Vercel
Vercel keeps stacking the deployment platform for the agent era
A side-by-side editorial comparison of Supabase and Merge — release velocity, themes, recent moves, and the top alternatives to consider.
| Feature | Supabase | Merge |
|---|---|---|
| Sector | Infra & APIs, DevOps | Infra & APIs |
| Velocity score | 6.3 | 5.0 |
| Sparks · 30d | 0 | 0 |
| Top themes | security-defaults, rls-testing, breaking-changes, oauth-compliance | unified-api, accounting-integrations, multi-tenant-identity, object-urls |
| Last editorial update | 1mo ago | 10d ago |
| Website | Visit → | — |
Supabase is reversing its biggest security default - public-schema tables no longer auto-exposed via PostgREST.
The headline shipping move is a deliberate change to Supabase's security posture: new projects can opt out of automatic Data API and GraphQL exposure for public-schema tables, with broader defaults flipping in May. Around it: an OAuth 2.1 compliance fix, an RLS Tester preview to make policy verification possible from the UI, and a steady drumbeat of platform improvements summarized in the monthly developer update.
Merge raises the floor on integration fidelity — object URLs and per-tenant identity, week after week.
Merge ships a weekly changelog rhythm across Accounting, ATS, CRM, File Storage, and Chat. Recent weeks emphasize two motifs: making cross-system object URLs first-class in unified responses (Xero, NetSuite, Oracle Fusion) and exposing per-tenant identification on linked accounts so B2B SaaS customers can disambiguate multi-org installs (HubSpot, Dynamics, Zoho, Pipedrive). The cadence is dense and field-level, weighted toward mapping enhancements, webhook fidelity, and edge-case fixes per integration.
The headline shipping move is a deliberate change to Supabase's security posture: new projects can opt out of automatic Data API and GraphQL exposure for public-schema tables, with broader defaults flipping in May. Around it: an OAuth 2.1 compliance fix, an RLS Tester preview to make policy verification possible from the UI, and a steady drumbeat of platform improvements summarized in the monthly developer update.
Supabase is rebuilding the security defaults that made it fast to start with but easy to misconfigure. Combine the no-auto-expose change with the RLS Tester preview and the direction is clear: the platform is moving from convention-based exposure to explicit, testable access control. The OAuth compliance fix and developer updates suggest steady investment in standards conformance rather than new product surface this window.
Expect the no-auto-expose default to apply to existing projects (with a long opt-out runway), and the RLS Tester to graduate from preview into the dashboard as a first-class panel. Continued breaking-change drumbeat tied to OAuth/OIDC compliance is likely.
Merge ships a weekly changelog rhythm across Accounting, ATS, CRM, File Storage, and Chat. Recent weeks emphasize two motifs: making cross-system object URLs first-class in unified responses (Xero, NetSuite, Oracle Fusion) and exposing per-tenant identification on linked accounts so B2B SaaS customers can disambiguate multi-org installs (HubSpot, Dynamics, Zoho, Pipedrive). The cadence is dense and field-level, weighted toward mapping enhancements, webhook fidelity, and edge-case fixes per integration.
Two clear pulls. First, raising the floor on data fidelity — every endpoint should surface an object URL, every linked account should expose tenant identity. Second, expanding Accounting Unified API coverage in both directions, with Oracle Fusion Cloud ERP joining in beta alongside continued NetSuite and QuickBooks polish. Merge is treating the unified API less as a thin translation layer and more as a normalization product where the parity bar keeps moving up.
Expect Oracle Fusion Cloud ERP to graduate from beta with broader endpoint coverage, more tenant-identification rollouts to less-mature CRM connectors, and continued webhook-parity work for write operations across Accounting providers.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Supabase or Merge.
Vercel keeps stacking the deployment platform for the agent era
Auth0 is re-tooling identity for AI agents and B2B multi-tenancy
GitHub bends its security stack toward governing the coding agents now writing the code.
Buildkite goes agent-native and secretless while easing the path off GitHub Actions
Ably is rebuilding its realtime stack around AI agents: transport SDK and agent-native CLI
Cohere is widening from chat into a full enterprise model suite: code, audio, and retrieval.
See all Supabase alternatives → · See all Merge alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Supabase is currently shipping more aggressively (velocity 6.3 vs 5.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Supabase is currently shipping more aggressively (velocity 6.3 vs 5.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Supabase alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Supabase alternatives" section above for the current picks, or visit /alternatives/supabase for the full list with editorial commentary on each.
Top Merge alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Merge alternatives" section above for the current picks, or visit /alternatives/merge-dev for the full list with editorial commentary on each.