/static/img/libraries/svelte-icon.svg'
+import VuejsLogo from '@site/static/img/libraries/vuejs-icon.svg'
+
+import useBaseUrl from '@docusaurus/useBaseUrl'
+import Link from '@docusaurus/Link'
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+const frameworks = [
+ {
+ name: 'Angular',
+ logo: AngularLogo,
+ href: '/docs/guides/with-angular',
+ },
+ {
+ name: 'Expo',
+ logo: ExpoLogo,
+ href: 'https://github.com/supabase/supabase/tree/master/examples/todo-list/expo-todo-list',
+ },
+ { name: 'Flutter', logo: DartLogo, href: '/docs/guides/with-flutter' },
+ {
+ name: 'JavaScript',
+ logo: JavascriptLogo,
+ href: 'https://github.com/supabase/supabase/tree/master/examples/auth/javascript-auth',
+ },
+ {
+ name: 'Next.js',
+ themed: true,
+ logo: {
+ dark: '/img/libraries/nextjs-dark-icon.svg',
+ light: '/img/libraries/nextjs-light-icon.svg',
+ },
+ href: '/docs/guides/with-nextjs',
+ },
+ { name: 'React', logo: ReactLogo, href: '/docs/guides/with-react' },
+ { name: 'RedwoodJS', logo: RedwoodJsLogo, href: '/docs/guides/with-redwoodjs' },
+ { name: 'SolidJS', logo: SolidJSLogo, href: '/docs/guides/with-solidjs' },
+ { name: 'Svelte', logo: SvelteLogo, href: '/docs/guides/with-svelte' },
+ { name: 'Vue', logo: VuejsLogo, href: '/docs/guides/with-vue-3' },
+]
+
+Supabase is an open source Firebase alternative providing all the backend features you need to build a product.
+You can use it completely, or just the features you need.
+
+[Start a project](https://app.supabase.com) with the hosted platform or learn how to [host Supabase](/docs/guides/hosting/overview) yourself.
+
+## Learn about features
+
+
+
+ {/* Database */}
+
+
+
+
Database
+
A dedicated, scalable Postgres database.
+
+
+
+ {/* API */}
+
+
+
+
Auto-generated APIs
+
Instantly generate APIs for your database.
+
+
+
+ {/* Functions */}
+
+
+
+
Edge Functions
+
Server-side functions, distributed globally.
+
+
+
+ {/* Auth */}
+
+
+
+
Auth
+
User management with Row Level Security.
+
+
+
+ {/* Storage */}
+
+
+
+
File Storage
+
Store, organize, and serve large files.
+
+
+
+ {/* Observability */}
+
+
+
+
Observability
+
Monitor and debug your infrastucture.
+
+
+
+ {/* */}
+
+
+
+## Start with a framework
+
+Supabase is just Postgres, which makes it compatible with a large number of tools and frameworks.
+
+
+
+ {frameworks.map((x) => (
+
+
+
+ {x.logo && !x.themed ? (
+
+ ) : (
+
+ )}
+
{x.name}
+
+
+
+ ))}
+
+
diff --git a/apps/reference/docs/architecture.mdx b/apps/reference/docs/architecture.mdx
new file mode 100755
index 00000000000..c65037a76f0
--- /dev/null
+++ b/apps/reference/docs/architecture.mdx
@@ -0,0 +1,17 @@
+---
+id: architecture
+title: Architecture
+description: 'Supabase design and architecture'
+# hide_table_of_contents: true
+---
+
+Supabase is open source. Wherever possible, we use and support existing tools rather than developing from scratch.
+We choose open source tools which are scalable and we make them simple to use.
+
+
+
+Supabase is not a 1-to-1 mapping of Firebase. While we are building many of the features that Firebase offers, we are not going about it the same way.
+
+Our technological choices are quite different from Firebase. Everything we use is open source. Wherever possible, we use and support existing tools rather than developing from scratch.
+
+Most notably, we use Postgres rather than a NoSQL store. This choice was deliberate. We believe that no other database offers the scalability and functionality required to compete with Firebase.
diff --git a/apps/reference/docs/company/aup.md b/apps/reference/docs/company/aup.md
new file mode 100644
index 00000000000..5e02cae3a8a
--- /dev/null
+++ b/apps/reference/docs/company/aup.md
@@ -0,0 +1,52 @@
+---
+id: aup
+title: Acceptable Use Policy
+---
+
+`Last Modified: 15 April 2021`
+
+This Acceptable Use Policy (this “Policy”) describes prohibited uses of the web services offered by Supabase, Inc. and its affiliates (the “Services”) and the website located at https://supabase.com (the “Supabase Site”). The examples described in this Policy are not exhaustive. We may modify this Policy at any time by posting a revised version on the Supabase Site. By using the Services or accessing the Supabase Site, you agree to the latest version of this Policy. If you violate the Policy or authorize or help others to do so, we may suspend or terminate your use of the Services.
+
+## No Illegal, Harmful, or Offensive Use or Content
+
+You may not use, or encourage, promote, facilitate or instruct others to use, the Services or Supabase Site for any illegal, harmful, fraudulent, infringing or offensive use, or to transmit, store, display, distribute or otherwise make available content that is illegal, harmful, fraudulent, infringing or offensive. Prohibited activities or content include:
+
+- **Illegal, Harmful or Fraudulent Activities.** Any activities that are illegal, that violate the rights of others, or that may be harmful to others, our operations or reputation, including disseminating, promoting or facilitating child pornography, offering or disseminating fraudulent goods, services, schemes, or promotions, make-money-fast schemes, ponzi and pyramid schemes, phishing, or pharming.
+- **Infringing Content.** Content that infringes or misappropriates the intellectual property or proprietary rights of others.
+- **Offensive Content.** Content that is defamatory, obscene, abusive, invasive of privacy, or otherwise objectionable, including content that constitutes child pornography, relates to bestiality, or depicts non-consensual sex acts.
+- **Harmful Content.** Content or other computer technology that may damage, interfere with, surreptitiously intercept, or expropriate any system, program, or data, including viruses, Trojan horses, worms, time bombs, or cancelbots.
+- **Platform compliance.** Any activities that are deemed unacceptable by the platforms used by the Supabase Site and Services, including [AWS](https://aws.amazon.com/aup/).
+
+## No Security Violations
+
+You may not use the Services to violate the security or integrity of any network, computer or communications system, software application, or network or computing device (each, a “System”). Prohibited activities include:
+
+- **Unauthorized Access.** Accessing or using any System without permission, including attempting to probe, scan, or test the vulnerability of a System or to breach any security or authentication measures used by a System.
+- **Interception.** Monitoring of data or traffic on a System without permission.
+- **Falsification of Origin.** Forging TCP-IP packet headers, e-mail headers, or any part of a message describing its origin or route. The legitimate use of aliases and anonymous remailers is not prohibited by this provision.
+
+## No Network Abuse
+
+You may not make network connections to any users, hosts, or networks unless you have permission to communicate with them. Prohibited activities include:
+
+- **Monitoring or Crawling.** Monitoring or crawling of a System that impairs or disrupts the System being monitored or crawled.
+- **Denial of Service (DoS).** Inundating a target with communications requests so the target either cannot respond to legitimate traffic or responds so slowly that it becomes ineffective.
+- **Intentional Interference.** Interfering with the proper functioning of any System, including any deliberate attempt to overload a system by mail bombing, news bombing, broadcast attacks, or flooding techniques.
+- **Operation of Certain Network Services.** Operating network services like open proxies, open mail relays, or open recursive domain name servers.
+- **Avoiding System Restrictions.** Using manual or electronic means to avoid any use limitations placed on a System, such as access and storage restrictions.
+
+## No E-Mail or Other Message Abuse
+
+You will not distribute, publish, send, or facilitate the sending of unsolicited mass e-mail or other messages, promotions, advertising, or solicitations (like “spam”), including commercial advertising and informational announcements. You will not alter or obscure mail headers or assume a sender’s identity without the sender’s explicit permission. You will not collect replies to messages sent from another internet service provider if those messages violate this Policy or the acceptable use policy of that provider.
+
+## Our Monitoring and Enforcement
+
+We reserve the right, but do not assume the obligation, to investigate any violation of this Policy or misuse of the Services or Supabase Site. We may:
+
+- investigate violations of this Policy or misuse of the Services or Supabase Site; or
+- remove, disable access to, or modify any content or resource that violates this Policy or any other agreement we have with you for use of the Services or the Supabase Site.
+
+We may report any activity that we suspect violates any law or regulation to appropriate law enforcement officials, regulators, or other appropriate third parties. Our reporting may include disclosing appropriate customer information. We also may cooperate with appropriate law enforcement agencies, regulators, or other appropriate third parties to help with the investigation and prosecution of illegal conduct by providing network and systems information related to alleged violations of this Policy.
+Reporting of Violations of this Policy
+
+If you become aware of any violation of this Policy, you will immediately notify us and provide us with assistance, as requested, to stop or remedy the violation. To report any violation of this Policy, please contact us at support@supabase.io.
diff --git a/apps/reference/docs/company/privacy.md b/apps/reference/docs/company/privacy.md
new file mode 100644
index 00000000000..2d5e6ab833b
--- /dev/null
+++ b/apps/reference/docs/company/privacy.md
@@ -0,0 +1,292 @@
+---
+id: privacy
+title: Privacy Policy
+---
+
+`Last modified: 27 March 2021`
+
+Thank you for your interest in Supabase, Inc., ("**_Supabase_**," "**_we_**", "**_our_**" or "**_us_**"). Supabase provides a suite of open source tools, stitched together to build a seamless developer experience. This Privacy Notice explains how information about you, that directly identifies you, or that makes you identifiable ("**_personal information_**") is collected, used and disclosed by Supabase in connection with our website at [supabase.com](https://supabase.com) (the "**_Site_**") and our services offered in connection with the Site (collectively with the Site, the "**_Service_**").
+
+We may also provide you with additional privacy notices or disclosures where the scope of the inquiry, request, or personal information we require falls outside the scope of this Privacy Notice. In that case, the additional Privacy Notice or disclosures will govern how we may process the information you provide at that time. Please note that this Privacy Notice does not cover or apply to our processing of information about our employees or contractors.
+
+This Policy explains how we use your personal information when we act as a data controller. As far as you use our Service as a natural person, we are the controller of your personal information. We are responsible for, and control, the processing of your personal information.
+
+Wherever our customers use our Service to submit, manage, or otherwise use content relating to our customers’ end users ("**_Customer Data_**") during the provision of our Service, we have contractually committed ourselves to only process such information on behalf and under the instruction of the respective customer, who is the data controller. This Privacy Notice does not apply to such processing and we recommend you read the Privacy Notice of the respective customer, if their processing concerns your personal information.
+
+## Region-specific Disclosures
+
+- **California - Your California Privacy Rights:** If you are a California resident, California Civil Code Section 1798.83 permits you to request information regarding the disclosure of personal information to third parties for their direct marketing purposes during the immediately preceding calendar year. Note we do not share your personal information with third parties for their own marketing purposes.
+- **Nevada:** Chapter 603A of the Nevada Revised Statutes permits a Nevada resident to opt out of future sales of certain covered information that a website operator has collected or will collect about the resident. Note we do not sell your personal information within the meaning of Chapter 603A. However, if you would still like to submit such a request, please contact us at support@supabase.io.
+- **European Economic Area, United Kingdom or Switzerland:** If you are located in the European Economic Area ("**_EEA_**"), United Kingdom or Switzerland, or otherwise engage with Supabase’s European operations, please see the **Privacy Disclosures for the European Economic Area, United Kingdom and Switzerland** for additional European-specific privacy disclosures, including what constitutes your personal information, the lawful bases we rely on to process your personal information, how we use cookies when you access our Sites from the EEA, UK or Switzerland and your rights in respect of your personal information.
+
+**Note for International Visitors:** Personal information may be transferred to, stored and processed in a country other than the one in which it was collected. For example, the Sites are primarily hosted in and provided from the United States. Please note the country to which personal data is transferred may not provide the same level of protection for personal information as the country from which it was transferred.
+
+## 1. Information we collect and our use
+
+We collect personal information in connection with your visits to and use of the Service. This collection includes information that you provide in connection with the Service, information from third parties, and information that is collected automatically such as through the use of cookies and other technologies.
+
+### Information That You Provide
+
+We collect personal information from you. The categories of information we collect can include:
+
+- **_Registration information._** We collect personal and/or business information that you provide when you register for an account at the Site. This information may include your name, email address, GitHub username. We use this information to administer your account, provide you with the relevant services and information, communicate with you regarding your account, the Site and for customer support purposes.
+- **_Information collected through the Use of the Service._** After registration, you may create, upload or transmit files, documents, videos, images, data or information as part of your use of the Service (collectively, "**_User Content_**"). User Content and any information contained in the User Content, including personal information you may have included, is stored and collected as part of the Service. You have full control of the information included in the User Content.
+- **_Payment information._** If you make a purchase or payment on the Site, such as for a subscription, we collect transactional information provided in connection with your purchase or payment. Please note that we use third party payment processors, including Stripe, to process payments made to us. As such, we do not retain any personally identifiable financial information such as credit card numbers. Rather, all such information is provided directly by you to our third-party processor. The payment processor’s use of your personal information is governed by their privacy notice. To view Stripe’s privacy notice, please visit: .
+- **_Communications._** If you communicate with us through any paper or electronic form, we may collect your name, email address, mailing address, phone number, or any other personal information you choose to provide to us. We use this information to investigate and respond to your inquiries, and to communicate with you, to enhance the services we offer to our users and to manage and grow our organization. If you register for our newsletters or updates, we may communicate with you by email. To unsubscribe from promotional messages, please follow the instructions within our messages and review the **Control Over Your Information** section below. If you become a contributor, we may also collect your GitHub name and feature you on our website.
+- **_Inquiries and Feedback._** If you contact us, we will collect the information that you provide us, such as your contact information and the contents of your communication with us.
+
+You are free to choose which personal information you want to provide to us or whether you want to provide us with personal information at all. However, some information, such as your name, address, payment transaction information, and information on your requested Services may be necessary for the performance of our contractual obligations.
+
+### Information from Third Party Sources
+
+We may receive personal information about you from our business partners and service providers and combine this information with other data we collect from you. The third-parties may include website and service operators, payment processors, marketing partners, and shipping providers. The information may include contact information, demographic information, information about your communications and related activities, and information about your orders. We may use this information to administer and facilitate our services, your orders and our marketing activities.
+
+- **_Single Sign-On._** We use single sign-on ("**SSO**") such as GitHub to allow a user to authenticate their account using one set of login information. We will have access to certain information from those third parties in accordance with the authorization procedures determined by those third parties, including, for example, your name, username, email address, language preference, and profile picture. We use this information to operate, maintain, and provide to you the features and functionality of the Service. We may also send you service-related emails or messages (e.g., account verification, purchase confirmation, customer support, changes or updates to features of the Site, technical and security notices).
+- **_Social Media._** When you interact with our Site through various social media, such as when you click on the social media icon on the Site, follow us on a social media site, or post a comment to one of our pages, we may receive information from the social network such as your profile information, profile picture, gender, user name, user ID associated with your social media account, age range, language, country, and any other information you permit the social network to share with third parties. The data we receive is dependent upon your privacy settings with the social network. We use this information to operate, maintain, and provide to you the features and functionality of the Service, as well as to communicate directly with you, such as to send you email messages about products and services that may be of interest to you.
+- **_Employment Applications._** If you apply for employment, we collect your contact and demographic information, educational and work history, employment interests, information obtained during interviews and any other information you choose to provide. We use the information provided to evaluate your candidacy for employment, to communicate with you during the application process and to facilitate the onboarding process.
+- **_Information from Other Sources._** We may obtain information from other sources, including through third-party information providers, our shareholders, customers, or through transactions such as mergers and acquisitions. We may combine this information with other information we collect from or about you. In these cases, our Privacy Notice governs the handling of the combined personal information. We use this information to operate, maintain, and provide to you the features and functionality of the Service, as well as to communicate directly with you, such as to send you email messages about products and services that may be of interest to you.
+
+### Other Uses of Personal Information
+
+In addition to the uses described above, we may collect and use personal information for the following purposes:
+
+- For our business activities, including to operate the Service and to provide you with the features and functionality of the Service;
+- To communicate with you and respond to your requests, such as to respond to your questions, contact you about changes to the Service, and communicate about account related matters;
+- For marketing and advertising purposes, such as to market to you or offer you with information and updates on our products or services we think that you may be interested in. While we may use your personal information in this manner, please note that we do not use User Content to serve you ads, and we will never share User Content with any third parties for marketing or advertising purposes, unless you have explicitly submitted it to us for that purpose;
+- For analytics and research purposes;
+- To enforce our **Terms of Service**, to resolve disputes, to carry out our obligations and enforce our rights, and to protect our business interests and the interests and rights of third parties;
+- To comply with contractual and legal obligations and requirements;
+- To fulfill any other purpose for which you provide personal information; and
+- For any other lawful purpose, or other purpose that you consent to.
+
+## 2. How we share personal information
+
+We may share your personal information in the instances described below. For further information on your choices regarding your information, see **Control Over Your Information**.
+
+- We may share your personal information with third-party service providers or business partners who help us deliver or improve our Site or services, or who perform services on our behalf, which are subject to reasonable confidentiality terms, and may include processing payments, providing web hosting services, or providing analytics.
+- Third parties as required by law or subpoena or if we reasonably believe that such action is necessary to (a) comply with the law and the reasonable requests of law enforcement; (b) to enforce our **Terms of Service** or other agreements or to protect the security or integrity of the Supabase services, including to prevent harm or financial loss, or in connection with preventing fraud or illegal activity; and/or (c) to exercise or protect the rights, property, or personal safety of Supabase, our Customers, visitors, or others.
+- We may share with other companies and brands owned or controlled by Supabase, and other companies owned by or under common ownership as Supabase. These companies will use your personal information in the same way as we can under this Privacy Notice.
+- We may transfer any information we collect in the event we sell or transfer all or a portion of our business or assets (including any shares in the company) or any portion or combination of our products, services, businesses and/or assets. Should such a transaction occur (whether a divestiture, merger, acquisition, bankruptcy, dissolution, reorganization, liquidation, or similar transaction or proceeding), we will use reasonable efforts to ensure that any transferred information is treated in a manner consistent with this Privacy Notice.
+- We may disclose your information publicly or with another third party with your prior authorization.
+- With others in an aggregated or otherwise anonymized form that does not reasonably identify you directly as an individual.
+
+## 3. Control over your information
+
+### Email Communications
+
+From time to time, we may send you emails regarding updates to our Service, products or services, notices about our organization, or information about products/services we offer (or promotional offers from third parties) that we think may be of interest to you. If you wish to unsubscribe from such emails, simply click the "unsubscribe link" provided at the bottom of the email communication. Note that you cannot unsubscribe from certain services-related email communications (e.g., account verification, confirmations of transactions, technical or legal notices).
+
+### Modifying Account Information
+
+If you have an online account with us, you have the ability to modify certain information in your account (e.g., your contact information) through the account options provided on the Site. If there is personal information in your User Content, you can use the features and functionality of the Service to edit or delete the personal information or User Content. Not all personal information is maintained in a format that you can access or change. If you would like to request access to, or correction or deletion of personal information, you may send your request to us at the email provided below. We will review your request and may require you to provide additional information to identify yourself, but we do not promise that we will be able to satisfy your request.
+
+## 4. How We Use Cookies and Other Tracking Technology to Collect Information
+
+We, and our third-party partners, automatically collect certain types of usage information when you visit our Site, read our emails, or otherwise engage with us. We typically collect this information through a variety of tracking technologies, including cookies, web beacons, embedded scripts, location-identifying technologies, file information, and similar technology (collectively, "**tracking technologies**").
+
+We, and our third-party partners, use tracking technologies to automatically collect usage and device information, such as:
+
+- Information about your device and its software, such as your IP address, browser type, Internet service provider, device type/model/manufacturer, operating system, date and time stamp, and a unique ID that allows us to uniquely identify your browser or your account (including, for example, a persistent device identifier), and other such information.
+- When you access our sites from a mobile device, we may collect unique identification numbers associated with your device or our mobile application mobile carrier, device type, model and manufacturer, mobile device operating system brand and model, and depending on your mobile device settings, we may be able to approximate a device’s location by analyzing other information, like an IP address.
+- Information about the way you access and use our services, for example, the site from which you came and the site to which you are going when you leave our services, the pages you visit, the links you click, whether you open emails or click the links contained in emails, whether you access the services from multiple devices, and other actions you take on the Sites.
+
+We use the data collected through tracking technologies to: (a) remember information so that you will not have to re-enter it during your visit or the next time you visit the site; (b) provide custom content and information; (c) identify you across multiple devices; (d) provide and monitor the effectiveness of our services; (e) monitor aggregate metrics such as total number of visitors, traffic, usage, and demographic patterns on our Site; (f) diagnose or fix technology problems; and (g) to provide, plan for, and enhance our services.
+
+**Note we do not engage in online targeted advertising.**
+
+**Cookies and Other Tracking Technologies Opt-Out.** Depending on your browser or mobile device, you may be able to set your browser to delete or notify you of cookies and other tracking technology by actively managing the settings on your browser or mobile device.
+
+If you would prefer not to accept cookies, most browsers will allow you to: (i) change your browser settings to notify you when you receive a cookie, which lets you choose whether or not to accept it; (ii) disable existing cookies; or (iii) set your browser to automatically reject cookies. Please note that doing so may negatively impact your experience using the sites, as some features and services on our sites may not work properly. Depending on your mobile device and operating system, you may not be able to delete or block all cookies. You may also set your e-mail options to prevent the automatic downloading of images that may contain technologies that would allow us to know whether you have accessed our e-mail and performed certain functions with it.
+
+## 5. Data Retention and Security
+
+We will retain your personal information for the length of time needed to fulfill the purposes outlined in this Privacy Notice, unless a longer retention period is required or permitted by law. We store data on servers in the U.S. or any other country in which Supabase or its affiliates, subsidiaries, agents or contractors maintain facilities. If you are located in the European Union or other regions with laws governing data collection and use that may differ from U.S. law, please note that your personal information may be transferred to a country and jurisdiction that does not have the same data protection laws as your jurisdiction. When you register for use with Supabase you have the option of where you store your information and we will not transfer it without providing information to you in advance.
+
+Supabase cares about the security of your information and uses commercially reasonable physical, technical and organizational measures designed to preserve the integrity and security of all information we collect. However, no security system is impenetrable, and we cannot guarantee the security of our systems 100%. In the event that any information under our control is compromised as a result of a breach of security, we will take reasonable steps to investigate the situation and where appropriate, notify those individuals whose information may have been compromised and take other steps, in accordance with any applicable laws and regulations.
+
+## 6. Links to Third-Party Websites and Services
+
+For your convenience, our Site may provide links to third-party websites or services that we do not own or operate. We are not responsible for the practices employed by any websites or services linked to or from the services, including the information or content contained within them. Your browsing and interaction on any other website or service are subject to the applicable third party’s rules and policies, not ours. If you are using a third-party website or service, you do so at your own risk. We encourage you to review the privacy policies of any site or service before providing any personal information.
+
+## 7. Children’s Privacy
+
+Our services are not intended for children under the age of 13. We do not knowingly solicit or collect personal information from children under the age of 13. If we learn that any personal information has been collected inadvertently from a child under 13, we will delete the information as soon as possible. If you believe that we might have collected information from a child under 13, please contact us at privacy@supabase.io.
+
+## 8. Changes to Privacy Notice
+
+We reserve the right to change this Privacy Notice from time to time in our sole discretion. We will notify you about material changes in the way we treat personal data by sending a notice to the primary email address specified in your Supabase account and/or by placing a prominent notice on our Site. It is your responsibility to review this Privacy Notice periodically. When we do change the Privacy Notice, we will also revise the "last modified" date.
+
+## 9. Contact Us
+
+For additional inquiries about this Privacy Notice, please send us an email at privacy@supabase.io.
+
+This Privacy Notice was last modified on 27th March 2021
+
+## Privacy disclosures for the European economic area, United Kingdom, and Switzerland.
+
+While we are primarily based in the United States, Supabase maintains operations in Europe and may direct our services to individuals located in the European Economic Area ("**_EEA_**"), United Kingdom and Switzerland, including through our Site [supabase.com](/) (collectively, our "**_European Services_**"). The following disclosures ("**_Privacy Disclosures_**") apply to our processing of personal data in connection with our European Services.
+
+Supabase, Inc. is the data controller responsible for the processing of personal data in connection with our European Services. This means that we determine and are responsible for how your personal information is used.
+
+**Personal Data:** When we use the term "personal data" in this section, we mean information relating to an identified or identifiable natural person.
+
+### 1. Personal data we collect from you when you use the Supabase European Services, and how we use it.
+
+We collect the categories of personal data that you voluntarily submit directly to us when you use the European Services, as set forth in our Privacy Notice under the section entitled **Information We Collect and Our Use**. The table at **Annex 1** sets out in detail the categories of personal data we collect about you and how we use that information when you use the European Services, as well as the legal basis which we rely on to process the personal information and recipients of that personal information.
+
+### 2. Information we collect about you automatically.
+
+We also automatically collect personal information indirectly about how you access and use the European Services, and information about the device you use to access the European Services. For example, we may collect:
+
+(a) information about the features you use and the pages you view on the European Services;
+
+(b) information about your device (such as your IP address, device identifier, device type, model and manufacturer); and
+
+(c) information about your usage patterns (such as how often you use the Supabase European Services and your language settings).
+
+We use this information to provide you the features and functionality of the European Services, to monitor and improve the European Services and to develop new services.
+
+The table at **Annex 2** sets out further information about the categories of personal information we collect about you automatically and how we use that information. The table also lists the legal basis which we rely on to process the personal information and recipients of that personal information.
+
+We may link or combine the personal information we collect about you and the information we collect automatically.
+
+We may anonymise and aggregate any of the personal information we collect (so that it does not directly identify you). We may use anonymised information for purposes that include testing our IT systems, research, data analysis, improving the Supabase European Services. We may also share such anonymised and aggregated information with others.
+
+### 3. How long will we store your personal information
+
+We will usually store the personal information we collect about you for no longer than necessary for the purposes set out in Annex 1 and Annex 2, in accordance with our legal obligations and legitimate business interests.
+
+The criteria used to determine the period for which personal information about you will be retained varies depending on the legal basis under which we process the personal information:
+
+1. **Legitimate Interests.** Where we are processing personal information based on our legitimate interests, we generally will retain such information for a reasonable period of time based on the particular interest, taking into account the fundamental interests and the rights and freedoms of data subjects.
+2. **Consent.** Where we are processing personal information based on your consent, we generally will retain the information until you withdraw your consent, or otherwise for the period of time necessary to fulfill the underlying agreement with you or provide you with the applicable service for which we process that personal information.
+3. **Contract.** Where we are processing personal information based on contract, we generally will retain the information for the duration of the contract plus some additional limited period of time that is necessary to comply with law or that represents the statute of limitations for legal claims that could arise from the contractual relationship.
+4. **Legal Obligation.** Where we are processing personal information based on a legal obligation, we generally will retain the information for the period of time necessary to fulfill the legal obligation.
+5. **Legal Claim.** We may need to apply a "legal hold" that retains information beyond our typical retention period where we face threat of legal claim. In that case, we will retain the information until the hold is removed, which typically means the claim or threat of claim has been resolved.
+
+In all cases, in addition to the purposes and legal bases, we consider the amount, nature and sensitivity of the personal information, as well as the potential risk of harm from unauthorized use or disclosure of your personal information.
+
+### 4. Recipients of Personal Information
+
+In addition to the recipients listed in Annexes 1 and 2, we may also share your personal information with the following (as required in accordance with the uses set out in Annexes 1 and 2):
+
+1. **Service providers and advisors**: we may share your personal information with third party vendors and other service providers that perform services for us or on our behalf, which may include providing professional services, such as legal and accounting services, mailing, email or chat services, fraud prevention, web hosting, or providing analytic services.
+2. **Affiliates**. Other companies owned by or under common ownership as Supabase, including our subsidiaries (i.e., any organization we own or control) and our ultimate holding company (i.e., any organization that owns or controls us) and any subsidiaries it owns. These companies will use your personal information in the same way as we can under these Privacy Disclosures.
+3. **Purchasers and third parties in connection with a business transaction**: your personal information may be disclosed to third parties in connection with a transaction, such as a merger, sale of assets or shares, reorganization, financing, change of control or acquisition of all or a portion of our business.
+4. **Law enforcement, regulators and other parties for legal reasons**: we may share your personal information with third parties as required by law or if we reasonably believe that such action is necessary to (i) comply with the law and the reasonable requests of law enforcement; (ii) detect and investigate illegal activities and breaches of agreements, including our Terms; and/or (iii) exercise or protect the rights, property, or personal safety of Supabase, its users or others.
+
+### 5. Marketing and Advertising
+
+From time to time we may contact you with information about our services, including sending you marketing messages and asking for your feedback on our services. Most marketing messages we send will be by email. For some marketing messages, we may use personal information we collect about you to help us determine the most relevant marketing information to share with you.
+
+We will only send you marketing messages if you have given us your consent to do so. You can withdraw your consent at a later date by clicking on the unsubscribe link at the bottom of our marketing emails or by updating your preferences via your account on the Site.
+
+### 6. Storing and transferring your personal information
+
+**Security**. We implement appropriate technical and organizational measures to protect your personal information against accidental or unlawful destruction, loss, change or damage. All personal information we collect will be stored by our cloud hosting provider on secure servers. We will never send you unsolicited emails or contact you by phone requesting credit or debit card information or national identification numbers.
+
+**International Transfers of your Personal Information**. The personal information we collect may be transferred to and stored in countries outside of the jurisdiction you are in where we and our third party service providers have operations. If you are located in the EEA, United Kingdom or Switzerland, your personal information may be processed outside of those regions, including in the United States.
+
+In the event of such a transfer, we ensure that: (i) the personal information is transferred to countries recognized as offering an equivalent level of protection; or (ii) the transfer is made pursuant to appropriate safeguards, such as standard data protection clauses adopted by the European Commission.
+
+If you wish to enquire further about these safeguards used, please contact us using the details set out at the end of these Privacy Disclosures.
+
+### 7. Profiling
+
+We may analyze personal data we have collected about you to create a profile of your interests and send product updates. We may also use personal data about you to detect and reduce fraud.
+
+### 8. Your rights in respect of your personal information
+
+In accordance with applicable privacy law, you have the following rights in respect of your personal information that we hold:
+
+1. **Right of access**. You have the right to obtain:
+ 1. confirmation of whether, and where, we are processing your personal information;
+ 2. information about the categories of personal information we are processing, the purposes for which we process your personal information and information as to how we determine applicable retention periods;
+ 3. information about the categories of recipients with whom we may share your personal information; and
+ 4. a copy of the personal information we hold about you.
+2. **Right of portability**. You have the right, in certain circumstances, to receive a copy of the personal information you have provided to us in a structured, commonly used, machine-readable format that supports re-use, or to request the transfer of your personal data to another person.
+3. **Right to rectification**. You have the right to obtain rectification of any inaccurate or incomplete personal information we hold about you without undue delay.
+4. **Right to erasure**. You have the right, in some circumstances, to require us to erase your personal information without undue delay if the continued processing of that personal information is not justified.
+5. **Right to restriction**. You have the right, in some circumstances, to require us to limit the purposes for which we process your personal information if the continued processing of the personal information in this way is not justified, such as where the accuracy of the personal information is contested by you.
+6. **Right to withdraw consent**. There are certain circumstances where we require your consent to process your personal information. In these instances, and if you have provided consent, you have the right to withdraw your consent. If you withdraw your consent, this will not affect the lawfulness of our use of your personal information before your withdrawal.
+
+**You also have the right to object to any processing based on our legitimate interests where there are grounds relating to your particular situation. There may be compelling reasons for continuing to process your personal information, and we will assess and inform you if that is the case. You can object to marketing activities for any reason.**
+
+You also have the right to lodge a complaint to your local data protection authority. If you are based in the European Union, information about how to contact your local data protection authority is available [here](http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm). If you are based in the UK or Switzerland, your local data protection authorities are the UK Information Commissioner's Office () and the Swiss Federal Data Protection and Information Commissioner ().
+
+If you wish to exercise one of these rights, please contact us using the contact details at the end of these Privacy Disclosures.
+
+Due to the confidential nature of data processing we may ask you to provide proof of identity when exercising the above rights. This can be done by providing a scanned copy of a valid identity document or a signed photocopy of a valid identity document.
+
+### 9. Cookies and similar technologies used on our European Services
+
+Our European Services uses cookies and similar technologies such as pixels and Local Storage Objects (LSOs) like HTML5 (together "**_cookies_**") to distinguish you from other users of our European Services. This helps us to provide you with a good experience when you browse our European Services and also allows us to monitor and analyse how you use and interact with our European Services so that we can continue to improve our European Services.
+
+Cookies are pieces of code that allow for personalization of our European Services experience by saving your information such as user ID and other preferences. A cookie is a small data file that we transfer to your computer's hard disk for record-keeping purposes.
+
+We use the following types of cookies:
+
+1. **Strictly necessary cookies**. These are cookies that are required for the operation of our European Services. They include, for example, cookies that enable you to log into secure areas of our European Services.
+
+Please see **Annex 3** for more information about the cookies we use on the European Services.
+
+Most browsers also allow you to change your cookie settings to block certain cookies. Depending on your mobile device and operating system, you may not be able to delete or block all cookies. Please note that if you choose to refuse all cookies you may not be able to use the full functionality of our European Services. These settings will typically be found in the "options" or "preferences" menu of your browser. In order to understand these settings, the following links may be helpful, otherwise you should use the "Help" option in your browser for more details.
+
+- [Cookie settings in Internet Explorer](https://support.microsoft.com/en-gb/help/278835/how-to-delete-cookie-files-in-internet-explorer)
+- [Cookie settings in Firefox](http://support.mozilla.org/en-US/kb/cookies)
+- [Cookie settings in Chrome](https://support.google.com/chrome/answer/95647?hl=en)
+- [Cookies settings in Safari web](https://support.apple.com/en-gb/guide/safari/manage-cookies-and-website-data-sfri11471/mac) and [iOS](https://support.apple.com/en-gb/HT201265).
+
+If you would like to find out more about cookies and other similar technologies, please visit [allaboutcookies.org](http://www.allaboutcookies.org).
+
+Please note that deleting or blocking cookies may not be effective for all types of tracking technologies, such as Local Storage Objects (LSOs) like HTML5.
+
+### 10. Tracking technologies used in our emails
+
+Our emails may contain tracking pixels that identify if and when you have opened an email that we have sent you, how many times you have read it and whether you have clicked on any links in that email. This helps us measure the effectiveness of our marketing email campaigns, make the emails we send to you more relevant to your interests and to understand if you have opened and read any important administrative emails we might send you.
+
+Most popular email clients will allow you to block these pixels by disabling certain external images in emails. You can do this through the settings on your email client – these generally give you the option of choosing whether emails will display "remote images", "remote content" or "images" by default.
+
+Some browsers also give you the option of downloading and installing extensions that block pixels and other tracking technologies.
+
+## Annex 1 – Personal information you provide to us
+
+| **Category of Personal Information** | **How we may use the Personal Information** | **Legal Bases for Processing** | **Recipients of Personal Information** |
+| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
+| **Contact information**, such as first name, last name and email address. | We may use this information to set up and authenticate your account on the Service. | The processing is necessary for the performance of a contract with you and to take steps prior to entering into a contract with you, namely our Terms of Service. |
We may share this information with the following service providers through the provision of the Service: Segment, Auth0, Stripe, Intercom, Hubspot, Mixpanel, Notion, Slack, Amazon Web Services, and BigQuery (Google Cloud).
|
+| | We may use this information to communicate with you, including sending service-related communications. | The processing is necessary for the performance of a contract with you, namely our Terms of Service. | |
+| | We may use this information to deal with enquiries and complaints made by or about you relating to the Service. | The processing is necessary for our legitimate interests, namely administering the Service, and for communicating with you effectively to respond to your queries or complaints. | |
+| | We may use this information in connection with providing you with marketing communications in accordance with your preferences. | We will only use your personal information in this way to the extent you have given us consent to do so. | |
+| **Your registration / account information** such as your full name, email, and password. |
We may use this information to create your account on the Service.
|
The processing is necessary for the performance of a contract with you.
|
We may share this information with the following service providers through the provision of the Service: Segment, Auth0, Stripe, Amazon Web Services.
|
+| |
We use this information to deal with enquiries and complaints made by or about you relating to the Service.
| The processing is necessary for our legitimate interests, namely for communicating with our members effectively to respond to any queries or complaints. | |
+| **Payment transaction information.** When you make a purchase, we may collect information such as your billing address and other information such as date and time of your transaction. |
We may use this information to process your orders through the Service.
| The processing is necessary for the performance of a contract. |
We may share this information with the following service providers through the provision of the Service: Stripe, and Amazon Web Services.
|
+| | We may use this information to verify your identity in connection with the detection and prevention of fraud or financial crime. | The processing is necessary for our and third partiers' legitimate interests, namely the detection and prevention of fraud and financial crime. | |
+| **Approximate Location information.** When you visit our Service, we may collect information about your location. This information may be derived from WiFi positioning or your IP address. | We may use information to present the Service to you on your device. | The processing is necessary for performance of a contract with you. |
We may share this information with the following service providers through the provision of the Service: Sentry, BigQuery (Google Cloud), and Amazon Web Services.
|
+| | We may use this information to localise features of the Service. | The processing is necessary for our legitimate interest, namely localising features of the Service and tailoring the Service so that it is more relevant to our users. | |
+| | We may use this information to determine content that may be of interest to you. | The processing is necessary for our legitimate interests, namely tailoring the Service so that it is more relevant to you. | |
+| **Chat, comments and opinions.** When you contact us directly, e.g. by email or phone we will record your comments and opinions. | We may use this information to address your questions, issues and concerns. | The processing is necessary for our legitimate interests, namely communicating with you and responding to queries, complaints and concerns. |
We may share this information with the following service providers through the provision of the Service: Intercom, Hubspot, Google Gsuite, and Slack.
|
+| | We may use this information to improve the Service. | The processing is necessary for our legitimate interests (to develop and improve our service). | |
+| **Information received from third parties, such as social networks.** If you interact with us through a social network, we may receive information from the social network such as your name, profile information, and any other information you permit the social network to share with third parties. We use single sign-on ("**_SSO_**") such as GitHub to allow a user to authenticate their account using one set of login information. The data we receive is dependent on your privacy settings with the social network. | We may use this information to reshare content created through the use of the Service | The processing is necessary for our legitimate interests (to develop our service and inform our marketing strategy) | We may share this information with the following service providers through the provision of the Service: Auth0 and Slack. |
+| |
We may use this information to authenticate you and allow you to access the Service.
| The processing is necessary for the performance of a contract with you. | |
+| **Your preferences**, such as preferences set for notifications, marketing communications, how the Service is displayed and the active functionalities on the Service. |
We use this information to provide notifications, send news, alerts and marketing communications and provide the Service in accordance with your choices.
|
The processing is necessary for our legitimate interest, namely ensuring the user receives the correct marketing and other communications, and that this is displayed in accordance with the user's preferences.
| We may share this information with the following service providers through the provision of the Service: Segment, Intercom and Hubspot. |
+| |
We use this information to ensure that we comply with our legal obligation to send only those marketing communications to which you have consented.
| The processing is necessary for compliance with a legal obligation to which we are subject. | |
+
+## Annex 2 – Personal information collected automatically
+
+| **Category of personal information** | **How we may use it** | **Legal basis for the processing** | **Recipients of Personal Data** |
+| :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
+| **Approximate location information.** Other than information you choose to provide to us, we do not collect information about your precise location. Your device’s IP address may however help us determine an approximate location. | We may use information you provide to us about your location to monitor and detect fraud or suspicious activity in relation to your Supabase account. | The processing is necessary for our legitimate interests, namely to protect our business and your account from fraud and other illegal activities. |
**Approximate location information:** We may share this information with the following service providers through the provision of the Service: Sentry, BigQuery (Google Cloud), and Amazon Web Services.
**Information about how you access and use the Service.** We may share this information with the following service providers through the provision of the Service: Segment, Mixpanel, Intercom, Hubspot, BigQuery (Google Cloud), and Amazon Web Services.
**Log files and information about your device.** We may share this information with the following service providers through the provision of the Service: Segment, Mixpanel, Intercom, Hubspot, Sentry, BigQuery (Google Cloud), and Amazon Web Services.
|
+| | We may use this information to tailor how the Service is displayed to you (such as the language in which it is provided to you). | The processing is necessary for our legitimate interest, namely tailoring our service so that it is more relevant to our users. | |
+| **Information about how you access and use the Service.** For example, how frequently you access the Service, the time you access the Service and how long you use it for, the approximate location that you access the Service from, the site from which you came and the site to which you are going when you leave our website, the website pages you visit, the links you click, whether you open emails or click the links contained in emails, whether you access the Service from multiple devices, and other actions you take on the Service. |
We may use information about how you use and connect to the Service to present the Service to you on your device.
| The processing is necessary for our legitimate interests, namely to tailor the Service to the user. | |
+| | We may use this information to determine products and services that may be of interest to you for marketing purposes. | The processing is necessary for our legitimate interests, namely to inform our direct marketing. | |
+| |
We may use this information to monitor and improve the Service and business, resolve issues and to inform the development of new products and services.
| The processing is necessary for our legitimate interests, namely to monitor and resolve issues with the Service and to improve the Service generally. | |
+| **Log files and information about your device.** We also collect information about the tablet, smartphone or other electronic device you use to connect to the Service. This information can include details about the, operating systems, browsers and applications connected to the Service through the device and your IP address. |
We may use information about how you use and connect to the Service to present the Service to you on your device.
| The processing is necessary for our legitimate interests, namely to tailor the Service to the user. | |
+| |
We may use this information to monitor and improve the Service and business, resolve issues and to inform the development of new products and services.
| The processing is necessary for our legitimate interests, namely to monitor and resolve issues with the Service and to improve the Service generally. | |
+
+## Annex 3 - Cookies
+
+| **Cookie Name** | **Type of cookie** | **How long does the cookie stay on my device?** | **Purpose of the cookie** |
+| :----------------------------- | :----------------- | :---------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
+|
Privacy-enhanced cookie, essential for embedded videos. [Link.](https://support.google.com/youtube/answer/171780)
Privacy Enhanced Mode allows you to embed YouTube videos without using cookies that track viewing behavior. This means no activity is collected to personalize the viewing experience.
|
diff --git a/apps/reference/docs/company/sla.md b/apps/reference/docs/company/sla.md
new file mode 100644
index 00000000000..00cbf36e740
--- /dev/null
+++ b/apps/reference/docs/company/sla.md
@@ -0,0 +1,88 @@
+---
+id: sla
+title: Service Level Agreement
+---
+
+The following Service Level Agreement, which is incorporated into and forms part of the Subscription Agreement between Supabase, Inc. ("Supabase") and Customer (the "Agreement"), will apply to the Services for Enterprise Customers specified in an Order Form during the applicable Subscription Term:
+
+## Platform
+
+### 1. Uptime Commitment
+
+Supabase will provide Actual Availability for at least ninety-nine and nine tenths percent (99.9%) of the total time in each calendar month during the Subscription Term, as measured by Supabase (the **"Uptime Commitment"**).
+
+### 2. Service Credits
+
+If the Uptime Commitment is not met during any particular calendar month during the Subscription Term, then Customer will be eligible for a service credit ("Service Credit"), provided that Customer reports to Supabase such failure to meet the Uptime Commitment and requests such Service Credit in accordance with this Exhibit. The amount of any Service Credit due hereunder shall be calculated as follows:
+X \* Y, where X = the total fees due from Customer to Supabase for the affected Services for the relevant calendar month (regardless of when billed or payable), and Y = the Credit Percentage corresponding with the Actual Availability provided (as a percentage of total time) for the relevant calendar month, as set forth in the table below.
+
+| Actual Availability | Credit Percentage |
+| -------------------------------------------------- | ----------------- |
+| Less than 99.9% but greater than or equal to 99.0% | 10% |
+| Less than 99.0% but greater than or equal to 98.0% | 15% |
+| Less than 98.0% but greater than or equal to 96.0% | 20% |
+| Less than 96.0% | 30% |
+
+### 3. Credit Requests and Payment
+
+To request a Service Credit, Customer must send an email to Supabase at support@supabase.io within thirty (30) days of the end of the month in which the Uptime Commitment was not met. Customer must include either its account ID or registered email address, and the previously reported dates and times that there was no Service Availability. If Supabase confirms that Customer is eligible for a Service Credit, Supabase will issue a credit to Customer’s account within thirty (30) days. Service Credits are not refunds, cannot be exchanged into a cash amount, and may only be used against future billing charges. Except as set forth in Section 4 below, the Service Credits shall be Customer’s sole and exclusive remedy, and Supabase’s sole and exclusive liability, for any failure by Supabase to meet the Uptime Commitment.
+
+### 4. Definitions
+
+All capitalized words used but not defined in this Service Level Agreement have the meaning set forth in the Agreement.
+
+#### 4.1 Scheduled Availability
+
+"Scheduled Availability" means the time, in minutes, that the applicable Services are generally accessible and available to Customer’s Permitted Users.
+
+#### 4.2 Unscheduled Downtime
+
+"Unscheduled Downtime" means the time, in minutes, that the applicable Services are not generally accessible and available to Customer’s Permitted Users, excluding inaccessibility or unavailability due to Customer’s or Permitted Users’ acts or omissions, force majeure events, scheduled maintenance disclosed with at least 24 hours’ notice by email, hacking or virus attacks, or reasonable emergency maintenance.
+
+#### 4.3 Actual Availability
+
+"Actual Availability" means Scheduled Availability less Unscheduled Downtime.
+
+## Support
+
+Supabase Support Service Level Agreements.
+
+### 1. Urgent
+
+**Critical Issue**
+
+Defect resulting in full or partial system outage or a condition that makes Supabase unusable
+or unavailable in production for all of Customer’s Users.
+
+### 2. High
+
+**Significant Business Disruption**
+
+Issue resulting in a situation meaning major functionality is impacted and
+significant performance degradation is experienced. Issue impacts significant proportion of user base and / or major
+Supabase functionality.
+
+### 3. Normal
+
+**Minor Feature or Functional Issue / General Question**
+
+Issue results in a component of Supabase not
+performing as expected or documented. An inquiry by a Customer representative regarding a general technical issue
+or general question.
+
+### 4. Low
+
+**Minor Issue / Feature Request**
+
+An Information request about Supabase or feature request.
+
+## Target response times
+
+| Severity Level | Standard | Priority | Priority Plus |
+| -------------- | ------------------------------------- | ------------------------------------- | -------------------------------------- |
+| 1. Urgent | 1 business hour 24/7 × 365 | 1 business hour 24/7 × 365 | 1 business hour 24/7 × 365 |
+| 2. High | 4 business hours Monday - Friday | 2 business hours Monday - Friday | 2 business hours 24/7 × 365 |
+| 3. Normal | 1 business day Monday - Friday | 1 business day Monday - Friday | 12 business hours Monday - Friday |
+| 4. Low | 2 business days Monday - Friday | 2 business days Monday - Friday | 1 business day Monday - Friday |
+
+Business hours are from 6am to 6pm (local time), except where otherwise stated.
diff --git a/apps/reference/docs/company/terms.md b/apps/reference/docs/company/terms.md
new file mode 100644
index 00000000000..60fd3ce9eb4
--- /dev/null
+++ b/apps/reference/docs/company/terms.md
@@ -0,0 +1,235 @@
+---
+id: terms
+title: Terms of Service
+---
+
+`Last Modified: 20 November 2020`
+
+These Customer Terms and Conditions (this "**Agreement**"), effective as of the date on which you click a button or check a box (or something similar) acknowledging your acceptance of this Agreement (the "**Effective Date**"), is by and between Supabase, Inc., a Delaware corporation with offices located at 970 Toa Payoh North #07-04, Singapore 318992 ("**Supabase**") and the entity on whose behalf the individual accepting this Agreement accepts this Agreement ("**Customer**"). The individual accepting this Agreement hereby represents and warrants that it is duly authorized by the entity on whose behalf it accepts this Agreement to so accept this Agreement. Supabase and Customer may be referred to herein collectively as the "**Parties**" or individually as a "**Party**." The Parties agree as follows:
+
+## 1. Definitions.
+
+1. "**Aggregated Data**" means data and information related to or derived from Customer Data or Customer's use of the Services that is used by Supabase in an aggregate and anonymized manner, including to compile statistical and performance information related to the Services.
+2. "**Authorized User**" means Customer's employees, consultants, contractors, and agents (i) who are authorized by Customer to access and use the Services under the rights granted to Customer pursuant to this Agreement; and (ii) for whom access to the Services has been purchased hereunder.
+3. "**Customer Data**" means information, data, and other content, in any form or medium, that is submitted, posted, or otherwise transmitted by or on behalf of Customer or an Authorized User through the Services; provided that, for purposes of clarity, Customer Data does not include Aggregated Data.
+4. "**Documentation**" means Supabase's end user documentation relating to the Services available at [supabase.io](https://supabase.com).
+5. "**Harmful Code**" means any software, hardware, or other technology, device, or means, including any virus, worm, malware, or other malicious computer code, the purpose or effect of which is to permit unauthorized access to, or to destroy, disrupt, disable, distort, or otherwise harm or impede in any manner any (i) computer, software, firmware, hardware, system, or network; or (ii) any application or function of any of the foregoing or the security, integrity, confidentiality, or use of any data processed thereby.
+6. "**Order**" means: (i) the purchase order, order form, or other ordering document entered into by the Parties that incorporates this Agreement by reference; or (ii) if Customer registered for the Services through Supabase's online ordering process, the results of such online ordering process.
+7. "**Personal Information**" means any information that, individually or in combination, does or can identify a specific individual or by or from which a specific individual may be identified, contacted, or located, including without limitation all data considered "personal data", "personally identifiable information", or something similar under applicable laws, rules, or regulations relating to data privacy.
+8. "**Supabase IP**" means the Services, the Documentation, and any and all intellectual property provided to Customer or any Authorized User in connection with the foregoing. For the avoidance of doubt, Supabase IP includes Aggregated Data and any information, data, or other content derived from Supabase's provision of the Services but does not include Customer Data.
+9. "**Services**" means Supabase's proprietary hosted software platform, as made available by Supabase to Authorized Users from time to time.
+10. "**Subscription Period**" means the time period identified on the Order during which Customer's Authorized Users may access and use the Services.
+11. "**Third-Party Products**" means any third-party products provided with, integrated with, or incorporated into the Services.
+12. "**Usage Limitations**" means the usage limitations set forth in this Agreement and the Order, including without limitation any limitations on the number of Authorized Users (if any), and the applicable product, pricing, and support tiers agreed-upon by the Parties.
+
+## 2. Access and Use.
+
+### 1. Provision of Access.
+
+Subject to and conditioned on Customer's compliance with the terms and conditions of this Agreement, including without limitation the Usage Limitations, Supabase will make available to Customer during the Subscription Period, on a non-exclusive, non-transferable (except in compliance with Section 13.8), and non-sublicensable basis, access to and use of the Services, solely for use by Authorized Users. Such use is limited to Customer's internal business purposes and the features and functionalities specified in the Order. Supabase shall provide to Customer the necessary access credentials to allow Customer to access the Services.
+
+### 2. Documentation License.
+
+Subject to and conditioned on Customer's compliance with the terms and conditions of this Agreement, Supabase hereby grants to Customer a non-exclusive, non-transferable (except in compliance with Section 13.8), and non-sublicensable license to use the Documentation during the Subscription Period solely for Customer's internal business purposes in connection with its use of the Services.
+
+### 3. Use Restrictions.
+
+Customer shall not use the Services for any purposes beyond the scope of the access granted in this Agreement. Customer shall not at any time, directly or indirectly, and shall not permit any Authorized Users to: (i) copy, modify, or create derivative works of any Supabase IP, whether in whole or in part; (ii) rent, lease, lend, sell, license, sublicense, assign, distribute, publish, transfer, or otherwise make available the Services or Documentation to any third party; (iii) reverse engineer, disassemble, decompile, decode, adapt, or otherwise attempt to derive or gain access to any software component of the Services, in whole or in part; (iv) remove any proprietary notices from any Supabase IP; (v) use any Supabase IP in any manner or for any purpose that infringes, misappropriates, or otherwise violates any intellectual property right or other right of any person, or that violates any applicable law; (vi) access or use any Supabase IP for purposes of competitive analysis of Supabase or the Services, the development, provision, or use of a competing software service or product, or any other purpose that is to Supabase's detriment or commercial disadvantage; (vii) bypass or breach any security device or protection used by the Services or access or use the Services other than by an Authorized User through the use of valid access credentials; or (vii) input, upload, transmit, or otherwise provide to or through the Services any information or materials that are unlawful or injurious, or that contain, transmit, or activate any Harmful Code.
+
+### 4. Reservation of Rights.
+
+Supabase reserves all rights not expressly granted to Customer in this Agreement. Except for the limited rights and licenses expressly granted under this Agreement, nothing in this Agreement grants, by implication, waiver, estoppel, or otherwise, to Customer or any third party any intellectual property rights or other right, title, or interest in or to the Supabase IP.
+
+### 5. Suspension.
+
+Notwithstanding anything to the contrary in this Agreement, Supabase may temporarily suspend Customer's and any Authorized User's access to any portion or all of the Services if: (i) Supabase reasonably determines that (A) there is a threat or attack on any of the Supabase IP; (B) Customer's or any Authorized User's use of the Supabase IP disrupts or poses a security risk to the Supabase IP or to any other customer or vendor of Supabase; (C) Customer, or any Authorized User, is using the Supabase IP for fraudulent or illegal activities; (D) subject to applicable law, Customer has ceased to continue its business in the ordinary course, made an assignment for the benefit of creditors or similar disposition of its assets, or become the subject of any bankruptcy, reorganization, liquidation, dissolution, or similar proceeding; or (E) Supabase's provision of the Services to Customer or any Authorized User is prohibited by applicable law; (ii) any vendor of Supabase has suspended or terminated Supabase's access to or use of any Third-Party Products required to enable Customer to access the Services; or (iii) in accordance with Section 5.1 (any such suspension described in subclause (i), (ii), or (iii), a "**Service Suspension**"). Supabase shall use commercially reasonable efforts to provide written notice of any Service Suspension to Customer and to provide updates regarding resumption of access to the Services following any Service Suspension. Supabase shall use commercially reasonable efforts to resume providing access to the Services as soon as reasonably possible after the event giving rise to the Service Suspension is cured. Supabase will have no liability for any damage, liabilities, losses (including any loss of data or profits), or any other consequences that Customer or any Authorized User may incur as a result of a Service Suspension.
+
+### 6. Aggregated Data.
+
+Notwithstanding anything to the contrary in this Agreement, Supabase may monitor Customer's use of the Services and collect and compile Aggregated Data. As between Supabase and Customer, all right, title, and interest in Aggregated Data, and all intellectual property rights therein, belong to and are retained solely by Supabase. Customer acknowledges that Supabase may compile Aggregated Data based on Customer Data input into the Services. Customer agrees that Supabase may (i) make Aggregated Data available to third parties including its other customers in compliance with applicable law, and (ii) use Aggregated Data to the extent and in the manner permitted under applicable law.
+
+## 3. Customer Responsibilities.
+
+### 1. General.
+
+Customer is responsible and liable for all uses of the Services and Documentation resulting from access provided by Customer, directly or indirectly, whether such access or use is permitted by or in violation of this Agreement. Without limiting the generality of the foregoing, Customer is responsible for all acts and omissions of Authorized Users, and any act or omission by an Authorized User that would constitute a breach of this Agreement if taken by Customer will be deemed a breach of this Agreement by Customer. Customer shall use reasonable efforts to make all Authorized Users aware of this Agreement's provisions as applicable to such Authorized User's use of the Services and shall cause Authorized Users to comply with such provisions.
+
+### 2. Third-Party Products.
+
+Supabase may from time to time make Third-Party Products available to Customer or Supabase may allow for certain Third-Party Products to be integrated with the Services to allow for the transmission of Customer Data from such Third-Party Products into the Services. For purposes of this Agreement, such Third-Party Products are subject to their own terms and conditions. If Customer does not agree to abide by the applicable terms for any such Third-Party Products, then Customer should not install or use such Third-Party Products. By authorizing Supabase to transmit Customer Data from Third-Party Products into the Services, Customer represents and warrants to Supabase that it has all right, power, and authority to provide such authorization.
+
+### 3. Customer Control and Responsibility.
+
+Customer has and will retain sole responsibility for: (i) all Customer Data, including its content and use; (ii) all information, instructions, and materials provided by or on behalf of Customer or any Authorized User in connection with the Services; (iii) Customer's information technology infrastructure, including computers, software, databases, electronic systems (including database management systems), and networks, whether operated directly by Customer or through the use of third-party services ("**Customer Systems**"); (iv) the security and use of Customer's and its Authorized Users' access credentials; and (v) all access to and use of the Services directly or indirectly by or through the Customer Systems or its or its Authorized Users' access credentials, with or without Customer's knowledge or consent, including all results obtained from, and all conclusions, decisions, and actions based on, such access or use.
+
+## 4. Support.
+
+During the Subscription Period, Supabase will use commercially reasonable efforts to provide Customer with basic customer support via Supabase's standard support channels during Supabase's normal business hours.
+
+## 5. Fees and Taxes.
+
+### 1. Fees.
+
+Where paid for services are agreed between Supabase and Customer per the Order, Customer shall pay Supabase the fees ("**Fees**") identified in the Order without offset or deduction at the cadence identified in the Order (e.g., monthly or annually). Fees paid by Customer are non-refundable. If Customer fails to make any payment when due, and Customer has not notified Supabase in writing within ten (10) days of the payment becoming due and payable that the payment is subject to a good faith dispute, without limiting Supabase's other rights and remedies: (i) Supabase may charge interest on the undisputed past due amount at the rate of 1.5% per month, calculated daily and compounded monthly or, if lower, the highest rate permitted under applicable law; (ii) Customer shall reimburse Supabase for all reasonable costs incurred by Supabase in collecting any late payments or interest, including attorneys' fees, court costs, and collection agency fees; and (iii) if such failure continues for ten (10) days or more, Supabase may suspend Customer's and its Authorized Users' access to any portion or all of the Services until such amounts are paid in full.
+
+### 2. Taxes.
+
+All Fees and other amounts payable by Customer under this Agreement are exclusive of taxes and similar assessments. Customer is responsible for all sales, use, and excise taxes, and any other similar taxes, duties, and charges of any kind imposed by any federal, state, or local governmental or regulatory authority on any amounts payable by Customer hereunder, other than any taxes imposed on Supabase's income. To the extent that Supabase is required by law to pay any such taxes, duties, or other charges to any governmental or regulatory authority, Supabase may invoice Customer for such taxes, duties, or other charges and Customer will pay such invoiced amounts in accordance with this Agreement.
+
+## 6. Confidential Information.
+
+### 1. Definition.
+
+From time to time during the Subscription Period, either Party may disclose or make available to the other Party information about its business affairs, products, confidential intellectual property, trade secrets, third-party confidential information, and other sensitive or proprietary information, whether orally or in written, electronic, or other form or media that: (i) is marked, designated or otherwise identified as "confidential" or something similar at the time of disclosure or within a reasonable period of time thereafter; or (ii) would be considered confidential by a reasonable person given the nature of the information or the circumstances of its disclosure (collectively, "**Confidential Information**"). Except for Personal Information, Confidential Information does not include information that, at the time of disclosure is: (a) in the public domain; (b) known to the receiving Party at the time of disclosure; (c) rightfully obtained by the receiving Party on a non-confidential basis from a third party; or (d) independently developed by the receiving Party without use of, reference to, or reliance upon the disclosing Party's Confidential Information.
+
+### 2. Duty.
+
+The receiving Party shall not disclose the disclosing Party's Confidential Information to any person or entity, except to the receiving Party's employees, contractors, and agents who have a need to know the Confidential Information for the receiving Party to exercise its rights or perform its obligations hereunder ("**Representatives**"). The receiving Party will be responsible for all the acts and omissions of its Representatives as they relate to Confidential Information hereunder. Notwithstanding the foregoing, each Party may disclose Confidential Information to the limited extent required (i) in order to comply with the order of a court or other governmental body, or as otherwise necessary to comply with applicable law, provided that the Party making the disclosure pursuant to the order shall first have given written notice to the other Party and made a reasonable effort to obtain a protective order; or (ii) to establish a Party's rights under this Agreement, including to make required court filings. Further, notwithstanding the foregoing, each Party may disclose the terms and existence of this Agreement to its actual or potential investors, debtholders, acquirers, or merger partners under customary confidentiality terms.
+
+### 3. Return of Materials; Effects of Termination/Expiration.
+
+On the expiration or termination of the Agreement, the receiving Party shall promptly return to the disclosing Party all copies, whether in written, electronic, or other form or media, of the disclosing Party's Confidential Information, or destroy all such copies and certify in writing to the disclosing Party that such Confidential Information has been destroyed. Each Party's obligations of non-use and non-disclosure with regard to Confidential Information are effective as of the Effective Date and will expire three (3) years from the date of termination or expiration of this Agreement; provided, however, with respect to any Confidential Information that constitutes a trade secret (as determined under applicable law), such obligations of non-disclosure will survive the termination or expiration of this Agreement for as long as such Confidential Information remains subject to trade secret protection under applicable law.
+
+## 7. Personal Information.
+
+Customer will ensure that its Customer Data, and its use of such Customer Data, complies with this Agreement and any applicable law. Customer is responsible for properly configuring and using the Services and taking its own steps to maintain appropriate security, protection, and backup of Customer Data. Customer may not store or process protected health information (as defined in HIPAA) using the Services unless Customer signs a Business Associate Agreement with Supabase. Customer may not store any payment cardholder information using the Services without Supabase's prior written approval.
+
+## 8. Intellectual Property Ownership; Feedback.
+
+### 1. Supabase IP.
+
+Customer acknowledges that, as between Customer and Supabase, Supabase owns all right, title, and interest, including all intellectual property rights, in and to the Supabase IP and, with respect to Third-Party Products, the applicable third-party providers own all right, title, and interest, including all intellectual property rights, in and to the Third-Party Products.
+
+### 2. Customer Data.
+
+Supabase acknowledges that, as between Supabase and Customer, Customer owns all right, title, and interest, including all intellectual property rights, in and to the Customer Data. Customer hereby grants to Supabase a non-exclusive, royalty-free, worldwide license to reproduce, distribute, and otherwise use and display the Customer Data and perform all acts with respect to the Customer Data as may be necessary for Supabase to provide the Services to Customer, and a non-exclusive, perpetual, irrevocable, royalty-free, worldwide license to reproduce, distribute, modify, and otherwise use and display Customer Data incorporated within the Aggregated Data. Customer may export the Customer Data at any time through the features and functionalities made available via the Services.
+
+### 3. Feedback.
+
+If Customer or any of its employees or contractors sends or transmits any communications or materials to Supabase by mail, email, telephone, or otherwise, suggesting or recommending changes to the Supabase IP, including without limitation, new features or functionality relating thereto, or any comments, questions, suggestions, or the like ("**Feedback**"), Supabase is free to use such Feedback irrespective of any other obligation or limitation between the Parties governing such Feedback so long as Supabase does not identify Customer as the source of the Feedback without Customer's prior approval.
+
+## 9. Warranty Disclaimer.
+
+The Supabase IP is provided "as is" and Supabase
+hereby disclaims all warranties, whether express, implied, statutory, or
+otherwise. Supabase specifically disclaims all implied warranties of
+merchantability, fitness for a particular purpose, title, and non-infringement,
+and all warranties arising from course of dealing, usage, or trade practice. Supabase
+makes no warranty of any kind that the Supabase IP, or any products or results
+of the use thereof, will meet Customer’s or any other person’s requirements,
+operate without interruption, achieve any intended result, be compatible or
+work with any software, system or other services, or be secure, accurate,
+complete, free of harmful code, or error free.
+
+## 10. Indemnification.
+
+### 1. Supabase Indemnification.
+
+1. Supabase shall indemnify, defend, and hold harmless Customer from and against any and all losses, damages, liabilities, costs (including reasonable attorneys' fees) ("**Losses**") incurred by Customer resulting from any third-party claim, suit, action, or proceeding ("**Third-Party Claim**") that the Services, or any use of the Services in accordance with this Agreement, infringes or misappropriates such third party's US copyrights or trade secrets; provided that Customer promptly notifies Supabase in writing of the claim, cooperates with Supabase, and allows Supabase sole authority to control the defense and settlement of such claim.
+2. If such a claim is made or appears possible, Customer agrees to permit Supabase, at Supabase's sole discretion: to (i) modify or replace the Services, or component or part thereof, to make it non-infringing; or (ii) obtain the right for Customer to continue use. If Supabase determines that neither alternative is reasonably commercially available, Supabase may terminate this Agreement, in its entirety or with respect to the affected component or part, effective immediately on written notice to Customer.
+3. This Section 10.1 will not apply to the extent that the alleged infringement arises from: (i) use of the Services in combination with data, software, hardware, equipment, or technology not provided by Supabase or authorized by Supabase in writing; (ii) modifications to the Services not made by Supabase; (iii) Customer Data; or (iv) Third-Party Products.
+
+### 2. Customer Indemnification.
+
+Customer shall indemnify, hold harmless, and, at Supabase's option, defend Supabase from and against any Losses resulting from any Third-Party Claim that the Customer Data, or any use of the Customer Data in accordance with this Agreement, infringes or misappropriates such third party's US intellectual property or other rights and any Third-Party Claims based on Customer's or any Authorized User's (i) negligence or willful misconduct; (ii) use of the Services in a manner not authorized by this Agreement; or (iii) use of the Services in combination with data, software, hardware, equipment or technology not provided by Supabase or authorized by Supabase in writing; in each case provided that Customer may not settle any Third-Party Claim against Supabase unless Supabase consents to such settlement, and further provided that Supabase will have the right, at its option, to defend itself against any such Third-Party Claim or to participate in the defense thereof by counsel of its own choice.
+
+### 3. Sole Remedy.
+
+This section 10.3 sets forth Customer's sole remedies and Supabase's sole liability and obligation for any actual, threatened, or alleged claims that the services infringe, misappropriate, or otherwise violate any intellectual property rights of any third party.
+
+## 11. Limitations of Liability.
+
+Except for: (i) a party’s breach of its confidentiality obligations;
+(ii) a party’s indemnity obligations; or (iii) a party’s gross negligence,
+fraud, or willful misconduct ("**Excluded Liabilities**"), (a) in no
+event will either party be liable under or in connection with this agreement
+under any legal or equitable theory, including breach of contract, tort
+(including negligence), strict liability, and otherwise, for any: (1)
+consequential, incidental, indirect, exemplary, special, enhanced, or punitive
+damages; (2) increased costs, diminution in value or lost business, production,
+revenues, or profits; (3) loss of goodwill or reputation; (4) use, inability to
+use, loss, interruption, delay or recovery of any data, or breach of data or
+system security; or (5) cost of replacement goods or services, in each case
+regardless of whether such party was advised of the possibility of such losses
+or damages or such losses or damages were otherwise foreseeable; and (b) in no
+event will either party’s aggregate liability arising out of or related to this
+agreement under any legal or equitable theory, including breach of contract,
+tort (including negligence), strict liability, and otherwise exceed the total
+amounts paid and/or payable to Supabase under this agreement in the twelve (12)
+months immediately preceding the claim; provided that, notwithstanding the
+foregoing, Supabase's aggregate liability arising out of or relating to any
+excluded liabilities will not exceed three times (3x) the total amounts paid
+and/or payable to Supabase by Customer under this agreement in the twelve (12)
+months immediately preceding the claim.
+
+## 12. Subscription Period and Termination.
+
+### 1. Subscription Period.
+
+The initial term of this Agreement begins on the Effective Date and, unless terminated earlier pursuant to Section 12.2, will continue in effect for the period identified in the Order (the "**Initial Subscription Period**"). This Agreement will automatically renew for additional successive terms equal to the length of the Initial Subscription Period unless earlier terminated pursuant to this Agreement's express provisions or either Party gives the other Party written notice of non-renewal at least thirty (30) days prior to the expiration of the then-current term (each a "**Renewal Subscription Period**" and together with the Initial Subscription Period, the "**Subscription Period**").]
+
+#### 2. Termination.
+
+In addition to any other express termination right set forth in this Agreement:
+
+1. Supabase may terminate this Agreement, effective on written notice to Customer, if Customer: (i) fails to pay any amount when due hereunder, and such failure continues more than ten (10) calendar days after Supabase's delivery of written notice thereof; or (ii) breaches any of its obligations under Section 2.3 or Section 6;
+2. either Party may terminate this Agreement, effective on written notice to the other Party, if the other Party materially breaches this Agreement, and such breach: (i) is incapable of cure; or (ii) being capable of cure, remains uncured thirty (30) calendar days after the non-breaching Party provides the breaching Party with written notice of such breach; or
+3. either Party may terminate this Agreement, effective immediately upon written notice to the other Party, if the other Party: (i) becomes insolvent or is generally unable to pay, or fails to pay, its debts as they become due; (ii) files or has filed against it, a petition for voluntary or involuntary bankruptcy or otherwise becomes subject, voluntarily or involuntarily, to any proceeding under any domestic or foreign bankruptcy or insolvency law; (iii) makes or seeks to make a general assignment for the benefit of its creditors; or (iv) applies for or has appointed a receiver, trustee, custodian, or similar agent appointed by order of any court of competent jurisdiction to take charge of or sell any material portion of its property or business.
+
+### 3. Effect of Expiration or Termination.
+
+Upon expiration or earlier termination of this Agreement, Customer shall immediately discontinue use of the Supabase IP and, without limiting Customer's obligations under Section 6, Customer shall delete, destroy, or return all copies of the Supabase IP and certify in writing to the Supabase that the Supabase IP has been deleted or destroyed. No expiration or termination will affect Customer's obligation to pay all Fees that may have become due before such expiration or termination or entitle Customer to any refund.
+
+### 4. Survival.
+
+This Section 12.4 and Sections 1, 5, 6, 8, 9, 10, 11, and 13 survive any termination or expiration of this Agreement. No other provisions of this Agreement survive the expiration or earlier termination of this Agreement.
+
+## 13. Miscellaneous.
+
+### 1. Entire Agreement.
+
+This Agreement, together with any other documents incorporated herein by reference, constitutes the sole and entire agreement of the Parties with respect to the subject matter of this Agreement and supersedes all prior and contemporaneous understandings, agreements, and representations and warranties, both written and oral, with respect to such subject matter. In the event of any inconsistency between the statements made in the body of this Agreement, the related Exhibits, and any other documents incorporated herein by reference, the following order of precedence governs: (i) first, this Agreement; and (ii) second, any other documents incorporated herein by reference.
+
+### 2. Notices.
+
+All notices, requests, consents, claims, demands, waivers, and other communications hereunder (each, a "**Notice**") must be in writing and addressed to the Parties at the addresses set forth on the first page of this Agreement or as identified on the Order Form (or to such other address that may be designated by the Party giving Notice from time to time in accordance with this Section). All Notices must be delivered by personal delivery, nationally recognized signed for on delivery courier (with all fees pre-paid), or email (with confirmation of transmission). All email Notices to Supabase must be sent to [legal@supabase.io](mailto:legal@supabase.io). Except as otherwise provided in this Agreement, a Notice is effective only: (i) upon receipt by the receiving Party; and (ii) if the Party giving the Notice has complied with the requirements of this Section.
+
+### 3. Force Majeure.
+
+In no event shall either Party be liable to the other Party, or be deemed to have breached this Agreement, for any failure or delay in performing its obligations under this Agreement (except for any obligations to make payments), if and to the extent such failure or delay is caused by any circumstances beyond such Party's reasonable control, including but not limited to acts of God, flood, fire, earthquake, explosion, war, terrorism, invasion, riot or other civil unrest, strikes, labor stoppages or slowdowns or other industrial disturbances, or passage of law or any action taken by a governmental or public authority, including imposing an embargo.
+
+### 4. Amendment and Modification.
+
+Supabase may change this Agreement (except for any Orders) from time to time at its discretion. The date on which the Agreement was last modified will be updated at the top of this Agreement. Supabase will provide Customer with reasonable notice prior to any amendments or modifications taking effect, either by emailing the email address associated with Customer's account on the Services or by another method reasonably designed to provide notice to Customer. If Customer accesses or uses the Services after the effective date of the revised Agreement, such access and use will constitute Customer's acceptance of the revised Agreement beginning at the next Renewal Subscription Period or, if Customer enters into a new Order with Supabase, as of the date of execution of such Order.
+
+### 5. Waiver.
+
+No failure or delay by either Party in exercising any right or remedy available to it in connection with this Agreement will constitute a waiver of such right or remedy. No waiver under this Agreement will be effective unless made in writing and signed by an authorized representative of the Party granting the waiver.
+
+### 6. Severability.
+
+If any provision of this Agreement is invalid, illegal, or unenforceable in any jurisdiction, such invalidity, illegality, or unenforceability will not affect any other term or provision of this Agreement or invalidate or render unenforceable such term or provision in any other jurisdiction. Upon such determination that any term or other provision is invalid, illegal, or unenforceable, the Parties shall negotiate in good faith to modify this Agreement so as to effect their original intent as closely as possible in a mutually acceptable manner in order that the transactions contemplated hereby be consummated as originally contemplated to the greatest extent possible.
+
+### 7. Governing Law; Submission to Jurisdiction.
+
+This Agreement is governed by and construed in accordance with the internal laws of the State of California without giving effect to any choice or conflict of law provision or rule that would require or permit the application of the laws of any jurisdiction other than those of the State of California. Any legal suit, action, or proceeding arising out of or related to this Agreement or the licenses granted hereunder must be instituted in the federal courts of the United States or the courts of the State of California in each case located in San Francisco County, California and each Party irrevocably submits to the exclusive jurisdiction of such courts in any such suit, action, or proceeding.
+
+### 8. Assignment.
+
+Customer may not assign any of its rights or delegate any of its obligations hereunder, in each case whether voluntarily, involuntarily, by operation of law or otherwise, without the prior written consent of Supabase. Any purported assignment or delegation in violation of this Section will be null and void. No assignment or delegation will relieve the assigning or delegating Party of any of its obligations hereunder. This Agreement is binding upon and inures to the benefit of the Parties and their respective permitted successors and assigns.
+
+### 9. Export Regulation.
+
+The Services utilize software and technology that may be subject to US export control laws, including the US Export Administration Act and its associated regulations. Customer shall not, directly or indirectly, export, re-export, or release the Services or the underlying software or technology to, or make the Services or the underlying software or technology accessible from, any jurisdiction or country to which export, re-export, or release is prohibited by law, rule, or regulation. Customer shall comply with all applicable federal laws, regulations, and rules, and complete all required undertakings (including obtaining any necessary export license or other governmental approval), prior to exporting, re-exporting, releasing, or otherwise making the Services or the underlying software or technology available outside the US.
+
+### 10. US Government Rights.
+
+Each of the Documentation and the software components that constitute the Services is a "commercial item" as that term is defined at 48 C.F.R. § 2.101, consisting of "commercial computer software" and "commercial computer software documentation" as such terms are used in 48 C.F.R. § 12.212. Accordingly, if Customer is an agency of the US Government or any contractor therefor, Customer only receives those rights with respect to the Services and Documentation as are granted to all other end users, in accordance with (a) 48 C.F.R. § 227.7201 through 48 C.F.R. § 227.7204, with respect to the Department of Defense and their contractors, or (b) 48 C.F.R. § 12.212, with respect to all other US Government users and their contractors.
+
+### 11. Equitable Relief.
+
+Each Party acknowledges and agrees that a breach or threatened breach by such Party of any of its obligations under Section 6 or, in the case of Customer, Section 2.3, would cause the other Party irreparable harm for which monetary damages would not be an adequate remedy and agrees that, in the event of such breach or threatened breach, the other Party will be entitled to equitable relief, including a restraining order, an injunction, specific performance and any other relief that may be available from any court, without any requirement to post a bond or other security, or to prove actual damages or that monetary damages are not an adequate remedy. Such remedies are not exclusive and are in addition to all other remedies that may be available at law, in equity or otherwise.
+
+### 12. Publicity.
+
+Supabase may identify Customer as a user of the Services and may use Customer's name, logo, and other trademarks in Supabase's customer list, press releases, blog posts, advertisements, and website (and all use thereof and goodwill arising therefrom shall inure to the sole and exclusive benefit of Customer). Otherwise, neither Party may use the name, logo, or other trademarks of the other Party for any purpose without the other Party's prior written approval.
diff --git a/apps/reference/docs/faq.md b/apps/reference/docs/faq.md
new file mode 100755
index 00000000000..044a73f9ec0
--- /dev/null
+++ b/apps/reference/docs/faq.md
@@ -0,0 +1,38 @@
+---
+id: faq
+title: FAQs
+description: 'Most frequently asked questions regarding Supabase'
+---
+
+### Where do I find support?
+
+Choose the support channel relevant for your situation here: [supabase.com/support](https://supabase.com/support)
+
+### How much does it cost?
+
+Self-hosting Supabase is free. If you wish to use our cloud-platform, we provide [simple, predictable pricing](https://supabase.com/pricing).
+
+### How do I host Supabase?
+
+You can use the docker-compose script [here](https://github.com/supabase/supabase/tree/master/docker), and find detailed instructions [here](/docs/guides/hosting/overview).
+
+Supabase is an amalgamation of open source tools. Some of these tools are made by Supabase (like our [Realtime Server](https://github.com/supabase/realtime)), some we support directly (like [PostgREST](http://postgrest.org/en/v7.0.0/)), and some are third-party tools (like [KonSupabase is an amalgamation open sourceg](https://github.com/Kong/kong)).
+
+All of the tools we use in Supabase are MIT, Apache 2.0, or PostgreSQL licensed. This is one of the requirements to be considered for the Supabase stack.
+
+### How can you be a Firebase alternative if you're built with a relational database?
+
+We started Supabase because we love the functionality of Firebase, but we personally experienced the scaling issues that many others experienced. We chose Postgres because it's well-trusted, with phenomenal scalability.
+
+Our goal is to make Postgres as easy to use as Firebase, so that you no longer have to choose between usability and scalability.
+We're sure that once you start using Postgres, you'll love it more than any other database.
+
+### Do you support `[some other database]`?
+
+We only support PostgreSQL. It's unlikely we'll ever move away from Postgres; however, you can [vote on a new database](https://github.com/supabase/supabase/discussions/6) if you want us to start development.
+
+### Do you have a library for `[some other language]`?
+
+We officially support [JavaScript](/docs/reference/javascript/installing) and [Dart](/docs/reference/dart/installing).
+
+You can find community-supported libraries in our [GitHub Community](https://github.com/supabase-community), and you can also help us to identify the most popular languages by [voting for a new client library](https://github.com/supabase/supabase/discussions/5).
diff --git a/apps/reference/docs/going-into-prod.mdx b/apps/reference/docs/going-into-prod.mdx
new file mode 100644
index 00000000000..1abefc05cdb
--- /dev/null
+++ b/apps/reference/docs/going-into-prod.mdx
@@ -0,0 +1,63 @@
+---
+id: going-into-prod
+title: 'Production Readiness'
+description: 'Things to do before making your app publicly available'
+---
+
+After developing your project and deciding it's time to Go Live With Real Users, you should run through this checklist to ensure that your project is:
+
+- secure
+- won't falter under the expected load
+- remains available whilst in production
+
+## Security
+
+- Ensure RLS is enabled
+ - Tables that do not have RLS enabled with reasonable policies allow any client to access and modify their data. This is unlikely to be what you want in the majority of cases.
+ - [Learn more about RLS](/docs/guides/auth/row-level-security).
+- Enable replication on tables containing sensitive data by enabling Row Level Security (RLS) and setting row security policies:
+ - Go to the Authentication > Policies page in the Supabase Dashboard to enable RLS and create security policies.
+ - Go to the Database > Replication page in the Supabase Dashboard to manage replication tables.
+- Enable 2FA on GitHub. Since your GitHub account gives you administrative rights to your Supabase project, you should protect it with a strong password and 2FA using a U2F key or a TOTP app.
+- Ensure email confirmations are enabled in the `Auth > Settings` page.
+- Use a custom SMTP server for auth emails so that your users can see that the mails are coming from a trusted domain (preferably the same domain that your app is hosted on). Grab SMTP credentials from any major email provider such as SendGrid, AWS SES, etc.
+- Think hard about how _you_ would abuse your service as an attacker, and mitigate.
+- Review these [common cybersecurity threats](https://auth0.com/docs/security/prevent-threats).
+
+## Performance
+
+- Ensure that you have suitable indices to cater to your common query patterns
+ - [Learn more about indexes in Postgres](https://www.enterprisedb.com/postgres-tutorials/overview-postgresql-indexes).
+ - `pg_stat_statements` can help you [identify hot or slow queries](https://www.virtual-dba.com/blog/postgresql-performance-identifying-hot-and-slow-queries/).
+- Perform load testing (preferably on a staging env)
+ - Tools like [k6](https://k6.io/) can simulate traffic from many different users.
+- Upgrade your database if you require more resources. If you need anything beyond what is listed, contact enterprise@supabase.io.
+- If you are expecting a surge in traffic (for a big launch), let the team know by sending your Project Ref to us (support@supabase.io) with more details about your launch. We'll keep an eye on your project.
+
+## Availability
+
+- Use your own SMTP credentials so that you have full control over the deliverability of your transactional auth emails (see Auth > Settings)
+ - you can grab SMTP credentials from any major email provider such as SendGrid, AWS SES, etc.
+ - The default rate limit for auth emails provided by Supabase is 30 new users per hour, if doing a major public announcement you will likely require more than this.
+- If your application is on the free tier and is **not** expected to be queried at least once every 7 days, then it may be paused by Supabase to save on server resources.
+ - You can restore paused projects from the Supabase dashboard.
+ - Upgrade to Pro to guarantee that your project will not be paused for inactivity.
+- Database backups are not available for download on the free tier.
+ - You can set up your own backup systems using tools like [pg_dump](https://www.postgresqltutorial.com/postgresql-backup-database/) or [wal-g](https://github.com/wal-g/wal-g).
+ - Nightly backups for Pro tier projects are available on the Supabase dashboard for up to 7 days.
+- Upgrading to the Supabase Pro Tier will give you access to email support on support@supabase.io
+
+## Platform status
+
+If Supabase experiences outages, we keep you as informed as possible, as early as possible. We provide the following feedback channels:
+
+- Status page: [status.supabase.com](https://status.supabase.com/)
+- RSS Feed: [status.supabase.com/history.rss](https://status.supabase.com/history.rss)
+- Atom Feed: [status.supabase.com/history.atom](https://status.supabase.com/history.atom)
+- Slack Alerts: You can receive updates via the RSS feed, using Slack's [built-in RSS functionality](https://slack.com/help/articles/218688467-Add-RSS-feeds-to-Slack) `/feed subscribe https://status.supabase.com/history.atom`
+
+Make sure to review our [SLA](/docs/company/sla) for details on our commitment to Platform Stability.
+
+## Next steps
+
+This checklist is always growing so be sure to check back frequently, and also feel free to suggest additions and amendments by making a PR on [GitHub](https://github.com/supabase/supabase).
diff --git a/apps/reference/docs/gotrue/client/.gitkeep b/apps/reference/docs/gotrue/client/.gitkeep
new file mode 100644
index 00000000000..e69de29bb2d
diff --git a/apps/reference/docs/gotrue/server/about.md b/apps/reference/docs/gotrue/server/about.md
new file mode 100644
index 00000000000..e84698de591
--- /dev/null
+++ b/apps/reference/docs/gotrue/server/about.md
@@ -0,0 +1,708 @@
+---
+id: about
+title: GoTrue Auth Server
+description: An SWT based API for managing users and issuing SWT tokens
+---
+
+GoTrue is a small open-source API written in golang, that can act as a self-standing
+API service for handling user registration and authentication for JAM projects.
+
+It's based on OAuth2 and JWT and will handle user signup, authentication and custom
+user data.
+
+## Configuration
+
+You may configure GoTrue using either a configuration file named `.env`,
+environment variables, or a combination of both. Environment variables are prefixed with `GOTRUE_`, and will always have precedence over values provided via file.
+
+### Top-Level
+
+```
+GOTRUE_SITE_URL=https://example.netlify.com/
+```
+
+`SITE_URL` - `string` **required**
+
+The base URL your site is located at. Currently used in combination with other settings to construct URLs used in emails.
+
+`OPERATOR_TOKEN` - `string` _Multi-instance mode only_
+
+The shared secret with an operator (usually Netlify) for this microservice. Used to verify requests have been proxied through the operator and
+the payload values can be trusted.
+
+`DISABLE_SIGNUP` - `bool`
+
+When signup is disabled the only way to create new users is through invites. Defaults to `false`, all signups enabled.
+
+`GOTRUE_RATE_LIMIT_HEADER` - `string`
+
+Header on which to rate limit the `/token` endpoint.
+
+### API
+
+```
+GOTRUE_API_HOST=localhost
+PORT=9999
+```
+
+`API_HOST` - `string`
+
+Hostname to listen on.
+
+`PORT` (no prefix) / `API_PORT` - `number`
+
+Port number to listen on. Defaults to `8081`.
+
+`API_ENDPOINT` - `string` _Multi-instance mode only_
+
+Controls what endpoint Netlify can access this API on.
+
+`REQUEST_ID_HEADER` - `string`
+
+If you wish to inherit a request ID from the incoming request, specify the name in this value.
+
+### Database
+
+```
+GOTRUE_DB_DRIVER=mysql
+DATABASE_URL=root@localhost/gotrue
+```
+
+`DB_DRIVER` - `string` **required**
+
+Chooses what dialect of database you want. Must be `mysql`.
+
+`DATABASE_URL` (no prefix) / `DB_DATABASE_URL` - `string` **required**
+
+Connection string for the database.
+
+`DB_NAMESPACE` - `string`
+
+Adds a prefix to all table names.
+
+**Migrations Note**
+
+Migrations are not applied automatically, so you will need to run them after
+you've built gotrue.
+
+- If built locally: `./gotrue migrate`
+- Using Docker: `docker run --rm gotrue gotrue migrate`
+
+### Logging
+
+```
+LOG_LEVEL=debug # available without GOTRUE prefix (exception)
+GOTRUE_LOG_FILE=/var/log/go/gotrue.log
+```
+
+`LOG_LEVEL` - `string`
+
+Controls what log levels are output. Choose from `panic`, `fatal`, `error`, `warn`, `info`, or `debug`. Defaults to `info`.
+
+`LOG_FILE` - `string`
+
+If you wish logs to be written to a file, set `log_file` to a valid file path.
+
+### JSON Web Tokens (JWT)
+
+```
+GOTRUE_JWT_SECRET=supersecretvalue
+GOTRUE_JWT_EXP=3600
+GOTRUE_JWT_AUD=netlify
+```
+
+`JWT_SECRET` - `string` **required**
+
+The secret used to sign JWT tokens with.
+
+`JWT_EXP` - `number`
+
+How long tokens are valid for, in seconds. Defaults to 3600 (1 hour).
+
+`JWT_AUD` - `string`
+
+The default JWT audience. Use audiences to group users.
+
+`JWT_ADMIN_GROUP_NAME` - `string`
+
+The name of the admin group (if enabled). Defaults to `admin`.
+
+`JWT_DEFAULT_GROUP_NAME` - `string`
+
+The default group to assign all new users to.
+
+### External Authentication Providers
+
+We support `bitbucket`, `github`, `gitlab`, and `google` for external authentication.
+Use the names as the keys underneath `external` to configure each separately.
+
+```
+GOTRUE_EXTERNAL_GITHUB_CLIENT_ID=myappclientid
+GOTRUE_EXTERNAL_GITHUB_SECRET=clientsecretvaluessssh
+```
+
+No external providers are required, but you must provide the required values if you choose to enable any.
+
+`EXTERNAL_X_ENABLED` - `bool`
+
+Whether this external provider is enabled or not
+
+`EXTERNAL_X_CLIENT_ID` - `string` **required**
+
+The OAuth2 Client ID registered with the external provider.
+
+`EXTERNAL_X_SECRET` - `string` **required**
+
+The OAuth2 Client Secret provided by the external provider when you registered.
+
+`EXTERNAL_X_REDIRECT_URI` - `string` **required for gitlab**
+
+The URI a OAuth2 provider will redirect to with the `code` and `state` values.
+
+`EXTERNAL_X_URL` - `string`
+
+The base URL used for constructing the URLs to request authorization and access tokens. Used by `gitlab` only. Defaults to `https://gitlab.com`.
+
+### E-Mail
+
+Sending email is not required, but highly recommended for password recovery.
+If enabled, you must provide the required values below.
+
+```
+GOTRUE_SMTP_HOST=smtp.mandrillapp.com
+GOTRUE_SMTP_PORT=587
+GOTRUE_SMTP_USER=smtp-delivery@example.com
+GOTRUE_SMTP_PASS=correcthorsebatterystaple
+GOTRUE_SMTP_ADMIN_EMAIL=support@example.com
+GOTRUE_MAILER_SUBJECTS_CONFIRMATION="Please confirm"
+```
+
+`SMTP_ADMIN_EMAIL` - `string` **required**
+
+The `From` email address for all emails sent.
+
+`SMTP_HOST` - `string` **required**
+
+The mail server hostname to send emails through.
+
+`SMTP_PORT` - `number` **required**
+
+The port number to connect to the mail server on.
+
+`SMTP_USER` - `string`
+
+If the mail server requires authentication, the username to use.
+
+`SMTP_PASS` - `string`
+
+If the mail server requires authentication, the password to use.
+
+`SMTP_MAX_FREQUENCY` - `number`
+
+Controls the minimum amount of time that must pass before sending another signup confirmation or password reset email. The value is the number of seconds. Defaults to 900 (15 minutes).
+
+`MAILER_AUTOCONFIRM` - `bool`
+
+If you do not require email confirmation, you may set this to `true`. Defaults to `false`.
+
+`MAILER_SECURE_EMAIL_CHANGE_ENABLED` - `bool`
+
+If `true`, send an email to both the user's current and new email with a confirmation link, otherwise send an email with confirmation link only to new email. Defaults to `true`.
+
+`MAILER_URLPATHS_INVITE` - `string`
+
+URL path to use in the user invite email. Defaults to `/`.
+
+`MAILER_URLPATHS_CONFIRMATION` - `string`
+
+URL path to use in the signup confirmation email. Defaults to `/`.
+
+`MAILER_URLPATHS_RECOVERY` - `string`
+
+URL path to use in the password reset email. Defaults to `/`.
+
+`MAILER_URLPATHS_EMAIL_CHANGE` - `string`
+
+URL path to use in the email change confirmation email. Defaults to `/`.
+
+`MAILER_SUBJECTS_INVITE` - `string`
+
+Email subject to use for user invite. Defaults to `You have been invited`.
+
+`MAILER_SUBJECTS_CONFIRMATION` - `string`
+
+Email subject to use for signup confirmation. Defaults to `Confirm Your Signup`.
+
+`MAILER_SUBJECTS_RECOVERY` - `string`
+
+Email subject to use for password reset. Defaults to `Reset Your Password`.
+
+`MAILER_SUBJECTS_MAGIC_LINK` - `string`
+
+Email subject to use for magic link email. Defaults to `Your Magic Link`.
+
+`MAILER_SUBJECTS_EMAIL_CHANGE` - `string`
+
+Email subject to use for email change confirmation. Defaults to `Confirm Email Change`.
+
+`MAILER_TEMPLATES_INVITE` - `string`
+
+URL path to an email template to use when inviting a user.
+`SiteURL`, `Email`, and `ConfirmationURL` variables are available.
+
+Default Content (if template is unavailable):
+
+```html
+
You have been invited
+
+
+ You have been invited to create a user on {{ .SiteURL }}. Follow this link to
+ accept the invite:
+
+```
+
+`MAILER_TEMPLATES_CONFIRMATION` - `string`
+
+URL path to an email template to use when confirming a signup.
+`SiteURL`, `Email`, and `ConfirmationURL` variables are available.
+
+Default Content (if template is unavailable):
+
+```html
+
+```
+
+`MAILER_TEMPLATES_RECOVERY` - `string`
+
+URL path to an email template to use when resetting a password.
+`SiteURL`, `Email`, and `ConfirmationURL` variables are available.
+
+Default Content (if template is unavailable):
+
+```html
+
Reset Password
+
+
Follow this link to reset the password for your user:
+```
+
+`MAILER_TEMPLATES_MAGIC_LINK` - `string`
+
+URL path to an email template to use when sending magic link.
+`SiteURL`, `Email`, and `ConfirmationURL` variables are available.
+
+Default Content (if template is unavailable):
+
+```html
+
+```
+
+`MAILER_TEMPLATES_EMAIL_CHANGE` - `string`
+
+URL path to an email template to use when confirming the change of an email address.
+`SiteURL`, `Email`, `NewEmail`, and `ConfirmationURL` variables are available.
+
+Default Content (if template is unavailable):
+
+```html
+
Confirm Change of Email
+
+
+ Follow this link to confirm the update of your email from {{ .Email }} to {{
+ .NewEmail }}:
+
+```
+
+## Endpoints
+
+GoTrue exposes the following endpoints:
+
+### **GET /settings**
+
+Returns the publicly available settings for this gotrue instance.
+
+```json
+{
+ "external": {
+ "bitbucket": true,
+ "github": true,
+ "gitlab": true,
+ "google": true
+ },
+ "disable_signup": false,
+ "autoconfirm": false
+}
+```
+
+### **POST /signup**
+
+Register a new user with an email and password.
+
+```json
+{
+ "email": "email@example.com",
+ "password": "secret"
+}
+```
+
+Returns:
+
+```json
+{
+ "id": "11111111-2222-3333-4444-5555555555555",
+ "email": "email@example.com",
+ "confirmation_sent_at": "2016-05-15T20:49:40.882805774-07:00",
+ "created_at": "2016-05-15T19:53:12.368652374-07:00",
+ "updated_at": "2016-05-15T19:53:12.368652374-07:00"
+}
+```
+
+### **POST /invite**
+
+Invites a new user with an email.
+This endpoint requires the `service_role` or `supabase_admin` JWT set as an Auth Bearer header:
+
+e.g.
+
+```json
+headers: {
+ "Authorization" : "Bearer eyJhbGciOiJI...M3A90LCkxxtX9oNP9KZO"
+}
+```
+
+```json
+{
+ "email": "email@example.com"
+}
+```
+
+Returns:
+
+```json
+{
+ "id": "11111111-2222-3333-4444-5555555555555",
+ "email": "email@example.com",
+ "confirmation_sent_at": "2016-05-15T20:49:40.882805774-07:00",
+ "created_at": "2016-05-15T19:53:12.368652374-07:00",
+ "updated_at": "2016-05-15T19:53:12.368652374-07:00",
+ "invited_at": "2016-05-15T19:53:12.368652374-07:00"
+}
+```
+
+### **POST /verify**
+
+Verify a registration or a password recovery. Type can be `signup` or `recovery` or `invite`
+and the `token` is a token returned from either `/signup` or `/recover`.
+
+```json
+{
+ "type": "signup",
+ "token": "confirmation-code-delivered-in-email"
+}
+```
+
+`password` is required for signup verification if no existing password exists.
+
+Returns:
+
+```json
+{
+ "access_token": "jwt-token-representing-the-user",
+ "token_type": "bearer",
+ "expires_in": 3600,
+ "refresh_token": "a-refresh-token",
+ "type": "signup | recovery | invite"
+}
+```
+
+### **GET /verify**
+
+Verify a registration or a password recovery. Type can be `signup` or `recovery` or `magiclink` or `invite`
+and the `token` is a token returned from either `/signup` or `/recover` or `/magiclink`.
+
+query params:
+
+```json
+{
+ "type": "signup",
+ "token": "confirmation-code-delivered-in-email"
+}
+```
+
+User will be logged in and redirected to:
+
+```json
+SITE_URL/#access_token=jwt-token-representing-the-user&token_type=bearer&expires_in=3600&refresh_token=a-refresh-token&type=invite
+```
+
+Your app should detect the query params in the fragment and use them to set the session (supabase-js does this automatically)
+
+You can use the `type` param to redirect the user to a password set form in the case of `invite` or `recovery`,
+or show an account confirmed/welcome message in the case of `signup`, or direct them to some additional onboarding flow
+
+### **POST /magiclink**
+
+Magic Link. Will deliver a link (e.g. `/verify?type=magiclink&token=fgtyuf68ddqdaDd`) to the user based on
+email address which they can use to redeem an access_token.
+
+By default Magic Links can only be sent once every 60 seconds
+
+```json
+{
+ "email": "email@example.com"
+}
+```
+
+Returns:
+
+```json
+{}
+```
+
+when clicked the magic link will redirect the user to `#access_token=x&refresh_token=y&expires_in=z&token_type=bearer&type=magiclink` (see `/verify` above)
+
+### **POST /recover**
+
+Password recovery. Will deliver a password recovery mail to the user based on
+email address.
+
+By default recovery links can only be sent once every 60 seconds
+
+```json
+{
+ "email": "email@example.com"
+}
+```
+
+Returns:
+
+```json
+{}
+```
+
+### **POST /token**
+
+This is an OAuth2 endpoint that currently implements
+the password and refresh_token grant types
+
+query params:
+
+```
+?grant_type=password
+```
+
+body:
+
+```json
+{
+ "email": "name@domain.com",
+ "password": "somepassword"
+}
+```
+
+or
+
+query params:
+
+```
+grant_type=refresh_token
+```
+
+body:
+
+```json
+{
+ "refresh_token": "a-refresh-token"
+}
+```
+
+Once you have an access token, you can access the methods requiring authentication
+by settings the `Authorization: Bearer YOUR_ACCESS_TOKEN_HERE` header.
+
+Returns:
+
+```json
+{
+ "access_token": "jwt-token-representing-the-user",
+ "token_type": "bearer",
+ "expires_in": 3600,
+ "refresh_token": "a-refresh-token"
+}
+```
+
+### **GET /user**
+
+Get the JSON object for the logged in user (requires authentication)
+
+Returns:
+
+```json
+{
+ "id": "11111111-2222-3333-4444-5555555555555",
+ "email": "email@example.com",
+ "confirmation_sent_at": "2016-05-15T20:49:40.882805774-07:00",
+ "created_at": "2016-05-15T19:53:12.368652374-07:00",
+ "updated_at": "2016-05-15T19:53:12.368652374-07:00"
+}
+```
+
+### **PUT /user**
+
+Update a user (Requires authentication). Apart from changing email/password, this
+method can be used to set custom user data.
+
+```json
+{
+ "email": "new-email@example.com",
+ "password": "new-password",
+ "data": {
+ "key": "value",
+ "number": 10,
+ "admin": false
+ }
+}
+```
+
+Returns:
+
+```json
+{
+ "id": "11111111-2222-3333-4444-5555555555555",
+ "email": "email@example.com",
+ "confirmation_sent_at": "2016-05-15T20:49:40.882805774-07:00",
+ "created_at": "2016-05-15T19:53:12.368652374-07:00",
+ "updated_at": "2016-05-15T19:53:12.368652374-07:00"
+}
+```
+
+### **POST /admin/users**
+
+Creates a new user. Requires your `service_role` API key and thus should only be
+used in secure server-side environments.
+
+```json
+{
+ "email": "new-email@example.com",
+ "password": "new-password",
+ "data": {
+ "key": "value",
+ "number": 10,
+ "admin": false
+ }
+}
+```
+
+Returns:
+
+```json
+{
+ "id": "11111111-2222-3333-4444-5555555555555",
+ "aud": "authenticated",
+ "role": "authenticated",
+ "email": "email@example.com",
+ "app_metadata": {
+ "provider": "email"
+ },
+ "user_metadata": null,
+ "created_at": "2016-05-15T19:53:12.368652374-07:00",
+ "updated_at": "2016-05-15T19:53:12.368652374-07:00"
+}
+```
+
+### **GET /admin/users/{user_id}**
+
+Gets a user. Requires your `service_role` API key and thus should only be used
+in secure server-side environments.
+
+Returns:
+
+```json
+{
+ "id": "11111111-2222-3333-4444-5555555555555",
+ "aud": "authenticated",
+ "role": "authenticated",
+ "email": "email@example.com",
+ "app_metadata": {
+ "provider": "email"
+ },
+ "user_metadata": {},
+ "created_at": "2016-05-15T19:53:12.368652374-07:00",
+ "updated_at": "2016-05-15T19:53:12.368652374-07:00"
+}
+```
+
+### **PUT /admin/users/{user_id}**
+
+Updates a user. Requires your `service_role` API key and thus should only be
+used in secure server-side environments.
+
+```json
+{
+ "email": "email@example.com",
+ "password": "updated-password",
+ "data": {
+ "key": "updated-value",
+ "number": 10,
+ "admin": false
+ }
+}
+```
+
+Returns:
+
+```json
+{
+ "id": "11111111-2222-3333-4444-5555555555555",
+ "aud": "authenticated",
+ "role": "authenticated",
+ "email": "email@example.com",
+ "app_metadata": {
+ "provider": "email"
+ },
+ "user_metadata": {},
+ "created_at": "2016-05-15T19:53:12.368652374-07:00",
+ "updated_at": "2016-05-15T19:53:12.368652374-07:00"
+}
+```
+
+### **DELETE /admin/users/{user_id}**
+
+Deletes a user. Requires your `service_role` API key and thus should only be
+used in secure server-side environments.
+
+### **POST /logout**
+
+Logout a user (Requires authentication).
+
+This will revoke all refresh tokens for the user. Remember that the JWT tokens
+will still be valid for stateless auth until they expires.
+
+### **GET /authorize**
+
+Get access_token from external oauth provider
+
+query params:
+
+```
+provider=google | bitbucket | github | gitlab
+```
+
+Redirects to provider and then to `/callback`
+
+### **GET /callback**
+
+External provider should redirect to here
+
+Redirects to `#access_token=&refresh_token=&expires_in=3600&provider=`
+
+## Pre-built
+
+- [Docker](https://hub.docker.com/repository/docker/supabase/gotrue)
diff --git a/apps/reference/docs/guides/api.mdx b/apps/reference/docs/guides/api.mdx
new file mode 100644
index 00000000000..3d9c80e88f1
--- /dev/null
+++ b/apps/reference/docs/guides/api.mdx
@@ -0,0 +1,402 @@
+---
+id: api
+title: APIs
+description: Auto-generating and Realtime APIs.
+sidebar_label: Overview
+---
+
+import Tabs from '@theme/Tabs';
+import TabItem from '@theme/TabItem';
+
+## Overview
+
+Supabase generates three types of API directly from your database schema.
+
+- REST - interact with your database through a restful interface.
+- Realtime - listen to database changes.
+- GraphQL - [in beta](https://supabase.com/blog/2021/12/03/pg-graphql).
+
+The APIs are:
+
+- **Instant and auto-generated.** As you update your database the changes are immediately accessible through your API.
+- **Self documenting.** Supabase generates documentation in the Dashboard which updates as you make database changes.
+- **Secure.** The API is configured to work with PostgreSQL's Row Level Security, provisioned behind an API gateway with key-auth enabled.
+- **Fast.** Our benchmarks for basic reads are more than 300% faster than Firebase. The API is a very thin layer on top of Postgres, which does most of the heavy lifting.
+- **Scalable.** The API can serve thousands of simultaneous requests, and works well for Serverless workloads.
+
+
+### REST API {#rest-api-overview}
+
+Supabase provides a RESTful API using [PostgREST](https://postgrest.org/). This is a very thin API layer on top of Postgres.
+It provides everything you need from a CRUD API:
+
+- Basic CRUD operations
+- Deeply nested joins, allowing you to fetch data from multiple tables in a single fetch
+- Works with Postgres Views
+- Works with Postgres Functions
+- Works with the Postgres security model - including Row Level Security, Roles, and Grants.
+
+
+
+### GraphQL API {#graphql-api-overview}
+
+:::note
+
+GraphQL is in Beta, and may have breaking changes. It is only available on self-hosted setups and Supabase projects created after 28th March 2022.
+
+:::
+
+GraphQL in Supabase works through [pg_graphql](https://supabase.com/blog/2021/12/03/pg-graphql), an open source PostgreSQL extension for GraphQL.
+
+### Realtime API {#realtime-api-overview}
+
+Supabase provides a Realtime API using [Realtime](https://github.com/supabase/realtime). You can use this to listen to database changes over websockets.
+Realtime leverages PostgreSQL's built-in logical replication. You can manage your Realtime API simply by managing Postgres publications.
+
+## Getting started
+
+All APIs are auto-created from Database tables. After you have added tables or functions to your database, you can use the APIs provided.
+
+### Creating API Routes
+
+API routes are automatically created when you create Postgres Tables, Views, or Functions.
+
+Let's create our first
+API route by creating a table called `todos` to store tasks.
+This creates a corresponding route `todos` which can accept `GET`, `POST`, `PATCH`, & `DELETE` requests.
+
+
+
+
+
+1. Go to the [Table editor](https://app.supabase.com/project/_/editor) page in the Dashboard.
+1. Click **New Table** and create a table with the name `todos`.
+1. Click **Save**.
+1. Click **New Column** and create a column with the name `task` and type `text`.
+1. Click **Save**.
+
+
+
+
+
+
+```sql
+-- Create a table called "todos" with a column to store tasks.
+
+create table todos (
+ id bigint generated by default as identity primary key,
+ task text check (char_length(task) > 3)
+);
+```
+
+
+
+
+### API URL and Keys
+
+Every Supabase project has a unique API URL. Your API is secured behind an API gateway which requires an API Key for every request.
+
+1. Go to the [Settings](https://app.supabase.com/project/_/settings/general) page in the Dashboard.
+2. Click **API** in the sidebar.
+3. Find your API `URL`, `anon`, and `service_role` keys on this page.
+
+
+
+The REST API and the GraphQL API are both accessible through this URL:
+
+- REST: `https://.supabase.co/rest/v1`
+- GraphQL: `https://.supabase.co/graphql/v1`
+
+Both of these routes require the `anon` key to be passed through an `apikey` header.
+
+#### API Keys
+
+You are provided with two keys:
+
+- an `anon` key, which is safe to be used in a browser context.
+- a `service_role` key, which should only be used on a server. This key can bypass Row Level Security. NEVER use this key in a browser.
+
+
+### Accessing the docs in the Dashboard
+
+#### REST API {#rest-api-dashboard-docs}
+
+Supabase generates documentation in the [Dashboard](https://app.supabase.com) which updates as you make database changes.
+Let's view the documentation for a `countries` table which we created in our database.
+
+1. Go to the [API](https://app.supabase.com/project/_/api) page in the Dashboard.
+2. Find the `countries` table under **Tables and Views** in the sidebar.
+3. Switch between the JavaScript and the cURL docs using the tabs.
+
+
+
+#### GraphQL
+
+The GraphQL Endpoint that we provide (`https://.supabase.co/graphql/v1`) is compatible with any GraphiQL implementation that can pass an `apikey` header.
+Some suggested applications:
+
+- [paw.cloud](https://paw.cloud)
+- [insomnia.rest](https://insomnia.rest)
+- [postman.com/graphql](https://www.postman.com/graphql/)
+- Self-hosted GraphiQL: GraphiQL can be served through a simple HTML file. See [this discussion](https://github.com/supabase/supabase/discussions/6144) for more details.
+
+## Using the API
+
+
+### REST API
+
+You can interact with your API directly via HTTP requests, or you can use the client libraries which we provide.
+
+Let's see how to make a request to the `todos` table which we created in the first step,
+using the API URL (`SUPABASE_URL`) and Key (`SUPABASE_ANON_KEY`) we provided:
+
+
+
+
+
+
+```javascript
+// Initialize the JS client
+import { createClient } from '@supabase/supabase-js'
+const supabase = createClient(SUPABASE_URL, SUPABASE_ANON_KEY)
+
+// Make a request
+const { data: todos, error } = await supabase
+ .from('todos')
+ .select('*')
+```
+
+
+
+
+```bash
+# Append /rest/v1/ to your URL, and then use the table name as the route
+curl '/rest/v1/todos' \
+-H "apikey: " \
+-H "Authorization: Bearer "
+```
+
+
+
+
+JS Reference: [select()](/docs/reference/javascript/select),
+[insert()](/docs/reference/javascript/insert),
+[update()](/docs/reference/javascript/update),
+[upsert()](/docs/reference/javascript/upsert),
+[delete()](/docs/reference/javascript/delete),
+[rpc()](/docs/reference/javascript/rpc) (call Postgres functions).
+
+
+### GraphQL API
+
+:::note
+
+To rebuild your GraphQL schema from the SQL schema, call `select graphql.rebuild_schema();`.
+Be sure to rebuild the GraphQL schema after altering the SQL schema.
+
+:::
+
+You can use any GraphQL client with the Supabase GraphQL API. For our GraphQL example we will use [urql](https://formidable.com/open-source/urql/docs/).
+
+
+
+
+
+```javascript
+import { createClient, useQuery } from 'urql'
+
+// Prepare API key and Authorization header
+const headers = {
+ apikey: ,
+ authorization: `Bearer: ${
+}
+
+// Create GraphQL client
+// See: https://formidable.com/open-source/urql/docs/basics/react-preact/#setting-up-the-client
+const client = createClient({
+ url: '/graphql/v1',
+ fetchOptions: function createFetchOptions() {
+ return { headers }
+ },
+})
+
+// Prepare our GraphQL query
+const TodosQuery = `
+ query {
+ todosCollection {
+ edges {
+ node {
+ id
+ title
+ }
+ }
+ }
+ }
+`
+
+// Query for the data (React)
+const [result, reexecuteQuery] = useQuery({
+ query: TodosQuery,
+})
+
+// Read the result
+const { data, fetching, error } = result
+```
+
+
+
+
+```bash
+# Append /graphql/v1/ to your URL, and then use the table name as the route
+curl --request POST '/graphql/v1' \
+-H 'apikey: ' \
+-H 'Authorization: Bearer ' \
+-d '{ "query":"{ todos(first: 3) { edges { node { id } } } }" }'
+```
+
+
+
+
+
+### Realtime API
+
+By default Realtime is disabled on your database. Let's turn on Realtime for the `todos` table.
+
+
+
+
+
+1. Go to the [Database](https://app.supabase.com/project/_/database/tables) page in the Dashboard.
+2. Click on **Replication** in the sidebar.
+3. Control which database events are sent by toggling **Insert**, **Update**, and **Delete**.
+4. Control which tables broadcast changes by selecting **Source** and toggling each table.
+
+
+
+
+
+
+```sql
+alter publication supabase_realtime add table todos;
+```
+
+
+
+
+From the client, we can listen to any new data that is inserted into the `todos` table:
+
+```javascript
+// Initialize the JS client
+import { createClient } from '@supabase/supabase-js'
+const supabase = createClient(SUPABASE_URL, SUPABASE_ANON_KEY)
+
+// Create a function to handle inserts
+const handleInserts = (payload) => {
+ console.log('Change received!', payload)
+}
+
+// Listen to inserts
+const { data: todos, error } = await supabase
+ .from('todos')
+ .on('INSERT', handleInserts)
+ .subscribe()
+```
+
+Use [subscribe()](/docs/reference/javascript/subscribe) to listen to database changes.
+The Realtime API works through PostgreSQL's replication functionality. Postgres sends database changes to a [publication](/docs/guides/database/replication#publications)
+called `supabase_realtime`, and by managing this publication you can control which data is broadcast.
+
+## API Security
+
+
+### Securing your Routes
+
+
+Your API is designed to work with Postgres Row Level Security (RLS). If you use Supabase [Auth](/docs/guides/auth), you can restrict data based on the logged-in user.
+To control access to your data, you can use [Policies](/docs/guides/auth#policies).
+When you create a table in Postgres, Row Level Security is disabled by default. To enable RLS:
+
+
+
+
+
+1. Go to the [Authentication](https://app.supabase.com/project/_/auth/users) page in the Dashboard.
+2. Click on **Policies** in the sidebar.
+3. Select **Enable RLS** to enable Row Level Security.
+
+
+
+
+```sql
+alter table todos enable row level security;
+```
+
+
+
+
+### The `service_role` key
+
+Never expose the `service_role` key in a browser or anywhere where a user can see it. This Key can is designed to bypass Row Level Security - so it should only be used on a private server.
+
+We have [partnered with GitHub](https://supabase.com/blog/2022/03/28/community-day#supabase-is-now-a-github-secret-scanning-partner) to scan for Supabase `service_role` keys pushed to public repositories.
+If they detect any keys with service_role privileges being pushed to GitHub, they will forward the API key to us, so that we can automatically revoke the detected secrets and notify you, protecting your data against malicious actors.
+
+### Safeguards towards accidental deletes and updates
+
+For all projects, by default, the Postgres extension [safeupdate](https://github.com/eradman/pg-safeupdate) is enabled for all queries coming from the API.
+This ensures that any `delete()` or `update()` would fail if there are no accompanying filters provided.
+To confirm that safeupdate is enabled for queries going through the API of your project, the following query could be run:
+```sql
+select usename,useconfig from pg_shadow where usename = 'authenticator' ;
+```
+
+The expected value for `useconfig` should be:
+```
+["session_preload_libraries=supautils, safeupdate"]
+```
diff --git a/apps/reference/docs/guides/api/generating-types.mdx b/apps/reference/docs/guides/api/generating-types.mdx
new file mode 100644
index 00000000000..db7882f66d0
--- /dev/null
+++ b/apps/reference/docs/guides/api/generating-types.mdx
@@ -0,0 +1,118 @@
+---
+id: generating-types
+title: "Generating Types"
+description: How to generate types for your API and Supabase libraries.
+---
+
+Supabase APIs are generated from your database, which means that we can use database introspection to generate type-safe API definitions.
+
+### Generating types from OpenAPI specification
+
+Supabase generates an OpenAPI specification file for your database which can be used to generate your data types for usage with TypeScript.
+
+The OpenAPI specification for your Supabase project can be accessed as follows:
+
+```txt
+https://your-project.supabase.co/rest/v1/?apikey=your-anon-key
+```
+
+Using the open source [openapi-typescript](https://github.com/drwpow/openapi-typescript#%EF%B8%8F-reading-specs-from-remote-resource) tool you can generate your types and store them locally:
+
+```bash
+npx openapi-typescript https://your-project.supabase.co/rest/v1/?apikey=your-anon-key --output types/supabase.ts
+```
+
+Important notes:
+
+- Since the generator uses JSON API, there is no way to determine if a column is an Array. It will generate array types as `string`, even though Supabase handles this automatically and returns arrays.
+ You can fix this manually in the files by changing the type, e.g. `names: string` -> `names: string[]`
+- The types won't automatically stay in sync with your database, so make sure to regenerate your types after your make changes to your database.
+
+After you have generated your types, you can use them in your TypeScript projects:
+
+```ts
+import { NextApiRequest, NextApiResponse } from "next"
+import { createClient } from "@supabase/supabase-js"
+import { definitions } from "../../types/supabase"
+
+const supabase = createClient(
+ process.env.NEXT_PUBLIC_SUPABASE_URL,
+ process.env.SUPABASE_SECRET_KEY
+)
+
+export default async (req: NextApiRequest, res: NextApiResponse) => {
+ const allOnlineUsers = await supabase
+ .from("users")
+ .select("*")
+ .eq("status", "ONLINE")
+ res.status(200).json(allOnlineUsers)
+};
+```
+
+For more advance type-support, check out [`postgrest-js-tools`](https://github.com/mzalevski/postgrest-js-tools).
+
+## Update types automatically with GitHub Actions
+
+One way to keep your type definitions in sync with your database is to set up a GitHub action that runs on a schedule.
+
+The following script can be run in your terminal to produce the file `types/database/index.ts`.
+```
+npx openapi-typescript https://your-project.supabase.co/rest/v1/?apikey=your-anon-key --output types/database/index.ts
+```
+
+You can add this script to your `package.json` and run it using `npm run update-types`:
+
+```
+"update-types": "npx openapi-typescript \"${SUPABASE_URL}/rest/v1/?apikey=${SUPABASE_ANON_KEY}\" --version=2 --output types/database/index.ts"
+```
+
+You can use GitHub actions to generate this file automatically. This script will commit the change to your repo every night.
+Create a file `.github/workflows/update-types.yml` and add the following snippet into this file to define the action along with the environment variables.
+
+```yml
+name: Update database types
+
+on:
+ schedule:
+ # sets the action to run daily. You can modify this to run the action more or less frequently
+ - cron: '0 0 * * *'
+
+jobs:
+ update:
+ runs-on: ubuntu-latest
+ env:
+ SUPABASE_URL: ${{secrets.SUPABASE_URL}}
+ SUPABASE_ANON_KEY: ${{secrets.SUPABASE_ANON_KEY}}
+ steps:
+ - uses: actions/checkout@v2
+ with:
+ persist-credentials: false
+ fetch-depth: 0
+ - uses: actions/setup-node@v2.1.5
+ with:
+ node-version: 14
+ - run: npm run update-types
+ - name: check for file changes
+ id: git_status
+ run: |
+ echo "::set-output name=status::$(git status -s)"
+ - name: Commit files
+ if: ${{contains(steps.git_status.outputs.status, ' ')}}
+ run: |
+ git add types/database/index.ts
+ git config --local user.email "41898282+github-actions[bot]@users.noreply.github.com"
+ git config --local user.name "github-actions[bot]"
+ git commit -m "Update database types" -a
+ - name: Push changes
+ if: ${{contains(steps.git_status.outputs.status, ' ')}}
+ uses: ad-m/github-push-action@master
+ with:
+ github_token: ${{ secrets.GITHUB_TOKEN }}
+ branch: ${{ github.ref }}
+```
+
+Alternatively, you can use a community-supported GitHub action: [generate-supabase-db-types-github-action](https://github.com/lyqht/generate-supabase-db-types-github-action).
+
+## Resources
+
+- [Generating Supabase types with GitHub Actions](https://blog.esteetey.dev/how-to-create-and-test-a-github-action-that-generates-types-from-supabase-database)
\ No newline at end of file
diff --git a/apps/reference/docs/guides/auth.mdx b/apps/reference/docs/guides/auth.mdx
new file mode 100644
index 00000000000..6efba7332ff
--- /dev/null
+++ b/apps/reference/docs/guides/auth.mdx
@@ -0,0 +1,167 @@
+---
+id: auth
+title: Auth
+description: Use Supabase to Authenticate and Authorize your users.
+sidebar_label: Overview
+---
+
+import Link from '@docusaurus/Link'
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+import providers from '@site/src/data/authProviders'
+
+
+
+## Overview
+
+There are two parts to every Auth system:
+
+- **Authentication:** should this person be allowed in? If yes, who are they?
+- **Authorization:** once they are in, what are they allowed to do?
+
+Supabase Auth is designed to work either as a standalone product, or deeply integrated with the other Supabase products.
+Postgres is at the heart of everything we do, and the Auth system follows this principle. We leverage Postgres' built-in Auth functionality wherever possible.
+
+## Authentication
+
+You can authenticate your users in several ways:
+
+- Email & password.
+- Magic links (one-click logins).
+- Social providers.
+- Phone logins.
+
+### Providers
+
+We provide a suite of Providers and login methods.
+
+
+
+
+### Simple interface
+
+You can enable third-providers with the click of a button by navigating to Authentication > Settings > External OAuth Providers and inputting your `Client ID` and `Secret` for each.
+
+
+
+
+## Authorization
+
+
+When you need granular authorization rules, nothing beats PostgreSQL's Row Level Security (RLS).
+
+Policies are PostgreSQL's rule engine. They are incredibly powerful and flexible, allowing you to write complex SQL rules which fit your unique business needs.
+
+Get started with our [Row Level Security Guides](/docs/guides/auth/row-level-security).
+
+
+### Row Level Security
+
+Authentication only gets you so far. When you need granular authorization rules, nothing beats PostgreSQL's [Row Level Security (RLS)](https://www.postgresql.org/docs/current/ddl-rowsecurity.html). Supabase makes it simple to turn RLS on and off.
+
+
+
+### Policies
+
+[Policies](https://www.postgresql.org/docs/current/sql-createpolicy.html) are PostgreSQL's rule engine. They are incredibly powerful and flexible, allowing you to write complex SQL rules which fit your unique business needs.
+
+
+
+With policies, your database becomes the rules engine. Instead of repetitively filtering your queries, like this ...
+
+```js
+const loggedInUserId = 'd0714948'
+let { data, error } = await supabase
+ .from('users')
+ .select('user_id, name')
+ .eq('user_id', loggedInUserId)
+
+// console.log(data)
+// => { id: 'd0714948', name: 'Jane' }
+```
+
+... you can simply define a rule on your database table, `auth.uid() = user_id`, and your request will return the rows which pass the rule, even when you remove the filter from your middleware:
+
+```js
+let { data, error } = await supabase.from('users').select('user_id, name')
+
+// console.log(data)
+// Still => { id: 'd0714948', name: 'Jane' }
+```
+
+
+### How It Works
+
+1. A user signs up. Supabase creates a new user in the `auth.users` table.
+2. Supabase returns a new JWT, which contains the user's `UUID`.
+3. Every request to your database also sends the JWT.
+4. Postgres inspects the JWT to determine the user making the request.
+5. The user's UID can be used in policies to restrict access to rows.
+
+Supabase provides a special function in Postgres, `auth.uid()`, which extracts the user's UID from the JWT. This is especially useful when creating policies.
+
+
+
+## User Management
+
+Supabase makes it simple to manage your users.
+
+
+
+When users sign up, Supabase assigns them a unique ID. You can reference this ID anywhere in your database. For example, you might create a `profiles` table referencing `id` in the `auth.users` table using a `user_id` field.
+
+Supabase provides the routes to [sign up](/docs/reference/javascript/auth-signup), [log in](/docs/reference/javascript/auth-signin),
+[log out](/docs/reference/javascript/auth-signout), and manage users in your apps and websites.
+
+
+## Next Steps
+
+- Sign in: [app.supabase.com](https://app.supabase.com)
diff --git a/apps/reference/docs/guides/auth/auth-apple.mdx b/apps/reference/docs/guides/auth/auth-apple.mdx
new file mode 100644
index 00000000000..fc3f776eca1
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-apple.mdx
@@ -0,0 +1,214 @@
+---
+id: auth-apple
+title: 'Login with Apple'
+description: Add Apple OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable Apple Auth for your project, you need to set up an Apple OAuth application and add the application credentials to your Supabase Dashboard.
+
+## Overview
+
+Apple OAuth consists of six broad steps:
+
+- Obtaining an `App Id` with “Sign In with Apple” capabilities.
+- Obtaining a `Services Id` - this will serve as the `client_id`.
+- Obtaining a `secret key` that will be used to get our `client_secret`.
+- Generating the `client_secret` using the `secret key`.
+- Add your `client id` and `client secret` keys to your [Supabase Project](https://app.supabase.com).
+- Add the login code to your [Supabase JS Client App](https://github.com/supabase/supabase-js).
+
+## Steps
+
+### Access your Apple Developer account
+
+- Go to [developer.apple.com](https://developer.apple.com).
+- Click on `Account` at the top right to log in.
+
+
+
+### Obtain an App ID
+
+- Go to `Certificates, Identifiers & Profiles`.
+- Click on `Identifiers` at the left.
+- Click on the `+` sign in the upper left next to `Identifiers`.
+- Select `App IDs` and click `Continue`.
+- Select type `App` and click `Continue`.
+- Fill out your app information:
+ - App description.
+ - Bundle ID (Apple recommends reverse-domain name style, so if your domain is acme.com and your app is called roadrunner, use: "com.acme.roadrunner").
+ - Scroll down and check `Sign In With Apple`.
+ - Click `Continue` at the top right.
+ - Click `Register` at the top right.
+
+### Obtain a Services ID
+
+This will serve as the `client_id` when you make API calls to authenticate the user.
+
+- Go to `Certificates, Identifiers & Profiles`.
+- Click on `Identifiers` at the left.
+- Click on the `+` sign in the upper left next to `Identifiers`.
+- Select `Services IDs` and click `Continue`.
+- Fill out your information:
+ - App description.
+ - Bundle ID (you can't use the same Bundle ID from the previous step, but you can just add something to the beginning, such as "app." to make it app.com.acme.roadrunner").
+ - SAVE THIS ID -- this ID will become your `client_id` later.
+ - Click `Continue` at the top right.
+ - Click `Register` at the top right.
+
+### Find your callback URL
+
+The next step requires a callback URL, which looks like this:
+
+`https://.supabase.co/auth/v1/callback`
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- Click on the `Settings` icon at the bottom of the left sidebar.
+- Click on `API` in the list.
+- Under Config / URL you'll find your API URL, you can click `Copy` to copy it to the clipboard.
+- Now just add `/auth/v1/callback` to the end of that to get your full `OAuth Redirect URI`.
+
+
+
+### Configure your Services ID
+
+- Under `Identifiers`, click on your newly-created Services ID.
+- Check the box next to `Sign In With Apple` to enable it.
+- Click `Configure` to the right.
+- Make sure your newly created Bundle ID is selected under `Primary App ID`
+- Add your domain to the `Domains and Subdomains` box (do not add `https://`, just add the domain).
+- In the `Return URLs` box, type the callback URL of your app which you found in the previous step and click `Next` at the bottom right.
+- Click `Done` at the bottom.
+- Click `Continue` at the top right.
+- Click `Save` at the top right.
+
+### Download your secret key
+
+Now you'll need to download a `secret key` file from Apple that will be used to generate your `client_secret`.
+
+- Go to `Certificates, Identifiers & Profiles`.
+- Click on `Keys` at the left.
+- Click on the `+` sign in the upper left next to `Keys`.
+- Enter a `Key Name`.
+- Check `Sign In with Apple`.
+- Click `Configure` to the right.
+- Select your newly-created Services ID from the dropdown selector.
+- Click `Save` at the top right.
+- Click `Continue` at the top right.
+- Click `Register` at the top right.
+- Click `Download` at the top right.
+- Save the downloaded file -- this contains your "secret key" that will be used to generate your `client_secret`.
+- Click `Done` at the top right.
+
+### Generate a `client_secret`
+
+The `secret key` you downloaded is used to create the `client_secret` string you'll need to authenticate your users.
+
+According to the [Apple Docs](https://developer.apple.com/documentation/signinwithapplerestapi/generate_and_validate_tokens) it needs to be a JWT
+token encrypted using the Elliptic Curve Digital Signature Algorithm (ECDSA) with the P-256 curve and the SHA-256 hash algorithm.
+
+At this time, the easiest way to generate this JWT token is with [Ruby](https://www.ruby-lang.org/en/).
+If you don't have Ruby installed, you can [Download Ruby Here](https://www.ruby-lang.org/en/downloads).
+
+- Install Ruby (or check to make sure it's installed on your system).
+- Install [ruby-jwt](https://github.com/jwt/ruby-jwt).
+- From the command line, run: `sudo gem install jwt`.
+
+Create the script below using a text editor: `secret_gen.rb`
+
+```ruby
+require "jwt"
+
+key_file = "Path to the private key"
+team_id = "Your Team ID"
+client_id = "The Service ID of the service you created"
+key_id = "The Key ID of the private key"
+
+validity_period = 180 # In days. Max 180 (6 months) according to Apple docs.
+
+private_key = OpenSSL::PKey::EC.new IO.read key_file
+
+token = JWT.encode(
+ {
+ iss: team_id,
+ iat: Time.now.to_i,
+ exp: Time.now.to_i + 86400 * validity_period,
+ aud: "https://appleid.apple.com",
+ sub: client_id
+ },
+ private_key,
+ "ES256",
+ header_fields=
+ {
+ kid: key_id
+ }
+)
+puts token
+```
+
+1. Edit the `secret_gen.rb` file:
+
+- `key_file` = "Path to the private key you downloaded from Apple". It should look like this: `AuthKey_XXXXXXXXXX.p8`.
+- `team_id` = "Your Team ID". This is found at the top right of the Apple Developer site (next to your name).
+- `client_id` = "The Service ID of the service you created". This is the `Services ID` you created in the above step `Obtain a Services ID`. If you've lost this ID, you can find it in the Apple Developer Site:
+ - Go to `Certificates, Identifiers & Profiles`.
+ - Click `Identifiers` at the left.
+ - At the top right drop-down, select `Services IDs`.
+ - Find your Identifier in the list (i.e. app.com.acme.roadrunner).
+- `key_id` = "The Key ID of the private key". This can be found in the name of your downloaded secret file (For a file named `AuthKey_XXXXXXXXXX.p8` your key_id is `XXXXXXXXXX`). If you've lost this ID, you can find it in the Apple Developer Site:
+ - Go to `Certificates, Identifiers & Profiles`.
+ - Click `Keys` at the left.
+ - Click on your newly-created key in the list.
+ - Look under `Key ID` to find your key_id.
+
+2. From the command line, run: `ruby secret_gen.rb > client_secret.txt`.
+3. Your `client_secret` is now stored in this `client_secret.txt` file.
+
+### Add your OAuth credentials to Supabase
+
+- Go to your [Supabase Dashboard](https://app.supabase.com).
+- In the left sidebar, click the `Authentication` icon (near the top).
+- Click `Settings` from the list to go to the `Authentication Settings` page.
+- Enter the final (hosted) URL of your app under `Site URL` (this is important).
+- Under `External OAuth Providers` turn `Apple Enabled` to ON.
+- Enter your `client_id` and `client_secret` saved in the previous steps.
+- Click `Save`.
+
+### Add login code to your client app
+
+The JavaScript client code is documented in the [Supabase OAuth Reference](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers).
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'apple',
+})
+```
+
+Add a function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithApple() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'apple',
+ })
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- [Apple Developer Account](https://developer.apple.com).
+- [Ruby](https://www.ruby-lang.org/en/) Docs.
+- [ruby-jwt](https://github.com/jwt/ruby-jwt) library.
+- Thanks to [Janak Amarasena](https://medium.com/@janakda) who did all the heavy lifting in [How to configure Sign In with Apple](https://medium.com/identity-beyond-borders/how-to-configure-sign-in-with-apple-77c61e336003).
diff --git a/apps/reference/docs/guides/auth/auth-azure.mdx b/apps/reference/docs/guides/auth/auth-azure.mdx
new file mode 100644
index 00000000000..9b8b0e0ccf1
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-azure.mdx
@@ -0,0 +1,101 @@
+---
+id: auth-azure
+title: 'Login with Azure'
+description: Add Azure OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable Azure Auth for your project, you need to set up an Azure OAuth application and add the application credentials to your Supabase Dashboard.
+
+## Overview
+
+Azure OAuth consists of four broad steps:
+
+- Create an application under Azure Active Directory.
+- Obtain a `Application (client) ID` with “Sign In with Azure” capabilities. This will be used as the `client id`.
+- Create a `Secret ID` with “Sign In with Azure” capabilities. The value of the secret will be used as the `client secret`.
+- Whitelist the callback url of your application.
+
+## Steps
+
+### Access your Azure Developer account
+
+- Go to [portal.azure.com](https://portal.azure.com/#home).
+- Login and select "Azure Active Directory" under the list of Azure Services.
+
+### Register an application
+
+- Under Azure Active Directory, select "App registrations" in the side panel.
+- Select "New registration".
+- Choose a name and select your preferred option for the supported account types.
+- Specify the "Redirect URI".
+- The redirect / callback URI should look like this: `https://.supabase.co/auth/v1/callback`
+- Click "Register" at the bottom of the form.
+
+
+
+### Obtain a Client ID
+
+This will serve as the `client_id` when you make API calls to authenticate the user.
+
+- Once your app has been registered, the client id can be found under the [list of app registrations](https://portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/RegisteredApps) under the column titled "Application (client) ID".
+
+
+
+### Obtain a Secret ID
+
+This will serve as the `client_secret` when you make API calls to authenticate the user.
+
+- Click on the name of the app registered above.
+- Under "Essentials", click on "Client credentials".
+- Navigate to the "Client secrets" tab and select "New client secret".
+- Enter a description and choose your preferred expiry for the secret.
+- Once the secret is generated, save the `value` (not the secret ID).
+
+
+
+## Obtain the Tenant URL
+
+This will allow your users to use your custom Azure login page when logging in.
+
+- Select the Directory (Tenant) ID value.
+- The Azure Tenant URL should look like this: `https://login.microsoftonline.com/`
+
+
+
+### Add login code to your client app
+
+The JavaScript client code is documented in the [Supabase OAuth Reference](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers).
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'azure',
+})
+```
+
+Add a function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithAzure() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'azure',
+ }, {
+ scopes: 'email',
+ })
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- [Azure Developer Account](https://portal.azure.com).
+- [GitHub Discussion](https://github.com/supabase/gotrue/pull/54#issuecomment-757043573).
diff --git a/apps/reference/docs/guides/auth/auth-bitbucket.mdx b/apps/reference/docs/guides/auth/auth-bitbucket.mdx
new file mode 100644
index 00000000000..774cd32c91d
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-bitbucket.mdx
@@ -0,0 +1,102 @@
+---
+id: auth-bitbucket
+title: 'Login with Bitbucket'
+description: Add Bitbucket OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable Bitbucket Auth for your project, you need to set up a BitBucket OAuth application and add the application credentials to your Supabase Dashboard.
+
+## Overview
+
+Setting up Bitbucket logins for your application consists of 3 parts:
+
+- Create and configure a Bitbucket OAuth Consumer on [Bitbucket](https://bitbucket.org)
+- Add your Bitbucket OAuth Consumer keys to your [Supabase Project](https://app.supabase.com)
+- Add the login code to your [Supabase JS Client App](https://github.com/supabase/supabase-js)
+
+## Steps
+
+### Access your Bitbucket account
+
+- Go to [bitbucket.org](https://bitbucket.org/).
+- Click on `Login` at the top right to log in.
+
+
+
+### Find your callback URL
+
+The next step requires a callback URL, which looks like this:
+
+`https://.supabase.co/auth/v1/callback`
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- Click on the `Settings` icon at the bottom of the left sidebar.
+- Click on `API` in the list.
+- Under Config / URL you'll find your API URL, you can click `Copy` to copy it to the clipboard.
+- Now just add `/auth/v1/callback` to the end of that to get your full `OAuth Redirect URI`.
+
+
+
+### Create a Bitbucket OAuth app
+
+- Click on your profile icon at the bottom left
+- Click on `All Workspaces`
+- Select a workspace and click on it to select it
+- Click on `Settings` on the left
+- Click on `OAuth consumers` on the left under `Apps and Features` (near the bottom)
+- Click `Add Consumer` at the top
+- Enter the name of your app under `Name`
+- In `Callback URL`, type the callback URL of your app
+- Check the permissions you need (Email, Read should be enough)
+- Click `Save` at the bottom
+- Click on your app name (the name of your new OAuth Consumer)
+- Copy your `Key` (`client_key`) and `Secret` (`client_secret`) codes
+
+### Add your Bitbucket credentials into your Supabase Project
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com)
+- In the left sidebar, click the `Authentication` icon (near the top)
+- Click `Settings` from the list to go to the `Authentication Settings` page
+- Enter the final (hosted) URL of your app under `Site URL` (this is important)
+- Under `External OAuth Providers` turn `Bitbucket Enabled` to ON
+- Enter your `client_id` and `client_secret` saved in the previous step
+- Click `Save`
+
+### Add login code to your client app
+
+The JavaScript client code is documented here: [Supabase OAuth Client Code](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers)
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'bitbucket',
+})
+```
+
+Add this function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithBitbucket() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'bitbucket',
+ })
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [Bitbucket Account](https://bitbucket.org)
diff --git a/apps/reference/docs/guides/auth/auth-discord.mdx b/apps/reference/docs/guides/auth/auth-discord.mdx
new file mode 100644
index 00000000000..05ea31a6eea
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-discord.mdx
@@ -0,0 +1,108 @@
+---
+id: auth-discord
+title: 'Login with Discord'
+description: Add Discord OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable Discord Auth for your project, you need to set up a Discord Application and add the Application OAuth credentials to your Supabase Dashboard.
+
+## Overview
+
+Setting up Discord logins for your application consists of 3 parts:
+
+- Create and configure a Discord Application [Discord Developer Portal](https://discord.com/developers)
+- Add your Discord OAuth Consumer keys to your [Supabase Project](https://app.supabase.com)
+- Add the login code to your [Supabase JS Client App](https://github.com/supabase/supabase-js)
+
+## Steps
+
+### Access your Discord account
+
+- Go to [discord.com](https://discord.com/).
+- Click on `Login` at the top right to log in.
+
+
+
+- Once logged in, go to [discord.com/developers](https://discord.com/developers).
+
+
+
+### Find your callback URL
+
+In the next step you require a callback URL, which looks like this:
+
+`https://.supabase.co/auth/v1/callback`
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- Click on the `Settings` icon at the bottom of the left sidebar.
+- Click on `API` in the list.
+- Under Config / URL you'll find your API URL, you can click `Copy` to copy it to the clipboard.
+- Now just add `/auth/v1/callback` to the end of that to get your full `OAuth Redirect URI`.
+
+
+
+### Create a Discord Application
+
+- Click on `New Application` at the top right.
+- Enter the name of your application and click `Create`.
+- Click on `OAuth2` under `Settings` in the left side panel.
+- Click `Add Redirect` under `Redirects`.
+- Type or paste your `callback URL` into the `Redirects` box.
+- Click `Save Changes` at the bottom.
+- Copy your `Client ID` and `Client Secret` under `Client information`.
+
+### Add your Discord credentials into your Supabase Project
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com)
+- In the left sidebar, click the `Authentication` icon (near the top)
+- Click `Settings` from the list to go to the `Authentication Settings` page
+- Enter the final (hosted) URL of your app under `Site URL` (this is important)
+- Under `External OAuth Providers` turn `Discord Enabled` to ON
+- Enter your `client_id` and `client_secret` saved in the previous step
+- Click `Save`
+
+### Add login code to your client app
+
+The JavaScript client code is documented here: [Supabase OAuth Client Code](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers)
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'discord',
+})
+```
+
+:::note
+
+If you call `signIn()` when already logged in, Discord will prompt the user again for authorization.
+
+:::
+
+Add this function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithDiscord() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'discord',
+ })
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [Discord Account](https://discord.com)
+- [Discord Developer Portal](https://discord.com/developers)
diff --git a/apps/reference/docs/guides/auth/auth-email.mdx b/apps/reference/docs/guides/auth/auth-email.mdx
new file mode 100644
index 00000000000..8edcca138e2
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-email.mdx
@@ -0,0 +1,143 @@
+---
+id: auth-email
+title: 'Login With Email'
+description: Use Supabase to Authenticate and Authorize your users using email.
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+## Overview
+
+Setting up Email logins for your Supabase application.
+
+- Add Email authenticator to your [Supabase Project](https://app.supabase.com)
+- Add the login code to your application - [JavaScript](https://github.com/supabase/supabase-js) | [Dart](https://github.com/supabase/supabase-dart)
+
+## Configure email settings
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com)
+- In the left sidebar, click the `Authentication` icon (near the top)
+- Click `Settings` from the list to go to the `Authentication Settings` page
+- Enter the final (hosted) URL of your app under `Site URL`
+- Under `Email Auth` turn `Enable Email Signup` to ON
+- Click `Save`
+
+:::note Self hosting
+
+For self-hosting, you can update your project configuration using the files and environment variables provided.
+See the [self-hosting docs](/docs/guides/hosting/overview#configuration) for details.
+
+:::
+
+### Add login code to your client app
+
+Add logins using our client libraries:
+
+- [JavaScript](/docs/reference/javascript/auth-signin#sign-in-with-email)
+- [Dart](/docs/reference/dart/auth-signin#sign-in-with-email)
+
+
+
+
+
+```js
+const { user, error } = await supabase.auth.signIn({
+ email: 'example@email.com',
+ password: 'example-password',
+})
+```
+
+
+
+
+
+```dart
+final res = await supabase.auth.signIn(
+ email: 'example@email.com',
+ password: 'example-password'
+);
+
+final user = res.data?.user;
+final error = res.error;
+```
+
+
+
+
+
+Add this function which you can call from a button, link, or UI element.
+
+
+
+
+
+```js
+async function signInWithEmail() {
+ const { user, error } = await supabase.auth.signIn({
+ email: 'example@email.com',
+ password: 'example-password',
+ })
+}
+```
+
+
+
+
+
+```dart
+Future signInWithEmail() async {
+ await supabase.auth.signIn(
+ email: 'example@email.com',
+ password: 'example-password'
+ );
+}
+```
+
+
+
+
+
+To log out:
+
+
+
+
+
+```js
+async function signOut() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+
+
+
+
+```dart
+Future signOut() async {
+ await supabase.auth.signOut();
+}
+```
+
+
+
+
+
+## Resources
+
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [Supabase Dart Client](https://github.com/supabase/supabase-dart)
diff --git a/apps/reference/docs/guides/auth/auth-facebook.mdx b/apps/reference/docs/guides/auth/auth-facebook.mdx
new file mode 100644
index 00000000000..d3fcccb5c06
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-facebook.mdx
@@ -0,0 +1,119 @@
+---
+id: auth-facebook
+title: 'Login with Facebook'
+description: Add Facebook OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable Facebook Auth for your project, you need to set up a Facebook OAuth application and add the application credentials to your Supabase Dashboard.
+
+## Overview
+
+Setting up Facebook logins for your application consists of 3 parts:
+
+- Create and configure a Facebook Application on the [Facebook Developers Site](https://developers.facebook.com)
+- Add your Facebook keys to your [Supabase Project](https://app.supabase.com)
+- Add the login code to your [Supabase JS Client App](https://github.com/supabase/supabase-js)
+
+## Steps
+
+### Access your Facebook Developer account
+
+- Go to [developers.facebook.com](https://developers.facebook.com).
+- Click on `Log In` at the top right to log in.
+
+
+
+### Create a Facebook App
+
+- Click on `My Apps` at the top right.
+- Click `Create App` near the top right.
+- Select your app type and click `Continue`.
+- Fill in your app information, then click `Create App`.
+- This should bring you to the screen: `Add Products to Your App`. (Alternatively you can click on `Add Product` in the left sidebar to get to this screen.)
+
+### Find your callback URI
+
+The next step requires a callback URI, which looks like this:
+
+`https://.supabase.co/auth/v1/callback`
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- Click on the `Settings` icon at the bottom of the left sidebar.
+- Click on `API` in the list.
+- Under Config / URL you'll find your API URL, you can click `Copy` to copy it to the clipboard.
+- Now just add `/auth/v1/callback` to the end of that to get your full `OAuth Redirect URI`.
+
+
+
+### Set up FaceBook Login for your Facebook App
+
+From the `Add Products to your App` screen:
+
+- Click `Setup` under `Facebook Login`
+- Skip the Quickstart screen, instead, in the left sidebar, click `Settings` under `Facebook Login`
+- Enter your callback URI under `Valid OAuth Redirect URIs` on the `Facebook Login Settings` page
+- Enter this in the `Valid OAuth Redirect URIs` box
+- Click `Save Changes` at the bottom right
+
+Be aware that you have to set the right access levels on your Facebook App to enable 3rd party applications to read the email address.
+From the `App Review -> Permissions and Features` screen:
+
+- Click the button `Request Advanced Access` on the right side of `public_profile` and `email`
+
+You can read more about access levels [here](https://developers.facebook.com/docs/graph-api/overview/access-levels/)
+
+### Copy your Facebook App ID and Secret
+
+- Click `Settings / Basic` in the left sidebar
+- Copy your App ID from the top of the `Basic Settings` page
+- Under `App Secret` click `Show` then copy your secret
+- Make sure all required fields are completed on this screen.
+
+### Enter your Facebook App ID and Secret into your Supabase Project
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com)
+- In the left sidebar, click the `Authentication` icon (near the top)
+- Click `Settings` from the list to go to the `Authentication Settings` page
+- Enter the final (hosted) URL of your app under `Site URL` (this is important)
+- Under `External OAuth Providers` turn `Facebook Enabled` to ON
+- Enter your `Facebook client ID` and `Facebook secret` saved in the previous step
+- Click `Save`
+
+### Add login code to your client app
+
+The JavaScript client code is documented here: [Supabase OAuth Client Code](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers)
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'facebook',
+})
+```
+
+Add this function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithFacebook() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'facebook',
+ })
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [Facebook Developers Dashboard](https://developers.facebook.com/)
diff --git a/apps/reference/docs/guides/auth/auth-github.mdx b/apps/reference/docs/guides/auth/auth-github.mdx
new file mode 100644
index 00000000000..c2d43ba9108
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-github.mdx
@@ -0,0 +1,112 @@
+---
+id: auth-github
+title: 'Login with GitHub'
+description: Add GitHub OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable GitHub Auth for your project, you need to set up a GitHub OAuth application and add the application credentials to your Supabase Dashboard.
+
+## Overview
+
+Setting up GitHub logins for your application consists of 3 parts:
+
+- Create and configure a GitHub OAuth App on [GitHub](https://github.com)
+- Add your GitHub OAuth keys to your [Supabase Project](https://app.supabase.com)
+- Add the login code to your [Supabase JS Client App](https://github.com/supabase/supabase-js)
+
+## Steps
+
+### Access your GitHub account
+
+- Go to [github.com](https://github.com).
+- Click on `Sign In` at the top right to log in.
+
+
+
+### Create a GitHub Oauth App
+
+Go to the [GitHub Developer Settings](https://github.com/settings/developers) page:
+
+- Click on your profile photo at the top right
+- Click Settings near the bottom of the menu
+- In the left sidebar, click `Developer settings` (near the bottom)
+- In the left sidebar, click `OAuth Apps`
+
+### Find your callback URL
+
+The next step requires a callback URL, which looks like this:
+
+`https://.supabase.co/auth/v1/callback`
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- Click on the `Settings` icon at the bottom of the left sidebar.
+- Click on `API` in the list.
+- Under Config / URL you'll find your API URL, you can click `Copy` to copy it to the clipboard.
+- Now just add `/auth/v1/callback` to the end of that to get your full `OAuth Redirect URI`.
+
+
+
+### Register a new OAuth application
+
+- Click `Register a new application`. If you've created an app before, click `New OAuth App` here.
+- In `Application name`, type the name of your app.
+- In `Homepage URL`, type the full URL to your app's website.
+- In `Authorization callback URL`, type the callback URL of your app.
+- Enter the URL in the `Valid OAuth Redirect URIs` box.
+- Click `Save Changes` at the bottom right.
+- Click `Register Application`.
+
+Copy your new OAuth credentials
+
+- Copy and save your `Client ID`.
+- Click `Generate a new client secret`.
+- Copy and save your `Client secret`.
+
+### Enter your GitHub credentials into your Supabase Project
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com)
+- In the left sidebar, click the `Authentication` icon (near the top)
+- Click `Settings` from the list to go to the `Authentication Settings` page
+- Enter the final (hosted) URL of your app under `Site URL` (this is important)
+- Under `External OAuth Providers` turn `GitHub Enabled` to ON
+- Enter your `GitHub Client ID` and `GitHub Client Secret` saved in the previous step
+- Click `Save`
+
+### Add login code to your client app
+
+The JavaScript client code is documented here: [Supabase OAuth Client Code](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers)
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'github',
+})
+```
+
+Add this function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithGithub() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'github',
+ })
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [GitHub Developer Settings](https://github.com/settings/developers)
diff --git a/apps/reference/docs/guides/auth/auth-gitlab.mdx b/apps/reference/docs/guides/auth/auth-gitlab.mdx
new file mode 100644
index 00000000000..5bcd2971232
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-gitlab.mdx
@@ -0,0 +1,99 @@
+---
+id: auth-gitlab
+title: 'Login with GitLab'
+description: Add GitLab OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable GitLab Auth for your project, you need to set up a GitLab OAuth application and add the application credentials to your Supabase Dashboard.
+
+## Overview
+
+Setting up GitLab logins for your application consists of 3 parts:
+
+- Create and configure a GitLab Application on [GitLab](https://gitlab.com)
+- Add your GitLab Application keys to your [Supabase Project](https://app.supabase.com)
+- Add the login code to your [Supabase JS Client App](https://github.com/supabase/supabase-js)
+
+## Steps
+
+### Access your GitLab account
+
+- Go to [gitlab.com](https://gitlab.com).
+- Click on `Login` at the top right to log in.
+
+
+
+### Find your callback URL
+
+The next step requires a callback URL, which looks like this:
+
+`https://.supabase.co/auth/v1/callback`
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- Click on the `Settings` icon at the bottom of the left sidebar.
+- Click on `API` in the list.
+- Under Config / URL you'll find your API URL, you can click `Copy` to copy it to the clipboard.
+- Now just add `/auth/v1/callback` to the end of that to get your full `OAuth Redirect URI`.
+
+
+
+### Create your GitLab Application
+
+- Click on your `profile logo` (avatar) in the top-right corner.
+- Select `Edit profile`.
+- In the left sidebar, select Applications.
+- Enter the name of the application.
+- In the `Redirect URI` box, type the callback URL of your app.
+- Check the box next to `Confidential` (make sure it is checked).
+- Check the scope named `read_user` (this is the only required scope).
+- Click `Save Application` at the bottom.
+- Copy and save your `Application ID` (`client_id`) and `Secret` (`client_secret`) which you'll need later.
+
+### Add your GitLab credentials into your Supabase Project
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- In the left sidebar, click the `Authentication` icon (near the top).
+- Click `Settings` from the list to go to the `Authentication Settings` page.
+- Enter the final (hosted) URL of your app under `Site URL` (this is important).
+- Under `External OAuth Providers` turn `GitLab Enabled` to ON.
+- Enter your `client_id` and `client_secret` saved in the previous step.
+- Click `Save`.
+
+### Add login code to your client app
+
+The JavaScript client code is documented here: [Supabase OAuth Client Code](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers)
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'gitlab',
+})
+```
+
+Add this function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithGitLab() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'gitlab',
+ })
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [GitLab Account](https://gitlab.com)
diff --git a/apps/reference/docs/guides/auth/auth-google.mdx b/apps/reference/docs/guides/auth/auth-google.mdx
new file mode 100644
index 00000000000..aeb92d43f12
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-google.mdx
@@ -0,0 +1,127 @@
+---
+id: auth-google
+title: 'Login with Google'
+description: Add Google OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable Google Auth for your project, you need to set up a Google OAuth application and add the application credentials to your Supabase Dashboard.
+
+## Overview
+
+Setting up Google logins for your application consists of 3 parts:
+
+- Create and configure a Google Project on the [Google Cloud Platform Console](https://console.cloud.google.com/home/dashboard)
+- Add your Google OAuth keys to your [Supabase Project](https://app.supabase.com)
+- Add the login code to your [Supabase JS Client App](https://github.com/supabase/supabase-js)
+
+## Steps
+
+### Access your Google Cloud Platform account
+
+- Go to [cloud.google.com](https://cloud.google.com).
+- Click on `Sign in` at the top right to log in.
+
+
+
+### Create a Google Cloud Platform Project
+
+- Click on `Select a Project` at the top left.
+ - (Or, if a project is currently selected, click on the current project name at the top left.)
+- Click `New Project` at the top right.
+- Fill in your app information, then click `Create`.
+ - (This can take a few minutes.)
+- This should bring you to the dashboard for your new project.
+
+### Create the OAuth Keys for your project
+
+From your project's dashboard screen:
+
+- In the search bar at the top labeled `Search products and resources` type `OAuth`.
+- Click on `OAuth consent screen` from the list of results.
+- On the `OAuth consent screen` page select `External`.
+- Click `Create`.
+
+### Edit your app information
+
+- On the `Edit app registration` page fill out your app information.
+- Click `Save and continue` at the bottom.
+
+### Find your callback URL
+
+The next step requires a callback URL, which looks like this:
+
+`https://.supabase.co/auth/v1/callback`
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- Click on the `Settings` icon at the bottom of the left sidebar.
+- Click on `API` in the list.
+- Under Config / URL you'll find your API URL, you can click `Copy` to copy it to the clipboard.
+- Now just add `/auth/v1/callback` to the end of that to get your full `OAuth Redirect URI`.
+
+
+
+### Create your credentials
+
+- Click `Credentials` at the left to go to the `Credentials` page
+- Click `Create Credentials` near the top then select `OAuth client ID`
+- On the `Create OAuth client ID` page, select your application type. If you're not sure, choose `Web application`.
+- Fill in your app name.
+- At the bottom, under `Authorized redirect URIs` click `Add URI`.
+- Enter your callback URI under `Authorized redirect URIs` at the bottom.
+- Enter your callback URI in the `Valid OAuth Redirect URIs` box.
+- Click `Save Changes` at the bottom right.
+- Click `Create`.
+
+Copy your new OAuth credentials
+
+- A box will appear called `OAuth client created`.
+- Copy and save the values under `Your Client ID` and `Your Client Secret`.
+
+### Enter your Google credentials into your Supabase Project
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com)
+- In the left sidebar, click the `Authentication` icon (near the top)
+- Click `Settings` from the list to go to the `Authentication Settings` page
+- Enter the final (hosted) URL of your app under `Site URL` (this is important)
+- Under `External OAuth Providers` turn `Google Enabled` to ON
+- Enter your `Google Client ID` and `Google Client Secret` saved in the previous step
+- Click `Save`
+
+### Add login code to your client app
+
+The JavaScript client code is documented here: [Supabase OAuth Client Code](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers)
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'google',
+})
+```
+
+Add this function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithGoogle() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'google',
+ })
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [Google Cloud Platform Console](https://console.cloud.google.com/home/dashboard)
diff --git a/apps/reference/docs/guides/auth/auth-keycloak.mdx b/apps/reference/docs/guides/auth/auth-keycloak.mdx
new file mode 100644
index 00000000000..03834670c77
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-keycloak.mdx
@@ -0,0 +1,95 @@
+---
+id: auth-keycloak
+title: 'Login with Keycloak'
+description: Add Keycloak OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable Keycloak Auth for your project, you need to set up an Keycloak OAuth application and add the application credentials to your Supabase Dashboard.
+
+## Overview
+
+To get started with Keycloak, you can run it in a docker container with: `docker run -e KEYCLOAK_USER=admin -e KEYCLOAK_PASSWORD=admin -p 8080:8080 jboss/keycloak:latest`
+
+This guide will be assuming that you are running keycloak in a docker container as described in the command above.
+
+Keycloak OAuth consists of five broad steps:
+
+- Create a new client in your specified keycloak realm.
+- Obtain the `issuer` from the "OpenID Endpoint Configuration". This will be used as the `Keycloak URL`.
+- Ensure that the new client has the "Client Protocol" set to "openid-connect" and the "Access Type" is set to "confidential".
+- The `Client ID` of the client created will be used as the `client id`.
+- Obtain the `Secret` from the credentials tab which will be used as the `client secret`.
+- Whitelist the callback url of your application.
+
+## Steps
+
+### Access your Keycloak Admin console
+
+- Login by visiting [`http://localhost:8080`](http://localhost:8080) and clicking on "Administration Console".
+
+### Create a Keycloak Realm
+
+- Once you've logged in to the Keycloak console, you can add a realm from the side panel. The default realm should be named "Master".
+- After you've added a new realm, you can retrieve the `issuer` from the "OpenID Endpoint Configuration" endpoint. The `issuer` will be used as the `Keycloak URL`.
+- You can find this endpoint from the realm settings under the "General Tab" or visit [`http://localhost:8080/realms/my_realm_name/.well-known/openid-configuration`](http://localhost:8080/realms/my_realm_name/.well-known/openid-configuration)
+
+
+
+### Create a Keycloak Client
+
+The "Client ID" of the created client will serve as the `client_id` when you make API calls to authenticate the user.
+
+
+
+### Client Settings
+
+After you've created the client successfully, ensure that you set the following settings:
+1. The "Client Protocol" should be set to "openid-connect".
+2. The "Access Type" should be set to "confidential".
+3. The "Valid Redirect URIs" should be set to: `https://.supabase.co/auth/v1/callback`.
+
+
+
+
+### Obtain the Client Secret
+
+This will serve as the `client_secret` when you make API calls to authenticate the user.
+Under the "Credentials" tab, the `Secret` value will be used as the `client secret`.
+
+
+
+### Add login code to your client app
+
+The JavaScript client code is documented in the [Supabase OAuth Reference](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers).
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'keycloak',
+})
+```
+
+Add a function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithKeycloak() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'keycloak',
+ }
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- You can find the keycloak openid endpoint configuration under the realm settings.
+
diff --git a/apps/reference/docs/guides/auth/auth-linkedin.mdx b/apps/reference/docs/guides/auth/auth-linkedin.mdx
new file mode 100644
index 00000000000..b7031776217
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-linkedin.mdx
@@ -0,0 +1,98 @@
+---
+id: auth-linkedin
+title: 'Login with LinkedIn'
+description: Add LinkedIn OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable LinkedIn Auth for your project, you need to set up a LinkedIn OAuth application and add the application credentials to your Supabase Dashboard.
+
+## Overview
+
+Setting up LinkedIn logins for your application consists of 3 parts:
+
+- Create and configure a LinkedIn Project and App on the [LinkedIn Developer Dashboard](https://www.linkedin.com/developers/apps).
+- Add your LinkedIn `API Key` and `API Secret Key` to your [Supabase Project](https://app.supabase.com).
+- Add the login code to your [Supabase JS Client App](https://github.com/supabase/supabase-js).
+
+## Steps
+
+### Access your LinkedIn Developer account
+
+- Go to [LinkedIn Developer Dashboard](https://www.linkedin.com/developers/apps).
+- Log in (if necessary.)
+
+
+
+### Find your callback URL
+
+The next step requires a callback URL, which looks like this:
+
+`https://.supabase.co/auth/v1/callback`
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- Click on the `Settings` icon at the bottom of the left sidebar.
+- Click on `API` in the list.
+- Under Config / URL you'll find your API URL, you can click `Copy` to copy it to the clipboard.
+- Now just add `/auth/v1/callback` to the end of that to get your full `OAuth Redirect URI`.
+
+
+
+### Create a LinkedIn OAuth app
+
+- Go to [LinkedIn Developer Dashboard](https://www.linkedin.com/developers/apps).
+- Click on `Create App` at the top right
+- Enter your `LinkedIn Page` and `App Logo`
+- Save your app
+- Click `Auth` from the top menu
+- Add your `Redirect URL` to the `Authorized Redirect URLs for your app` section
+- Copy and save your newly-generated `Client ID`
+- Copy and save your newly-generated `Client Secret`
+
+### Enter your LinkedIn credentials into your Supabase Project
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- In the left sidebar, click the `Authentication` icon (near the top).
+- Click `Settings` from the list to go to the `Authentication Settings` page.
+- Enter the final (hosted) URL of your app under `Site URL` (this is important).
+- Under `External OAuth Providers` turn `LinkedIn Enabled` to ON.
+- Enter your `API Key` (`client_id`) and `API Secret Key` (`client_secret`) saved in the previous step.
+- Click `Save`.
+
+### Add login code to your client app
+
+The JavaScript client code is documented here: [Supabase OAuth Client Code](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers).
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'LinkedIn',
+})
+```
+
+Add this function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithLinkedIn() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'LinkedIn',
+ })
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [LinkedIn Developer Dashboard](https://api.LinkedIn.com/apps)
diff --git a/apps/reference/docs/guides/auth/auth-magic-link.mdx b/apps/reference/docs/guides/auth/auth-magic-link.mdx
new file mode 100644
index 00000000000..5d320a55abe
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-magic-link.mdx
@@ -0,0 +1,129 @@
+---
+id: auth-magic-link
+title: 'Login With Magic Link'
+description: Use Supabase to Authenticate and Authorize your users using Magic Link.
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+By default, if no password is provided, the user will be sent a "magic link" to their email address, which they can click to open your application with a valid session. By default, a given user can only request a Magic Link once every 60 seconds.
+
+## Overview
+
+Setting up Magic Link logins for your Supabase application.
+
+- Add Magic Link authenticator to your [Supabase Project](https://app.supabase.com)
+- Add the login code to your application - [JavaScript](https://github.com/supabase/supabase-js) | [Dart](https://github.com/supabase/supabase-dart)
+
+## Add Magic Link into your Supabase Project
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com)
+- In the left sidebar, click the `Authentication` icon (near the top)
+- Click `Settings` from the list to go to the `Authentication Settings` page
+- Enter the final (hosted) URL of your app under `Site URL` (this is important)
+- Under `Email Auth` turn `Enable Email Signup` to ON
+- Click `Save`
+
+### Add login code to your client app
+
+Add logins using our client libraries:
+
+- [JavaScript](/docs/reference/javascript/auth-signin#sign-in-with-magic-link)
+- [Dart](/docs/reference/dart/auth-signin#sign-in-with-magic-link)
+
+
+
+
+
+```js
+const { user, error } = await supabase.auth.signIn({
+ email: 'example@email.com',
+})
+```
+
+
+
+
+
+```dart
+final res = await supabase.auth.signIn(email: 'example@email.com');
+
+final error = res.error;
+```
+
+
+
+
+
+Add this function which you can call from a button, link, or UI element.
+
+
+
+
+
+```js
+async function signInWithEmail() {
+ const { user, error } = await supabase.auth.signIn({
+ email: 'example@email.com',
+ })
+}
+```
+
+
+
+
+
+```dart
+Future signInWithEmail() async {
+ await supabase.auth.signIn(email: 'example@email.com');
+}
+```
+
+
+
+
+
+To log out:
+
+
+
+
+
+```js
+async function signOut() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+
+
+
+
+```dart
+Future signOut() async {
+ await supabase.auth.signOut();
+}
+```
+
+
+
+
+
+## Resources
+
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [Supabase Dart Client](https://github.com/supabase/supabase-dart)
diff --git a/apps/reference/docs/guides/auth/auth-messagebird.mdx b/apps/reference/docs/guides/auth/auth-messagebird.mdx
new file mode 100644
index 00000000000..dd806ecb6b7
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-messagebird.mdx
@@ -0,0 +1,282 @@
+---
+id: auth-messagebird
+title: Phone Auth with MessageBird
+description: How to set up and use Mobile OTP with MessageBird and Supabase.
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+## Overview
+
+In this guide we'll show you how to authenticate your users with SMS based OTP (One-Time Password) tokens.
+
+There are two reasons to use Supabase SMS OTP tokens:
+
+- You want users to log in with mobile + password, and the mobile should be verified via SMS
+- You want users to log in with mobile ONLY (i.e. passwordless login)
+
+We'll cover:
+
+- [Finding your MessageBird credentials](#finding-your-messagebird-credentials)
+- [Using OTP with password based logins](#using-otp-with-password-based-logins)
+- [Using OTP as a passwordless sign-in mechanism](#using-otp-as-a-passwordless-sign-in-mechanism)
+
+What you'll need:
+
+- A MessageBird account (sign up here: https://dashboard.messagebird.com/en/sign-up)
+- A Supabase project (create one here: https://app.supabase.com)
+- A mobile phone capable of receiving SMS
+
+## Steps
+
+### Finding your MessageBird credentials
+
+Start by logging into your MessageBird account and verify the mobile number you'll be using to test with: https://dashboard.messagebird.com/en/getting-started/sms
+
+This is the number that will be receiving the SMS OTPs.
+
+
+
+
+
+Navigate to the [dashboard settings](https://dashboard.messagebird.com/en/settings/sms) to set the default originator. The messagebird originator is the name or number from which the message is sent.
+For more information, you can refer to the messagebird article on choosing an originator [here](https://support.messagebird.com/hc/en-us/articles/115002628665-Choosing-an-originator)
+
+
+
+You will need the following values to get started:
+
+- Live API Key / Test API Key
+- MessageBird originator
+
+Now go to the Auth > Settings page in the Supabase dashboard (https://app.supabase.com/project/YOUR-PROJECT-REF/auth/settings).
+
+You should see an option to enable Phone Signup.
+
+
+
+Toggle it on, and copy the 2 values over from the messagebird dashboard. Click save.
+
+Note: If you use the Test API Key, the OTP will not be delivered to the mobile number specified but messagebird will log the response in the dashboard.
+If the Live API Key is used instead, the OTP will be delivered and there will be a deduction in your free credits.
+
+
+Plugin MessageBird credentials
+
+Now the backend should be setup, we can proceed to add our client-side code!
+
+#### SMS custom template
+
+The SMS message sent to a phone containing an OTP code can be customized. This is useful if you need to mention a brand name or display a website address.
+
+Go to Auth > Templates page in the Supabase dashboard (https://app.supabase.com/project/YOUR-PROJECT-REF/auth/templates).
+
+Use the variable `.Code` in the template to display the code.
+
+### Using OTP with password based logins
+
+In this use scenario we'll be using the user's mobile phone number as an alternative to an email address when signing up along with a password. You may want to think hard about the permanency of this however. It is not uncommon for mobile phone numbers to be recycled by phone networks when users cancel their phone contracts or move countries, therefore granting access to the user's account to whoever takes over the phone number in the future. Soon we'll add multi-factor auth, which will mitigate this risk, but for now you may want to give some thought to allowing your users to recover their account by some other means in an emergency.
+
+Using supabase-js on the client you'll want to use the same `signUp` method that you'd use for email based sign ups, but with the `phone` param instead of the `email param`:
+
+
+
+
+```js
+let { user, error } = await supabase.auth.signUp({
+ phone: '+13334445555',
+ password: 'some-password',
+})
+```
+
+
+
+
+```bash
+curl -X POST 'https://cvwawazfelidkloqmbma.supabase.co/auth/v1/signup' \
+-H "apikey: SUPABASE_KEY" \
+-H "Content-Type: application/json" \
+-d '{
+ "phone": "+13334445555",
+ "password": "some-password"
+}'
+```
+
+
+
+
+The user will now receive an SMS with a 6-digit pin that you will need to receive from them within 60-seconds before they can login to their account.
+
+You should present a form to the user so they can input the 6 digit pin, then send it along with the phone number to `verifyOTP`:
+
+
+
+
+```js
+let { session, error } = await supabase.auth.verifyOTP({
+ phone: '+13334445555',
+ token: '123456',
+})
+```
+
+
+
+
+```bash
+curl -X POST 'https://cvwawazfelidkloqmbma.supabase.co/auth/v1/verify' \
+-H "apikey: SUPABASE_KEY" \
+-H "Content-Type: application/json" \
+-d '{
+ "type": "sms",
+ "phone": "+13334445555",
+ "token": "123456"
+}'
+```
+
+
+
+
+If successful the user will now be logged in and you should receive a valid session like:
+
+```json
+{
+ "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJhdXRoZW50aWNhdGVkIiwiZXhwIjoxNjI3MjkxNTc3LCJzdWIiOiJmYTA2NTQ1Zi1kYmI1LTQxY2EtYjk1NC1kOGUyOTg4YzcxOTEiLCJlbWFpbCI6IiIsInBob25lIjoiNjU4NzUyMjAyOSIsImFwcF9tZXRhZGF0YSI6eyJwcm92aWRlciI6InBob25lIn0sInVzZXJfbWV0YWRhdGEiOnt9LCJyb2xlIjoiYXV0aGVudGljYXRlZCJ9.1BqRi0NbS_yr1f6hnr4q3s1ylMR3c1vkiJ4e_N55dhM",
+ "token_type": "bearer",
+ "expires_in": 3600,
+ "refresh_token": "LSp8LglPPvf0DxGMSj-vaQ"
+}
+```
+
+The access token can be sent in the Authorization header as a Bearer token for any CRUD operations on supabase-js. See our guide on [Row Level Security](/docs/guides/auth#row-level-security) for more info on restricting access on a user basis.
+
+Also now that the mobile has been verified, the user can use the number and password to sign in without needing to verify their number each time:
+
+
+
+
+```js
+let { user, error } = await supabase.auth.signIn({
+ phone: '+13334445555',
+ password: 'some-password',
+})
+```
+
+
+
+
+```bash
+curl -X POST 'https://cvwawazfelidkloqmbma.supabase.co/auth/v1/token?grant_type=password' \
+-H "apikey: SUPABASE_KEY" \
+-H "Content-Type: application/json" \
+-d '{
+ "phone": "+13334445555",
+ "password": "some-password"
+}'
+```
+
+
+
+
+### Using OTP as a passwordless sign-in mechanism
+
+In this scenario you are granting your user's the ability to login to their account without needing to set a password on their account, all they have to do to log in is verify their mobile each time using the OTP.
+
+In javascript we can use the `signIn` method with a single parameter: `phone`
+
+
+
+
+```js
+let { user, error } = await supabase.auth.signIn({
+ phone: '+13334445555',
+})
+```
+
+
+
+
+```bash
+curl -X POST 'https://cvwawazfelidkloqmbma.supabase.co/auth/v1/otp' \
+-H "apikey: SUPABASE_KEY" \
+-H "Content-Type: application/json" \
+-d '{
+ "phone": "+13334445555"
+}'
+```
+
+
+
+
+The second step is the same as the previous section, you need to collect the 6-digit pin from the user and pass it along with their phone number to the verify method:
+
+
+
+
+```js
+let { session, error } = await supabase.auth.verifyOTP({
+ phone: '+13334445555',
+ token: '123456',
+})
+```
+
+
+
+
+```bash
+curl -X POST 'https://cvwawazfelidkloqmbma.supabase.co/auth/v1/verify' \
+-H "apikey: SUPABASE_KEY" \
+-H "Content-Type: application/json" \
+-d '{
+ "type": "sms",
+ "phone": "+13334445555",
+ "token": "123456"
+}'
+```
+
+
+
+
+and the response should also be the same as above:
+
+```json
+{
+ "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJhdXRoZW50aWNhdGVkIiwiZXhwIjoxNjI3MjkxNTc3LCJzdWIiOiJmYTA2NTQ1Zi1kYmI1LTQxY2EtYjk1NC1kOGUyOTg4YzcxOTEiLCJlbWFpbCI6IiIsInBob25lIjoiNjU4NzUyMjAyOSIsImFwcF9tZXRhZGF0YSI6eyJwcm92aWRlciI6InBob25lIn0sInVzZXJfbWV0YWRhdGEiOnt9LCJyb2xlIjoiYXV0aGVudGljYXRlZCJ9.1BqRi0NbS_yr1f6hnr4q3s1ylMR3c1vkiJ4e_N55dhM",
+ "token_type": "bearer",
+ "expires_in": 3600,
+ "refresh_token": "LSp8LglPPvf0DxGMSj-vaQ"
+}
+```
+
+The user does not have a password therefore will need to sign in via this method each time they want to access your service.
+
+## Resources
+
+- [MessageBird Signup](https://dashboard.messagebird.com/en/sign-up)
+- [Supabase Dashboard](https://app.supabase.com)
+- [Supabase Row Level Security](/docs/guides/auth#row-level-security)
diff --git a/apps/reference/docs/guides/auth/auth-notion.mdx b/apps/reference/docs/guides/auth/auth-notion.mdx
new file mode 100644
index 00000000000..44a6464c03d
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-notion.mdx
@@ -0,0 +1,101 @@
+---
+id: auth-notion
+title: 'Login with Notion'
+description: Add Notion OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable Notion Auth for your project, you need to set up a Notion Application and add the Application OAuth credentials to your Supabase Dashboard.
+
+## Overview
+
+Setting up Notion logins for your application consists of 3 parts:
+
+- Create and configure a Notion Application [Notion Developer Portal](https://www.notion.so/my-integrations)
+- Retrieve your OAuth client ID and OAuth client secret and add them to your [Supabase Project](https://app.supabase.com)
+- Add the login code to your [Supabase JS Client App](https://github.com/supabase/supabase-js)
+
+## Steps
+
+### Create your notion integration
+
+- Go to [developers.notion.com](https://developers.notion.com/).
+- Click "View my integrations" and login.
+
+
+
+- Once logged in, go to [notion.so/my-integrations](https://notion.so/my-integrations) and create a new integration.
+- When creating your integration, ensure that you select "Public integration" under "Integration type" and "Read user information including email addresses" under "Capabilities".
+- You will need to add a redirect uri, see [Add the redirect uri](#add-the-redirect-uri)
+- Once you've filled in the necessary fields, click "Submit" to finish creating the integration.
+
+
+
+### Add the redirect uri
+- After selecting "Public integration", you should see an option to add "Redirect URIs".
+
+
+
+You can retrieve the redirect uri with the following steps:
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- Click on the `Settings` icon at the bottom of the left sidebar.
+- Click on `API` in the list.
+- Under Config / URL you'll find your API URL, you can click `Copy` to copy it to the clipboard.
+- Add `/auth/v1/callback` to the end of that to get your full `OAuth Redirect URI`.
+
+Your redirect uri should look like the following: `https://.supabase.co/auth/v1/callback`
+
+
+
+### Add your Notion credentials into your Supabase Project
+
+- Once you've created your notion integration, you should be able to retrieve the "OAuth client ID" and "OAuth client secret" from the "OAuth Domain and URIs" tab.
+
+
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com)
+- In the left sidebar, click the `Authentication` icon (near the top)
+- Click `Settings` from the list to go to the `Authentication Settings` page
+- Under `External OAuth Providers` turn `Notion Enabled` to ON
+- Enter the "OAuth client ID" and "OAuth client secret" obtained in the `client id` and `client secret` fields.
+- Click `Save`
+
+### Add login code to your client app
+
+The JavaScript client code is documented here: [Supabase OAuth Client Code](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers)
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'notion',
+})
+```
+
+Add this function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithNotion() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'notion',
+ })
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [Notion Account](https://notion.so)
+- [Notion Developer Portal](https://www.notion.so/my-integrations)
diff --git a/apps/reference/docs/guides/auth/auth-slack.mdx b/apps/reference/docs/guides/auth/auth-slack.mdx
new file mode 100644
index 00000000000..fd60e76a8b1
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-slack.mdx
@@ -0,0 +1,111 @@
+---
+id: auth-slack
+title: 'Login with Slack'
+description: Add Slack OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable Slack Auth for your project, you need to set up a Slack OAuth application and add the application credentials to your Supabase Dashboard.
+
+## Overview
+
+Setting up Slack logins for your application consists of 3 parts:
+
+- Create and configure a Slack Project and App on the [Slack Developer Dashboard](https://api.slack.com/apps).
+- Add your Slack `API Key` and `API Secret Key` to your [Supabase Project](https://app.supabase.com).
+- Add the login code to your [Supabase JS Client App](https://github.com/supabase/supabase-js).
+
+## Steps
+
+### Access your Slack Developer account
+
+- Go to [api.slack.com](https://api.slack.com/apps).
+- Click on `Your Apps` at the top right to log in.
+
+
+
+### Find your callback URL
+
+The next step requires a callback URL, which looks like this:
+
+`https://.supabase.co/auth/v1/callback`
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- Click on the `Settings` icon at the bottom of the left sidebar.
+- Click on `API` in the list.
+- Under Config / URL you'll find your API URL, you can click `Copy` to copy it to the clipboard.
+- Now just add `/auth/v1/callback` to the end of that to get your full `OAuth Redirect URI`.
+
+
+
+### Create a Slack OAuth app
+
+- Go to [api.slack.com](https://api.slack.com/apps).
+- Click on `Create an App`
+
+Under `Create an app...`:
+
+- Click `From scratch`
+- Type the name of your app
+- Select your `Slack Workspace`
+- Click `Create App`
+
+Under `App Credentials`:
+
+- Copy and save your newly-generated `Client ID`
+- Copy and save your newly-generated `Client Secret`
+- Click `Permissions`
+
+Under `Redirect URLs`:
+
+- Click `Add New Redirect URL`
+- Paste your `Callback URL` then click `Add`
+- Click `Save URLs`
+
+### Enter your Slack credentials into your Supabase Project
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- In the left sidebar, click the `Authentication` icon (near the top).
+- Click `Settings` from the list to go to the `Authentication Settings` page.
+- Enter the final (hosted) URL of your app under `Site URL` (this is important).
+- Under `External OAuth Providers` turn `Slack Enabled` to ON.
+- Enter your `Client ID` (`client_id`) and `Client Secret` (`client_secret`) saved in the previous step.
+- Click `Save`.
+
+### Add login code to your client app
+
+The JavaScript client code is documented here: [Supabase OAuth Client Code](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers).
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'slack',
+})
+```
+
+Add this function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithSlack() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'slack',
+ })
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [Slack Developer Dashboard](https://api.slack.com/apps)
diff --git a/apps/reference/docs/guides/auth/auth-spotify.mdx b/apps/reference/docs/guides/auth/auth-spotify.mdx
new file mode 100644
index 00000000000..760eaf85d04
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-spotify.mdx
@@ -0,0 +1,106 @@
+---
+id: auth-spotify
+title: 'Login with Spotify'
+description: Add Spotify OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable Spotify Auth for your project, you need to set up a Spotify OAuth application and add the application credentials to your Supabase Dashboard.
+
+## Overview
+
+Setting up Spotify logins for your application consists of 3 parts:
+
+- Create and configure a Spotify Project and App on the [Spotify Developer Dashboard](https://developer.spotify.com/dashboard/).
+- Add your Spotify `API Key` and `API Secret Key` to your [Supabase Project](https://app.supabase.com).
+- Add the login code to your [Supabase JS Client App](https://github.com/supabase/supabase-js).
+
+## Steps
+
+### Access your Spotify Developer account
+
+- Log into [Spotify](https://spotify.com)
+- Access the [Spotify Developer Dashboard](https://developer.spotify.com/dashboard)
+
+
+
+### Find your callback URL
+
+The next step requires a callback URL, which looks like this:
+
+`https://.supabase.co/auth/v1/callback`
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- Click on the `Settings` icon at the bottom of the left sidebar.
+- Click on `API` in the list.
+- Under Config / URL you'll find your API URL, you can click `Copy` to copy it to the clipboard.
+- Now just add `/auth/v1/callback` to the end of that to get your full `OAuth Redirect URI`.
+
+
+
+### Create a Spotify OAuth app
+
+- Log into [Spotify](https://spotify.com).
+- Go to the [Spotify Developer Dashboard](https://developer.spotify.com/dashboard)
+- Click `Create an App`
+- Type your `App name`
+- Type your `App description`
+- Check the box to agree with the `Developer TOS and Branding Guidelines`
+- Click `Create`
+- Save your `Client ID`
+- Save your `Client Secret`
+- Click `Edit Settings`
+
+Under `Redirect URIs`:
+
+- Paste your Supabase Callback URL in the box
+- Click `Add`
+- Click `Save` at the bottom
+
+### Enter your Spotify credentials into your Supabase Project
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- In the left sidebar, click the `Authentication` icon (near the top).
+- Click `Settings` from the list to go to the `Authentication Settings` page.
+- Enter the final (hosted) URL of your app under `Site URL` (this is important).
+- Under `External OAuth Providers` turn `Spotify Enabled` to ON.
+- Enter your `Client ID` (`client_id`) and `Client Secret` (`client_secret`) saved in the previous step.
+- Click `Save`.
+
+### Add login code to your client app
+
+The JavaScript client code is documented here: [Supabase OAuth Client Code](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers).
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'spotify',
+})
+```
+
+Add this function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithSpotify() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'spotify',
+ })
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [Spotify Developer Dashboard](https://developer.spotify.com/dashboard/)
diff --git a/apps/reference/docs/guides/auth/auth-twilio.mdx b/apps/reference/docs/guides/auth/auth-twilio.mdx
new file mode 100644
index 00000000000..ba9ac6fec27
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-twilio.mdx
@@ -0,0 +1,301 @@
+---
+id: auth-twilio
+title: Phone Auth with Twilio
+description: How to set up and use Mobile OTP with Twilio and Supabase.
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+## Overview
+
+In this guide we'll show you how to authenticate your users with SMS based One-Time Password (OTP) tokens.
+
+There are two reasons to use Supabase SMS OTP tokens:
+
+- You want users to log in with mobile number + password, and the mobile number should be verified via SMS
+- You want users to log in with mobile number ONLY (i.e. passwordless login)
+
+We'll cover:
+
+- [Finding your Twilio credentials](#finding-your-twilio-credentials)
+- [Using OTP with password based logins](#using-otp-with-password-based-logins)
+- [Using OTP as a passwordless sign-in mechanism](#using-otp-as-a-passwordless-sign-in-mechanism)
+
+What you'll need:
+
+- A Twilio account (sign up here: https://www.twilio.com/try-twilio)
+- A Supabase project (create one here: https://app.supabase.com)
+- A mobile phone capable of receiving SMS
+
+## Video
+
+
+
+## Steps
+
+### Finding your Twilio credentials
+
+Start by logging into your Twilio account and starting a new project: https://www.twilio.com/console/projects/create
+
+Give your project a name and verify the mobile number you'll be using to test with. This is the number that will be receiving the SMS OTPs.
+
+
+
+
+Select 'SMS', 'Identity & Verification', and 'With code' as options on the welcome form.
+
+
+
+When you're back on the [Twilio console screen](https://www.twilio.com/console), you need to scroll down and click 'Get a trial phone number' - this is the number that you'll be sending SMSs from.
+
+
+
+
+
+You should now be able to see all three values you'll need to get started:
+
+- Account SID
+- Auth Token
+- Sender Phone Number
+
+
+
+Now go to the Auth > Settings page in the Supabase dashboard (https://app.supabase.com/project/YOUR-PROJECT-REF/auth/settings).
+
+You should see an option to enable Phone Signup:
+
+
+
+Toggle it on, and copy the 3 values over from the twilio dashboard. Click save.
+
+Note: for "Twilio Message Service SID" you can use the Sender Phone Number generated above.
+
+
+
+Now the backend should be setup, we can proceed to add our client-side code!
+
+#### SMS custom template
+
+The SMS message sent to a phone containing an OTP code can be customized. This is useful if you need to mention a brand name or display a website address.
+
+Go to Auth > Templates page in the Supabase dashboard (https://app.supabase.com/project/YOUR-PROJECT-REF/auth/templates).
+
+Use the variable `.Code` in the template to display the OTP code. Here's an example in the SMS template.
+
+
+
+### Using OTP with password based logins
+
+In this scenario we'll be using the user's mobile phone number and a corresponding password as an alternative to signing up with an email address. Note: please thoroughly consider potential security implications when signing up with a combination of phone number and password. Phone numbers are sometimes recycled by phone networks when users cancel their phone contracts or move countries, thereby granting access to the user's account to the subsequent owner of the phone number. In the near future Supabase will support multifactor authentication, which will mitigate this risk, but for now you may want to consider allowing your users to recover their account by some other means in an emergency.
+
+Using supabase-js on the client you'll want to use the same `signUp` method that you'd use for email based sign ups, but with the `phone` param instead of the `email param`:
+
+
+
+
+```js
+let { user, error } = await supabase.auth.signUp({
+ phone: '+13334445555',
+ password: 'some-password',
+})
+```
+
+
+
+
+```bash
+curl -X POST 'https://cvwawazfelidkloqmbma.supabase.co/auth/v1/signup' \
+-H "apikey: SUPABASE_KEY" \
+-H "Content-Type: application/json" \
+-d '{
+ "phone": "+13334445555",
+ "password": "some-password"
+}'
+```
+
+
+
+
+The user will now receive an SMS with a 6-digit pin that you will need to receive from them within 60-seconds before they can login to their account.
+
+You should present a form to the user so they can input the 6 digit pin, then send it along with the phone number to `verifyOTP`:
+
+
+
+
+```js
+let { session, error } = await supabase.auth.verifyOTP({
+ phone: '+13334445555',
+ token: '123456',
+})
+```
+
+
+
+
+```bash
+curl -X POST 'https://cvwawazfelidkloqmbma.supabase.co/auth/v1/verify' \
+-H "apikey: SUPABASE_KEY" \
+-H "Content-Type: application/json" \
+-d '{
+ "type": "sms",
+ "phone": "+13334445555",
+ "token": "123456"
+}'
+```
+
+
+
+
+If successful the user will now be logged in and you should receive a valid session like:
+
+```json
+{
+ "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJhdXRoZW50aWNhdGVkIiwiZXhwIjoxNjI3MjkxNTc3LCJzdWIiOiJmYTA2NTQ1Zi1kYmI1LTQxY2EtYjk1NC1kOGUyOTg4YzcxOTEiLCJlbWFpbCI6IiIsInBob25lIjoiNjU4NzUyMjAyOSIsImFwcF9tZXRhZGF0YSI6eyJwcm92aWRlciI6InBob25lIn0sInVzZXJfbWV0YWRhdGEiOnt9LCJyb2xlIjoiYXV0aGVudGljYXRlZCJ9.1BqRi0NbS_yr1f6hnr4q3s1ylMR3c1vkiJ4e_N55dhM",
+ "token_type": "bearer",
+ "expires_in": 3600,
+ "refresh_token": "LSp8LglPPvf0DxGMSj-vaQ"
+}
+```
+
+The access token can be sent in the Authorization header as a Bearer token for any CRUD operations on supabase-js. See our guide on [Row Level Security](/docs/guides/auth#row-level-security) for more info on restricting access on a user basis.
+
+Also now that the mobile has been verified, the user can use the number and password to sign in without needing to verify their number each time:
+
+
+
+
+```js
+let { user, error } = await supabase.auth.signIn({
+ phone: '+13334445555',
+ password: 'some-password',
+})
+```
+
+
+
+
+```bash
+curl -X POST 'https://cvwawazfelidkloqmbma.supabase.co/auth/v1/token?grant_type=password' \
+-H "apikey: SUPABASE_KEY" \
+-H "Content-Type: application/json" \
+-d '{
+ "phone": "+13334445555",
+ "password": "some-password"
+}'
+```
+
+
+
+
+### Using OTP as a passwordless sign-in mechanism
+
+In this scenario you are granting your user's the ability to login to their account without needing to set a password on their account, all they have to do to log in is verify their mobile each time using the OTP.
+
+In javascript we can use the `signIn` method with a single parameter: `phone`
+
+
+
+
+```js
+let { user, error } = await supabase.auth.signIn({
+ phone: '+13334445555',
+})
+```
+
+
+
+
+```bash
+curl -X POST 'https://cvwawazfelidkloqmbma.supabase.co/auth/v1/otp' \
+-H "apikey: SUPABASE_KEY" \
+-H "Content-Type: application/json" \
+-d '{
+ "phone": "+13334445555"
+}'
+```
+
+
+
+
+The second step is the same as the previous section, you need to collect the 6-digit pin from the user and pass it along with their phone number to the verify method:
+
+
+
+
+```js
+let { session, error } = await supabase.auth.verifyOTP({
+ phone: '+13334445555',
+ token: '123456',
+})
+```
+
+
+
+
+```bash
+curl -X POST 'https://cvwawazfelidkloqmbma.supabase.co/auth/v1/verify' \
+-H "apikey: SUPABASE_KEY" \
+-H "Content-Type: application/json" \
+-d '{
+ "type": "sms",
+ "phone": "+13334445555",
+ "token": "123456"
+}'
+```
+
+
+
+
+and the response should also be the same as above:
+
+```json
+{
+ "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJhdXRoZW50aWNhdGVkIiwiZXhwIjoxNjI3MjkxNTc3LCJzdWIiOiJmYTA2NTQ1Zi1kYmI1LTQxY2EtYjk1NC1kOGUyOTg4YzcxOTEiLCJlbWFpbCI6IiIsInBob25lIjoiNjU4NzUyMjAyOSIsImFwcF9tZXRhZGF0YSI6eyJwcm92aWRlciI6InBob25lIn0sInVzZXJfbWV0YWRhdGEiOnt9LCJyb2xlIjoiYXV0aGVudGljYXRlZCJ9.1BqRi0NbS_yr1f6hnr4q3s1ylMR3c1vkiJ4e_N55dhM",
+ "token_type": "bearer",
+ "expires_in": 3600,
+ "refresh_token": "LSp8LglPPvf0DxGMSj-vaQ"
+}
+```
+
+The user does not have a password therefore will need to sign in via this method each time they want to access your service.
+
+## Resources
+
+- [Twilio Signup](https://www.twilio.com/try-twilio)
+- [Supabase Dashboard](https://app.supabase.com)
+- [Supabase Row Level Security](/docs/guides/auth#row-level-security)
diff --git a/apps/reference/docs/guides/auth/auth-twitch.mdx b/apps/reference/docs/guides/auth/auth-twitch.mdx
new file mode 100644
index 00000000000..4c5b5519598
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-twitch.mdx
@@ -0,0 +1,118 @@
+---
+id: auth-twitch
+title: 'Login with Twitch'
+description: Add Twitch OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable Twitch Auth for your project, you need to set up a Twitch Application and add the Application OAuth credentials to your Supabase Dashboard.
+
+## Overview
+
+Setting up Twitch logins for your application consists of 3 parts:
+
+- Create and configure a Twitch Application [Twitch Developer Console](https://dev.twitch.tv/console)
+- Add your Twitch OAuth Consumer keys to your [Supabase Project](https://app.supabase.com)
+- Add the login code to your [Supabase JS Client App](https://github.com/supabase/supabase-js)
+
+## Steps
+
+### Access your Twitch Developer account
+
+- Go to [dev.twitch.tv](https://dev.twitch.tv).
+- Click on `Log in with Twitch` at the top right to log in.
+- If you have not already enabled 2-Factor Authentication for your Twitch Account, you will need to do that at [Twitch Security Settings](https://www.twitch.tv/settings/security) before you can continue.
+
+
+
+- Once logged in, go to the [Twitch Developer Console](https://dev.twitch.tv/console).
+
+
+
+### Find your callback URL
+
+In the next step you require a callback URL, which looks like this:
+
+`https://.supabase.co/auth/v1/callback`
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- Click on the `Settings` icon at the bottom of the left sidebar.
+- Click on `API` in the list.
+- Under Config / URL you'll find your API URL, you can click `Copy` to copy it to the clipboard.
+- Now just add `/auth/v1/callback` to the end of that to get your full `OAuth Redirect URI`.
+
+
+
+### Create a Twitch Application
+
+
+
+- Click on `+ Register Your Application` at the top right.
+
+
+
+- Enter the name of your application.
+- Type or paste your `OAuth Redirect URL` (the callback URL from the previous step.)
+- Select a category for your app.
+- Check the Captcha box and click `Create`.
+
+### Retrieve your Twitch OAuth Client ID and Client Secret
+
+- Click `Manage` at the right of your application entry in the list.
+
+
+
+- Copy your Client ID.
+- Click `New Secret` to create a new Client Secret.
+- Copy your Client Secret.
+
+
+
+### Add your Twitch credentials into your Supabase Project
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com)
+- In the left sidebar, click the `Authentication` icon (near the top)
+- Click `Settings` from the list to go to the `Authentication Settings` page
+- Enter the final (hosted) URL of your app under `Site URL` (this is important)
+- Under `External OAuth Providers` turn `Twitch Enabled` to ON
+- Enter your `client_id` and `client_secret` saved in the previous step
+- Click `Save`
+
+### Add login code to your client app
+
+The JavaScript client code is documented here: [Supabase OAuth Client Code](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers)
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'twitch',
+})
+```
+
+Add this function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithTwitch() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'twitch',
+ })
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [Twitch Account](https://twitch.tv)
+- [Twitch Developer Console](https://dev.twitch.tv/console)
diff --git a/apps/reference/docs/guides/auth/auth-twitter.mdx b/apps/reference/docs/guides/auth/auth-twitter.mdx
new file mode 100644
index 00000000000..537137ea5ab
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-twitter.mdx
@@ -0,0 +1,107 @@
+---
+id: auth-twitter
+title: 'Login with Twitter'
+description: Add Twitter OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable Twitter Auth for your project, you need to set up a Twitter OAuth application and add the application credentials to your Supabase Dashboard.
+
+## Overview
+
+Setting up Twitter logins for your application consists of 3 parts:
+
+- Create and configure a Twitter Project and App on the [Twitter Developer Dashboard](https://developer.twitter.com/en/portal/dashboard).
+- Add your Twitter `API Key` and `API Secret Key` to your [Supabase Project](https://app.supabase.com).
+- Add the login code to your [Supabase JS Client App](https://github.com/supabase/supabase-js).
+
+## Steps
+
+### Access your Twitter Developer account
+
+- Go to [developer.twitter.com](https://developer.twitter.com).
+- Click on `Sign in` at the top right to log in.
+
+
+
+### Find your callback URL
+
+The next step requires a callback URL, which looks like this:
+
+`https://.supabase.co/auth/v1/callback`
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- Click on the `Settings` icon at the bottom of the left sidebar.
+- Click on `API` in the list.
+- Under Config / URL you'll find your API URL, you can click `Copy` to copy it to the clipboard.
+- Now just add `/auth/v1/callback` to the end of that to get your full `OAuth Redirect URI`.
+
+
+
+### Create a Twitter OAuth app
+
+- Click `+ Create Project`.
+ - Enter your project name, click `Next`.
+ - Select your use case, click `Next`.
+ - Enter a description for your project, click `Next`.
+ - Enter a name for your app, click `Complete`.
+ - Copy and save your `API Key` (this is your `client_id`).
+ - Copy and save your `API Secret Key` (this is your `client_secret`).
+- At the bottom, under `Next, setup your App` click the link `enable 3rd party authentication`.
+- Under `App Settings`, click on the gear icon next to your app name to go to `App Settings`.
+- At the bottom, next to `Authentication settings`, click `Edit`.
+- Turn `Enable 3-legged OAuth` ON.
+- Turn `Request email address from users` ON.
+- Enter your `Callback URL`.
+- Enter your `Website URL`.
+- Enter your `Terms of service URL`.
+- Enter your `Privacy policy URL`.
+- Click `Save`.
+
+### Enter your Twitter credentials into your Supabase Project
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- In the left sidebar, click the `Authentication` icon (near the top).
+- Click `Settings` from the list to go to the `Authentication Settings` page.
+- Enter the final (hosted) URL of your app under `Site URL` (this is important).
+- Under `External OAuth Providers` turn `Twitter Enabled` to ON.
+- Enter your `API Key` (`client_id`) and `API Secret Key` (`client_secret`) saved in the previous step.
+- Click `Save`.
+
+### Add login code to your client app
+
+The JavaScript client code is documented here: [Supabase OAuth Client Code](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers).
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'twitter',
+})
+```
+
+Add this function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithTwitter() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'twitter',
+ })
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [Twitter Developer Dashboard](https://developer.twitter.com/en/portal/dashboard)
diff --git a/apps/reference/docs/guides/auth/auth-vonage.mdx b/apps/reference/docs/guides/auth/auth-vonage.mdx
new file mode 100644
index 00000000000..109101c6cb5
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-vonage.mdx
@@ -0,0 +1,274 @@
+---
+id: auth-vonage
+title: Phone Auth with Vonage
+description: How to set up and use Mobile OTP with Vonage and Supabase.
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+## Overview
+
+In this guide we'll show you how to authenticate your users with SMS based OTP (One-Time Password) tokens.
+
+There are two reasons to use Supabase SMS OTP tokens:
+
+- You want users to log in with mobile + password, and the mobile should be verified via SMS
+- You want users to log in with mobile ONLY (i.e. passwordless login)
+
+We'll cover:
+
+- [Getting your Vonage API Key](#finding-your-vonage-api-key)
+- [Using OTP with password based logins](#using-otp-with-password-based-logins)
+- [Using OTP as a passwordless sign-in mechanism](#using-otp-as-a-passwordless-sign-in-mechanism)
+
+What you'll need:
+
+- A Vonage account (sign up here: https://dashboard.nexmo.com/sign-up)
+- A Supabase project (create one here: https://app.supabase.com)
+- A mobile phone capable of receiving SMS
+
+## Steps
+
+### Getting your Vonage credentials
+
+Start by logging into your Vonage Dashboard at https://dashboard.nexmo.com/
+
+You will see you API Key and API Secret here, which is actually all you need to get started.
+
+In most countries, a phone number is actually optional and you can also use any Alphanumeric Sender ID of up to 11 characters length (8 for India) as a Sender ID (from). This means you do not need a number to test with in most cases.
+
+To find out more about supported countries for Alphanumeric Sender ID, check this overview: https://help.nexmo.com/hc/en-us/articles/115011781468-SMS-Features-Overview-Outbound-only-
+
+Hint: Some countries might need a Sender ID Registration to allow sending with an Alphanumeric Sender ID. You can find this information in the help article as well. If Alpha Sender IDs are not supported, you will need to buy a phone number.
+
+### Getting a phone number (optional)
+
+If you want a phone number to send SMS from, you can buy one from the Vonage Dashboard under Numbers > Buy Numbers (https://dashboard.nexmo.com/buy-numbers).
+
+Select the country you want a number for. You will need a mobile phone number with SMS or SMS+Voice capability. After you have bought the number, you will be able to send SMS from it.
+
+### Configure Supabase
+
+Now go to the Auth > Settings page in the Supabase dashboard (https://app.supabase.com/project/YOUR-PROJECT-REF/auth/settings).
+
+You should see an option to enable Phone Signup.
+
+Toggle it on, and copy the api key, api secret and optionally phone number values over from the Vonage dashboard. Click save.
+
+Now the backend should be setup, we can proceed to add our client-side code!
+
+#### SMS custom template
+
+The SMS message sent to a phone containing an OTP code can be customized. This is useful if you need to mention a brand name or display a website address.
+
+Go to Auth > Templates page in the Supabase dashboard (https://app.supabase.com/project/YOUR-PROJECT-REF/auth/templates).
+
+Use the variable `.Code` in the template to display the code.
+
+### Using OTP with password based logins
+
+In this use scenario we'll be using the user's mobile phone number as an alternative to an email address when signing up along with a password. You may want to think hard about the permanency of this however. It is not uncommon for mobile phone numbers to be recycled by phone networks when users cancel their phone contracts or move countries, therefore granting access to the user's account to whoever takes over the phone number in the future.
+
+Using supabase-js on the client you'll want to use the same `signUp` method that you'd use for email based sign ups, but with the `phone` param instead of the `email param`:
+
+
+
+
+```js
+let { user, error } = await supabase.auth.signUp({
+ phone: '491512223334444',
+ password: 'some-password',
+})
+```
+
+
+
+
+```bash
+curl -X POST 'https://xxx.supabase.co/auth/v1/signup' \
+-H "apikey: SUPABASE_KEY" \
+-H "Content-Type: application/json" \
+-d '{
+ "phone": "491512223334444",
+ "password": "some-password"
+}'
+```
+
+
+
+
+The user will now receive an SMS with a 6-digit pin that you will need to receive from them within 60-seconds before they can login to their account.
+
+You should present a form to the user so they can input the 6 digit pin, then send it along with the phone number to `verifyOTP`:
+
+
+
+
+```js
+let { session, error } = await supabase.auth.verifyOTP({
+ phone: '491512223334444',
+ token: '123456',
+})
+```
+
+
+
+
+```bash
+curl -X POST 'https://xxx.supabase.co/auth/v1/verify' \
+-H "apikey: SUPABASE_KEY" \
+-H "Content-Type: application/json" \
+-d '{
+ "type": "sms",
+ "phone": "491512223334444",
+ "token": "123456"
+}'
+```
+
+
+
+
+If successful the user will now be logged in and you should receive a valid session like:
+
+```json
+{
+ "access_token": "eyJxxx...",
+ "token_type": "bearer",
+ "expires_in": 3600,
+ "refresh_token": "yyy..."
+}
+```
+
+The access token can be sent in the Authorization header as a Bearer token for any CRUD operations on supabase-js. See our guide on [Row Level Security](/docs/guides/auth#row-level-security) for more info on restricting access on a user basis.
+
+Also now that the mobile has been verified, the user can use the number and password to sign in without needing to verify their number each time:
+
+
+
+
+```js
+let { user, error } = await supabase.auth.signIn({
+ phone: '491512223334444',
+ password: 'some-password',
+})
+```
+
+
+
+
+```bash
+curl -X POST 'https://xxx.supabase.co/auth/v1/token?grant_type=password' \
+-H "apikey: SUPABASE_KEY" \
+-H "Content-Type: application/json" \
+-d '{
+ "phone": "491512223334444",
+ "password": "some-password"
+}'
+```
+
+
+
+
+### Using OTP as a passwordless sign-in mechanism
+
+In this scenario you are granting your user's the ability to login to their account without needing to set a password on their account, all they have to do to log in is verify their mobile each time using the OTP.
+
+In javascript we can use the `signIn` method with a single parameter: `phone`
+
+
+
+
+```js
+let { user, error } = await supabase.auth.signIn({
+ phone: '491512223334444',
+})
+```
+
+
+
+
+```bash
+curl -X POST 'https://xxx.supabase.co/auth/v1/otp' \
+-H "apikey: SUPABASE_KEY" \
+-H "Content-Type: application/json" \
+-d '{
+ "phone": "491512223334444"
+}'
+```
+
+
+
+
+The second step is the same as the previous section, you need to collect the 6-digit pin from the user and pass it along with their phone number to the verify method:
+
+
+
+
+```js
+let { session, error } = await supabase.auth.verifyOTP({
+ phone: '491512223334444',
+ token: '123456',
+})
+```
+
+
+
+
+```bash
+curl -X POST 'https://xxx.supabase.co/auth/v1/verify' \
+-H "apikey: SUPABASE_KEY" \
+-H "Content-Type: application/json" \
+-d '{
+ "type": "sms",
+ "phone": "491512223334444",
+ "token": "123456"
+}'
+```
+
+
+
+
+and the response should also be the same as above:
+
+```json
+{
+ "access_token": "eyJxxx...",
+ "token_type": "bearer",
+ "expires_in": 3600,
+ "refresh_token": "yyy..."
+}
+```
+
+The user does not have a password therefore will need to sign in via this method each time they want to access your service.
+
+## Resources
+
+- [Vonage Signup](https://dashboard.nexmo.com/sign-up)
+- [Supabase Dashboard](https://app.supabase.com)
+- [Supabase Row Level Security](/docs/guides/auth#row-level-security)
\ No newline at end of file
diff --git a/apps/reference/docs/guides/auth/auth-workos.mdx b/apps/reference/docs/guides/auth/auth-workos.mdx
new file mode 100644
index 00000000000..5a4b1abb306
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-workos.mdx
@@ -0,0 +1,102 @@
+---
+id: auth-workos
+title: 'Login with WorkOS'
+description: Add WorkOS OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable WorkOS Auth for your project, you need to set up WorkOS OAuth application and add the application credentials to your Supabase Dashboard.
+
+## Overview
+
+In this guide, we will cover how to use Supabase OAuth with WorkOS to implement Single-Sign-On(SSO).
+
+The procedure consists of five broad steps:
+
+- Create a new organization from your WorkOS Dashboard.
+- Obtain the `Client ID` from the Configuration tab and configure redirect URI.
+- Obtain the `WorkOS Secret` from the credentials tab.
+- Connect a WorkOS Supported Identity Provider
+- Add your WorkOS credentials into your Supabase project
+
+## Steps
+
+### Create a WorkOS Organization
+
+Log in to the dashboard and hop over to the Organizations tab to create and organization
+
+
+### Obtain the Client ID and configure Redirect URI
+
+Head over to the Configuration tab and configure the redirect URI.The redirect URI should look like `https://.supabase.co/auth/v1/callback`
+Note that this is distinct from the redirect URI referred to in the Supabase dashboard
+
+
+
+### Obtain the WorkOS Secret
+
+Head over to the API Keys page and obtain the secret key.
+
+
+
+### Connect a WorkOS Supported Identity Provider
+
+Set up the identity provider by visiting the setup link.
+
+
+
+You can pick between any one of the many identity providers that WorkOS supports.
+
+### Add your WorkOS credentials into your Supabase Project
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com)
+- In the left sidebar, click the `Authentication` icon (near the top)
+- Click `Settings` from the list to go to the `Authentication Settings` page
+- Under `External OAuth Providers` turn `WorkOS Enabled` to ON
+- Enter the `Client ID`, `Secret`, and `WorkOS URL` saved in the previous steps. The ``WorkOS URL` setting should be set to https://api.workos.com/
+- Click `Save`
+
+
+
+### Add login code to your client app
+
+The JavaScript client code is documented in the [Supabase OAuth Reference](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers). Note that you only need to include one of the three parameters: `connection`, `organization`, and `provider`.
+You can refer to the [WorkOS Documentation](https://workos.com/docs/reference/sso/authorize/) to learn more about the different methods.
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'workos',
+}, {
+ connection: "",
+ organization: ""
+})
+```
+
+Add a function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithWorkOS() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'workos',
+ }, {
+ connection: "",
+ organization: ""
+ })
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- [WorkOS Documentation](https://workos.com/docs/sso/guide)
diff --git a/apps/reference/docs/guides/auth/auth-zoom.mdx b/apps/reference/docs/guides/auth/auth-zoom.mdx
new file mode 100644
index 00000000000..3d2e3b7b478
--- /dev/null
+++ b/apps/reference/docs/guides/auth/auth-zoom.mdx
@@ -0,0 +1,107 @@
+---
+id: auth-zoom
+title: 'Login with Zoom'
+description: Add Zoom OAuth to your Supabase project
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+To enable Zoom Auth for your project, you need to set up a Zoom OAuth application and add the application credentials to your Supabase Dashboard.
+
+## Overview
+
+Setting up Zoom logins for your application consists of 3 parts:
+
+- Create and configure a Zoom OAuth App on [Zoom App Marketplace](https://marketplace.zoom.us/)
+- Add your Zoom OAuth keys to your [Supabase Project](https://app.supabase.com)
+- Add the login code to your [Supabase JS Client App](https://github.com/supabase/supabase-js)
+
+## Steps
+
+### Access your Zoom Developer account
+
+- Go to [marketplace.zoom.us](https://marketplace.zoom.us/).
+- Click on `Sign In` at the top right to log in.
+
+
+
+### Find your callback URL
+
+The next step requires a callback URL, which looks like this:
+
+`https://.supabase.co/auth/v1/callback`
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com).
+- Click on the `Settings` icon at the bottom of the left sidebar.
+- Click on `API` in the list.
+- Under Config / URL you'll find your API URL, you can click `Copy` to copy it to the clipboard.
+- Now just add `/auth/v1/callback` to the end of that to get your full `OAuth Redirect URI`.
+
+
+
+### Create a Zoom Oauth App
+
+- Go to [marketplace.zoom.us](https://marketplace.zoom.us/).
+- Click on `Sign In` at the top right to log in.
+- Click `Build App` (from the dropdown Develop)
+- In the OAuth card, click `Create`
+- Type the name of your app
+- Choose app type
+- Click `Create`
+
+Under `App credentials`
+
+- Copy and save your `Client ID`.
+- Copy and save your `Client secret`.
+
+Under `Redirect URL for OAuth`
+
+- Paste your `Callback URL`
+- Click `Continue`
+
+### Enter your Zoom credentials into your Supabase Project
+
+- Go to your [Supabase Project Dashboard](https://app.supabase.com)
+- In the left sidebar, click the `Authentication` icon (near the top)
+- Click `Settings` from the list to go to the `Authentication Settings` page
+- Enter the final (hosted) URL of your app under `Site URL` (this is important)
+- Under `External OAuth Providers` turn `Zoom Enabled` to ON
+- Enter your `Zoom Client ID` and `Zoom Client Secret` saved in the previous step
+- Click `Save`
+
+### Add login code to your client app
+
+The JavaScript client code is documented here: [Supabase OAuth Client Code](/docs/reference/javascript/auth-signin#sign-in-using-third-party-providers)
+
+```js
+const { user, session, error } = await supabase.auth.signIn({
+ provider: 'zoom',
+})
+```
+
+Add this function which you can call from a button, link, or UI element.
+
+```js
+async function signInWithZoom() {
+ const { user, session, error } = await supabase.auth.signIn({
+ provider: 'zoom',
+ })
+}
+```
+
+To log out:
+
+```js
+async function signout() {
+ const { error } = await supabase.auth.signOut()
+}
+```
+
+## Resources
+
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [Zoom App Marketplace](https://marketplace.zoom.us/)
diff --git a/apps/reference/docs/guides/auth/intro.mdx b/apps/reference/docs/guides/auth/intro.mdx
new file mode 100644
index 00000000000..104a5359024
--- /dev/null
+++ b/apps/reference/docs/guides/auth/intro.mdx
@@ -0,0 +1,84 @@
+---
+id: intro
+title: Supabase Auth
+sidebar_label: Introduction
+description: Use Supabase to Authenticate and Authorize your users.
+# hide_table_of_contents: true
+---
+
+import Link from '@docusaurus/Link'
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+import providers from '@site/src/data/authProviders'
+
+
+
+## Introduction
+
+Supabase Auth is designed to work with Postgres. There are two parts to every Auth system:
+
+- **Authentication:** should this person be allowed in? If yes, who are they?
+- **Authorization:** once they are in, what are they allowed to do?
+
+## Authentication
+
+You can authenticate your users in several ways:
+
+- Email & password.
+- Magic links (one-click logins).
+- Social providers.
+- Phone logins.
+
+
+
+
+## Authorization
+
+
+When you need granular authorization rules, nothing beats PostgreSQL's Row Level Security (RLS).
+
+Policies are PostgreSQL's rule engine. They are incredibly powerful and flexible, allowing you to write complex SQL rules which fit your unique business needs.
+
+Get started with our [Row Level Security Guides](/docs/guides/auth/row-level-security).
\ No newline at end of file
diff --git a/apps/reference/docs/guides/auth/managing-user-data.mdx b/apps/reference/docs/guides/auth/managing-user-data.mdx
new file mode 100644
index 00000000000..d0affd2a189
--- /dev/null
+++ b/apps/reference/docs/guides/auth/managing-user-data.mdx
@@ -0,0 +1,109 @@
+---
+id: managing-user-data
+title: Managing User Data
+description: Securing your user data with Row Level Security.
+---
+
+For security purposes, the `auth` schema is not exposed on the auto-generated API.
+
+Even though Supabase provides an `auth.users` table, it can be helpful to create tables in the `public` schema for storing user data that you want to access via the API.
+
+## Creating user tables
+
+When you create tables to store user data, it's helpful to reference the `auth.users` table in the primary key. This ensures data integrity.
+
+For example, a `public.profiles` table might look like this:
+
+```sql
+create table public.profiles (
+ id uuid references auth.users not null,
+ first_name text,
+ last_name text,
+
+ primary key (id)
+);
+
+alter table public.profiles enable row level security;
+```
+
+
+## Public access
+
+Since Row Level Security is enabled, this table is accessible via the API but no data will be returned unless we set up some Policies.
+If we wanted the data to be _readable_ by everyone but only allow logged-in users to update their own data, the Policies would look like this:
+
+```sql
+create policy "Public profiles are viewable by everyone."
+ on profiles for select
+ using ( true );
+
+create policy "Users can insert their own profile."
+ on profiles for insert
+ with check ( auth.uid() = id );
+
+create policy "Users can update own profile."
+ on profiles for update
+ using ( auth.uid() = id );
+```
+
+## Private access
+
+If the data should only be _readable_ by the user who owns the data, we just need to change the `for select` query above.
+
+```sql
+create policy "Profiles are viewable by users who created them."
+ on profiles for select
+ using ( auth.uid() = id );
+```
+
+The nice thing about this pattern? We can now query this table via the API and we don't need to include data filters in our API queries - the Policies will handle that for us:
+
+```js
+// This will return nothing while the user is logged out
+const { data } = await supabase
+ .from('profiles')
+ .select('id, username, avatar_url, website')
+
+// After the user is logged in, this will only return
+// the logged-in user's data - in this case a single row
+const { error } = await supabase.auth.signIn({ email })
+const { data: profile } = await supabase
+ .from('profiles')
+ .select('id, username, avatar_url, website')
+```
+
+## Bypassing Row Level Security
+
+If you need to fetch a full list of user profiles, we supply a `service_key` which you can use with your API and Client Libraries to bypass Row Level Security.
+
+Make sure you _NEVER_ expose this publicly. But it can be used on the server-side to fetch all of the profiles.
+
+
+## Advanced techniques
+
+### Using triggers
+
+If you want to add a row to your `public.profiles` table every time a user signs up, you can use triggers.
+If the trigger fails however, it could block the user sign ups - so make sure that the code is well-tested.
+
+For example:
+
+```sql
+-- inserts a row into public.users
+create function public.handle_new_user()
+returns trigger
+language plpgsql
+security definer set search_path = public
+as $$
+begin
+ insert into public.profiles (id)
+ values (new.id);
+ return new;
+end;
+$$;
+
+-- trigger the function every time a user is created
+create trigger on_auth_user_created
+ after insert on auth.users
+ for each row execute procedure public.handle_new_user();
+```
diff --git a/apps/reference/docs/guides/auth/row-level-security.mdx b/apps/reference/docs/guides/auth/row-level-security.mdx
new file mode 100644
index 00000000000..88d91d049c8
--- /dev/null
+++ b/apps/reference/docs/guides/auth/row-level-security.mdx
@@ -0,0 +1,364 @@
+---
+id: row-level-security
+title: Row Level Security
+description: Secure your data using Postgres Row Level Security.
+---
+
+When you need granular authorization rules, nothing beats PostgreSQL's [Row Level Security (RLS)](https://www.postgresql.org/docs/current/ddl-rowsecurity.html).
+
+[Policies](https://www.postgresql.org/docs/current/sql-createpolicy.html) are PostgreSQL's rule engine. They are incredibly powerful and flexible, allowing you to write complex SQL rules which fit your unique business needs.
+
+
+
+## Policies
+
+Policies are easy to understand once you get the hang of them. Each policy is attached to a table, and the policy is executed
+every time a table is accessed.
+You can just think of them as adding a `WHERE` clause to every query. For example a policy like this ...
+
+```sql
+create policy "Individuals can view their own todos."
+ on todos for select
+ using ( auth.uid() = user_id );
+```
+
+.. would translate to this whenever a user tries to select from the todos table:
+
+```sql
+select *
+from todos
+where auth.uid() = todos.user_id; -- Policy is implicitly added.
+```
+
+## Helper Functions
+
+Supabase provides you with a few easy functions that you can use with your policies.
+
+### `auth.uid()`
+
+Returns the ID of the user making the request.
+
+### `auth.jwt()`
+
+Returns the JWT of the user making the request.
+
+### `auth.role()`
+
+:::caution
+
+Deprecated
+
+:::
+
+The `auth.role()` function has been deprecated in favour of using the `TO` field, natively supported within Postgres.
+
+```sql
+-- DEPRECATED
+create policy "Public profiles are viewable by everyone."
+on profiles for select using (
+ auth.role() = 'authenticated' or auth.role() = 'anon'
+);
+
+-- RECOMMENDED
+create policy "Public profiles are viewable by everyone."
+on profiles for select
+to authenticated, anon
+using (
+ true
+);
+```
+
+### `auth.email()`
+
+:::caution
+
+Deprecated. Use `auth.jwt() ->> 'email'` instead.
+
+:::
+
+Returns the email of the user making the request.
+
+## Examples
+
+Here are some examples to show you the power of PostgreSQL's RLS.
+
+### Allow read access
+
+```sql
+-- 1. Create table
+create table profiles (
+ id uuid references auth.users,
+ avatar_url text
+);
+
+-- 2. Enable RLS
+alter table profiles
+ enable row level security;
+
+-- 3. Create Policy
+create policy "Public profiles are viewable by everyone."
+ on profiles for select using (
+ true
+ );
+```
+
+1. Creates a table called `profiles` in the public schema (default schema).
+2. Enables Row Level Security.
+3. Creates a policy which allows all `select` queries to run.
+
+### Restrict updates
+
+```sql
+-- 1. Create table
+create table profiles (
+ id uuid references auth.users,
+ avatar_url text
+);
+
+-- 2. Enable RLS
+alter table profiles
+ enable row level security;
+
+-- 3. Create Policy
+create policy "Users can update their own profiles."
+ on profiles for update using (
+ auth.uid() = id
+ );
+```
+
+1. Creates a table called `profiles` in the public schema (default schema).
+2. Enables RLS.
+3. Creates a policy which allows logged in users to update their own data.
+
+### Only anon or authenticated access
+
+You can add a Postgres role
+
+```sql
+create policy "Public profiles are viewable by everyone."
+on profiles for select
+to authenticated, anon
+using (
+ true
+);
+```
+
+### Policies with joins
+
+Policies can even include table joins. This example shows how you can query "external" tables to build more advanced rules.
+
+```sql
+create table teams (
+ id serial primary key,
+ name text
+);
+
+-- 2. Create many to many join
+create table members (
+ team_id bigint references teams,
+ user_id uuid references auth.users
+);
+
+-- 3. Enable RLS
+alter table teams
+ enable row level security;
+
+-- 4. Create Policy
+create policy "Team members can update team details if they belong to the team."
+ on teams
+ for update using (
+ auth.uid() in (
+ select user_id from members
+ where team_id = id
+ )
+ );
+```
+
+**Note:** If RLS is also enabled for _members_, the user must also have read (_select_) access to _members_. Otherwise the joined query will not yield any results.
+
+### Policies with security definer functions
+
+Policies can also make use of `security definer functions`. This is useful in a many-to-many relationship where you want to restrict access to the linking table. Following the `teams` and `members` example from above, this example shows how you can use the security definer function in combination with a policy to control access to the `members` table.
+
+```sql
+-- 1. Follow example for 'Policies with joins' above
+
+-- 2. Enable RLS
+alter table members
+ enable row level security
+
+-- 3. Create security definer function
+create or replace function get_teams_for_authenticated_user()
+returns setof bigint
+language sql
+security definer
+set search_path = public
+stable
+as $$
+ select team_id
+ from members
+ where user_id = auth.uid()
+$$;
+
+-- 4. Create Policy
+create policy "Team members can update team members if they belong to the team."
+ on members
+ for all using (
+ team_id in (
+ select get_teams_for_authenticated_user()
+ )
+ );
+
+```
+
+### Verifying email domains
+
+Postgres has a function `right(string, n)` that returns the rightmost n characters of a string.
+You could use this to match staff member's email domains.
+
+```sql
+-- 1. Create table
+create table leaderboard (
+ id uuid references auth.users,
+ high_score bigint
+);
+
+-- 2. Enable RLS
+alter table leaderboard
+ enable row level security;
+
+-- 3. Create Policy
+create policy "Only Blizzard staff can update leaderboard"
+ on leaderboard
+ for update using (
+ right(auth.email(), 13) = '@blizzard.com'
+ );
+```
+
+### Time to live for rows
+
+Policies can also be used to implement TTL or time to live feature that you see in Instagram stories or Snapchat.
+In the following example, rows of `stories` table are available only if they have been created within the last 24 hours.
+
+```sql
+-- 1. Create table
+create table if not exists stories (
+ id uuid not null primary key DEFAULT uuid_generate_v4(),
+ created_at timestamp with time zone default timezone('utc' :: text, now()) not null,
+ content text not null
+);
+
+-- 2. Enable RLS
+alter table stories
+ enable row level security;
+
+-- 3. Create Policy
+create policy "Stories are live for a day"
+ on stories
+ for select using (
+ created_at > (current_timestamp - interval '1 day')
+ );
+```
+
+### Advanced policies
+
+Use the full power of SQL to build extremely advanced rules.
+
+In this example, we will create a `posts` and `comments` tables and then create a policy that depends on another policy.
+(In this case, the comments policy depends on the posts policy.)
+
+```sql
+create table posts (
+ id serial primary key,
+ creator_id uuid not null references auth.users(id),
+ title text not null,
+ body text not null,
+ publish_date date not null default now(),
+ audience uuid[] null -- many to many table omitted for brevity
+);
+
+create table comments (
+ id serial primary key,
+ post_id int not null references posts(id) on delete cascade,
+ user_id uuid not null references auth.users(id),
+ body text not null,
+ comment_date date not null default now()
+);
+
+create policy "Creator can see their own posts"
+on posts
+for select
+using (
+ auth.uid() = posts.creator_id
+);
+
+create policy "Logged in users can see the posts if they belong to the post 'audience'."
+on posts
+for select
+using (
+ auth.uid() = any (posts.audience)
+);
+
+create policy "Users can see all comments for posts they have access to."
+on comments
+for select
+using (
+ exists (
+ select 1 from posts
+ where posts.id = comments.post_id
+ )
+);
+```
+
+## Tips
+
+### Enable Realtime for database tables
+
+Realtime server broadcasts database changes to authorized users depending on your Row Level Security (RLS) policies.
+We recommend that you enable row level security and set row security policies on tables that you add to the publication.
+However, you may choose to disable RLS on a table and have changes broadcast to all connected clients.
+
+```sql
+/**
+ * REALTIME SUBSCRIPTIONS
+ * Realtime enables listening to any table in your public schema.
+ */
+
+begin;
+ -- remove the realtime publication
+ drop publication if exists supabase_realtime;
+
+ -- re-create the publication but don't enable it for any tables
+ create publication supabase_realtime;
+commit;
+
+-- add a table to the publication
+alter publication supabase_realtime add table products;
+
+-- add other tables to the publication
+alter publication supabase_realtime add table posts;
+```
+
+### You don't have to use policies
+
+You can also put your authorization rules in your middleware, similar to how you would create security rules with any other `backend <-> middleware <-> frontend` architecture.
+
+Policies are a tool. In the case of "serverless/Jamstack" setups, they are especially effective because you don't have to deploy any middleware at all.
+
+However, if you want to use another authorization method for your applications, that's also fine. Supabase is "just Postgres", so if your application
+works with Postgres, then it also works with Supabase.
+
+Tip: Make sure to enable RLS for all your tables, so that your tables are inaccessible. Then use the "Service" which we provide, which is designed to bypass RLS.
+
+### Never use a service key on the client
+
+Supabase provides special "Service" keys, which can be used to bypass all RLS.
+These should never be used in the browser or exposed to customers, but they are useful for administrative tasks.
diff --git a/apps/reference/docs/guides/client-libraries.mdx b/apps/reference/docs/guides/client-libraries.mdx
new file mode 100755
index 00000000000..54db0f94a72
--- /dev/null
+++ b/apps/reference/docs/guides/client-libraries.mdx
@@ -0,0 +1,525 @@
+---
+id: client-libraries
+title: Client Libraries
+description: 'Supabase provides client libraries in several languages.'
+---
+
+
+import Tabs from '@theme/Tabs';
+import TabItem from '@theme/TabItem';
+
+
+The [Supabase Client](/docs/reference/javascript/installing) makes it simple for developers to build secure and scalable products.
+
+## Auth
+
+
+Create new users using [`signUp()`](/docs/reference/javascript/auth-signup). By default, the user will need to verify their email address before logging in.
+If confirmations are disabled the response will contain an access token and also a confirmed_at value, otherwise it will just contain a confirmation_sent_at attribute.
+
+
+
+
+
+```js
+const { error, data } = await supabase.auth.signUp({
+ email: 'example@email.com',
+ password: 'example-password',
+})
+```
+
+
+
+
+
+```py
+import os
+from supabase import create_client, Client
+
+url: str = os.environ.get("SUPABASE_TEST_URL")
+key: str = os.environ.get("SUPABASE_TEST_KEY")
+supabase: Client = create_client(url, key)
+user = supabase.auth.sign_up(
+ email='example@email.com',
+ password='example-password',
+)
+```
+
+
+
+
+
+
+```dart
+import 'package:supabase/supabase.dart';
+
+void main() async {
+ final client = SupabaseClient('supabaseUrl', 'supabaseKey');
+
+ // Sign up user with email and password
+ final response = await client
+ .auth
+ .signUp('example@email.com', 'example-password');
+}
+```
+
+
+
+
+
+
+
+Existing users can log in using [`signIn()`](/docs/reference/javascript/auth-signin).
+
+
+
+
+
+```js
+const { error, data } = await supabase.auth.signIn({
+ email: 'example@email.com',
+ password: 'example-password'
+})
+```
+
+
+
+
+
+```py
+import os
+from supabase import create_client, Client
+
+url: str = os.environ.get("SUPABASE_TEST_URL")
+key: str = os.environ.get("SUPABASE_TEST_KEY")
+supabase: Client = create_client(url, key)
+user = supabase.auth.sign_in(
+ email='example@email.com',
+ password='example-password'
+)
+```
+
+
+
+
+
+
+```dart
+import 'package:supabase/supabase.dart';
+
+void main() async {
+ final client = SupabaseClient('supabaseUrl', 'supabaseKey');
+
+ // Sign in user with email and password
+ final response = await client
+ .auth
+ .signIn(email: 'example@email.com', password: 'example-password');
+}
+```
+
+
+
+
+
+
+If there is an email, but no password passed to [`signIn()`](/docs/reference/javascript/auth-signin), the user will receive a magic link.
+
+
+
+
+
+```js
+const { error, data } = await supabase.auth.signIn({
+ email: 'example@email.com'
+})
+```
+
+
+
+
+
+```py
+import os
+from supabase import create_client, Client
+
+url: str = os.environ.get("SUPABASE_TEST_URL")
+key: str = os.environ.get("SUPABASE_TEST_KEY")
+supabase: Client = create_client(url, key)
+user = supabase.auth.sign_in(
+ email='example@email.com'
+)
+```
+
+
+
+
+
+
+```dart
+import 'package:supabase/supabase.dart';
+
+void main() async {
+ final client = SupabaseClient('supabaseUrl', 'supabaseKey');
+
+ // Sign in user with email and magic link
+ final response = await client
+ .auth
+ .signIn(email: 'example@email.com');
+}
+```
+
+
+
+
+
+
+Third party logins are also handled through [`signIn()`](/docs/reference/javascript/auth-signin).
+
+
+
+
+
+
+```js
+const { user, error } = await supabase.auth.signIn({
+ // provider can be 'github', 'google', 'gitlab', or 'bitbucket'
+ provider: 'github'
+})
+```
+
+
+
+
+
+```py
+# Not yet implemented
+```
+
+
+
+
+
+
+```dart
+import 'package:supabase/supabase.dart';
+
+void main() async {
+ final client = SupabaseClient('supabaseUrl', 'supabaseKey');
+
+ final response = await client
+ .auth
+ .signIn(provider: Provider.github);
+}
+```
+
+
+
+
+
+## Managing data
+
+Since Postgres is a Relational database, the client makes it simple to query tables and fetch related data in one round-trip, using [`select()`](/docs/reference/javascript/select).
+
+
+
+
+
+
+```js
+const { data, error } = await supabase
+ .from('countries')
+ .select(`
+ name,
+ cities (
+ name
+ )
+ `)
+```
+
+
+
+
+
+```py
+import os
+from supabase import create_client, Client
+
+url: str = os.environ.get("SUPABASE_TEST_URL")
+key: str = os.environ.get("SUPABASE_TEST_KEY")
+supabase: Client = create_client(url, key)
+
+data = supabase.table('countries').select('name').execute()
+```
+
+
+
+
+
+
+```dart
+import 'package:supabase/supabase.dart';
+
+void main() async {
+ final client = SupabaseClient('supabaseUrl', 'supabaseKey');
+
+ // Query tables and fetch related data in one round-trip, using select()
+ final response = await client
+ .from('countries')
+ .select('name')
+ .execute();
+}
+```
+
+
+
+
+
+
+You can do advanced [filtering](/docs/reference/javascript/using-filters) to extract only the data that you need.
+
+
+
+
+
+
+```js
+const { data, error } = await supabase
+ .from('cities')
+ .select('name, country_id')
+ .lt('country_id', 100)
+ .limit(10)
+```
+
+
+
+
+
+```py
+data = supabase.table('cities').select('name, country_id').eq('name', 'Germany').execute()
+# Assert we pulled real data.
+assert len(data.get("data", [])) > 0
+```
+
+
+
+
+
+
+```dart
+import 'package:supabase/supabase.dart';
+
+void main() async {
+ final client = SupabaseClient('supabaseUrl', 'supabaseKey');
+
+ // When fetching data, use advanced filtering to only extract data, that you need.
+ final response = await client
+ .from('cities')
+ .select('name,country_id')
+ .lt('country_id', 100)
+ .limit(10)
+ .execute();
+}
+```
+
+
+
+
+
+
+You can create data easily using [`insert()`](/docs/reference/javascript/insert).
+
+
+
+
+
+
+
+```js
+const { data, error } = await supabase
+ .from('cities')
+ .insert([
+ { name: 'The Shire', country_id: 554 },
+ { name: 'Rohan', country_id: 555 },
+ ])
+```
+
+
+
+
+
+```py
+data = supabase.table('cities').insert({'name': 'Gotham', 'country_id': 556 }).execute()
+# assert if insert response is a success
+assert data.get("status_code") in (200, 201)
+
+# bulk insert
+data = supabase.table('cities').insert([
+{'name': 'Gotham', 'country_id': 556 },
+{'name': 'The Shire', 'country_id': 557 }
+]).execute()
+
+```
+
+
+
+
+
+
+```dart
+import 'package:supabase/supabase.dart';
+
+void main() async {
+ final client = SupabaseClient('supabaseUrl', 'supabaseKey');
+
+ // Create data easily, using insert()
+ final response = await client
+ .from('cities')
+ .insert([
+ { 'name': 'The Shire', 'country_id': 554 },
+ { 'name': 'Rohan', 'country_id': 555 },
+ ])
+ .execute();
+}
+```
+
+
+
+
+
+
+## Realtime Changes
+
+The Supabase client makes it simple to listen to realtime database changes, using [`subscribe()`](/docs/reference/javascript/subscribe).
+
+
+
+
+
+
+```js
+const mySubscription = supabase
+ .from('countries')
+ .on('*', payload => {
+ console.log('Change received!', payload)
+ })
+ .subscribe()
+```
+
+
+
+
+
+```py
+# Not yet implemented
+```
+
+
+
+
+
+
+```dart
+import 'package:supabase/supabase.dart';
+
+void main() async {
+ final client = SupabaseClient('supabaseUrl', 'supabaseKey');
+
+ // Listen to realtime database changes, using subscribe()
+ final response = await client
+ .from('countries')
+ .on(SupabaseEventTypes.all, (payload) {
+ print('Something happened: ${payload.eventType}');
+ })
+ .subscribe((String event, {String? errorMsg}) {
+ print('event: $event error: $errorMsg');
+ });
+}
+```
+
+
+
+
+
+
+You can even [listen to Row Level changes](/docs/reference/javascript/subscribe#listening-to-row-level-changes).
+
+
+
+
+
+
+```js
+const mySubscription = supabase
+ .from('countries:id.eq.200')
+ .on('UPDATE', handleRecordUpdated)
+ .subscribe()
+```
+
+
+
+
+
+```py
+# Not yet implemented
+```
+
+
+
+
+
+
+```dart
+import 'package:supabase/supabase.dart';
+
+void main() async {
+ final client = SupabaseClient('supabaseUrl', 'supabaseKey');
+
+ // You can even listen to Row Level changes
+ final response = await client
+ .from('countries:id.eq.200')
+ .on(SupabaseEventTypes.update, (payload) {
+ print('Something happened: ${payload.eventType}');
+ })
+ .subscribe((String event, {String? errorMsg}) {
+ print('event: $event error: $errorMsg');
+ });
+}
+```
+
+
+
+
+
+
+
+## Next steps
+
+- View the [Client Docs](/docs/reference/javascript/installing)
+- Sign in: [app.supabase.com](https://app.supabase.com)
diff --git a/apps/reference/docs/guides/database.mdx b/apps/reference/docs/guides/database.mdx
new file mode 100644
index 00000000000..2ee6736a54c
--- /dev/null
+++ b/apps/reference/docs/guides/database.mdx
@@ -0,0 +1,218 @@
+---
+id: database
+title: Database
+description: Use Supabase to manage your data.
+sidebar_label: Overview
+---
+
+Every Supabase project comes with a full [Postgres](https://www.postgresql.org/) database, a free and open source
+database which is considered one of the world's most stable and advanced databases.
+
+## Postgres or PostgreSQL?
+
+PostgreSQL the database was derived from the POSTGRES Project, a package written at the University of California at Berkeley in 1986.
+This package included a query language called "PostQUEL".
+
+In 1994, Postgres95 was built on top of POSTGRES code, adding an SQL language interpreter as a replacement for PostQUEL.
+Eventually, Postgres95 was renamed to PostgreSQL to reflect the SQL query capability.
+
+After this, many people referred to it as Postgres since it's less prone to confusion. Supabase is all about
+simplicity, so we also refer to it as Postgres.
+
+## Features
+
+### Table View
+
+You don't have to be a database expert to start using Supabase. Our table view makes Postgres as easy to use as a spreadsheet.
+
+
+
+### Relationships
+
+Dig into the relationships within your data.
+
+
+
+### Clone tables
+
+You can duplicate your tables, just like you would inside a spreadsheet.
+
+
+
+### The SQL Editor
+
+Supabase comes with a SQL Editor. You can also save your favorite queries to run later!
+
+
+
+### Additional features
+
+- Supabase extends Postgres with realtime functionality using our [Realtime Server](https://github.com/supabase/realtime).
+- Every project is a full Postgres database, with `postgres` level access.
+- Managed backups - Supabase handles all your database backups.[^backups]
+- Data imports - import directly from a CSV or excel spreadsheet.
+
+[^backups] Database backups do _NOT_ include objects stored via the Storage API, as the database only includes metadata about these objects. Restoring an old backup will not restore objects that have been deleted since then.
+
+### Extensions
+
+To expand the functionality of your Postgres database, you can use extensions.
+You can enable Postgres extensions with the click of a button within the Supabase dashboard.
+
+
+
+[Learn more](/docs/guides/database/extensions) about all the extensions provided on Supabase.
+
+## Tips
+
+### Realtime
+
+Supabase provides a realtime engine on top of Postgres, so that you can listen to changes as they happen.
+Our realtime engine uses the built-in replication functionality of Postgres.
+
+Realtime server broadcasts database changes to authorized users depending on your Row Level Security (RLS) policies.
+We recommend that you enable row level security and set row security policies on tables that you add to the publication.
+However, you may choose to disable RLS on a table and have changes broadcast to all connected clients.
+
+You can manage the realtime system, simply by
+[updating](/docs/guides/database/replication) the `supabase_realtime` publication.
+
+For example to enable realtime only for individual tables:
+
+```sql
+begin;
+ -- remove the realtime publication
+ drop publication if exists supabase_realtime;
+
+ -- re-create the publication but don't enable it for any tables
+ create publication supabase_realtime;
+commit;
+
+-- add a table to the publication
+alter publication supabase_realtime add table products;
+
+-- add other tables to the publication
+alter publication supabase_realtime add table posts;
+```
+
+By default only "new" values are sent, but if you want to receive the old record (previous values) whenever you `update` or `delete` a record,
+you can update the replica identity of your tables, setting it to `full`:
+
+```sql
+alter table your_table replica identity full;
+```
+
+### Migrating between projects
+
+Migrating projects can be achieved using standard PostgreSQL tooling. This is particularly useful for older projects (e.g. to use a newer Postgres version).
+
+#### Before you begin
+
+- Make sure [Postgres](https://www.postgresql.org/download/) is installed so you can run `psql` and `pg_dump`.
+- Create a new Supabase project.
+- If you enabled Database Webhooks on your old project, enable it on your new project.
+- Store the old project's database URL as `$OLD_DB_URL` and the new project's as `$NEW_DB_URL`.
+
+#### Migrate the database
+
+1. Run `ALTER ROLE postgres SUPERUSER` in the _old_ project's SQL editor
+2. Run `pg_dump --clean --if-exists --quote-all-identifiers -h $OLD_DB_URL -U postgres > dump.sql` from your terminal
+3. Run `ALTER ROLE postgres NOSUPERUSER` in the _old_ project's SQL editor
+4. Run `ALTER ROLE postgres SUPERUSER` in the _new_ project's SQL editor
+5. Run `psql -h $NEW_DB_URL -U postgres -f dump.sql` from your terminal
+6. Run `TRUNCATE storage.objects` in the _new_ project's SQL editor
+7. Run `ALTER ROLE postgres NOSUPERUSER` in the _new_ project's SQL editor
+
+#### Migrate storage objects
+
+This script moves storage objects from one project to another. If you have more than 10k objects, we can move the objects for you. Just contact us at [support@supabase.io](mailto:support@supabase.io).
+
+```js
+const { createClient } = require('@supabase/supabase-js')
+
+const OLD_PROJECT_URL = 'https://xxx.supabase.co'
+const OLD_PROJECT_SERVICE_KEY = 'old-project-service-key-xxx'
+
+const NEW_PROJECT_URL = 'https://yyy.supabase.co'
+const NEW_PROJECT_SERVICE_KEY = 'new-project-service-key-yyy'
+
+;(async () => {
+ const oldSupabaseRestClient = createClient(OLD_PROJECT_URL, OLD_PROJECT_SERVICE_KEY, {
+ schema: 'storage',
+ })
+ const oldSupabaseClient = createClient(OLD_PROJECT_URL, OLD_PROJECT_SERVICE_KEY)
+ const newSupabaseClient = createClient(NEW_PROJECT_URL, NEW_PROJECT_SERVICE_KEY)
+
+ // make sure you update max_rows in postgrest settings if you have a lot of objects
+ // or paginate here
+ const { data: oldObjects, error } = await oldSupabaseRestClient.from('objects').select()
+ if (error) {
+ console.log('error getting objects from old bucket')
+ throw error
+ }
+
+ for (const objectData of oldObjects) {
+ console.log(`moving ${objectData.id}`)
+ try {
+ const { data, error: downloadObjectError } = await oldSupabaseClient.storage
+ .from(objectData.bucket_id)
+ .download(objectData.name)
+ if (downloadObjectError) {
+ throw downloadObjectError
+ }
+
+ const { _, error: uploadObjectError } = await newSupabaseClient.storage
+ .from(objectData.bucket_id)
+ .upload(objectData.name, data, {
+ upsert: true,
+ contentType: objectData.metadata.mimetype,
+ cacheControl: objectData.metadata.cacheControl,
+ })
+ if (uploadObjectError) {
+ throw uploadObjectError
+ }
+ } catch (err) {
+ console.log('error moving ', objectData)
+ console.log(err)
+ }
+ }
+})()
+```
+
+#### Caveats
+
+- The new project will have the old project's Storage buckets, but not the objects. You will need to migrate Storage objects manually.
+
+### Resetting your project password
+
+When you create a new project in Supabase we ask for a password. You can use this password to connect directly to your Postgres database.
+
+If you forget your password, you can reset it from the Dashboard under the database settings page.
+
+Read more in [Database Configuration](/docs/guides/database/managing-passwords).
+
+### Changing the timezone of your server.
+
+Your database is initialized with the UTC timezone. We recommend keeping it this way, as it is helpful for time calculations.
+If, however, you want to update the timezone, you can do so using any of the [database timezones](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones).
+
+For example:
+
+```sql
+alter database postgres set timezone to 'America/New_York';
+```
+
+Read more in [Database Configuration](/docs/guides/database/managing-timezones).
+
+## Next steps
+
+- Read more about [Postgres](/docs/postgres/server/about)
+- Sign in: [app.supabase.com](https://app.supabase.com)
diff --git a/apps/reference/docs/guides/database/arrays.mdx b/apps/reference/docs/guides/database/arrays.mdx
new file mode 100644
index 00000000000..63c5a12716d
--- /dev/null
+++ b/apps/reference/docs/guides/database/arrays.mdx
@@ -0,0 +1,175 @@
+---
+id: arrays
+title: 'Working With Arrays'
+description: How to use arrays in PostgreSQL and the Supabase API.
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+PostgreSQL supports flexible [array types](https://www.postgresql.org/docs/12/arrays.html). These arrays are also supported in the Supabase Dashboard and in the JavaScript API.
+
+## Create a table with an array column
+
+Create a test table with a text array (an array of strings):
+
+
+
+
+
+1. Go to the [Table editor](https://app.supabase.com/project/_/editor) page in the Dashboard.
+1. Click **New Table** and create a table with the name `arraytest`.
+1. Click **Save**.
+1. Click **New Column** and create a column with the name `textarray`, type `text`, and select **Define as array**.
+1. Click **Save**.
+
+
+
+
+
+```sql
+CREATE TABLE arraytest (id integer NOT NULL, textarray text ARRAY);
+```
+
+
+
+
+## Insert a record with an array value
+
+
+
+
+
+1. Go to the [Table editor](https://app.supabase.com/project/_/editor) page in the Dashboard.
+1. Select the `arraytest` table.
+1. Click **Insert row** and add `["Harry", "Larry", "Moe"]`.
+1. Click **Save.**
+
+
+
+
+
+```sql
+INSERT INTO arraytest (id, textarray) VALUES (1, ARRAY['Harry', 'Larry', 'Moe']);
+```
+
+
+
+
+Insert a record from the JavaScript client:
+
+```js
+const { data, error } = await supabase
+ .from('arraytest')
+ .insert([{ id: 2, textarray: ['one', 'two', 'three', 'four'] }])
+```
+
+
+
+
+
+## View the results
+
+
+
+
+
+1. Go to the [Table editor](https://app.supabase.com/project/_/editor) page in the Dashboard.
+1. Select the `arraytest` table.
+
+You should see:
+
+| id | textarray |
+| --- | ----------------------- |
+| 1 | ["Harry","Larry","Moe"] |
+
+
+
+
+```sql
+SELECT * FROM arraytest;
+```
+
+You should see:
+
+| id | textarray |
+| --- | ----------------------- |
+| 1 | ["Harry","Larry","Moe"] |
+
+
+
+
+## Query array data
+
+PostgreSQL uses 1-based indexing (e.g., `textarray[1]` is the first item in the array).
+
+
+
+
+
+To select the first item from the array and get the total length of the array:
+
+```js
+SELECT textarray[1], array_length(textarray, 1) FROM arraytest;
+```
+
+returns:
+
+| textarray | array_length |
+| --------- | ------------ |
+| Harry | 3 |
+
+
+
+
+
+This returns the entire array field:
+
+```js
+const { data, error } = await supabase.from('arraytest').select('textarray[]')
+console.log(JSON.stringify(data, null, 2))
+```
+
+returns:
+
+```js
+[
+ {
+ textarray: ['Harry', 'Larry', 'Moe'],
+ },
+]
+```
+
+
+
+
+## Resources
+
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [PostgreSQL Arrays](https://www.postgresql.org/docs/12/arrays.html)
diff --git a/apps/reference/docs/guides/database/connecting-to-postgres.mdx b/apps/reference/docs/guides/database/connecting-to-postgres.mdx
new file mode 100644
index 00000000000..183c12580d4
--- /dev/null
+++ b/apps/reference/docs/guides/database/connecting-to-postgres.mdx
@@ -0,0 +1,135 @@
+---
+id: connecting-to-postgres
+title: 'Database Connections'
+description: There are various ways to connect to your Postgres database.
+---
+
+Supabase provides several options for programmatically connecting to your Postgres database:
+
+## Types of Connection
+
+- HTTP connections using the API.
+- Direct connections using Postgres' standard connection system.
+- Connection pooling using PgBouncer.
+
+### API vs Direct vs Pooling
+
+- The API is an auto-generated REST inteface. You should use this for all browser and application interactions.
+- A "direct connection" is when a connection is made to the database using Postgres' native connection implementation. You should use this for tools which are always alive - usually installed on a long-running server.
+- A "connection pool" is a system (external to Postgres) which keeps connections "open". You should use this for serverless functions and tools which disconnect from the database frequently.
+
+Why would you use a connection pool? Primarily because the way that Postgres handles connections isn't very scalable for a large number of _temporary_ connections.
+You can use these simple questions to determine which connection method to use:
+
+- Are you connecting to a database and _maintaining_ a connection? If yes, use a direct connection.
+- Are you connecting to your database and then _disconnecting_ immediately (e.g. a serverless environment)? If yes, use a connection pool.
+
+## API
+
+Supabase provides an auto-updating [API](/docs/guides/api). This is the easiest way to get started if you are managing data (fetching, inserting, updating).
+
+### Interfaces
+
+We provides several types of API to suit your preferences and use-case:
+
+- [REST](/docs/guides/api#rest-api): interact with your database through a REST interface.
+- [GraphQL](/docs/guides/api#graphql-api): interact with your database through a GraphQL interface.
+- [Realtime](/docs/guides/api#realtime-api): listen to database changes over websockets.
+
+You cannot manage the database schema via the API (for security reasons). To do that you can use the dashboard or connect directly to your database.
+
+### API URL and Keys
+
+You can find the API URL and Keys in the [Dashboard](https://app.supabase.com/project/_/settings/api).
+
+
+
+## Direct connections
+
+Every Supabase project provides a full Postgres database. You can connect to the database using any tool which supports Postgres.
+
+### Finding your connection string
+
+1. Go to the `Settings` section.
+2. Click `Database`.
+3. Find your Connection Info and Connection String. Direct connections are on port `5432`.
+
+
+
+## Connection Pool
+
+Connection pools are useful for managing a large number of _temporary_ connections. For example, if you are using [Prisma](/docs/guides/integrations/prisma) deployed to a Serverless environment.
+
+### How connection pooling works
+
+A "connection pool" is a system (external to Postgres) which manages connections, rather than PostgreSQL's native system. Supabase uses [PgBouncer](https://www.pgbouncer.org/) for connection pooling.
+
+When a client makes a request, PgBouncer "allocates" an available connection to the client.
+When the client transaction or session is completed the connection is returned to the pool and is free to be used by another client.
+
+
+
+### Pool modes
+
+Pool Mode determines how PgBouncer handles a connection.
+
+#### Session
+
+When a new client connects, a connection is assigned to the client until it disconnects. Afterward, the connection is returned back to the pool.
+
+All PostgreSQL features can be used with this option.
+
+#### Transaction
+
+This is the suggested option for serverless functions. A connection is only assigned to the client for the duration of a transaction. Two consecutive transactions from the same client
+could be executed over two different connections.
+
+Some session-based PostgreSQL features such as prepared statements are not available with this option.
+A comprehensive list of incompatible features can be found [here](https://www.pgbouncer.org/features.html).
+
+#### Statement
+
+This is the most granular option. Connections are returned to the pool after every statement. Transactions with multiple statements are not allowed. This is best used when `AUTOCOMMIT` is in use.
+
+### Finding the connection pool config
+
+1. Go to the `Settings` section.
+2. Click `Database`.
+3. Find your Connection Info and Connection String. Connection pooling is on port `6543`.
+
+
+
+## Connecting with SSL
+
+Use this when connecting to your database to prevent snooping and man-in-the-middle attacks.
+
+Obtain your connection info and Server root certificate from your application’s dashboard.
+
+
+Assuming you’ve downloaded your certificate and it’s located at `$HOME/Downloads/prod-ca-2021.cer`, and your Host address is `db.abcdefghijklm.supabase.co` you can connect to the DB with
+SSL enabled as illustrated below:
+
+1. With `psql`
+
+```
+psql "sslmode=verify-full sslrootcert=$HOME/Downloads/prod-ca-2021.cer host=db.abcdefghijklm.supabase.co dbname=postgres user=postgres"
+```
+
+2. With `pgAdmin`
+ a. Register a new Postgres server
+ 
+
+ b. Name your server to your liking and add the connection info.
+ 
+ 
+
+3. Navigate to the SSL tab and change the SSL mode to Require. Next navigate to the Root certificate input, it will open up a
+ file-picker modal. Select the certificate you downloaded from your Supabase dashboard and save the server details. PgAdmin
+ should now be able to connect to your Postgres via SSL.
+ 
diff --git a/apps/reference/docs/guides/database/extensions.mdx b/apps/reference/docs/guides/database/extensions.mdx
new file mode 100644
index 00000000000..fceef7106e5
--- /dev/null
+++ b/apps/reference/docs/guides/database/extensions.mdx
@@ -0,0 +1,62 @@
+---
+id: extensions
+title: Overview
+description: Using Postgres extensions.
+---
+
+import ExtensionsComponent from '@site/src/components/Extensions'
+import Tabs from '@theme/Tabs';
+import TabItem from '@theme/TabItem';
+
+Extensions are exactly as they sound - they "extend" the database with functionality which isn't part of the Postgres core.
+Supabase has pre-installed some of the most useful open source extensions.
+
+
+### Enable and disable extensions
+
+
+
+
+
+1. Go to the [Database](https://app.supabase.com/project/_/database/tables) page in the Dashboard.
+2. Click **Extensions** in the sidebar.
+3. Enable or disable an extension.
+
+
+
+
+
+
+
+```sql
+-- Example: enable the "pgtap" extension and ensure it is installed
+create extension pgtap with schema extensions;
+
+-- Example: disable the "pgtap" extension
+drop extension pgtap;
+```
+
+Even though the SQL code is `create extension`, this is the equivalent of "enabling the extension".
+To disable an extension call `drop extension`.
+
+:::caution
+Enabling some extensions with `create extension with schema extensions` may lead to permission issues (e.g., `dblink`, `http`, `pg_cron`).
+:::
+
+
+
+
+
+
+### Full list of extensions
+
+Supabase is pre-configured with over 50 extensions. You can also install your own SQL extensions directly in the database through our SQL editor.
+
+
diff --git a/apps/reference/docs/guides/database/extensions/http.mdx b/apps/reference/docs/guides/database/extensions/http.mdx
new file mode 100644
index 00000000000..3ae3da1b654
--- /dev/null
+++ b/apps/reference/docs/guides/database/extensions/http.mdx
@@ -0,0 +1,122 @@
+---
+id: http
+title: "http: RESTful Client"
+description: An HTTP Client for PostgreSQL Functions.
+---
+
+import Tabs from '@theme/Tabs';
+import TabItem from '@theme/TabItem';
+
+The `http` extension allows you to call RESTful endpoints within Postgres.
+
+## Quick demo
+
+
+
+## Overview
+
+Let's cover some basic concepts:
+
+- REST: stands for REpresentational State Transfer. It's simply a way to request data from external services.
+- RESTful APIs are servers which accept HTTP "calls". The calls are typically:
+ - `GET` − Read only access to a resource.
+ - `POST` − Creates a new resource.
+ - `DELETE` − Removes a resource.
+ - `PUT` − Updates an existing resource or creates a new resource.
+
+You can use the `http` extension to make these network requests from Postgres.
+
+## Usage
+
+
+### Enable the extension
+
+
+
+
+
+1. Go to the [Database](https://app.supabase.com/project/_/database/tables) page in the Dashboard.
+2. Click on **Extensions** in the sidebar.
+3. Search for "http" and enable the extension.
+
+
+
+
+```sql
+-- Example: enable the "http" extension
+create extension http with schema extensions;
+
+-- Example: disable the "http" extension
+drop extension if exists http;
+```
+
+Even though the SQL code is `create extension`, this is the equivalent of "enabling the extension".
+To disable an extension, call `drop extension`.
+
+It's good practice to create the extension within a separate schema (like `extensions`) to keep your database clean.
+
+
+
+
+
+### Available functions
+
+While the main usage is simply `http('http_request')`, there are 5 wrapper functions for specific functionality:
+
+- `http_get()`
+- `http_post()`
+- `http_put()`
+- `http_delete()`
+- `http_head()`
+
+### Returned values
+
+A successful call to a web URL from the `http` extension returns a record with the following fields:
+
+- `status`: integer
+- `content_type`: character varying
+- `headers`: http_header[]
+- `content`: character varying. Typically you would want to cast this to `jsonb` using the format `content::jsonb`
+
+## Examples
+
+### Simple `GET` example
+
+```sql
+select
+ "status", "content"::jsonb
+from
+ http_get('https://jsonplaceholder.typicode.com/todos/1');
+```
+
+
+### Simple `POST` example
+
+```sql
+select
+ "status", "content"::jsonb
+from
+ http_post(
+ 'https://jsonplaceholder.typicode.com/posts',
+ '{ "title": "foo", "body": "bar", "userId": 1 }',
+ 'application/json'
+ );
+```
+
+
+## Resources
+
+- Official [`http` GitHub Repository](https://github.com/pramsey/pgsql-http)
diff --git a/apps/reference/docs/guides/database/extensions/pgtap.mdx b/apps/reference/docs/guides/database/extensions/pgtap.mdx
new file mode 100644
index 00000000000..484a50f7afd
--- /dev/null
+++ b/apps/reference/docs/guides/database/extensions/pgtap.mdx
@@ -0,0 +1,126 @@
+---
+id: pgtap
+title: "pgTAP: Unit Testing"
+description: Unit testing in PostgreSQL.
+---
+
+import Tabs from '@theme/Tabs';
+import TabItem from '@theme/TabItem';
+
+`pgTAP` is a unit testing extension for PostgreSQL.
+
+## Overview
+
+Let's cover some basic concepts:
+
+- Unit tests: allow you to test small parts of a system (like a database table!).
+- TAP: stands for [Test Anything Protocol](http://testanything.org/). It is an framework which aims to simplify the error reporting during testing.
+
+## Usage
+
+### Enable the extension
+
+
+
+
+
+1. Go to the [Database](https://app.supabase.com/project/_/database/tables) page in the Dashboard.
+2. Click on **Extensions** in the sidebar.
+3. Search for "pgtap" and enable the extension.
+
+
+
+
+
+
+```sql
+-- Enable the "pgtap" extension
+create extension pgtap with schema extensions;
+
+-- Disable the "pgtap" extension
+drop extension if exists pgtap;
+```
+
+Even though the SQL code is `create extension`, this is the equivalent of "enabling the extension".
+To disable an extension you can call `drop extension`.
+
+It's good practice to create the extension within a separate schema (like `extensions`) to keep your database clean.
+
+
+
+
+
+### Managing tests
+
+It's a good practice to keep all your tests in a separate schema.
+
+```sql
+create schema tests;
+```
+
+### Creating a test
+
+
+@TODO
+
+- Create a plan
+- We should come up with a recommendation on how to run the tests. Via a function? External scripts?
+- Eventually this can be done via our CLI
+
+
+### Running a test
+
+@TODO
+
+
+## Examples
+
+Let's look at a few different tests which could be helpful in your project.
+
+
+### Testing tables
+
+
+```sql
+begin;
+select plan( 1 );
+
+select has_table( 'profiles' );
+
+select * from finish();
+rollback;
+```
+
+API:
+
+- [`has_table()`](https://pgtap.org/documentation.html#has_table)
+
+
+### Testing columns
+
+```sql
+begin;
+select plan( 1 );
+
+select has_column( 'profiles', 'id' );
+select col_is_pk( 'profiles', 'id' );
+
+select * from finish();
+rollback;
+```
+
+API:
+
+- [`has_column()`](https://pgtap.org/documentation.html#has_column)
+- [`col_is_pk()`](https://pgtap.org/documentation.html#col_is_pk)
+
+## Resources
+
+- Official [`pgTAP` documentation](https://pgtap.org/)
diff --git a/apps/reference/docs/guides/database/extensions/plv8.mdx b/apps/reference/docs/guides/database/extensions/plv8.mdx
new file mode 100644
index 00000000000..1eed5c92bac
--- /dev/null
+++ b/apps/reference/docs/guides/database/extensions/plv8.mdx
@@ -0,0 +1,146 @@
+---
+id: plv8
+title: "plv8: JavaScript Language"
+description: JavaScript language for PostgreSQL.
+---
+
+import Tabs from '@theme/Tabs';
+import TabItem from '@theme/TabItem';
+
+The `plv8` extension allows you use JavaScript within Postgres.
+
+## Overview
+
+While Postgres natively runs SQL, it can also run other "procedural languages".
+`plv8` allows you to run JavaScript code - specifically any code that runs on the [V8 JavaScript engine](https://v8.dev).
+
+It can be used for database functions, triggers, queries and more.
+
+## Usage
+
+### Enable the extension
+
+
+
+
+
+1. Go to the [Database](https://app.supabase.com/project/_/database/tables) page in the Dashboard.
+2. Click on **Extensions** in the sidebar.
+3. Search for "plv8" and enable the extension.
+
+
+
+
+```sql
+-- Example: enable the "plv8" extension
+create extension plv8;
+
+-- Example: disable the "plv8" extension
+drop extension if exists plv8;
+```
+
+Even though the SQL code is `create extension`, this is the equivalent of "enabling the extension".
+To disable an extension, call `drop extension`.
+
+Procedural languages are automatically installed within `pg_catalog`, so you don't need to specify a schema.
+
+
+
+
+### Create `plv8` functions
+
+Functions written in `plv8` are written just like any other PostgreSQL functions, only
+with the `language` identifier set to `plv8`.
+
+```sql
+create or replace function function_name()
+returns void as $$
+ // V8 JavaScript
+ // code
+ // here
+$$ language plv8;
+```
+
+You can call `plv8` functions like any other Postgres function:
+
+
+
+
+
+```sql
+select function_name();
+```
+
+
+
+
+```js
+const { data, error } = supabase.rpc('function_name')
+```
+
+
+
+
+## Examples
+
+### Scalar functions
+
+A [scalar function](https://plv8.github.io/#scalar-function-calls) is anything that takes in some user input and returns a single result.
+
+```sql
+create or replace function hello_world(name text)
+returns text as $$
+
+ let output = `Hello, ${name}!`;
+ return output;
+
+$$ language plv8;
+```
+
+### Executing SQL
+
+You can execute SQL within `plv8` code using the [`plv8.execute` function](https://plv8.github.io/#plv8-execute).
+
+```sql
+create or replace function update_user(id bigint, first_name text)
+returns smallint as $$
+
+ var num_affected = plv8.execute(
+ 'update profiles set first_name = $1 where id = $2',
+ [first_name, id]
+ );
+
+ return num_affected;
+$$ language plv8;
+```
+
+### Set-returning functions
+
+A [set-returning function](https://plv8.github.io/#set-returning-function-calls) is anything that returns a full set of results - for example, rows in a table.
+
+```sql
+create or replace function get_messages()
+returns setof messages as $$
+
+ var json_result = plv8.execute(
+ 'select * from messages'
+ );
+
+ return json_result;
+$$ language plv8;
+```
+
+## Resources
+
+- Official [`plv8` documentation](https://plv8.github.io/)
+- [plv8 GitHub Repository](https://github.com/plv8/plv8)
diff --git a/apps/reference/docs/guides/database/extensions/uuid-ossp.mdx b/apps/reference/docs/guides/database/extensions/uuid-ossp.mdx
new file mode 100644
index 00000000000..0fdb296c6b7
--- /dev/null
+++ b/apps/reference/docs/guides/database/extensions/uuid-ossp.mdx
@@ -0,0 +1,98 @@
+---
+id: uuid-ossp
+title: "uuid-ossp: Unique Identifiers"
+description: A UUID generator for PostgreSQL.
+---
+
+import Tabs from '@theme/Tabs';
+import TabItem from '@theme/TabItem';
+
+The `uuid-ossp` extension can be used to generate a `UUID`.
+
+
+## Overview
+
+A `UUID` is a "Universally Unique Identifer" and it is, for practical purposes, unique.
+This makes them particularly well suited as Primary Keys. It is occasionally referred to as a `GUID`, which stands for "Globally Unique Identifer".
+
+## Usage
+
+### Enable the extension
+
+
+
+
+
+1. Go to the [Database](https://app.supabase.com/project/_/database/tables) page in the Dashboard.
+2. Click on **Extensions** in the sidebar.
+3. Search for "uuid-ossp" and enable the extension.
+
+**Note**:
+Currently `uuid-ossp` extension is enabled by default and cannot be disabled.
+
+
+
+
+```sql
+-- Example: enable the "uuid-ossp" extension
+create extension "uuid-ossp" with schema extensions;
+
+-- Example: disable the "uuid-ossp" extension
+drop extension if exists "uuid-ossp";
+```
+
+Even though the SQL code is `create extension`, this is the equivalent of "enabling the extension".
+To disable an extension, call `drop extension`.
+
+It's good practice to create the extension within a separate schema (like `extensions`) to keep your database clean.
+
+**Note**:
+Currently `uuid-ossp` extension is enabled by default and cannot be disabled.
+
+
+
+
+
+### The `uuid` type
+
+Once the extension is enabled, you now have access to a `uuid` type.
+
+### `uuid_generate_v1()`
+
+Creates a UUID value based on the combination of computer’s MAC address, current timestamp, and a random value.
+
+### `uuid_generate_v4()`
+
+Creates UUID values based solely on random numbers.
+
+## Examples
+
+### Within a query
+
+```sql
+select uuid_generate_v4();
+```
+
+### As a Primary Key
+
+Automatically create a unique, random ID in a table:
+
+```sql
+create table contacts (
+ id uuid default uuid_generate_v4(),
+ first_name text,
+ last_name text,
+
+ primary key (id)
+);
+```
+
+
+## Resources
+
+- [The Basics Of PostgreSQL `UUID` Data Type](https://www.postgresqltutorial.com/postgresql-uuid/)
diff --git a/apps/reference/docs/guides/database/full-text-search.mdx b/apps/reference/docs/guides/database/full-text-search.mdx
new file mode 100644
index 00000000000..53698afc5d3
--- /dev/null
+++ b/apps/reference/docs/guides/database/full-text-search.mdx
@@ -0,0 +1,630 @@
+---
+id: full-text-search
+title: "Full Text Search"
+description: How to use full text search in PostgreSQL.
+---
+
+import Tabs from '@theme/Tabs';
+import TabItem from '@theme/TabItem';
+
+
+Postgres has built-in functions to handle `Full Text Search` queries. This is like a "search engine" within Postgres.
+
+
+## Preparation
+
+For this guide we'll use the following example data:
+
+
+
+
+
+
+```sql
+create table books (
+ id serial primary key,
+ title text,
+ author text,
+ description text
+);
+
+insert into books (title, author, description)
+values
+ ('The Poky Little Puppy','Janette Sebring Lowrey','Puppy is slower than other, bigger animals.'),
+ ('The Tale of Peter Rabbit','Beatrix Potter','Rabbit eats some vegetables.'),
+ ('Tootle','Gertrude Crampton','Little toy train has big dreams.'),
+ ('Green Eggs and Ham','Dr. Seuss','Sam has changing food preferences and eats unusually colored food.'),
+ ('Harry Potter and the Goblet of Fire','J.K. Rowling','Fourth year of school starts, big drama ensues.');
+```
+
+
+
+
+| id | title | author | description |
+| ---- | ---- | ---- | ----------- |
+| 1 | The Poky Little Puppy | Janette Sebring Lowrey | Puppy is slower than other, bigger animals. |
+| 2 | The Tale of Peter Rabbit | Beatrix Potter | Rabbit eats some vegetables. |
+| 3 | Tootle | Gertrude Crampton | Little toy train has big dreams. |
+| 4 | Green Eggs and Ham | Dr. Seuss | Sam has changing food preferences and eats unusually colored food. |
+| 5 | Harry Potter and the Goblet of Fire | J.K. Rowling | Fourth year of school starts, big drama ensues. |
+
+
+
+
+
+## Usage
+
+The functions we'll cover in this guide are:
+
+### `to_tsvector()`
+
+Converts your data into searchable "tokens". `to_tsvector()` stands for "to text search vector". For example:
+
+```sql
+select to_tsvector('green eggs and ham')
+
+-- Returns 'egg':2 'green':1 'ham':4
+```
+
+Collectively these tokens are called a "document" which Postgres can use for comparisons.
+
+### `to_tsquery()`
+
+Converts a query string into "tokens" to match. `to_tsquery()` stands for "to text search query".
+
+This conversion step is important because we will want to "fuzzy match" on keywords.
+For example if a user searches for "eggs", and a column has the value "egg", we probably still want to return a match.
+
+
+### Match: `@@`
+
+The `@@` symbol is the "match" symbol for Full Text Search. It returns any matches between a `to_tsvector` result and a `to_tsquery` result.
+
+Take the following example:
+
+
+
+
+```sql
+select *
+from books
+where title = 'Harry';
+```
+
+
+
+
+```js
+const { data, error } = await supabase
+ .from('books')
+ .select()
+ .eq('title', 'Harry')
+```
+
+
+
+
+
+```dart
+final result = await client
+ .from('books')
+ .select()
+ .eq('title', 'Harry')
+ .execute();
+```
+
+
+
+
+
+The equality symbol above (`=`) is very "strict" on what it matches. In a full text search context, we might want to find all "Harry Potter" books and so we can rewrite the
+example above:
+
+
+
+
+```sql
+select *
+from books
+where to_tsvector(title) @@ to_tsquery('Harry');
+```
+
+
+
+
+```js
+const { data, error } = await supabase
+ .from('books')
+ .select()
+ .textSearch('title', `'Harry'`)
+```
+
+
+
+
+```dart
+final result = await client
+ .from('books')
+ .select()
+ .textSearch('title', "'Harry'")
+ .execute();
+```
+
+
+
+
+## Basic Full Text Queries
+
+### Search a single column
+
+To find all `books` where the `description` contain the word `big`:
+
+
+
+
+```sql
+select
+ *
+from
+ books
+where
+ to_tsvector(description)
+ @@ to_tsquery('big');
+```
+
+
+
+
+```js
+const { data, error } = await supabase
+ .from('books')
+ .select()
+ .textSearch('description', `'big'`)
+```
+
+
+
+
+```dart
+final result = await client
+ .from('books')
+ .select()
+ .textSearch('description', "'big'")
+ .execute();
+```
+
+
+
+
+| id | title | author | description |
+| -- | ----------------------------------- | ----------------- | ----------------------------------------------- |
+| 3 | Tootle | Gertrude Crampton | Little toy train has big dreams. |
+| 5 | Harry Potter and the Goblet of Fire | J.K. Rowling | Fourth year of school starts, big drama ensues. |
+
+
+
+
+### Search multiple columns
+
+To find all `books` where `description` or `title` contain the word `little`:
+
+
+
+
+```sql
+select
+ *
+from
+ books
+where
+ to_tsvector(description || ' ' || title) -- concat columns, but be sure to include a space to separate them!
+ @@ to_tsquery('little');
+```
+
+
+
+
+| id | title | author | description |
+| -- | --------------------- | ---------------------- | ------------------------------------------- |
+| 1 | The Poky Little Puppy | Janette Sebring Lowrey | Puppy is slower than other, bigger animals. |
+| 3 | Tootle | Gertrude Crampton | Little toy train has big dreams. |
+
+
+
+
+### Match all search words
+
+To find all `books` where `description` contains BOTH of the words `little` and `big`, we can use the `&` symbol:
+
+
+
+
+```sql
+select
+ *
+from
+ books
+where
+ to_tsvector(description)
+ @@ to_tsquery('little & big'); -- use & for AND in the search query
+```
+
+
+
+
+```js
+const { data, error } = await supabase
+ .from('books')
+ .select()
+ .textSearch('description', `'little' & 'big'`)
+```
+
+
+
+
+```dart
+final result = await client
+ .from('books')
+ .select()
+ .textSearch('description', "'little' & 'big'")
+ .execute();
+```
+
+
+
+
+| id | title | author | description |
+| -- | ------ | ----------------- | -------------------------------- |
+| 3 | Tootle | Gertrude Crampton | Little toy train has big dreams. |
+
+
+
+
+### Match any search words
+
+To find all `books` where `description` contain ANY of the words `little` or `big`, use the `|` symbol:
+
+
+
+
+```sql
+select
+ *
+from
+ books
+where
+ to_tsvector(description)
+ @@ to_tsquery('little | big'); -- use | for OR in the search query
+```
+
+
+
+
+```js
+const { data, error } = await supabase
+ .from('books')
+ .select()
+ .textSearch('description', `'little' | 'big'`)
+```
+
+
+
+
+```dart
+final result = await client
+ .from('books')
+ .select()
+ .textSearch('description', "'little' | 'big'")
+ .execute();
+```
+
+
+
+
+| id | title | author | description |
+| -- | --------------------- | ---------------------- | ------------------------------------------- |
+| 1 | The Poky Little Puppy | Janette Sebring Lowrey | Puppy is slower than other, bigger animals. |
+| 3 | Tootle | Gertrude Crampton | Little toy train has big dreams. |
+
+
+
+
+Notice how searching for `big` includes results with the word `bigger` (or `biggest`, etc).
+
+## Creating Indexes
+
+Now that we have Full Text Search working, let's create an `index`. This will allow Postgres to "build" the documents pre-emptively so that they
+don't need to be created at the time we execute the query. This will make our queries much faster.
+
+### Searchable columns
+
+Let's create a new column `fts` inside the `books` table to store the searchable index of the `title` and `description` columns.
+
+We can use a special feature of Postgres called
+[Generated Columns](https://www.postgresql.org/docs/current/ddl-generated-columns.html)
+to ensure that the index is updated any time the values in the `title` and `description` columns change.
+
+
+
+
+```sql
+alter table
+ books
+add column
+ fts tsvector generated always as (to_tsvector('english', description || ' ' || title)) stored;
+
+create index books_fts on books using gin (fts); -- generate the index
+
+select id, fts
+from books;
+```
+
+
+
+
+| id | fts |
+| -- | --------------------------------------------------------------------------------------------------------------- |
+| 1 | 'anim':7 'bigger':6 'littl':10 'poki':9 'puppi':1,11 'slower':3 |
+| 2 | 'eat':2 'peter':8 'rabbit':1,9 'tale':6 'veget':4 |
+| 3 | 'big':5 'dream':6 'littl':1 'tootl':7 'toy':2 'train':3 |
+| 4 | 'chang':3 'color':9 'eat':7 'egg':12 'food':4,10 'green':11 'ham':14 'prefer':5 'sam':1 'unus':8 |
+| 5 | 'big':6 'drama':7 'ensu':8 'fire':15 'fourth':1 'goblet':13 'harri':9 'potter':10 'school':4 'start':5 'year':2 |
+
+
+
+
+### Search using the new column
+
+Now that we've created and populated our index, we can search it using the same techniques as before:
+
+
+
+
+```sql
+select
+ *
+from
+ books
+where
+ fts @@ to_tsquery('little & big');
+```
+
+
+
+
+```js
+const { data, error } = await supabase
+ .from('books')
+ .select()
+ .textSearch('fts', `'little' & 'big'`)
+```
+
+
+
+
+```dart
+final result = await client
+ .from('books')
+ .select()
+ .textSearch('fts', "'little' & 'big'")
+ .execute();
+```
+
+
+
+
+| id | title | author | description | fts |
+| -- | ------ | ----------------- | -------------------------------- | ------------------------------------------------------- |
+| 3 | Tootle | Gertrude Crampton | Little toy train has big dreams. | 'big':5 'dream':6 'littl':1 'tootl':7 'toy':2 'train':3 |
+
+
+
+
+## Query Operators
+
+Visit [PostgreSQL: Text Search Functions and Operators](https://www.postgresql.org/docs/current/functions-textsearch.html)
+to learn about additional query operators you can use to do more advanced `full text queries`, such as:
+
+### Proximity: `<->`
+
+The proximity symbol is useful for searching for terms that are a certain "distance" apart.
+For example, to find the phrase `big dreams`, where the a match for "big" is followed immediately by a match for "dreams":
+
+
+
+
+
+```sql
+select
+ *
+from
+ books
+where
+ to_tsvector(description) @@ to_tsquery('big <-> dreams');
+```
+
+
+
+
+```js
+const { data, error } = await supabase
+ .from('books')
+ .select()
+ .textSearch('description', `'big' <-> 'dreams'`)
+```
+
+
+
+
+```dart
+final result = await client
+ .from('books')
+ .select()
+ .textSearch('description', "'big' <-> 'dreams'")
+ .execute();
+```
+
+
+
+
+
+We can also use the `<->` to find words within a certain distance of eachother. For example to find `year` and `school` within 2 words of each other:
+
+
+
+
+```sql
+select
+ *
+from
+ books
+where
+ to_tsvector(description) @@ to_tsquery('year <2> school');
+```
+
+
+
+
+```js
+const { data, error } = await supabase
+ .from('books')
+ .select()
+ .textSearch('description', `'year' <2> 'school'`)
+```
+
+
+
+
+```dart
+final result = await client
+ .from('books')
+ .select()
+ .textSearch('description', "'year' <2> 'school'")
+ .execute();
+```
+
+
+
+
+
+### Negation: `!`
+
+The negation symbol can be used to find phrases which _don't_ contain a search term.
+For example, to find records that have the word `big` but not `little`:
+
+
+
+
+```sql
+select
+ *
+from
+ books
+where
+ to_tsvector(description) @@ to_tsquery('big & !little');
+```
+
+
+
+
+```js
+const { data, error } = await supabase
+ .from('books')
+ .select()
+ .textSearch('description', `'big' & !'little'`)
+```
+
+
+
+
+```dart
+final result = await client
+ .from('books')
+ .select()
+ .textSearch('description', "'big' & !'little'")
+ .execute();
+```
+
+
+
+
+
+## Resources
+
+* [PostgreSQL: Text Search Functions and Operators](https://www.postgresql.org/docs/12/functions-textsearch.html)
+
+
+
diff --git a/apps/reference/docs/guides/database/functions.mdx b/apps/reference/docs/guides/database/functions.mdx
new file mode 100644
index 00000000000..507643e7a31
--- /dev/null
+++ b/apps/reference/docs/guides/database/functions.mdx
@@ -0,0 +1,362 @@
+---
+id: functions
+title: Database Functions
+description: Creating and using Postgres functions.
+---
+
+import Tabs from '@theme/Tabs';
+import TabItem from '@theme/TabItem';
+
+
+Postgres has built-in support for [SQL functions](https://www.postgresql.org/docs/current/sql-createfunction.html).
+These functions live inside your database, and they can be [used with the API](/docs/reference/javascript/rpc).
+
+## Quick demo
+
+
+
+## Getting started
+
+Supabase provides several options for creating database functions. You can use the Dashboard or create them directly using SQL.
+We provide a SQL editor within the Dashboard, or you can [connect](/docs/guides/database/connecting/connecting-to-postgres) to your database
+and run the SQL queries yourself.
+
+
+1. Go to the "SQL editor" section.
+2. Click "New Query".
+3. Enter the SQL to create or replace your Database function.
+4. Click "Run" or cmd+enter (ctrl+enter).
+
+
+## Simple Functions
+
+Let's create a basic Database Function which returns a string "hello world".
+
+```sql
+create or replace function hello_world() -- 1
+returns text -- 2
+language sql -- 3
+as $$ -- 4
+ select 'hello world'; -- 5
+$$; --6
+
+```
+
+
+Show/Hide Details
+
+At it's most basic a function has the following parts:
+
+1. `create or replace function hello_world()`: The function declaration, where `hello_world` is the name of the function. You can use either `create` when creating a new function or `replace` when replacing an existing function. Or you can use `create or replace` together to handle either.
+2. `returns text`: The type of data that the function returns. If it returns nothing, you can `returns void`.
+3. `language sql`: The language used inside the function body. This can also be a procedural language: `plpgsql`, `plv8`, `plpython`, etc.
+4. `as $$`: The function wrapper. Anything enclosed inside the `$$` symbols will be part of the function body.
+5. `select 'hello world';`: A simple function body. The final `select` statement inside a function body will be returned if there are no statements following it.
+6. `$$;`: The closing symbols of the function wrapper.
+
+
+
+
+
+After the Function is created, we have several ways of "executing" the function - either directly inside the database using SQL, or with one of the client libraries.
+
+
+
+
+
+```sql
+select hello_world();
+```
+
+
+
+
+```js
+const { data, error } = await supabase
+ .rpc('hello_world')
+```
+
+Reference: [rpc()](/docs/reference/javascript/rpc)
+
+
+
+
+```dart
+final res = await supabase
+ .rpc('hello_world')
+ .execute();
+```
+
+Reference: [rpc()](/docs/reference/dart/rpc)
+
+
+
+
+
+
+## Returning data sets
+
+Database Functions can also return data sets from [Tables](/docs/guides/database/tables) or Views.
+
+For example, if we had a database with some Star Wars data inside:
+
+
+
+
+
+```sql
+create table planets (
+ id serial primary key,
+ name text
+);
+
+insert into planets (id, name)
+values
+ (1, 'Tattoine'),
+ (2, 'Alderaan'),
+ (3, 'Kashyyyk');
+
+create table people (
+ id serial primary key,
+ name text,
+ planet_id bigint references planets
+);
+
+insert into people (id, name, planet_id)
+values
+ (1, 'Anakin Skywalker', 1),
+ (2, 'Luke Skywalker', 1),
+ (3, 'Princess Leia', 2),
+ (4, 'Chewbacca', 3);
+```
+
+
+
+
+
+
+| id | name | planet_id |
+| ---- | ---- | ---- |
+| 1 | Anakin Skywalker | 1 |
+| 2 | Luke Skywalker | 1 |
+| 3 | Princess Leia | 2 |
+| 4 | Chewbacca | 3 |
+
+
+
+
+
+
+We could create a function which returns all the planets:
+
+```sql
+create or replace function get_planets()
+returns setof planets
+language sql
+as $$
+ select * from planets;
+$$;
+```
+
+Because this function returns a table set, we can also apply filters and selectors. For example, if we only wanted the first planet:
+
+
+
+
+
+```sql
+select *
+from get_planets()
+where id = 1;
+```
+
+
+
+
+```js
+const { data, error } = supabase
+ .rpc('get_planets')
+ .eq('id', 1)
+```
+
+
+
+
+```dart
+final res = await supabase
+ .rpc('get_planets')
+ .eq('id', 1)
+ .execute();
+```
+
+
+
+
+
+
+## Passing parameters
+
+Let's create a Function to insert a new planet into the `planets` table and return the new ID. Note that this time we're using the `plpgsql` language.
+
+```sql
+create or replace function add_planet(name text)
+returns bigint
+language plpgsql
+as $$
+declare
+ new_row bigint;
+begin
+ insert into planets(name)
+ values (add_planet.name)
+ returning id into new_row;
+
+ return new_row;
+end;
+$$;
+```
+
+Once again, you can execute this function either inside your database using a `select` query, or with the client libraries:
+
+
+
+
+
+```sql
+select * from add_planet('Jakku');
+```
+
+
+
+
+```js
+const { data, error } = await supabase
+ .rpc('add_planet', { name: 'Jakku' })
+```
+
+
+
+
+
+```dart
+final res = await supabase
+ .rpc('add_planet', params: { 'name': 'Jakku' })
+ .execute();
+```
+
+
+
+
+
+
+## Suggestions
+
+### Database Functions vs Edge Functions
+
+For data-intensive operations we recommend using [Database Functions](/docs/guides/database/functions), which are executed within your database
+and can be called remotely using the [REST and GraphQL API](/docs/guides/database/api).
+
+For use-cases which require low-latency we recommend [Edge Functions](/docs/guides/functions), which are globally-distributed and can be written in Typescript.
+
+### Security `definer` vs `invoker`
+
+Postgres allows you to specify whether you want the function to be executed as the user _calling_ the function (`invoker`), or as the _creator_ of the function (`definer`). For example:
+
+```sql
+create function hello_world()
+returns text
+language plpgsql
+security definer set search_path = public
+as $$
+begin
+ select 'hello world';
+end;
+$$;
+```
+
+It is best practice to use `security invoker` (which is also the default). If you ever use `security definer`, you _must_ set the `search_path`.
+This limits the potential damage if you allow access to schemas which the user executing the function should not have.
+
+## Resources
+
+
+- Official Client libraries: [JavaScript](/docs/reference/javascript/rpc) and [Dart](/docs/reference/dart/rpc)
+- Community client libraries: [github.com/supabase-community](https://github.com/supabase-community)
+- PostgreSQL Official Docs: [Chapter 9. Functions and Operators](https://www.postgresql.org/docs/current/functions.html)
+- PostgreSQL Reference: [CREATE FUNCTION](https://www.postgresql.org/docs/9.1/sql-createfunction.html)
+
+## Deep Dive
+
+### Create Database Functions
+
+
+
+### Call Database Functions using JavaScript
+
+
+
+### Using Database Functions to call an external API
+
+
diff --git a/apps/reference/docs/guides/database/json.mdx b/apps/reference/docs/guides/database/json.mdx
new file mode 100644
index 00000000000..0af74c68906
--- /dev/null
+++ b/apps/reference/docs/guides/database/json.mdx
@@ -0,0 +1,278 @@
+---
+id: json
+title: 'JSON'
+description: Using the JSON data type in PostgreSQL.
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+PostgreSQL supports [JSON functions and operators](https://www.postgresql.org/docs/current/functions-json.html) which gives flexibility when storing data inside a database column.
+
+PostgreSQL supports two types of JSON columns: `JSON` and `JSONB`.
+The recommended type is `JSONB` for almost all cases.
+When you use the `JSONB` format, the data is parsed when it's put into the database so it's faster when querying and also it can be indexed.
+
+## Create a table with a JSON column
+
+
+
+
+
+1. Go to the [Table Editor](https://app.supabase.com/project/_/editor) page in the Dashboard.
+2. Click **New Table** and create a table called `books`.
+3. Include a primary key with the following properties:
+ - Name: `id`
+ - Type: `int8`
+ - Default value: `Automatically generate as indentity`
+4. Click **Save**.
+5. Click **New Column** and add 3 columns with the following properties:
+ - **title** column
+ - Name: `title`
+ - Type: `text`
+ - **author** column
+ - Name: `author`
+ - Type: `text`
+ - **metadata** column
+ - Name: `metadata`
+ - Type: `jsonb`
+
+
+
+
+
+```sql
+create table books (
+ id serial primary key,
+ title text,
+ author text,
+ metadata jsonb
+);
+```
+
+
+
+
+## Insert data into the table
+
+
+
+
+
+1. Go to the [Table Editor](https://app.supabase.com/project/_/editor) page in the Dashboard.
+2. Select the `books` table in the sidebar.
+3. Click **+ Insert row** and add 5 rows with the following properties:
+
+| id | title | author | metadata |
+| --- | ----------------------------------- | ---------------------- | -------------------------------------------------------------------------------------------------------------- |
+| 1 | The Poky Little Puppy | Janette Sebring Lowrey | {"ages":[3,6],"price":5.95,"description":"Puppy is slower than other, bigger animals."} |
+| 2 | The Tale of Peter Rabbit | Beatrix Potter | {"ages":[2,5],"price":4.49,"description":"Rabbit eats some vegetables."} |
+| 3 | Tootle | Gertrude Crampton | {"ages":[2,5],"price":3.99,"description":"Little toy train has big dreams."} |
+| 4 | Green Eggs and Ham | Dr. Seuss | {"ages":[4,8],"price":7.49,"description":"Sam has changing food preferences and eats unusually colored food."} |
+| 5 | Harry Potter and the Goblet of Fire | J.K. Rowling | {"ages":[10,99],"price":24.95,"description":"Fourth year of school starts, big drama ensues."} |
+
+
+
+
+
+```sql
+insert into books
+ (title, author, metadata)
+values
+ (
+ 'The Poky Little Puppy',
+ 'Janette Sebring Lowrey',
+ '{"description":"Puppy is slower than other, bigger animals.","price":5.95,"ages":[3,6]}'
+ ),
+ (
+ 'The Tale of Peter Rabbit',
+ 'Beatrix Potter',
+ '{"description":"Rabbit eats some vegetables.","price":4.49,"ages":[2,5]}'
+ ),
+ (
+ 'Tootle',
+ 'Gertrude Crampton',
+ '{"description":"Little toy train has big dreams.","price":3.99,"ages":[2,5]}'
+ ),
+ (
+ 'Green Eggs and Ham',
+ 'Dr. Seuss',
+ '{"description":"Sam has changing food preferences and eats unusually colored food.","price":7.49,"ages":[4,8]}'
+ ),
+ (
+ 'Harry Potter and the Goblet of Fire',
+ 'J.K. Rowling',
+ '{"description":"Fourth year of school starts, big drama ensues.","price":24.95,"ages":[10,99]}'
+ );
+```
+
+
+
+
+
+```js
+const { data, error } = await supabase.from('books').insert([
+ {
+ title: 'The Poky Little Puppy',
+ author: 'Janette Sebring Lowrey',
+ metadata: {
+ description: 'Puppy is slower than other, bigger animals.',
+ price: 5.95,
+ ages: [3, 6],
+ },
+ },
+ {
+ title: 'The Tale of Peter Rabbit',
+ author: 'Beatrix Potter',
+ metadata: { description: 'Rabbit eats some vegetables.', price: 4.49, ages: [2, 5] },
+ },
+ {
+ title: 'Tootle',
+ author: 'Gertrude Crampton',
+ metadata: { description: 'Little toy train has big dreams.', price: 3.99, ages: [2, 5] },
+ },
+ {
+ title: 'Green Eggs and Ham',
+ author: 'Dr. Seuss',
+ metadata: {
+ description: 'Sam has changing food preferences and eats unusually colored food.',
+ price: 7.49,
+ ages: [4, 8],
+ },
+ },
+ {
+ title: 'Harry Potter and the Goblet of Fire',
+ author: 'J.K. Rowling',
+ metadata: {
+ description: 'Fourth year of school starts, big drama ensues.',
+ price: 24.95,
+ ages: [10, 99],
+ },
+ },
+])
+```
+
+
+
+
+## View the data
+
+
+
+
+
+```sql
+select *
+from books;
+```
+
+
+
+
+
+```js
+const { data, error } = await supabase.from('books').select('*')
+console.log(JSON.stringify(data, null, 2))
+```
+
+
+
+
+
+| id | title | author | metadata |
+| --- | ----------------------------------- | ---------------------- | -------------------------------------------------------------------------------------------------------------- |
+| 1 | The Poky Little Puppy | Janette Sebring Lowrey | {"ages":[3,6],"price":5.95,"description":"Puppy is slower than other, bigger animals."} |
+| 2 | The Tale of Peter Rabbit | Beatrix Potter | {"ages":[2,5],"price":4.49,"description":"Rabbit eats some vegetables."} |
+| 3 | Tootle | Gertrude Crampton | {"ages":[2,5],"price":3.99,"description":"Little toy train has big dreams."} |
+| 4 | Green Eggs and Ham | Dr. Seuss | {"ages":[4,8],"price":7.49,"description":"Sam has changing food preferences and eats unusually colored food."} |
+| 5 | Harry Potter and the Goblet of Fire | J.K. Rowling | {"ages":[10,99],"price":24.95,"description":"Fourth year of school starts, big drama ensues."} |
+
+The data as it appears here has the `JSONB` fields in a different order than when inserted. As mentioned earlier, data is parsed as its inserted when using the JSONB format.
+
+
+
+
+## Query the `JSONB` data
+
+Select the title, description, price, and age range for each book.
+
+
+
+
+
+```sql
+select
+ title,
+ metadata -> 'description' AS description,
+ metadata -> 'price' as price,
+ metadata -> 'ages' -> 0 as low_age,
+ metadata -> 'ages' -> 1 as high_age
+from
+ books;
+```
+
+
+
+
+
+```js
+const { data, error } = await supabase
+ .from('books')
+ .select(
+ 'title,description:metadata->description,price:metadata->price,low_age:metadata->ages->0,high_age:metadata->ages->1'
+ )
+console.log(JSON.stringify(data, null, 2))
+```
+
+
+
+
+
+| title | description | price | low_age | high_age |
+| ----------------------------------- | ------------------------------------------------------------------ | ----- | ------- | -------- |
+| The Poky Little Puppy | Puppy is slower than other, bigger animals. | 5.95 | 3 | 6 |
+| The Tale of Peter Rabbit | Rabbit eats some vegetables. | 4.49 | 2 | 5 |
+| Tootle | Little toy train has big dreams. | 3.99 | 2 | 5 |
+| Green Eggs and Ham | Sam has changing food preferences and eats unusually colored food. | 7.49 | 4 | 8 |
+| Harry Potter and the Goblet of Fire | Fourth year of school starts, big drama ensues. | 24.95 | 10 | 99 |
+
+
+
+
+Note that the `->` operator returns JSONB data. If you want TEXT/STRING data returned, use the `->>` operator.
+
+- metadata -> 'description' (returns a JSON object)
+- metadata ->> 'description' (returns STRING/TEXT data)
+
+## Resources
+
+- [Supabase JS Client](https://github.com/supabase/supabase-js)
+- [PostgreSQL: JSON Functions and Operators](https://www.postgresql.org/docs/12/functions-json.html)
+- [PostgreSQL JSON types](https://www.postgresql.org/docs/12/datatype-json.html)
diff --git a/apps/reference/docs/guides/database/managing-passwords.mdx b/apps/reference/docs/guides/database/managing-passwords.mdx
new file mode 100644
index 00000000000..2d878632b43
--- /dev/null
+++ b/apps/reference/docs/guides/database/managing-passwords.mdx
@@ -0,0 +1,32 @@
+---
+id: managing-passwords
+title: "Passwords"
+description: How to change your PostgreSQL database password.
+---
+
+import Tabs from '@theme/Tabs';
+import TabItem from '@theme/TabItem';
+
+Your PostgreSQL database is the core of your Supabase project, so it's important that it has a strong, secure password at all times.
+
+If you use special symbols in your postgres password, you must remember to [percent-encode](https://en.wikipedia.org/wiki/Percent-encoding) your password later if using the postgres connection string e.g. `postgresql://postgres:p%3Dword@db.cvwawazfelidkloqmbma.supabase.co:5432/postgres`
+
+
+### Changing your project password
+
+When you created your project you were also asked to enter a password. This is actually the password for your database, specifically for the `postgres` user.
+You can update this from the Dashboard under the [database settings](https://app.supabase.com/project/_/settings/database) page.
+
+## Creating a secure password
+
+It's absolutely critical that you store your customers' data safely. Here are some tips for creating a secure password.
+
+- Use a password manager to generate it.
+- Make a long password (12 characters at least).
+- Don't use any common dictionary words.
+- Use both upper and lower case characters, numbers, and special symbols.
+
+## Resources
+
+- [PostgreSQL `ALTER USER` Documentation](https://www.postgresql.org/docs/12/sql-alteruser.html)
+
diff --git a/apps/reference/docs/guides/database/managing-timezones.mdx b/apps/reference/docs/guides/database/managing-timezones.mdx
new file mode 100644
index 00000000000..6092dd779b0
--- /dev/null
+++ b/apps/reference/docs/guides/database/managing-timezones.mdx
@@ -0,0 +1,85 @@
+---
+id: managing-timezones
+title: "Timezones"
+slug: managing-timezones
+description: How to change your database timezone.
+---
+
+import Tabs from '@theme/Tabs';
+import TabItem from '@theme/TabItem';
+
+
+Every Supabase database is set to UTC timezone by default. We strongly recommend keeping it this way, even if your users are in a different location.
+This is because it makes it much easier to calculate differences between timezones if you adopt the mental model that "everything in my database is in UTC time".
+
+
+### Change timezone
+
+
+
+
+
+
+
+```sql
+alter database postgres
+set timezone to 'America/New_York';
+```
+
+
+
+
+
+
+### Full list of timezones
+
+Get a full list of timezones supported by your database. This will return the following columns:
+
+- `name`: Time zone name
+- `abbrev`: Time zone abbreviation
+- `utc_offset`: Offset from UTC (positive means east of Greenwich)
+- `is_dst`: True if currently observing daylight savings
+
+
+
+
+
+
+```sql
+select name, abbrev, utc_offset, is_dst
+from pg_timezone_names()
+order by name;
+```
+
+
+
+
+
+
+### Search for a specific timezone
+
+Use `ilike` (case insensitive search) to find specific timezones.
+
+
+
+
+
+```sql
+select *
+from pg_timezone_names()
+where name ilike '%york%';
+```
+
+
+
+
+
\ No newline at end of file
diff --git a/apps/reference/docs/guides/database/replication.mdx b/apps/reference/docs/guides/database/replication.mdx
new file mode 100644
index 00000000000..1ed979fa4a2
--- /dev/null
+++ b/apps/reference/docs/guides/database/replication.mdx
@@ -0,0 +1,94 @@
+---
+id: replication
+title: "Replication"
+slug: replication
+---
+
+import Tabs from '@theme/Tabs';
+import TabItem from '@theme/TabItem';
+
+
+Replication is a technique for copying the data from one database to another. Supabase uses replication functionality to provide a real-time API. Replication is useful for:
+
+- Spreading out the "load." For example, if your database has a lot of reads, you might want to split it between two databases.
+- Reducing latency. For example, you may want one database in London to serve your European customers, and one in New York to serve the US.
+
+Replication is done through _publications_, a method of choosing which changes to send to other systems (usually another Postgres database). Publications can be managed in the [Dashboard](https://app.supabase.com) or with SQL.
+
+## Manage publications in the Dashboard
+
+1. Go to the [Database](https://app.supabase.com/project/_/database/tables) page in the Dashboard.
+2. Click on **Replication** in the sidebar.
+3. Control which database events are sent by toggling **Insert**, **Update**, and **Delete**.
+4. Control which tables broadcast changes by selecting **Source** and toggling each table.
+
+
+
+## Create a publication
+
+This publication contains changes to all tables.
+
+```sql
+create publication publication_name
+for all tables;
+```
+
+## Create a publication to listen to individual tables
+
+```sql
+create publication publication_name
+for table table_one, table_two;
+```
+
+## Add tables to an existing publication
+
+```sql
+alter publication publication_name
+add table table_name;
+```
+
+## Listen to `insert`
+
+```sql
+create publication publication_name
+for all tables
+with (publish = 'insert');
+```
+
+## Listen to `update`
+
+```sql
+create publication publication_name
+for all tables
+with (publish = 'update');
+```
+
+## Listen to `delete`
+
+```sql
+create publication publication_name
+for all tables
+with (publish = 'delete');
+```
+
+## Remove a publication
+
+```sql
+drop publication if exists publication_name;
+```
+
+## Recreate a publication
+
+If you're recreating a publication, it's best to do it in a transaction to ensure the operation succeeds.
+
+```sql
+begin;
+ -- remove the realtime publication
+ drop publication if exists publication_name;
+
+ -- re-create the publication but don't enable it for any tables
+ create publication publication_name;
+commit;
+```
diff --git a/apps/reference/docs/guides/database/sql-to-api.mdx b/apps/reference/docs/guides/database/sql-to-api.mdx
new file mode 100644
index 00000000000..4a07440ae3a
--- /dev/null
+++ b/apps/reference/docs/guides/database/sql-to-api.mdx
@@ -0,0 +1,83 @@
+---
+id: sql-to-api
+title: 'Converting SQL to JavaScript API'
+description: Implementing common SQL patterns in the JavaScript API
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+
+
+Select a set of columns from a single table with where, order by, and limit clauses.
+
+```sql
+select first_name, last_name, team_id, age from players
+where age between 20 and 24 and team_id <> 'STL'
+order by last_name, first_name desc
+limit 20
+```
+
+```js
+const { data, error } = await supabase
+ .from('players')
+ .select('first_name,last_name,team_id,age')
+ .gte('age', 20)
+ .lte('age', 24)
+ .not('team_id', 'eq', 'STL')
+ .order('last_name', { ascending: true }) // or just .order('last_name')
+ .order('first_name', { ascending: false })
+ .limit(20)
+```
+
+Select all columns from a single table with a complex where clause: OR AND OR
+
+```sql
+select * from players
+where ((team_id = 'CHN' or team_id is null) and (age > 35 or age is null))
+```
+
+```js
+const { data, error } = await supabase
+ .from('players')
+ .select() // or .select('*')
+ .or('team_id.eq.CHN,team_id.is.null')
+ .or('age.gt.35,age.is.null') // additional filters imply "AND"
+ .not('team_id', 'eq', 'STL')
+```
+
+Select all columns from a single table with a complex where clause: AND OR AND
+
+```sql
+select * from players
+where ((team_id = 'CHN' and age > 35) or (team_id <> 'CHN' and age is not null))
+```
+
+```js
+const { data, error } = await supabase
+ .from('players')
+ .select() // or .select('*')
+ .or('and(team_id.eq.CHN,age.gt.35),and(team_id.neq.CHN,.not.age.is.null)')
+```
+
+Get a count of rows, but don't return any data.
+
+```sql
+select count(*) from players
+where team_id = 'NYM'
+```
+
+```js
+const { data, error } = await supabase
+ .from('players')
+ .select('*', { count: 'exact', head: true }) // exact, planned, or executed
+ .eq('team_id', 'NYM')
+```
+
+## Resources
+
+- [Supabase Account - Free Tier OK](https://supabase.com)
+- [Postgrest Operators](https://postgrest.org/en/stable/api.html#operators)
+- [Supabase API: JavaScript select](/docs/reference/javascript/select)
+- [Supabase API: JavaScript modifiers](/docs/reference/javascript/using-modifiers)
+- [Supabase API: JavaScript filters](/docs/reference/javascript/using-filters)
diff --git a/apps/reference/docs/guides/database/tables.mdx b/apps/reference/docs/guides/database/tables.mdx
new file mode 100644
index 00000000000..f04015df257
--- /dev/null
+++ b/apps/reference/docs/guides/database/tables.mdx
@@ -0,0 +1,514 @@
+---
+id: tables
+title: Tables and Data
+description: Creating and using Postgres tables.
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+
+Tables are where you store your data.
+
+Tables are similar to excel spreadsheets. They contain columns and rows.
+For example, this table has 3 "columns" (`id`, `name`, `description`) and 4 "rows" of data:
+
+| `id` | `name` | `description` |
+| ---- | -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- |
+| 1 | The Phantom Menace | Two Jedi escape a hostile blockade to find allies and come across a young boy who may bring balance to the Force. |
+| 2 | Attack of the Clones | Ten years after the invasion of Naboo, the Galactic Republic is facing a Separatist movement. |
+| 3 | Revenge of the Sith | As Obi-Wan pursues a new threat, Anakin acts as a double agent between the Jedi Council and Palpatine and is lured into a sinister plan to rule the galaxy. |
+| 4 | Star Wars | Luke Skywalker joins forces with a Jedi Knight, a cocky pilot, a Wookiee and two droids to save the galaxy from the Empire's world-destroying battle station. |
+
+There are a few important differences from a spreadsheet, but it's a good starting point if you're new to Relational databases.
+
+## Creating Tables
+
+When creating a table, it's best practice to add columns at the same time.
+
+
+
+You must define the "data type" of each column when it is created. You can add and remove columns at any time after creating a table.
+
+Supabase provides several options for creating tables. You can use the Dashboard or create them directly using SQL.
+We provide a SQL editor within the Dashboard, or you can [connect](/docs/guides/database/connecting/connecting-to-postgres) to your database
+and run the SQL queries yourself.
+
+
+
+
+
+
+
+1. Go to the [Table Editor](https://app.supabase.com/project/_/editor) page in the Dashboard.
+2. Click **New Table** and create a table with the name `todos`.
+3. Click **Save**.
+4. Click **New Column** and create a column with the name `task` and type `text`.
+5. Click **Save**.
+
+
+
+
+```sql
+create table movies (
+ id bigint generated by default as identity primary key,
+ name text,
+ description text
+);
+```
+
+
+
+
+:::note
+When naming tables, use lowercase and underscores instead of spaces (e.g., `table_name`, not `Table Name`).
+:::
+
+## Columns
+
+You must define the "data type" when you create a column.
+
+### Data types
+
+Every column is a predefined type. PostgreSQL provides many [default types](https://www.postgresql.org/docs/current/datatype.html), and you can even design your own (or use extensions)
+if the default types don't fit your needs.
+
+
+Show/Hide default data types
+
+| `Name` | `Aliases` | `Description` |
+| --------------------------------- | ----------- | ---------------------------------------------------------------- |
+| bigint | int8 | signed eight-byte integer |
+| bigserial | serial8 | autoincrementing eight-byte integer |
+| bit | | fixed-length bit string |
+| bit varying | varbit | variable-length bit string |
+| boolean | bool | logical Boolean (true/false) |
+| box | | rectangular box on a plane |
+| bytea | | binary data (“byte array”) |
+| character | char | fixed-length character string |
+| character varying | varchar | variable-length character string |
+| cidr | | IPv4 or IPv6 network address |
+| circle | | circle on a plane |
+| date | | calendar date (year, month, day) |
+| double precision | float8 | double precision floating-point number (8 bytes) |
+| inet | | IPv4 or IPv6 host address |
+| integer | int, int4 | signed four-byte integer |
+| interval \[ fields \] | | time span |
+| json | | textual JSON data |
+| jsonb | | binary JSON data, decomposed |
+| line | | infinite line on a plane |
+| lseg | | line segment on a plane |
+| macaddr | | MAC (Media Access Control) address |
+| macaddr8 | | MAC (Media Access Control) address (EUI-64 format) |
+| money | | currency amount |
+| numeric | decimal | exact numeric of selectable precision |
+| path | | geometric path on a plane |
+| pg_lsn | | PostgreSQL Log Sequence Number |
+| pg_snapshot | | user-level transaction ID snapshot |
+| point | | geometric point on a plane |
+| polygon | | closed geometric path on a plane |
+| real | float4 | single precision floating-point number (4 bytes) |
+| smallint | int2 | signed two-byte integer |
+| smallserial | serial2 | autoincrementing two-byte integer |
+| serial | serial4 | autoincrementing four-byte integer |
+| text | | variable-length character string |
+| time \[ without time zone \] | | time of day (no time zone) |
+| time with time zone | timetz | time of day, including time zone |
+| timestamp \[ without time zone \] | | date and time (no time zone) |
+| timestamp with time zone | timestamptz | date and time, including time zone |
+| tsquery | | text search query |
+| tsvector | | text search document |
+| txid_snapshot | | user-level transaction ID snapshot (deprecated; see pg_snapshot) |
+| uuid | | universally unique identifier |
+| xml | | XML data |
+
+
+
+
+
+You can "cast" columns from one type to another, however there can be some incompatibilities between types.
+For example, if you cast a `timestamp` to a `date`, you will lose all the time information that was previously saved.
+
+### Primary Keys
+
+A table can have a "primary key" - a unique identifier for every row of data. A few tips for Primary Keys:
+
+- It's recommended to create a Primary Key for every table in your database.
+- You can use any column as a primary key, as long as it is unique for every row.
+- It's common to use a `uuid` type or a numbered `identity` column as your primary key.
+
+```sql
+create table movies (
+ id bigint generated always as identity primary key
+);
+```
+
+In the example above, we have:
+
+1. created a column called `id`
+1. assigned the data type `bigint`
+1. instructed the database that this should be `generated always as identity`, which means that Postgres will automatically assign a unique number to this column.
+1. Becuase it's unique, we can also use it as our `primary key`.
+
+We could also use `generated by default as identity`, which would allow us to insert our own unique values.
+
+```sql
+create table movies (
+ id bigint generated by default as identity primary key
+);
+```
+
+## Loading data
+
+There are several ways to load data in Supabase. You can load data directly into the database or using the [APIs](/docs/guides/api).
+Use the "Bulk Loading" instructions if you are loading large data sets.
+
+### Basic data loading
+
+
+
+
+
+```sql
+insert into movies
+ (name, description)
+values
+ ('The Empire Strikes Back', 'After the Rebels are brutally overpowered by the Empire on the ice planet Hoth, Luke Skywalker begins Jedi training with Yoda.'),
+ ('Return of the Jedi', 'After a daring mission to rescue Han Solo from Jabba the Hutt, the Rebels dispatch to Endor to destroy the second Death Star.');
+```
+
+
+
+
+
+```sql
+const { data, error } = await supabase
+ .from('movies')
+ .insert([{
+ name: 'The Empire Strikes Back',
+ description: 'After the Rebels are brutally overpowered by the Empire on the ice planet Hoth, Luke Skywalker begins Jedi training with Yoda.'
+ }, {
+ name: 'Return of the Jedi',
+ description: 'After a daring mission to rescue Han Solo from Jabba the Hutt, the Rebels dispatch to Endor to destroy the second Death Star.'
+ }])
+```
+
+
+
+
+
+```sql
+final res = await supabase
+ .from('movies')
+ .insert([{
+ name: 'The Empire Strikes Back',
+ description: 'After the Rebels are brutally overpowered by the Empire on the ice planet Hoth, Luke Skywalker begins Jedi training with Yoda.'
+ }, {
+ name: 'Return of the Jedi',
+ description: 'After a daring mission to rescue Han Solo from Jabba the Hutt, the Rebels dispatch to Endor to destroy the second Death Star.'
+ }]).execute();
+```
+
+
+
+
+### Bulk data loading
+
+When inserting large data sets it's best to use PostgreSQL's [COPY](https://www.postgresql.org/docs/current/sql-copy.html) command.
+This loads data directly from a file into a table. There are several file formats available for copying data: text, csv, binary, JSON, etc.
+
+For example, if you wanted to load a CSV file into your movies table:
+
+```csv title="./movies.csv"
+"The Empire Strikes Back", "After the Rebels are brutally overpowered by the Empire on the ice planet Hoth, Luke Skywalker begins Jedi training with Yoda."
+"Return of the Jedi", "After a daring mission to rescue Han Solo from Jabba the Hutt, the Rebels dispatch to Endor to destroy the second Death Star."
+```
+
+You would [connect](/docs/guides/database/connecting-to-postgres#direct-connections) to your database directly and load the file with the COPY command:
+
+```bash
+psql -h DATABASE_URL -p 5432 postgres -U postgres \
+ -c "COPY movies FROM './movies.csv';"
+```
+
+## Joining tables with Foreign Keys
+
+Tables can be "joined" together using Foreign Keys.
+
+
+
+This is where the "Relational" naming comes from, as data typically forms some sort of relationship.
+
+In our "movies" example above, we might want to add a "category" for each movie (for example, "Action", or "Documentary").
+Let's create a new table called `categories` and "link" our `movies` table.
+
+```sql
+create table categories (
+ id bigint generated always as identity primary key,
+ name text -- category name
+);
+
+alter table movies
+ add column category_id bigint references categories;
+```
+
+You can also create "many-to-many" relationships by creating a "join" table.
+For example if you had the following situations:
+
+- You have a list of `movies`.
+- A movie can have several `actors`.
+- An `actor` can perfom in several movies.
+
+
+
+
+
+
+
+
+
+
+
+```sql
+create table movies (
+ id bigint generated by default as identity primary key,
+ name text,
+ description text
+);
+
+create table actors (
+ id bigint generated by default as identity primary key,
+ name text
+);
+
+create table performances (
+ id bigint generated by default as identity primary key,
+ movie_id bigint not null references movies,
+ actor_id bigint not null references actors
+);
+```
+
+
+
+
+## Schemas
+
+Tables belong to `schemas`. Schemas are a way of organizing your tables, often for security reasons.
+
+
+
+If you don't explicitly pass a schema when creating a table, Postgres will assume that you want to create the table in the `public` schema.
+
+We can create schemas for organizing tables. For example, we might want a private schema which is hidden from our API:
+
+```sql
+create schema private;
+```
+
+Now we can create tables inside the `private` schema:
+
+```sql
+create table salaries (
+ id bigint generated by default as identity primary key,
+ salary bigint not null,
+ actor_id bigint not null references public.actors
+);
+```
+
+## Views
+
+A View is a convenient shortcut to a query. Creating a view does not involve new tables or data. When run, an underlying query is executed, returning its results to the user.
+
+:::caution
+
+By default, PostgreSQL views bypass Row Level Security unless you change their owner (see https://github.com/supabase/supabase/discussions/901). PostgreSQL v15 (coming soon) will have a more intuitive control for this through [security invoker views](https://www.depesz.com/2022/03/22/waiting-for-postgresql-15-add-support-for-security-invoker-views/) and the previous step won't be needed.
+
+:::
+
+Say we have the following tables from a database of a university:
+
+**`students`**
+
+| id | name | type |
+| --- | ---------------- | ------------- |
+| 1 | Princess Leia | undergraduate |
+| 2 | Yoda | graduate |
+| 3 | Anakin Skywalker | graduate |
+
+**`courses`**
+
+| id | title | code |
+| --- | ------------------------ | ------- |
+| 1 | Introduction to Postgres | PG101 |
+| 2 | Authentication Theories | AUTH205 |
+| 3 | Fundamentals of Supabase | SUP412 |
+
+**`grades`**
+
+| id | student_id | course_id | result |
+| --- | ---------- | --------- | ------ |
+| 1 | 1 | 1 | B+ |
+| 2 | 1 | 3 | A+ |
+| 3 | 2 | 2 | A |
+| 4 | 3 | 1 | A- |
+| 5 | 3 | 2 | A |
+| 6 | 3 | 3 | B- |
+
+Creating a view consisting of all the three tables will look like this:
+
+```sql
+create view transcripts as
+ select
+ students.name,
+ students.type,
+ courses.title,
+ courses.code,
+ grades.result
+ from grades
+ left join students on grades.student_id = students.id
+ left join courses on grades.course_id = courses.id;
+
+alter view transcripts owner to authenticated;
+```
+
+Once done, we can now access the underlying query with:
+
+```sql
+select * from transcripts;
+```
+
+### When to use views
+
+Views provide the several benefits:
+
+- Simplicity
+- Consistency
+- Logical Organization
+- Security
+
+#### Simplicity
+
+As a query becomes complex it becomes a hassle to call it. Especially when we run it at regularly. In the example above, instead of repeatedly running:
+
+```sql
+select
+ students.name,
+ students.type,
+ courses.title,
+ courses.code,
+ grades.result
+from grades
+left join students on grades.student_id = students.id
+left join courses on grades.course_id = courses.id;
+```
+
+We can run this instead:
+
+```sql
+select * from transcripts;
+```
+
+Additionally, a view behaves like a typical table. We can safely use it in table `JOIN`s or even create new views using existing views.
+
+#### Consistency
+
+Views ensure that the likelihood of mistakes decreases when repeatedly executing a query. In our example above, we may decide that we want to exclude the course _Introduction to Postgres_. The query would become:
+
+```sql
+select
+ students.name,
+ students.type,
+ courses.title,
+ courses.code,
+ grades.result
+from grades
+ left join students on grades.student_id = students.id
+ left join courses on grades.course_id = courses.id
+where courses.code != 'PG101';
+```
+
+Without a view, we would need to go into every dependent query to add the new rule. This would increase in the likelihood of errors and inconsistencies, as well as introducing a lot of effort for a developer. With views, we can alter just the underlying query in the view **transcripts**. The change will be applied to all applications using this view.
+
+#### Logical Organization
+
+With views, we can give our query a name. This is extremely useful for teams working with the same database. Instead of guessing what a query is supposed to do, a well-named view can easily explain it. For example, by looking at the name of the view **transcripts**, we can infer that the underlying query might involve the **students**, **courses**, and **grades** tables.
+
+#### Security
+
+Views can restrict the amount and type of data presented to a user. Instead of allowing a user direct access to a set of tables, we provide them a view instead. We can prevent them from reading sensitive columns by excluding them from the underlying query.
+
+### Materialized Views
+
+A [materialized view](https://www.postgresql.org/docs/12/rules-materializedviews.html) is a form of view but it also stores the results to disk. In subsequent reads of a materialized view, the time taken to return its results would be much faster than a conventional view. This is because the data is readily available for a materialized view while the conventional view executes the underlying query each time it is called.
+
+Using our example above, a materialized view can be created like this:
+
+```sql
+create materialized view transcripts as
+ select
+ students.name,
+ students.type,
+ courses.title,
+ courses.code,
+ grades.result
+ from grades
+ left join students on grades.student_id = students.id
+ left join courses on grades.course_id = courses.id;
+```
+
+Reading from the materialized view is the same as a conventional view:
+
+```sql
+select * from transcripts;
+```
+
+### Refreshing materialized views
+
+Unfortunately, there is a trade-off - data in materialized views are not always up to date. We need to refresh it regularly to prevent the data from becoming too stale. To do so:
+
+```sql
+refresh materialized view transcripts;
+```
+
+It's up to you how regularly refresh your materialized views, and it's probably different for each view depending on its use-case.
+
+### Materialized views vs Conventional views
+
+Materialized views are useful when execution times for queries or views are too slow. These could likely occur in views or queries involving multiple tables and billions of rows. When using such a view, however, there should be tolerance towards data being outdated. Some use-cases for materialized views are internal dashboards and analytics.
+
+Creating a materialized view is not a solution to inefficient queries. You should always seek to optimize a slow running query even if you are implementing a materialized view.
+
+## Resources
+
+- [Official Docs: Create table](https://www.postgresql.org/docs/current/sql-createtable.html)
+- [Official Docs: Create view](https://www.postgresql.org/docs/12/sql-createview.html)
+- [PostgreSQL Tutorial: Create tables](https://www.postgresqltutorial.com/postgresql-tutorial/postgresql-create-table/)
+- [PostgreSQL Tutorial: Add column](https://www.postgresqltutorial.com/postgresql-tutorial/postgresql-add-column/)
+- [PostgreSQL Tutorial: Views](https://www.postgresqltutorial.com/postgresql-views/)
diff --git a/apps/reference/docs/guides/database/timeouts.mdx b/apps/reference/docs/guides/database/timeouts.mdx
new file mode 100644
index 00000000000..2436c5dc0db
--- /dev/null
+++ b/apps/reference/docs/guides/database/timeouts.mdx
@@ -0,0 +1,27 @@
+---
+id: timeouts
+title: Timeouts
+description: Timeouts and optimization
+---
+
+By default, Supabase limits the maximum statement execution time to _3 seconds_ for users accessing the API using the anon key, and _8 seconds_ for authenticated users. Additionally, all users are subject to a global limit of _2 minutes_. This serves as a backstop against resource exhaustion due to either poorly written queries, or abusive usage.
+
+### Changing the default timeout
+
+The timeout values were picked as a reasonable default for the majority of use-cases, but can be modified using the [`alter role`](https://www.postgresql.org/docs/current/sql-alterrole.html) statement:
+
+```sql
+alter role authenticated set statement_timeout = '15s';
+```
+
+You can also update the statement timeout for a session:
+
+```sql
+set statement_timeout to 60000; -- 1 minute in milliseconds
+```
+
+### Statement Optimization
+
+All Supabase projects come with the [`pg_stat_statements`](https://www.postgresql.org/docs/current/pgstatstatements.html) extension installed, which tracks planning and execution statistics for all statements executed against it. These statistics can be used in order to diagnose the performance of your project.
+
+This data can further be used in conjunction with the [`explain`](https://www.postgresql.org/docs/current/using-explain.html) functionality of Postgres to optimize your usage.
diff --git a/apps/reference/docs/guides/examples.mdx b/apps/reference/docs/guides/examples.mdx
new file mode 100644
index 00000000000..70035bdfdb3
--- /dev/null
+++ b/apps/reference/docs/guides/examples.mdx
@@ -0,0 +1,159 @@
+---
+id: examples
+title: Examples and Resources
+description: 'Examples you can use to get started with Supabase'
+---
+
+We have a [set of examples](https://github.com/supabase/supabase/tree/master/examples) in our [main repository](https://github.com/supabase/supabase) to help you get started.
+
+## Featured
+
+
+### Supabase Crash Course
+
+By [Traversy Media](https://www.youtube.com/watch?v=7uKQBl9uZ00).
+
+
+
+### Build an App With Supabase and NextJS
+
+By [@jlengstorf](https://twitter.com/jlengstorf) and [@jonmeyers_io](https://twitter.com/jonmeyers_io).
+
+
+
+
+### Is Supabase Legit
+
+By [Fireship](https://www.youtube.com/watch?v=WiwfiVdfRIc).
+
+
+
+## Official Examples
+
+### Todo List
+
+Build a basic Todo List with Supabase and your favorite frontend framework:
+
+- [Expo Todo List.](https://github.com/supabase/supabase/tree/master/examples/todo-list/expo-todo-list)
+- [Next.js Todo List.](https://github.com/supabase/supabase/tree/master/examples/todo-list/nextjs-todo-list)
+- [React Todo List.](https://github.com/supabase/supabase/tree/master/examples/todo-list/react-todo-list)
+- [Svelte Todo List.](https://github.com/supabase/supabase/tree/master/examples/todo-list/sveltejs-todo-list)
+- [Vue 3 Todo List (Typescript).](https://github.com/supabase/supabase/tree/master/examples/todo-list/vue3-ts-todo-list)
+- [Angular Todo List.](https://github.com/supabase/supabase/tree/master/examples/todo-list/angular-todo-list)
+- [Nuxt 3 Todo List.](https://github.com/nuxt-community/supabase-module/tree/main/demo)
+
+### Auth examples
+
+- [Supabase Auth with vanilla JavaScript.](https://github.com/supabase/supabase/tree/master/examples/auth/javascript-auth). Use Supabase without any frontend frameworks.
+- [Supabase Auth with Next.js SSR.](https://github.com/supabase/supabase/tree/master/examples/nextjs-with-supabase-auth) Uses cookies to persist auth between the server and the client.
+- [Supabase Auth with RedwoodJS.](https://redwood-playground-auth.netlify.app/supabase) Try out Supabase authentication in the [RedwoodJS](https://redwoodjs.com) Authentication Playground complete with OAuth support and code samples.
+
+### Collaborative
+
+- [Next.js Slack Clone.](https://github.com/supabase/supabase/tree/master/examples/slack-clone/nextjs-slack-clone)
+
+## Community
+
+### Courses
+
+- Build a FullStack App with Next.js, Supabase & Prisma by [@gdangel0](https://twitter.com/gdangel0): [Free course](https://themodern.dev/courses/build-a-fullstack-app-with-nextjs-supabase-and-prisma-322389284337222224)
+
+### Libraries
+
+- D (in development): [GitHub](https://github.com/csharpdf/dupabase)
+- Dart (in development): [GitHub](https://github.com/supabase/supabase-dart)
+- Python (in development): [GitHub](https://github.com/supabase/supabase-py)
+- C# (in development): [GitHub](https://github.com/supabase/supabase-csharp)
+- Kotlin (in development): [GitHub](https://github.com/supabase-community/postgrest-kt)
+- `useSupabase`: Supabase React Hooks. [GitHub](https://github.com/gbibeaul/use-supabase)
+- `vue-supabase`: Supabase Vue wrapper. [GitHub](https://github.com/supabase/vue-supabase)
+- `vue-3-supabase`: Supabase Vue 3 wrapper. [GitHub](https://github.com/DidoMarchet/vue-3-supabase)
+- `nuxt-supabase`: Supabase Nuxt wrapper. [GitHub](https://github.com/supabase/nuxt-supabase)
+- `@nuxtjs/supabase`: Supabase Nuxt 3 module. [GitHub](https://github.com/nuxt-community/supabase-module)
+- `react-supabase`: Supabase React Hooks. [Docs](https://react-supabase.vercel.app) [GitHub](https://github.com/tmm/react-supabase)
+- ` @triniwiz/nativescript-supabase`: Supabase NativeScript. [GitHub](https://github.com/triniwiz/nativescript-plugins/tree/master/packages/nativescript-supabase)
+
+### Guides
+
+- Supabase Auth with Redwood. [Docs](https://redwoodjs.com/tutorial/authentication)
+- Supabase Auth with Sapper SSR. [Blog](https://dev.to/jakobbouchard/how-to-setup-supabase-auth-with-sapper-ssr-13od)
+- Switch from Firebase Auth to Supabase Auth. [Blog](https://msyyn.medium.com/switch-from-firebase-auth-to-supabase-auth-the-open-source-firebase-alternative-509746952b1b)
+- Setting up Umami Analytics with Supabase. [Blog](https://dev.to/jakobbouchard/setting-up-umami-with-vercel-and-supabase-3a73)
+- Creating New Supabase Users In NextJS. [Blog](https://www.aboutmonica.com/blog/creating-new-supabase-users-in-next-js)
+- Creating Protected Routes In NextJS With Supabase. [Blog](https://www.aboutmonica.com/blog/creating-protected-routes-in-next-js-with-supabase)
+- Migrate from Google Cloud Storage (GCS) to Supabase Storage [Gist](https://gist.github.com/danalloway/86f79efd5ca336ff7364554ac3104014)
+- Subscriptions with Supabase and Stripe Billing [Blog](https://www.sandromaglione.com/2021/04/29/supabase-auth-create-stripe-customer-subscription-supabase-stripe-billing-part-1/)
+- Flutter Supabase Authentication [Blog](https://www.sandromaglione.com/2021/04/24/flutter-supabase-authentication/)
+- Supabase in 6 minutes [Video](https://www.youtube.com/watch?v=c8DNV9yl0mg)
+- Let's build SupaAuth - Build an Authentication System using Supabase, Next.js and Typescript [6-part Blog Series](https://aalam.in/blog/supabase-auth-intro-setup-next)
+- In-depth self-hosting guide using Nginx [Blog](https://dev.to/chronsyn/self-hosting-with-supabase-1aii)
+- Build an Email and Social Auth for Next JS with Supabase, Tailwind CSS 3.0 and TypeScript [Blog](https://creativedesignsguru.com/next-js-supabase-auth/)
+- Link Shortener using Supabase and Ory [3-part Blog Series](https://www.ory.sh/tutorial-url-shortener-supabase-ory-integration-backend/)
+
+### Example apps
+
+- Supabase + Stripe + Next.js. [GitHub](https://github.com/vercel/nextjs-subscription-payments)
+- Supabase + Svelte Trello clone. [GitHub](https://github.com/joshnuss/supabase-kanban)
+- Supabase + Expo Starter. [GitHub](https://github.com/codingki/react-native-expo-template/tree/master/template-typescript-bottom-tabs-supabase-auth-flow)
+- Supabase + Nest.js. [GitHub](https://github.com/hiro1107/nestjs-supabase-auth)
+- Supabase + Cloudflare Workers. [GitHub](https://github.com/supabase/supabase/tree/master/examples/with-cloudflare-workers)
+- Supabase + Cloudflare Workers + Webpack. [GitHub](https://github.com/signalnerve/supabase-workers-proxy)
+- Realtime chat app with Supabase + React. [GitHub](https://github.com/shwosner/realtime-chat-supabase-react)
+- Repository.surf: GitHub insights dashboard. [GitHub](https://github.com/supabase/repository.surf)
+- Supabase + React Native Instagram Clone. [GitHub](https://github.com/NiketanG/instaclone)
+- KeepLink: Simple bookmark service with tags and archive. [GitHub](https://github.com/fengkx/keeplink)
+- Supabase + Next.js (Next.js Starter Kit) [GitHub](https://github.com/one-aalam/next-starter-kit/tree/auth-supabase)
+- Supabase + Svelte (Svelte Starter Kit) [GitHub](https://github.com/one-aalam/svelte-starter-kit)
+- Supabase + SolidJS (SolidJS Starter Kit) [GitHub](https://github.com/one-aalam/solid-starter-kit)
+- Supabase + Nuxt3 (Nuxt Starter Kit) [GitHub](https://github.com/one-aalam/nuxt-starter-kit)
+- Supabase + Remix (Remix Starter Kit) [GitHub](https://github.com/one-aalam/remix-starter-kit)
+- Supabase + Angular (Angular Starter Kit) [GitHub](https://github.com/one-aalam/ng-starter-kit)
+- Supabase + Nuxt3 + nuxtjs/supabase [Github](https://github.com/nuxt-community/supabase-module/tree/main/demo)
+- Supabase + Ory Kratos & Ory Oathkeeper [Github](https://github.com/ory/examples/tree/master/kratos-keto-oathkeeper-supabase)
+- Supabase + Ory Cloud [Github](https://github.com/ory/examples/tree/master/supabase-ory-cloud)
+
+### Blog Posts
+
+- Realtime Subscriptions using Vue + Supabase. [Blog](https://dev.to/ftonato/realtime-subscriptions-using-vue-supabase-1e11)
+- Creating a microblog using Vue + Supabase. [Blog](https://dev.to/ftonato/creating-a-microblog-using-vue-supabase-31p)
+- Track Real-time Page Views. [Blog](https://codebycorey.com/blog/page-views-nextjs-supabase)
+- Supabase as a Sentry alternative. [Blog](http://kopi.cloud/blog/2021/sentry-supabase/)
+- Using Supabase with Chartbrew. [Blog](https://chartbrew.com/blog/how-to-visualize-your-supabase-data-with-chartbrew/)
+- Authentication with Supabase and React. [Blog](https://hyperfoo.io/posts/supabase-authentication-react)
+- Supabase Schema Visualizer. [Blog](https://dev.to/zernonia/supabase-schema-visualizer-no-installation-login-49kg)
+- Create a real-time UI using Next.js + Supabase. [Blog](https://pablopunk.com/posts/how-to-create-a-real-time-ui-with-nextjs-and-supabase)
+- How to add Twitter auth quickly with Supabase to your Next.js site ⚡ [Blog](https://blog.avneesh.tech/how-to-add-twitter-auth-quickly-with-supabase-to-your-nextjs-site)
+- Under the hood: Architecture and Technology Stack of Supabase ⚡ [Blog](https://www.workingsoftware.dev/tech-stack-and-architecture-of-supabase/)
+
+### Podcasts
+
+- [Software Engineering Daily](https://softwareengineeringdaily.com/2020/10/15/supabase-open-source-firebase-with-paul-copplestone/)
+- [Heavy Bit](https://www.heavybit.com/library/podcasts/jamstack-radio/ep-71-open-source-firebase-alternative-with-paul-copplestone-of-supabase/)
+- [Log Rocket](https://podrocket.logrocket.com/9)
+- [FS Jam](https://fsjam.org/episodes/episode-33-supabase-with-paul-copplestone)
+
+
diff --git a/apps/reference/docs/guides/functions.mdx b/apps/reference/docs/guides/functions.mdx
new file mode 100644
index 00000000000..c2294657e3b
--- /dev/null
+++ b/apps/reference/docs/guides/functions.mdx
@@ -0,0 +1,296 @@
+---
+id: functions
+title: Edge Functions
+description: 'Globally distributed Typescript functions.'
+---
+
+import Tabs from '@theme/Tabs'
+import TabItem from '@theme/TabItem'
+const examples = [
+ {
+ name: 'With supabase-js',
+ description: 'Use the Supabase client inside your Edge Function.',
+ href: 'https://github.com/supabase/supabase/tree/master/examples/edge-functions',
+ },
+ {
+ name: 'With CORS headers',
+ description: 'Send CORS headers for invoking from the browser.',
+ href: 'https://github.com/supabase/supabase/tree/master/examples/edge-functions/supabase/functions/browser-with-cors/index.ts',
+ },
+ {
+ name: 'React Native with Stripe',
+ description: 'Full example for using Supabase and Stripe, with Expo.',
+ href: 'https://github.com/supabase-community/expo-stripe-payments-with-supabase-functions',
+ },
+ {
+ name: 'Flutter with Stripe',
+ description: 'Full example for using Supabase and Stripe, with Flutter.',
+ href: 'https://github.com/supabase-community/flutter-stripe-payments-with-supabase-functions',
+ },
+]
+
+Edge Functions are server-side Typescript functions, distributed globally at the edge - close to your users. They can be used for listening to webhooks or integrating your Supabase project with third-parties, like Stripe.
+
+Edge Functions are developed using [Deno](https://deno.com), which offers a few benefits to you as a developer:
+
+- It is open source.
+- It is portable. Supabase Edge Functions run locally, and on any other Deno-compatible platform (including self-hosted infrastructure).
+- It is Typescript first and supports WASM.
+- Edge Functions are globally distributed for low-latency.
+
+## Quickstart
+
+Learn how to develop Edge Functions in less than 7 minutes:
+
+
+
+## Prerequisites
+
+Follow the steps to prepare your Supabase project on your local machine.
+
+- Install the Supabase CLI. [Docs](/docs/reference/cli/installing-and-updating).
+- Login to the CLI using the command: `supabase login`. [Docs](/docs/reference/cli/supabase-login).
+- Initialize Supabase inside your project using the command: `supabase init`. [Docs](/docs/guides/local-development#getting-started).
+- Link to your Remote Project using the command `supabase link --project-ref your-project-ref`. [Docs](/docs/reference/cli/supabase-link).
+- Optional: Setup your environment: Follow [this setup guide](https://deno.land/manual/getting_started/setup_your_environment) to integrate the Deno language server with your editor.
+
+## Getting Started
+
+Let's build an Edge Function locally, then deploy it to the Supabase Platform.
+
+### Creating a function
+
+Let's create a new Edge Function called `hello-world` inside your project:
+
+```bash
+supabase functions new hello-world
+```
+
+This creates a function stub in your `supabase` folder at `./functions/hello-world/index.ts`.
+
+### Deploy to production
+
+```bash
+supabase functions deploy hello-world
+```
+
+This command bundles your Edge Function from `./functions/hello-world/index.ts` and deploys it to the Supabase platform.
+The command outputs a URL to the Supabase Dashboard which you can open to find view more details. Let's open the link to find the execution command.
+
+:::note
+
+By default Edge Functions require a valid JWT to be send in the authorization header. This header is automatically set when invoking your function via a Supabase client library.
+
+If you want to use Edge Functions to handle webhooks (e.g. [Stripe payment webhooks](https://github.com/supabase/supabase/tree/master/examples/edge-functions/supabase/functions/stripe-webhooks), or [chat bot webhooks](https://github.com/supabase/supabase/tree/master/examples/edge-functions/supabase/functions/telegram-bot) etc.), you need to pass the `--no-verify-jwt` flag when deploying your function.
+
+:::
+
+### Executing Remote Functions
+
+You can execute Edge Functions using curl. Copy the curl command from the Dashboard. It should look like this:
+
+```bash
+curl --request POST 'https://.functions.supabase.co/hello-world' \
+ --header 'Authorization: Bearer ANON_KEY' \
+ --header 'Content-Type: application/json' \
+ --data '{ "name":"Functions" }'
+```
+
+If you receive an error `Invalid JWT`, find the `ANON_KEY` of your project in the Dashboard under `Settings > API`.
+
+After invoking your Edge Function you should see the response `{ "message":"Hello Functions!" }`.
+
+## Debugging your Functions
+
+You can debug your deployed Edge Functions using the "Functions" section of the Dashboard. There are two types debugging tools available:
+
+- Invocations: shows the Request and Response for each execution.
+- Logs: shows any platform events, including deployments and errors.
+
+
+
+## Developing locally
+
+You can run your Edge Function locally using [`supabase functions serve`](/docs/reference/cli/supabase-functions-serve):
+
+```bash
+supabase start # start the supabase stack
+supabase functions serve hello-world # start the Function watcher
+```
+
+The `functions serve` command has hot-reloading capabilities. It will watch for any changes to your files and restart the Deno server.
+
+### Invoking Functions locally
+
+While serving your local Function, you can execute it using curl:
+
+```bash
+curl --request POST 'http://localhost:54321/functions/v1/hello-world' \
+ --header 'Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJzdXBhYmFzZS1kZW1vIiwicm9sZSI6ImFub24ifQ.625_WdcF3KHqz5amU0x2X5WWHP-OEs_4qj0ssLNHzTs' \
+ --header 'Content-Type: application/json' \
+ --data '{ "name":"Functions" }'
+```
+
+You should see the response `{ "message":"Hello Functions!" }`.
+
+
+Implementation details
+
+- All Edge Functions are `POST` requests.
+- The `Authorization` header is required. You can use either the `ANON` key, the `SERVICE_ROLE` key, or a logged-in user's JWT.
+- The Function is proxied through the local API (`http://localhost:54321`)
+
+
+
+
+If you execute Function with a different payload the response will change.
+Modify the `--data '{"name":"Functions"}'` line to `--data '{"name":"World"}'` and try invoking the command again!
+
+## Secrets and Environment Variables
+
+It's common that you will need to use sensitive information or environment-specific variables inside your Edge Functions. You can access these using Deno's built-in handler
+
+```js
+Deno.env.get(MY_SECRET_NAME)
+```
+
+### Default secrets
+
+By default, Edge Functions have access to these secrets:
+
+- `SUPABASE_URL`: The API gateway for your Supabase project.
+- `SUPABASE_ANON_KEY`: The `anon` key for your Supabase API. This is safe to use in a browser when you have [Row Level Security](/docs/guides/auth/row-level-security) enabled.
+- `SUPABASE_SERVICE_ROLE_KEY`: The `service_role` key for your Supabase API. This is safe to use in Edge Functions, but it should NEVER be used in a browser. This key will bypass [Row Level Security](/docs/guides/auth/row-level-security).
+- `SUPABASE_DB_URL`: The URL for your [PostgreSQL database](/docs/guides/database). You can use this to connect directly to your database.
+
+### Local secrets
+
+Let's create a local file for storing our secrets, and inside it we can store a secret `MY_NAME`:
+
+```jsx
+echo "MY_NAME=Yoda" >> ./supabase/.env.local
+```
+
+This creates a new file `./supabase/.env.local` for storing your local development secrets.
+
+:::caution
+
+Never check your .env files into Git!
+
+:::
+
+Now let's access this environment variable `MY_NAME` inside our Function. Anywhere in your function, add this line:
+
+```jsx
+console.log(Deno.env.get('MY_NAME'))
+```
+
+Now we can invoke our function locally, by serving it with our new `.env.local` file:
+
+```bash
+supabase functions serve hello-world --env-file ./supabase/.env.local
+```
+
+When the function starts you should see the name “Yoda” output to the terminal.
+
+### Production secrets
+
+Let's create a `.env` for production. In this case we'll just use the same as our local secrets:
+
+```bash
+cp ./supabase/.env.local ./supabase/.env
+```
+
+This creates a new file `./supabase/.env` for storing your production secrets.
+
+:::caution
+
+Never check your `.env` files into Git!
+
+:::
+
+Let's push all the secrets from the `.env` file to our remote project using [`supabase secrets set`](/docs/reference/cli/supabase-secrets-set):
+
+```bash
+supabase secrets set --env-file ./supabase/.env
+
+# You can also set secrets individually using:
+supabase secrets set MY_NAME=Chewbacca
+```
+
+You don't need to re-deploy after setting your secrets.
+
+To see all the secrets which you have set remotely, use [`supabase secrets list`](/docs/reference/cli/supabase-secrets-list):
+
+```bash
+supabase secrets list
+```
+
+## Examples
+
+You can find a list of useful [Edge Function Examples](https://github.com/supabase/supabase/tree/master/examples/edge-functions) in our GitHub repository.
+
+
+
+## Suggestions
+
+### Database Functions vs Edge Functions
+
+For data-intensive operations we recommend using [Database Functions](/docs/guides/database/functions), which are executed within your database
+and can be called remotely using the [REST and GraphQL API](/docs/guides/api).
+
+For use-cases which require low-latency we recommend [Edge Functions](/docs/guides/functions), which are globally-distributed and can be written in Typescript.
+
+
+### Organizing your Edge Functions
+
+We recommend developing “fat functions”. This means that you should develop few large functions, rather than many small functions. One common pattern when developing Functions is that you need to share code between two or more Functions. To do this, you can store any shared code in a folder prefixed with an underscore (`_`). We recommend this folder structure:
+
+```bash
+└── supabase
+ ├── functions
+ │ ├── _shared
+ │ | ├── supabaseAdmin.ts # Supabase client with SERVICE_ROLE key
+ │ │ └── supabaseClient.ts # Supabase client with ANON key
+ │ ├── function-one # use hyphens to name functions
+ │ │ └── index.ts
+ │ └── function-two
+ │ └── index.ts
+ ├── migrations
+ └── config.toml
+```
+
+### Naming Edge Functions
+
+We recommend using hyphens to name functions because hyphens are the most URL-friendly of all the naming conventions (snake_case, camelCase, PascalCase).
+
+## Limitations
+
+- Deno Deploy limitations
+ - Deno does not support outgoing connections to ports `25`, `465`, and `587`.
+ - Cannot write to File System
+- Edge Functions
+ - Local development - only one function at a time
+ - Supabase Functions only supports `POST` requests.
+ - Supabase Functions do not support HTML responses.
diff --git a/apps/reference/docs/guides/hosting/docker.mdx b/apps/reference/docs/guides/hosting/docker.mdx
new file mode 100644
index 00000000000..798d5e02999
--- /dev/null
+++ b/apps/reference/docs/guides/hosting/docker.mdx
@@ -0,0 +1,113 @@
+---
+id: docker
+title: Self-hosting with Docker
+description: How to configure and deploy Supabase.
+sidebar_label: Docker
+---
+
+Docker is the easiest way to get started with self-hosted Supabase.
+
+## Before you begin
+
+You need the following installed in your system:
+
+- [Docker](https://docs.docker.com/engine/install/) and [docker-compose](https://docs.docker.com/compose/install/)
+- [Git](https://git-scm.com/downloads)
+
+## Quick Start
+
+### Get the code
+
+Checkout the docker directory in the Supabase repo:
+
+```sh
+# Get the code
+git clone --depth 1 https://github.com/supabase/supabase
+
+# Go to the docker folder
+cd supabase/docker
+
+# Copy the fake env vars
+cp .env.example .env
+
+# Start
+docker-compose up
+```
+
+Now visit [http://localhost:3000](http://localhost:3000) to start using Supabase Studio.
+
+
+## Securing your setup
+
+While we provided you with some example secrets for getting started, you should NEVER deploy your Supabase setup using the defaults we have provided.
+
+Please follow these steps to secure your Docker setup. We [strongly recommend](/docs/guides/hosting/overview#managing-your-secrets) using a secrets manager when deploying to production.
+
+### Generate API Keys
+
+Use your `JWT_SECRET` to generate a `anon` and `service` API keys using the [JWT generator](/docs/guides/hosting/overview#api-keys).
+
+Replace the values in these files:
+
+- `.env`:
+ - `ANON_KEY` - replace with an `anon` key
+ - `SERVICE_ROLE_KEY` - replace with a `service` key
+- `volumes/api/kong.yml`
+ - `anon` - replace with an `anon` key
+ - `service_role` - replace with a `service` key
+
+### Update Secrets
+
+Update the `.env` file with your own secrets. In particular, these are required:
+
+- `POSTGRES_PASSWORD`: the password for the `postgres` role.
+- `JWT_SECRET`: used by PostgREST and GoTrue, among others.
+- `SITE_URL`: the base URL of your site.
+- `SMTP_*`: mail server credentials. You can use any SMTP server.
+
+
+### Securing the Dashboard
+
+The Docker setup doesn't include a management database for managing users and logins. If you plan to deploy the Studio to the web we suggest you put it behind a web proxy with Basic Auth or hide it behind a VPN.
+
+## Configuration
+
+Each system can be [configured](/docs/guides/hosting/overview#configuration) to suit your particular use-case.
+
+To keep the setup simple, we made some choices that may not be optimal for production:
+
+- the database is in the same machine as the servers
+- Storage uses the filesystem backend instead of S3
+- Auth should be configured with a production-ready SMTP server
+
+### Using an external database
+
+We strongly [recommend](/docs/guides/hosting/overview#managing-your-database) that you decouple your database from `docker-compose` before deploying.
+The middleware will run with any PostgreSQL database that has logical replication enabled. The following environment variables should be updated
+in the `.env` file to point to your external database:
+
+```env title=".env"
+POSTGRES_PASSWORD=your-super-secret-and-long-postgres-password
+
+POSTGRES_HOST=db
+POSTGRES_DB=postgres
+POSTGRES_USER=postgres
+POSTGRES_PORT=5432
+```
+
+Once you have done this, you can safely comment out the `db` section of the `docker-compose` file, and remove any instances where the services `depends_on` the `db` image.
+
+
+## Deploying
+
+See the following guides to deploy Docker Compose setup using your preferred tool and platform:
+
+- [Docker Swarm](https://docs.docker.com/engine/swarm/stack-deploy/)
+- [AWS Fargate](https://aws.amazon.com/blogs/containers/deploy-applications-on-amazon-ecs-using-docker-compose/)
+- [Using Kompose for Kubernetes](https://kubernetes.io/docs/tasks/configure-pod-container/translate-compose-kubernetes/)
+
+
+## Next steps
+
+- Got a question? [Ask here](https://github.com/supabase/supabase/discussions).
+- Sign in: [app.supabase.com](https://app.supabase.com)
diff --git a/apps/reference/docs/guides/hosting/overview.mdx b/apps/reference/docs/guides/hosting/overview.mdx
new file mode 100644
index 00000000000..db903c65d9c
--- /dev/null
+++ b/apps/reference/docs/guides/hosting/overview.mdx
@@ -0,0 +1,158 @@
+---
+id: overview
+title: Self Hosting
+sidebar_label: Overview
+description: Getting started with Self Hosting.
+---
+
+import JwtGenerator from '@site/src/components/JwtGenerator'
+
+There are several ways to use Supabase:
+
+- [Supabase Cloud](https://app.supabase.com): you don't need to deploy anything. We will manage and scale your infrastructure.
+- [Docker](/docs/guides/hosting/docker): deploy to your own infrastructure.
+- Kubernetes: coming soon.
+
+## Architecture
+
+Supabase is a combination of open source tools, each specifically chosen for Enterprise-readiness.
+
+If the tools and communities already exist, with an MIT, Apache 2, or equivalent open license, we will use and support that tool.
+If the tool doesn't exist, we build and open source it ourselves.
+
+
+
+- [Kong](https://github.com/Kong/kong) is a cloud-native API gateway.
+- [GoTrue](https://github.com/netlify/gotrue) is an SWT based API for managing users and issuing SWT tokens.
+- [PostgREST](http://postgrest.org/) is a web server that turns your PostgreSQL database directly into a RESTful API
+- [Realtime](https://github.com/supabase/realtime) is an Elixir server that allows you to listen to PostgreSQL inserts, updates, and deletes using websockets. Realtime polls Postgres' built-in replication functionality for database changes, converts changes to JSON, then broadcasts the JSON over websockets to authorized clients.
+- [Storage](https://github.com/supabase/storage-api) provides a RESTful interface for managing Files stored in S3, using Postgres to manage permissions.
+- [postgres-meta](https://github.com/supabase/postgres-meta) is a RESTful API for managing your Postgres, allowing you to fetch tables, add roles, and run queries, etc.
+- [PostgreSQL](https://www.postgresql.org/) is an object-relational database system with over 30 years of active development that has earned it a strong reputation for reliability, feature robustness, and performance.
+
+
+
+
+
+## Configuration
+
+Each system has a number of configuration options which can be found in the relevant product documentation.
+
+- [Postgres](https://hub.docker.com/_/postgres/)
+- [PostgREST](https://postgrest.org/en/stable/configuration.html)
+- [Realtime](https://github.com/supabase/realtime#server-set-up)
+- [GoTrue](https://github.com/supabase/gotrue)
+- [Storage](https://github.com/supabase/storage-api)
+- [Kong](https://docs.konghq.com/install/docker/)
+
+## Managing your database
+
+It is recommended that you decouple your database from the middleware so that you can upgrade the middleware without any downtime.
+The "middleware" is everything except Postgres, and it should work with any Postgres provider (such as AWS RDS), or your own Postgres cluster.
+
+### Database Extensions
+
+Supabase requires some Postgres extensions to be enabled by default for the API and Auth system to work. You can find the extensions inside the
+[schema initialization script](https://github.com/supabase/supabase/blob/master/docker/volumes/db/init/00-initial-schema.sql).
+
+
+We recommend installing all extensions into an `extensions` schema. This will keep your API clean,
+since all tables in the `public` schema are exposed via the API.
+
+```sql
+create schema if not exists extensions;
+create extension if not exists "uuid-ossp" with schema extensions;
+create extension if not exists pgcrypto with schema extensions;
+create extension if not exists pgjwt with schema extensions;
+```
+
+##### `uuid-ossp`
+
+For UUID functions, required for PostgreSQL <13.
+
+
+##### `pgcrypto` and `pgjwt`
+
+
+For working with JWT and Auth functions.
+
+### Database Roles
+
+Supabase creates several default roles in your Postgres database. To restore defaults at any time you can run the commands inside the
+[schema initialization script](https://github.com/supabase/supabase/blob/master/docker/volumes/db/init/00-initial-schema.sql).
+
+##### `postgres`
+
+The default PostgreSQL role. This has admin privileges.
+
+##### `anon`
+
+For "anonymous access". This is the role which the API (PostgREST) will use when a user _is not_ logged in.
+
+##### `authenticator`
+
+A special role for the API (PostgREST). It has very limited access, and is used to validate a JWT and then
+"change into" another role determined by the JWT verification.
+
+##### `authenticated`
+
+For "authenticated access". This is the role which the API (PostgREST) will use when a user _is_ logged in.
+
+##### `service_role`
+
+For elevated access. This role is used by the API (PostgREST) to bypass Row Level Security.
+
+##### `supabase_auth_admin`
+
+Used by the Auth middleware to connect to the database and run migration. Access is scoped to the `auth` schema.
+
+##### `supabase_storage_admin`
+
+Used by the Auth middleware to connect to the database and run migration. Access is scoped to the `storage` schema.
+
+##### `dashboard_user`
+
+For running commands via the Supabase UI.
+
+##### `supabase_admin`
+
+Supabase Administrative role for maintaining your database.
+
+## API Keys
+
+The API Gateway (Kong) uses JWT to authenticate access through to the database. The JWT should correspond to a relevant Postgres Role,
+and Supabase is designed to work with 2 roles: an `ANON_KEY` for unauthenticated access and a `SERVICE_KEY` for elevated access.
+
+Use this tool to generate keys:
+
+
+
+## Managing your secrets
+
+Many components inside Supabase use secure secrets and passwords. These are listed in the self-hosting
+[env file](https://github.com/supabase/supabase/blob/master/docker/.env.example), but we strongly recommend using a
+secrets manager when deploying to production. Plain text files like dotenv lead to accidental costly leaks.
+
+Some suggested systems include:
+
+- [Doppler](https://www.doppler.com/)
+- [Key Vault](https://docs.microsoft.com/en-us/azure/key-vault/general/overview) by Azure
+- [Secrets Manager](https://aws.amazon.com/secrets-manager/) by AWS
+- [Secrets Manager](https://cloud.google.com/secret-manager) by GCP
+- [Vault](https://www.hashicorp.com/products/vault) by Hashicorp
+
+## Migrating and Upgrading
+
+If you have decoupled your database from the middleware, then you should be able to redeploy the latest middleware at any time as long as it has no breaking changes.
+Supabase is evolving fast, and we'll continue to improve the migration strategy as part of our core offering.
+
+We realize that database migrations are difficult, and this is one of the problems we plan to make easy for developers.
+
+## Deployment options
+
+While Supabase officially supports Docker, we have several other deployment strategies managed by the community:
+
+- [supabase-docker](/docs/guides/hosting/docker) (Official)
+- [supabase-kubernetes](https://github.com/supabase-community/supabase-kubernetes) (Unofficial)
+- [supabase-terraform](https://github.com/supabase-community/supabase-terraform) (Unofficial)
+- [supabase-traefik](https://github.com/supabase-community/supabase-traefik) (Unofficial)
diff --git a/apps/reference/docs/guides/hosting/platform.mdx b/apps/reference/docs/guides/hosting/platform.mdx
new file mode 100644
index 00000000000..3543469ad40
--- /dev/null
+++ b/apps/reference/docs/guides/hosting/platform.mdx
@@ -0,0 +1,35 @@
+---
+id: platform
+title: Supabase Platform
+description: Getting started with the Supabase platform.
+---
+
+
+Supabase is a hosted platform which makes it very simple to get started without needing to manage any infrastructure.
+
+Visit [app.supabase.com](https://app.supabase.com) and sign in to start creating projects.
+
+## Organizations
+
+Organizations are a way to group your projects. Every Organization can be configured with different Team members and billing settings.
+
+### Managing Team Members
+
+You can invite your Team members into your Organizations so that you can collaborate on projects.
+
+
+
+## Projects
+
+Each project on Supabase comes with these features:
+
+- A dedicated Postgres database. [Learn more](/docs/guides/database)
+- Auto-generated APIs. [Learn more](/docs/guides/api)
+- Auth and User management. [Learn more](/docs/guides/auth)
+- Storage. [Learn more](/docs/guides/storage)
+
+## Next Steps
+
+- Sign in to [app.supabase.com](https://app.supabase.com)
diff --git a/apps/reference/docs/guides/integrations/appsmith.mdx b/apps/reference/docs/guides/integrations/appsmith.mdx
new file mode 100644
index 00000000000..ff9d330752a
--- /dev/null
+++ b/apps/reference/docs/guides/integrations/appsmith.mdx
@@ -0,0 +1,151 @@
+---
+id: appsmith
+title: 'Appsmith'
+description: 'Get started with Supabase and Appsmith, an open-source framework for building internal tools.'
+---
+
+This guide explains how to quickly build a Support Dashboard by connecting a Supabase back-end to an Appsmith front-end.
+
+[Appsmith](https://www.appsmith.com/) is an open-source framework for building internal tools. It lets you drag-and-drop UI components to build pages, connect to any API, database or GraphQL source and write logic with JavaScript objects.
+
+If you don’t have an Appsmith account, create one [here](https://app.appsmith.com/user/signup).
+
+Let’s get started!
+
+## Step 1: Set up your Backend on Supabase
+
+- On the [Supabase dashboard](https://app.supabase.com), click `New project` and set the name to **Support Dashboard**
+
+
+
+- Create a new table by clicking on the Create Table option on the side navigation.
+- Supabase provides many ways to add data to the tables, from writing queries to creating schemas using UI to simply uploading CSV files. For our support dashboard, we will be creating the **tickets** table by uploading the [CSV file](https://raw.githubusercontent.com/vihar/datasets/master/tickets.csv) on Supabase.
+
+
+
+The database is now set up.
+
+## Step 2: Connect the database to Appsmith
+
+- Note down the database connection information under Project Settings in Supabase.
+
+
+
+- On Appsmith, create a new application under the dashboard under your preferred organization.
+- Click on the `+` icon next to Datasources on the left navigation bar under Page1
+- Next, click on Create New tab and choose PostgreSQL datasource, you’ll see the following screenshot:
+
+
+
+- Fill out the form to connect to your Supabase instance. Click **Test** to test connection and then **Save** to save the datasource
+
+
+
+## Step 3: Build UI on Appsmith
+
+- Click on the + icon next to widgets and drag and drop a Tab widget. We can configure using the property pane by clicking on the cog icon on the top-right corner.
+- As seen in the below screenshot, we have added four tabs to support the dashboard.
+
+
+
+- Add widgets to the **Home** tab to create the dashboard as shown in the screenshot below. For eg: **Critical Open Issues** is a **Text** widget and below it is an **Input** widget which we will bind later to display the number of open tickets.
+
+- Set up the **New** button to open a modal which will have a form to raise a new ticket.
+
+
+
+- In the modal widget, add a few widgets to accept input when creating a new ticket. Please refer to the screenshot below.
+
+
+
+## Step 4: Writing Queries in Appsmith and binding data to widgets
+
+- Click on the + icon next to Datasources on the navigation bar and click New Query next to the Supabase connection here to create a new query.
+
+
+
+- Rename the query to create_new_ticket under the query pane; here we can write SQL that can collect the data from the widgets using mustache templates.
+
+```jsx
+INSERT INTO PUBLIC."tickets"("id","createdAt","user","updatedAt","description",
+"status","priority","category","assignedTo")
+VALUES('{{appsmith.store.ticket.id}}','{{moment().format('yyyy-mm-ddHH:MM:ss')}}','{{c_user.text}}',
+'{{moment().format('yyyy-mm-ddHH:MM:ss')}}','{{c_description.text}}','{{c_status.selectedOptionValue}}',
+'{{c_property.selectedOptionValue}}',
+'{{c_category.selectedOptionValue}}','{{c_assignee.selectedOptionValue}}');
+```
+
+- Click the **Confirm** button on the modal and under **Events**, set the **onClick** property to execute the create_new_ticket query.
+- Create a second query named **get_tickets** that will list all the tickets.
+
+ ****
+
+```jsx
+SELECT * FROM public."tickets";
+```
+
+- Drag and drop a table widget under the **Assigned To Me** tab. Open the property pane and add the following snippet under **Table Data** to bind the query results.
+
+```jsx
+{{get_tickets.data.filter(t => t.assignedTo === 'confidence@appsmith.com' && t.status !== 'closed')}}
+```
+
+- Drag and drop a table widget under the **Resolved** tab. Open the property pane and add the following snippet under **Table Data** to bind the query results.
+
+```jsx
+{{get_tickets.data.filter(t => t.status === 'open')}}
+```
+
+- Drag and drop a table widget under the **Closed** tab. Open the property pane and add the following snippet under **Table Data** to bind the query results.
+
+```jsx
+{{get_tickets.data.filter(t => t.status === 'closed')}}
+```
+
+## Step 5: Creating Charts in Appsmith
+
+- On the **Home** tab, click on the first Chart widget. Add Title **Open Issues By Category**. Change the **Chart Type** property to **Column Chart**.
+- Update the x-axis and y-axis Labels under **Axis** on the property pane.
+- Add the following code snippet under the **Series Data** property to bind the data to be displayed on the x and y axes.
+
+```jsx
+[
+ {
+ "x": "Hardware",
+ "y": {{get_tickets.data.filter(t => t.status==='open' && t.category==='hardware').length}}
+ },
+ {
+ "x": "Software",
+ "y": {{get_tickets.data.filter(t => t.status==='open' && t.category==='software').length}}
+ },
+ {
+ "x": "Other",
+ "y": {{get_tickets.data.filter(t => t.status==='open' && t.category==='other').length}}
+ }
+]
+```
+
+- The second chart will be a pie chart. Add the title, axes labels as mentioned above,
+- Add the following code snippet under the **Series Data** property of the pie chart.
+
+```jsx
+[
+ {
+ "x": "High",
+ "y": {{get_tickets.data.filter(t => t.status==='open' && t.priority==='high').length}}
+ },
+ {
+ "x": "Medium",
+ "y": {{get_tickets.data.filter(t => t.status==='open' && t.priority==='medium').length}}
+ },
+ {
+ "x": "Low",
+ "y": {{get_tickets.data.filter(t => t.status==='open' && t.priority==='low').length}}
+ }
+]
+```
+
+## Resources
+- [Appsmith](https://www.appsmith.com/) official website.
+- [Appsmith GitHub](https://github.com/appsmithorg).
+- [Appsmith](https://docs.appsmith.com/) documentation.
\ No newline at end of file
diff --git a/apps/reference/docs/guides/integrations/auth0.mdx b/apps/reference/docs/guides/integrations/auth0.mdx
new file mode 100644
index 00000000000..03dc5270dff
--- /dev/null
+++ b/apps/reference/docs/guides/integrations/auth0.mdx
@@ -0,0 +1,458 @@
+---
+id: auth0
+title: 'Auth0'
+description: 'Swap out Supabase authentication with Auth0. Let Auth0 handle tokens and signing users in and out, while Supabase enforces authorization policies with Row Level Security (RLS).'
+---
+
+This guide steps through building a Next.js application with Auth0 and Supabase. We configure Auth0 to handle authenticating users and managing tokens, while writing our authorization logic in Supabase - using Row Level Security policies.
+
+> Note: This guide is heavily inspired by the [Using Next.js and Auth0 with Supabase](https://auth0.com/blog/using-nextjs-and-auth0-with-supabase/) article on [Auth0's blog](https://auth0.com/blog/). Check it out for a practical step-by-step guide on integrating Auth0 and Supabase.
+
+The full code example for this guide can be found [here](https://github.com/dijonmusters/supabase-auth0-example).
+
+[Auth0](https://auth0.com/) is an authentication and authorization platform, offering numerous strategies to authenticate and manage users. It provides fine-grain control over how users sign in to your application, the token that is generated, and what data is stored about your users.
+
+[Next.js](https://nextjs.org/) is a web application framework built on top of React. We will be using it for this example, as it allows us to write server-side logic within our application. Auth0 have also written a [very well integrated authentication library](https://www.npmjs.com/package/@auth0/nextjs-auth0) specifically for Next.js.
+
+> Note: API routes (serverless functions) in Next.js closely resemble the structure of Node server frameworks - such as Express, Koa and Fastify. The server-side logic in this guide could easily be refactored in one of these frameworks and managed as a separate application to the front-end.
+
+If you don’t have an Auth0 account, create one [here](https://auth0.com/signup).
+
+You will also need a Supabase account, which can be created by signing in [here](https://app.supabase.com/).
+
+## Step 1: Creating an Auth0 tenant
+
+From the Auth0 dashboard, click the menu to the right of the Auth0 logo, and select `Create tenant`.
+
+
+
+Enter a `Domain` for your tenant - this will need to be unique.
+
+Select a `Region` - this should be geographically close to the majority of your users.
+
+Select `Development` for `Environment Tag` - this should be production when you're ready to go live.
+
+
+
+## Step 2: Setting up an Auth0 application
+
+From the sidebar menu, select `Applications` > `Applications` and click `Create Application`.
+
+Give your application a name, select the `Regular Web Applications` option and click `Create`.
+
+
+
+Select `Settings` and navigate to the `Application URIs` section, and update the following:
+
+`Allowed Callback URLs`: `http://localhost:3000/api/auth/callback`
+
+`Allowed Logout URLs`: `http://localhost:3000`
+
+Scroll to the bottom of the `Settings` section and reveal the `Advanced Settings`.
+
+Select `OAuth` and set `JSON Web Token Signature` to `RS256`.
+
+Confirm `OIDC Conformant` is `Enabled`.
+
+Click `Save` to update the settings.
+
+## Step 3: Creating a Supabase project
+
+From your [Supabase dashboard](https://app.supabase.com/), click `New project`.
+
+Enter a `Name` for your Supabase project.
+
+Enter a secure `Database Password`.
+
+Select the same `Region` you selected for your Auth0 tenant.
+
+Click `Create new project`.
+
+
+
+## Step 4: Creating data in Supabase
+
+From the sidebar menu in the [Supabase dashboard](https://app.supabase.com/), click `Table editor`, then `New table`.
+
+Enter `todo` as the `Name` field.
+
+Select `Enable Row Level Security (RLS)`.
+
+Create two new columns:
+
+- `title` as `text`
+- `user_id` as `text`
+- `is_complete` as `bool` with the default value `false`
+
+Click `Save` to create the new table.
+
+
+
+From the `Table editor` view, select the `todo` table and click `Insert row`.
+
+Fill out the `title` field and click `Save`.
+
+
+
+Click `Insert row` and add a couple of extra todos.
+
+
+
+## Step 5: Building a Next.js app
+
+Create a new Next.js project:
+
+```bash
+npx create-next-app
+```
+
+Create a `.env.local` file and enter the following values:
+
+```
+AUTH0_SECRET=any-secure-value
+AUTH0_BASE_URL=http://localhost:3000
+AUTH0_ISSUER_BASE_URL=https://..auth0.com
+AUTH0_CLIENT_ID=get-from-auth0-dashboard
+AUTH0_CLIENT_SECRET=get-from-auth0-dashboard
+NEXT_PUBLIC_SUPABASE_URL=get-from-supabase-dashboard
+NEXT_PUBLIC_SUPABASE_KEY=get-from-supabase-dashboard
+SUPABASE_SIGNING_SECRET=get-from-supabase-dashboard
+```
+
+> Note: Auth0 values can be found under `Settings > Basic Information` for your application.
+
+
+
+> Note: Supabase values can be found under `Settings > API` for your project.
+
+
+
+Restart your Next.js development server to read in the new values from `.env.local`.
+
+```bash
+npm run dev
+```
+
+## Step 6: Install Auth0 Next.js library
+
+Install the `@auth0/nextjs-auth0` library.
+
+```bash
+npm i @auth0/nextjs-auth0
+```
+
+Create a new file `pages/api/auth/[...auth0].js` and add:
+
+```jsx
+// pages/api/auth/[...auth0].js
+
+import { handleAuth } from '@auth0/nextjs-auth0'
+
+export default handleAuth()
+```
+
+> Note: This will create a few API routes for us. The main ones we will use are `/api/auth/login` and `/api/auth/logout` to handle signing users in and out.
+
+Open `pages/_app.js` and wrap our `Component` with the `UserProvider` from Auth0:
+
+```jsx
+// pages/_app.js
+
+import React from 'react'
+import { UserProvider } from '@auth0/nextjs-auth0'
+
+const App = ({ Component, pageProps }) => {
+ return (
+
+
+
+ )
+}
+
+export default App
+```
+
+Update `pages/index.js` to ensure the user is logged in to view the landing page.
+
+```jsx
+// pages/index.js
+
+import styles from '../styles/Home.module.css'
+import { withPageAuthRequired } from '@auth0/nextjs-auth0'
+import Link from 'next/link'
+
+const Index = ({ user }) => {
+ return (
+