Rather than a five-star ranking, here is a grid of ten verifiable criteria applied to six platforms – Aurabase, Supabase, Firebase, Appwrite, Convex and PocketBase – with dated and sourced figures rather than marketing slogans repeated as is.
The essentials
- No platform wins on the ten criteria of the grid: the right choice depends on your priority (SQL portability, startup speed, packaged self-hosting, or native AI).
- On the entry fee level, Aurabase (€25), Supabase ($25), Appwrite (from $25) and Convex ($25/developer) converge within a few euros — the difference comes down to the included quotas and the currency, not the order of magnitude.
- Three criteria distinguish Aurabase from the rest of the panel: native NL2SQL and RAG on Postgres, 15 named OAuth providers + unlimited OIDC, and verified production infrastructure in Germany and Finland.
- Firebase (proprietary NoSQL) and PocketBase (mono-binary SQLite) remain the quickest choices to get started — at the respective price of lock-in and the absence of an official managed cloud.
The grid of ten criteria, not a ranking
A “best BaaS” assumes a single axis of comparison. In practice, an independent developer who fears vendor lock-in, a CTO who must prove his GDPR compliance to a DPO and an AI developer who wants ready-to-use pgvector are not looking for the same thing.
This grid retains ten criteria which systematically come up in these three decisions: data engine, application core, authentication, real time, native AI, serverless functions, self-hosting, license, free tier and paid entry tier.
Each cell in the table is verified at its source: the Aurabase repository code for Aurabase product claims (see studio/lib/plans.ts, Cargo.toml, aura-auth, aura-ai), the official GitHub pricing and repository pages of the five other platforms, consulted on August 23, 2026. A cell marked "not documented to our knowledge" indicates an absence of proof found on that date, not a confirmed absence — check up-to-date documentation before deciding.
The table: six BaaS, ten criteria
Scroll horizontally on mobile. The Aurabase column is highlighted for reference, not to suggest an overall score.
| Criterion | Aurabase | Supabase | Firebase | Appwrite | Convex | PocketBase |
|---|---|---|---|---|---|---|
| Data engine | PostgreSQL 16 dedicated per project, RLS, pgvector 0.8.6 | Dedicated PostgreSQL per project, RLS | Firestore + Realtime DB (NoSQL, proprietary) | Internal multi-engine (TablesDB), no Postgres exposed | Proprietary reactive database (not SQL) | Embedded SQLite, single file |
| Application core | 100% Rust (axum), 12 services, shared internal libs | Multi-language: PostgREST (Haskell), GoTrue (Go), Realtime (Elixir), Storage (Node.js) | Google proprietary, not publicly documented | Multi-service platform (mainly Node.js) | Rust backend, TypeScript clients | GB, single-binary (~15 MB) |
| Authentication | 15 named OAuth providers + unlimited generic OIDC | Wide range of OAuth (evolving list, no fixed number published) | Multi-vendor OAuth + email/phone/anonymous | OAuth + magic links, multi-vendor | No native provider — delegation to a third party (not verified in detail here) | Email/password + configurable OAuth2 (Google, Facebook, GitHub, GitLab documented) |
| Real time | Native Postgres CDC via NATS JetStream | Native channels (postgres_changes, presence, broadcast) | Native on both bases (onSnapshot) | Dedicated Realtime service | Responsive by construction (read-set + WebSocket) | Integrated real-time subscriptions |
| Native AI (NL2SQL / RAG) | Native NL2SQL + RAG, embedded pgvector, 3 native LLMs | External AI connectors, no native NL2SQL documented | Genkit/Vertex AI on the GCP side, excluding BaaS backend itself | Not documented to our knowledge | No equivalent documented native NL2SQL capability | Not documented to our knowledge |
| Serverless/edge functions | Deno/TypeScript (V8) + Rust→WASM binaries (real Wasmtime) | Edge Functions (Deno) | Cloud Functions (Node.js, Python, other GCP runtimes) | Multi-runtime functions (15 documented runtimes) | TypeScript functions executed on the Rust backend side | Embedded JS hooks (integrated VM) + Go extension |
| Self-hosting | k3d / Helm in the repository, priority managed cloud | Official (Docker / CLI), documented production path | Not available | Official, central product axis (Docker, one-click DO/AWS) | Separate open source backend, prioritized managed cloud | Only mode available, no official cloud |
| License | MIT (Rust workspace + JS SDK) | Apache-2.0 | Proprietary, not open source | BSD-3-Clause | FSL-1.1-Apache-2.0 (Pure Apache 2 years after each release) | MIT |
| Free landing | 0€ · 3 projects · 512 MB DB · 1 GB storage | 0$ · 500 MB DB · 50,000 MAU · 2 active projects | Spark: Firestore 1 GiB + 50k reads/day · Realtime DB 1 GB | 0$ · 5 GB bandwidth · 2 GB storage · 75,000 MAU | 0$ + usage · 1M function calls · 0.5 GB DB | Unlimited by nature — the limit is your own server |
| Entrance fee level | 25€/month | $25/month | Pay-as-you-go (Blaze), no fixed level | from $25/month | $25/developer/month | Not applicable — no commercial offer |
One figure jumps out at the last line: four of the five commercial platforms converge on an entry fee level close to 25 (euros or dollars depending on the native currency of the platform). This isn't an isolated market coincidence — it's the point where "a few projects, a little real traffic" exceeds what a free tier can reasonably absorb, across the six platforms studied.
Firebase (Firestore)1024 MB
Convex512 MB
Aurabase512 MB
Supabase500 MB
Database storage included in the free tier, in MB. Sources: official pricing pages (supabase.com/pricing, firebase.google.com/pricing, convex.dev/pricing), consulted on August 23, 2026; Aurabase bearing checked in studio/lib/plans.ts. Appwrite and PocketBase excluded: the first does not isolate a database storage quota on its pricing page, the second does not have a commercial level (self-hosted, limit = your server).
Supabase: multi-language managed Postgres, the market benchmark
Supabase remains the benchmark in the managed Postgres market: standard RLS SQL, pg_dump portability to any Postgres server, and a supported multi-language stack (PostgREST in Haskell, GoTrue in Go, Realtime in Elixir, Storage in Node.js, Functions in Deno).
Best suited for: start on a mature managed Postgres, with an already broad ecosystem of integrations. Supabase relies on external AI connectors (ChatGPT, Claude, Perplexity) rather than native NL2SQL in the backend. Free tier: 500 MB basic, 50,000 MAU, limited to two active projects, paused after a week of inactivity. Entry fee level: $25/month.
Firebase: NoSQL Google, quick to start, locked to the ecosystem
Firebase remains the quickest choice to get started for a team already in the Google Cloud ecosystem: document-oriented NoSQL Firestore, nine free products regardless of the tier (Analytics, Crashlytics, Remote Config, etc.), and a Blaze plan for use with $300 credit.
Best suited for: rapid prototyping on the mobile/web side in a project already linked to GCP. The compromise is structural: proprietary Firestore format, no native SQL joins, and no GDPR/EU posture displayed on the pricing page — choosing a European Firestore region does not change the nationality of the parent company. Free tier: Firestore 1 GiB + 50,000 reads/day; Realtime Database 1 GB + 100 simultaneous connections. No fixed level beyond that, usage-based pricing (Blaze).
Appwrite: the all-in-one self-hosted platform
Appwrite assembles Auth, Databases, Storage, Functions (15 runtimes), Messaging and Realtime in a single repository under BSD-3-Clauselicense, with a Docker installer designed for self-hosting in production from day one — a product focus that Appwrite explicitly claims ("real engineering constraints, not feature marketing").
Best suited for: a team that wants to self-host a complete platform without assembling multiple services themselves. Free tier: 5 GB bandwidth, 2 GB storage, 750,000 executions, 75,000 MAU, limited to two projects. Entry fee level: from $25/month. The blind spot: none of the six platforms in this comparison, Appwrite included, is building a content pillar dedicated to GDPR/CLOUD Act compliance.
Convex: the reactive backend that refuses marketing benchmarks
Convex takes the opposite approach to comparative marketing: the team publicly admits not to publish benchmarks in the face of competition (“I don’t care about your database benchmarks”), and offers a reactive backend where each request remains synchronized by construction, without subscription code to write.
Best suited for: a TypeScript-first team that wants responsive native without manually assembling WebSockets and caching. A self-hosted open source backend exists (convex-backend, written in Rust, FSL-1.1-Apache-2.0 license which switches to Apache 2.0 pure two years after each version), even if the main commercial offering remains 100% managed cloud. Free tier: 1 million function calls, 0.5 GB of database storage. Entry fee level: $25/developer/month.
PocketBase: mono-binary for those who don't need more
PocketBase has no editorial blog, no AI connector, no official managed cloud — and that’s precisely its selling point. A single Go binary of around 15 MB includes an SQLite database, authentication (email/password + OAuth2), file storage and an admin dashboard, under MIT license.
Best suited for: an internal project, an MVP or a self-hosted tool that structurally does not need to scale beyond a single server. The compromise is just as structural: no commercial offer, no official support, and a community which had to build unofficial llms.txt repositories itself due to the lack of a version published by the maintainer.
Aurabase: Sovereign Postgres with native AI, without hiding its shortcomings
Aurabase builds its differentiator on three specific criteria of this grid rather than on the whole: a 100% unified Rust core (12 services, same internal libraries), native NL2SQL and RAG directly on Postgres (embedded pgvector, 3 native LLM providers — OpenAI, Anthropic, Gemini), and a production infrastructure verified in Germany (Nuremberg, Falkenstein) and in Finland (Helsinki), operated by a French company.
Best suited for: a team that wants standard relational Postgres with native AI, without relying on non-EU infrastructure. Free tier: 512 MB basic, 3 projects, 1 GB of storage. Entry fee level: €25/month (10 projects, 8 GB base).
The Python SDK (aurabase-py) and the Dart SDK are not yet published on their official registries (PyPI, pub.dev) — only the JavaScript SDK, 10 packages @aurabase/*, is published on npm as of today. And no WASM cold start benchmarks are published in the repository, despite an actual Wasmtime runtime in production for Edge functions compiled in Rust.
How to choose according to your profile
The grid above answers a general question. Here's how to read it according to three recurring decision profiles.
- Independent developer, fear of vendor lock-in — prioritize the “data engine” and “license” line of the grid: a standard Postgres exported by
pg_dumpremains portable to any host, which Firestore does not allow natively. See the Aurabase vs Supabase comparison and the Supabase → Aurabasemigration guide. - CTO or technical lead in SME, GDPR compliance to be documented — prioritize “self-hosting” and the question of sovereignty which does not appear in the generic table: none of the six BaaS studied builds a dedicated GDPR/CLOUD Act content pillar, apart from Aurabase. See the complete GDPR compliant and EU sovereign backend guide and the comparison Aurabase vs Firebase.
- AI developer, pgvector/RAG ready to use — prioritize the “native AI” line: this is the most discriminating criterion in the grid, with only one platform (Aurabase) documenting NL2SQL and RAG natively on Postgres at the date of this research. See the tutorial: building an NL2SQL endpoint on Postgres.
To go further on a specific face-to-face: Aurabase vs Appwrite, Aurabase vs Convex, or Aurabase vs PocketBase.
FAQs
Questions about this grid's methodology — for general questions about choosing a BaaS, see our dedicated FAQ.