shouldiuse.io

Categories

VERDICT

PostgREST 16 Review

Depends

Should I use PostgREST 16?

Standalone web server that turns your PostgreSQL database directly into a RESTful API. - postgrest.org

· 1 day ago

Buy it if you know Postgres well and want the database itself to be the API — it's free and mature. Skip it if you need vendor support, managed auth, or zero database administration.

Confidence

Medium. Based on ~30 public sources; many discuss PostgreSQL generally, fewer review PostgREST directly.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo support evidence found
  • Security posture

Pricing

Free

Open source

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes

Best for

  • Postgres-first developers
  • Internal tools and admin APIs
  • Teams treating the DB as single source of truth
  • CRUD backends without custom servers

Not for

  • Non-technical teams wanting a managed API — no vendor to call
  • Buyers needing SLAs, vendor support, or a pricing plan
  • Teams unwilling to own Postgres roles, RLS, and schema design
  • Projects needing custom business logic beyond CRUD endpoints

Gotchas - check before you buy

high

Leaving Supabase Cloud surfaces PostgREST config failures that produce no error

medium

PostgREST caps returned rows by default; check limits before scaling

medium

No security page on the site; you must track Postgres CVEs yourself

medium

Free means self-support: community docs, no vendor SLA

Pros and cons

Pros

  • Turns any PostgreSQL database into a RESTful API instantly
  • Database constraints and permissions define endpoints — one source of truth
  • Ten years of public use; Hacker News coverage since 2015
  • Detailed docs: RPC, aggregates, OpenAPI, observability

Cons

  • Requires deep PostgreSQL knowledge — roles, RLS, schema design
  • No dedicated security page found on
  • Supabase-to-self-hosted migrations hit silent PostgREST config failures
  • Default row caps can silently truncate API responses

Sources & method

- 8 sources - No known vulnerabilities found in the sources reviewed.

official x2review x4security x1news x1

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 8

    Sources

  • Analyzed

  • Value for money: 5/5. Free and open source
  • Ease of use: 3/5. Easy for Postgres pros; steep otherwise
  • Feature depth: 5/5. RPC, aggregates, OpenAPI, row-level auth documented
  • Support quality. No support evidence found
  • Security posture: 4/5. Delegates auth to Postgres roles and RLS
  • Free Starting price Open source, self-hosted
  • Yes Free tier Entire product is free
  • Since 2015 Track record Hacker News coverage since July 2015
  • 16 Version reviewed Latest major docs version

Pricing

Open source

Free

  • Full API server, self-hosted
  • Sponsorship-funded development

Security

No known vulnerabilities found in the sources reviewed.

What users say

Developers on Hacker News and Reddit praise PostgREST for spinning up APIs straight from Postgres, with complaints sparse in available sources.

“I use PostgREST for personal APIs”
Reddit, r/programming
“PostgREST is great”
Hacker News
“PostgREST caps returned rows”
Amdahl AI changelog

Companies that use it

Full analysis

Based on ~30 public sources; many discuss PostgreSQL generally, fewer review PostgREST directly.

Free, 10-year-old Postgres-to-REST server. Ideal for Postgres-fluent devs; wrong for teams wanting managed support.

Methodology

Based on ~30 public sources; many discuss PostgreSQL generally, fewer review PostgREST directly.

Read how a report is made.

Sources

  1. official
  2. official
  3. security
  4. review
  5. review
  6. review
  7. news
  8. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.