← Back to home
Comparison · Infra & APIs

Supabase vs Rootly

A side-by-side editorial comparison of Supabase and Rootly — release velocity, themes, recent moves, and the top alternatives to consider.

Supabase vs Rootly: at a glance

FeatureSupabaseRootly
SectorInfra & APIs, DevOpsInfra & APIs
Velocity score0.06.3
Sparks · 30d01
Top themessecure-defaults, breaking-changes, row-level-security, postgrestincident-response, on-call, ai-agents, observability
Last editorial update3h ago1h ago
WebsiteVisit →

What is Supabase?

Supabase is closing its most-exploited default: tables stop being public unless you say so.

The last month is dominated by tightening defaults rather than adding surface. New tables in the public schema will no longer be auto-exposed to the Data and GraphQL APIs, pg_graphql stops being enabled by default, and the OAuth token endpoint is being corrected to return 200 per OAuth 2.1. Alongside that, custom OAuth/OIDC providers landed for Auth and an RLS Tester entered preview.

Read the full Supabase trajectory →

What is Rootly?

Rootly's AI stops summarizing incidents and starts investigating them.

Rootly runs incident response — on-call, alerting, status pages, retrospectives — and its AI work has been arriving in a clear sequence rather than as one launch. In July the agent moved into the web app as a chat panel on every incident, retrospective templates gained AI blocks that draft from incident data, Slack, and call transcripts with prompts and sources visible, and the newest release lets the AI pull evidence from observability, code, infrastructure, feature flag, ticketing, and documentation tools. Alongside that, the operational surface kept filling in: Cortex catalog sync, Intune policy support on mobile, an on-call pay calculator, and a one-command setup that pages your phone to prove the configuration works.

Read the full Rootly trajectory →

Supabase vs Rootly: editorial side-by-side

Supabase logo
Supabase
INFRA · APISDEVOPS
0.0

Supabase is closing its most-exploited default: tables stop being public unless you say so.

◆ Current state

The last month is dominated by tightening defaults rather than adding surface. New tables in the public schema will no longer be auto-exposed to the Data and GraphQL APIs, pg_graphql stops being enabled by default, and the OAuth token endpoint is being corrected to return 200 per OAuth 2.1. Alongside that, custom OAuth/OIDC providers landed for Auth and an RLS Tester entered preview.

◆ Where it's heading

Supabase is paying down the security cost of its own convenience. Auto-exposing every public-schema table made the product fast to start with and easy to misconfigure; the fix is explicit Postgres grants, staged over six months from new projects in April to all existing projects on October 30. The RLS Tester is the same theme from the other side — the auto-exposure default only worked if row-level security was correct, and until now there was no way to check.

◆ Prediction

Expect the remaining rollout dates to hold and more of the developer experience to be rebuilt around explicit grants, with the RLS Tester graduating from preview as it becomes the tool people need to verify the new model. The October cutover for existing projects is the moment where this stops being an announcement and starts breaking things.

R
Rootly
INFRA · APIS
6.3

Rootly's AI stops summarizing incidents and starts investigating them.

◆ Current state

Rootly runs incident response — on-call, alerting, status pages, retrospectives — and its AI work has been arriving in a clear sequence rather than as one launch. In July the agent moved into the web app as a chat panel on every incident, retrospective templates gained AI blocks that draft from incident data, Slack, and call transcripts with prompts and sources visible, and the newest release lets the AI pull evidence from observability, code, infrastructure, feature flag, ticketing, and documentation tools. Alongside that, the operational surface kept filling in: Cortex catalog sync, Intune policy support on mobile, an on-call pay calculator, and a one-command setup that pages your phone to prove the configuration works.

◆ Where it's heading

The AI features are being built with their working shown — every prompt and source visible in retrospectives, evidence gathering that is explicitly read-only with nothing stored. That is a deliberate answer to the reason engineers distrust AI during an incident: an unattributed claim at 3am is worse than no claim. The direction is toward an agent that reaches into the same systems a responder would check, while the surrounding releases reduce the setup and configuration cost that has historically made incident tooling a quarter-long adoption project.

◆ Prediction

Evidence gathering that is read-only today is the obvious foundation for suggested remediation tomorrow; expect the next step to be Rootly proposing actions from that evidence, with the same source-visible framing used to make it reviewable.

Alternatives to Supabase and Rootly

Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Supabase or Rootly.

See all Supabase alternatives → · See all Rootly alternatives →

Recent activity from Supabase and Rootly

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 2d agoRootlyRootly AI now gathers incident evidence across your entire stack.
  2. 7d agoRootlyFrom sign up to incident-ready in minutes.
  3. 14d agoRootlyThe on-call widget, 24-hour time, and a new Alerts table.
  4. 21d agoRootlyRetrospective templates with customizable AI-blocks.
  5. 21d agoRootlyRetrospective templates with customizable AI-blocks
  6. 29d agoRootlyAsk anything about an incident, right in the web app.
  7. 2mo agoSupabaseDeprecation Notice: Dropping Support for Node.js 20
  8. 2mo agoSupabaseDeveloper Update - May 2026
  9. 3mo agoSupabaseBreaking Change: OAuth token endpoint will return HTTP 200 instead of 201
  10. 3mo agoSupabaseBreaking Change: Tables not exposed to Data and GraphQL API automatically
  11. 3mo agoSupabaseFragment of the no-auto-expose announcement
  12. 3mo agoSupabaseFeature Preview: RLS Tester

Frequently asked questions

What is the difference between Supabase and Rootly?

They serve adjacent needs but don't currently overlap on shipped themes. Rootly is currently shipping more aggressively (velocity 6.3 vs 0.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Supabase better than Rootly?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Rootly is currently shipping more aggressively (velocity 6.3 vs 0.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.

What are the best alternatives to Supabase?

Top Supabase alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Supabase alternatives" section above for the current picks, or visit /alternatives/supabase for the full list with editorial commentary on each.

What are the best alternatives to Rootly?

Top Rootly alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Rootly alternatives" section above for the current picks, or visit /alternatives/rootly for the full list with editorial commentary on each.