Build an API route in less than 2 minutes.
Create your first API route by creating a public leaderboard table.
This guide covers creating a REST route you can query using cURL or the browser by creating a database table called leaderboard to hold player scores. This creates a corresponding API route /rest/v1/leaderboard which can accept GET, POST, PATCH, and DELETE requests.
Create a new project in the Supabase Dashboard.
After your project is ready, create a table in your Supabase database. You can do this with either the Table Editor or the SQL Editor.
1-- Create a "leaderboard" table to store2-- player names and their scores.3create table leaderboard (4 id serial primary key,5 player text not null,6 score integer not null default 0,7 created_at timestamptz default now()8);Expose the leaderboard table through the Data API so it can be queried over HTTP. A leaderboard is meant to be public, so anonymous clients only need read access.
For more control over which tables and functions are exposed, read the Grant access explicitly guide.
1-- Allow read-only access for anonymous clients2grant select on public.leaderboard to anon;Enable Row Level Security (RLS) for this table and create the policies that control who can read and write rows. For a leaderboard, anyone should be able to read scores. Only authenticated users should be able to submit or update them.
1-- Turn on RLS2alter table "leaderboard"3enable row level security;45-- Anyone can read the leaderboard6create policy "Leaderboard is public"7 on leaderboard8 for select9 to anon, authenticated10 using (true);1112-- Authenticated users can submit and update scores13create policy "Authenticated users can submit scores"14 on leaderboard15 for insert16 to authenticated17 with check (true);1819create policy "Authenticated users can update scores"20 on leaderboard21 for update22 to authenticated23 using (true)24 with check (true);With RLS setup, grant write access to the authenticated and service_role roles.
1-- Grant write access only after RLS and policies are in place2grant select, insert, update, delete on public.leaderboard to authenticated;3grant select, insert, update, delete on public.leaderboard to service_role;Now add some scores to the table so the API has something to query.
1insert into leaderboard (player, score)2values3 ('alice', 4200),4 ('bob', 3700),5 ('carol', 5100),6 ('dave', 2900);You can find your API URL and Keys in the Settings > API Settings section of the Dashboard. Query the leaderboard table by appending /rest/v1/leaderboard to the API URL.
Copy this block of code, substitute <PROJECT_REF> and <PUBLISHABLE_KEY>, then run it from a terminal.
1curl 'https://<PROJECT_REF>.supabase.co/rest/v1/leaderboard?select=*&order=score.desc' \2-H "apikey: <PUBLISHABLE_KEY>"Bonus#
There are several options for accessing your data:
Browser#
You can query the route in your browser, by appending the publishable key as a query parameter:
https://<PROJECT_REF>.supabase.co/rest/v1/leaderboard?apikey=<PUBLISHABLE_KEY>
Curl#
1curl 'https://<PROJECT_REF>.supabase.co/rest/v1/leaderboard?select=*&order=score.desc' \2 -H "apikey: <PUBLISHABLE_KEY>" \Client libraries#
We provide a number of Client Libraries.
1const { data, error } = await supabase2 .from('leaderboard')3 .select()4 .order('score', { ascending: false })