Cloudflare D1 vs Supabase — a comparison that is usually a category error
Supabase is a backend platform built on Postgres. D1 is a SQLite database bound to your Worker. Comparing them head-to-head is wrong, and the right comparison is more useful. With real August 2026 pricing.
Most "D1 vs Supabase" posts line up two feature tables and pick a winner. That framing is broken before it starts.
Supabase is a backend platform — Postgres plus auth, storage, realtime, vector search, and edge functions, sold as one product. D1 is a database — SQLite, bound to a Worker, and nothing else.
So the honest comparison is not "which database is better." It is: do you want a platform that hands you five services, or primitives you assemble yourself? Answer that and the database question mostly answers itself.
FlareStarter Pro runs on D1. Here is the reasoning, including where Supabase is plainly the better tool.
The pricing, stated fairly
Published rates as of 2026-08-23.
Cloudflare D1 — included in the $5/month Workers Paid plan, not billed separately:
| Included | Overage | |
|---|---|---|
| Rows read | 25 billion / month | $0.001 / million |
| Rows written | 50 million / month | $1.00 / million |
| Storage | 5 GB | $0.75 / GB-month |
Free tier: 5 million rows read per day, 5 GB storage.
Supabase Pro — $25/month, including $10 of compute credit:
| Included | Overage | |
|---|---|---|
| Database storage | 8 GB | $0.125 / GB |
| MAU | 100,000 | $0.00325 / MAU |
| Egress | 250 GB | $0.09 / GB |
Free tier: 500 MB database, 50,000 MAU, 5 GB egress, max 2 projects — and free projects pause after one week of inactivity.
Two observations that matter more than the headline numbers:
The billing dimensions are different, so per-unit comparison is meaningless. D1 charges for rows touched. Supabase charges for storage, egress, and users. A read-heavy app with small rows is cheap on D1 and moderate on Supabase; a large-storage app with few queries inverts that.
25 billion included row reads is a very high ceiling. For typical B2B SaaS query patterns most teams will not approach it. That is the single strongest economic argument for D1.
The free-tier pause is the strongest argument against Supabase free. A side project that sleeps for a week comes back down. D1 has no such behaviour.
What Postgres has that SQLite does not
This is where D1 loses, and it loses clearly:
- Extensions.
pgvectorfor embeddings, PostGIS for geo, full-text search that is actually good. If you are building AI features that need vector search in the database, D1 does not have an answer and Supabase does. - Row Level Security. Supabase's whole client-side model rests on RLS — the browser talks to the database and policies enforce access. D1 has no equivalent; every query goes through your Worker, which enforces access in code.
- Concurrency. Postgres handles many concurrent writers. SQLite serialises writes by design.
- Types and SQL surface. Rich types, window functions, CTEs, materialised views. SQLite covers a lot of this now, but not all of it.
- Realtime subscriptions, out of the box, over websockets.
If any of those is load-bearing for your product, stop reading and use Supabase. This is not close.
What binding beats connecting
D1's advantage is not the database engine. It is where the database sits relative to your code.
A D1 database is a binding — an object injected into your Worker's environment. There is no connection string, no pool, no TLS handshake, no "too many connections" error at 3am. Serverless runtimes and connection-pooled databases have an awkward relationship, and Cloudflare sidestepped it by not having connections.
Supabase from Cloudflare Workers works, but you are reaching a Postgres instance over the network from an isolate. You use the HTTP layer or a pooler, and you accept the hop. That hop is usually fine. It is never zero.
In FlareStarter Pro this shows up as: organization membership, seat subscriptions, credit ledgers, API keys, and audit rows are all foreign-keyed in one D1 database, queried from the same Worker that serves the request, with no pool to exhaust and no separate service to be down.
Where D1 will bite you
Being specific about the pain, since most posts advocating D1 are not:
- Writes serialise. A write-heavy workload — high-frequency event ingestion, say — is the wrong shape for D1.
- Migrations are forever. Once production has applied a migration, its history is frozen. This is true of any database, but D1's tooling gives you less room to fix mistakes.
- The ecosystem is smaller. Fewer ORMs fully support it, fewer tools inspect it, fewer people have hit your bug.
- No RLS means access control is your code's job. That is a real, ongoing security responsibility that Supabase can push into the database.
- You assemble the rest. Auth, storage, realtime — Supabase includes them, D1 does not. You will be adding better-auth, R2, and Durable Objects yourself.
Choose Supabase if
- You need Postgres specifically — extensions, pgvector, full-text search, complex SQL.
- You want RLS, so the client can talk to the database safely.
- You want auth, storage, and realtime bundled and working on day one.
- Your workload is write-heavy or highly concurrent.
- You are not on Cloudflare, in which case D1's main advantage does not apply to you.
Choose D1 if
- You are already on Workers and want the database inside the same runtime.
- Your workload is read-heavy — that 25 billion row ceiling is real money saved.
- You want one bill and one platform rather than a stack of vendors.
- You are comfortable enforcing access control in application code.
- You want a free tier that does not go to sleep.
The summary
If you are not on Cloudflare, this comparison is easy: use Supabase. D1's advantage is proximity to the Worker, and if there is no Worker, there is no advantage.
If you are on Cloudflare, the question becomes whether you need Postgres's capabilities badly enough to reach across the network for them. For a CRUD-shaped B2B SaaS — organizations, subscriptions, ledgers, audit logs — you usually do not. For anything touching vectors, geo, or realtime, you usually do.
Pick on capabilities, not on benchmarks. The row-read ceiling only matters after the feature set already fits.
FlareStarter Pro is built on D1 and KV inside a single Worker — organizations, seat billing, an append-only credit ledger, API-key rate limiting, and an audit trail, all foreign-keyed in one database.
Pricing is from Cloudflare's and Supabase's published pages as of 2026-08-23 and will drift.