Skip to content
CAI
Software that uses CAICheck a score

supabase/supabase-swift

62.6

Adequate · 1 October 2026

36.5k

lines of production code

Swift

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This is the official Swift SDK for Supabase, providing a unified client library to interact with Supabase services including authentication, database queries, real-time subscriptions, storage, and edge functions. The system emphasizes type safety through compile-time checked query builders and macros, while supporting modern Swift concurrency patterns and robust error handling across all modules. It also includes comprehensive tooling for local development, testing, and observability via OpenTelemetry integration.

How it got here

2021–2023 — SDK v3 rewrite and modernization

26 changes.

The project underwent a comprehensive rewrite to prepare for SDK v3, replacing legacy implementations in Auth, Realtime, Storage, and Functions with modern, concurrency-safe architectures. This period introduced unified configuration, OpenTelemetry support, and a new Swift Testing suite, while significantly expanding the Examples app to demonstrate new capabilities and third-party integrations.

2024–2025 — HTTP refactoring and example expansion

18 changes.

This period focused on refactoring the HTTP layer to support streaming bodies, configurable retries, and a unified error protocol, while introducing a new Keychain storage implementation for Apple platforms. It also significantly expanded the Examples suite with comprehensive SwiftUI demonstrations for Storage, Realtime, Database, and Auth features, supported by new test utilities and integration test suites.

2026 — PostgREST type-safety and WebAuthn support

14 changes.

This period focused on introducing compile-time safety to the PostgREST client through Swift macros and typed APIs, replacing string-based queries with strongly-typed relations, filters, and mutations. Concurrently, experimental WebAuthn (passkey) authentication and MFA support was added to the Auth module, alongside infrastructure updates such as migrating logging to swift-log and unifying JSON value representations.

Features

Add UserManagement example app for Swift

The UserManagement example application is now available, demonstrating how to build a cross-platform (iOS and macOS) SwiftUI app with Supabase. It includes full authentication flows using OTP magic links with deep linking support, user profile management (reading, updating, and deleting accounts), and avatar image handling via Supabase Storage. The example also provides the necessary Supabase project configuration, including database migrations for a profiles table with Row Level Security policies and storage bucket setup.

Examples/UserManagement · high confidence

Add shared Xcode workspace and module-specific schemes

The repository now includes a shared Xcode workspace (Supabase.xcworkspace) that aggregates the library targets (Auth, Functions, PostgREST, Realtime, Storage, Supabase) and the Examples project. This change introduces individual, shared schemes for each module, allowing developers to build, test, profile, and archive specific libraries independently. The main Supabase scheme is configured to build all modules and run tests with code coverage enabled, while individual module schemes (like Auth and PostgREST) are set up to run their respective tests and generate coverage reports, improving the local development and CI experience.

Supabase.xcworkspace · high confidence

Added Supabase Edge Function example and Xcode workspace configuration

The Examples project now includes a new Supabase Edge Function example (hello-world) written in TypeScript using Deno, which accepts a JSON payload with a 'name' field and returns a greeting message. Additionally, the Xcode workspace configuration files have been added to properly set up the project structure for the Examples target.

Examples/Examples.xcodeproj/project.xcworkspace, Examples/supabase/functions · high confidence

Added Xcode schemes for Examples, SlackClone, and UserManagement apps

The Examples project now includes dedicated Xcode schemes for the Examples, SlackClone, and UserManagement sample applications. These schemes configure the build, test, launch, profile, analyze, and archive actions for each app, enabling developers to easily run and debug the individual sample apps directly from Xcode.

Examples/Examples.xcodeproj/xcshareddata · high confidence

Comprehensive UX overhaul of the Examples app with inline code documentation

The Examples app has been redesigned to provide a comprehensive user experience, featuring a new tabbed navigation structure (Database, Realtime, Storage, Functions, Profile) and a unified authentication flow. This update introduces a reusable \ActionState\ view for managing async UI states (idle, loading, success, failure with retry) and adds detailed inline code examples within the UI, such as in the new Multi-Factor Authentication (MFA) enrollment flow. The app now includes specific examples for third-party authentication integrations like Clerk, MetaMask, Google Sign-In, and Facebook, along with a password recovery flow and improved error handling via a dedicated \ErrorText\ component.

Examples/Examples · high confidence

Experimental WebAuthn (passkey) support for authentication and MFA

This change introduces experimental WebAuthn (passkey) capabilities to the Auth client, available under the \@\_spi(Experimental)\ flag. For end-users, this enables first-factor passkey authentication via \signInWithPasskey\ and \registerPasskey\ on iOS 16+/macOS 13+, as well as the ability to manage personal passkeys (list, rename, delete). It also adds WebAuthn as a second-factor (MFA) option, allowing users to enroll and verify passkey factors using native platform authenticators. Admins can now list and delete passkeys for any user via the \AuthAdmin\ extension. The implementation relies on \AuthenticationServices\ for the native UI and handles the full W3C credential exchange, including challenge generation and assertion verification.

Sources/Auth/WebAuthn · high confidence

Initial Supabase database schema and storage policies

The example application now includes a database migration that creates a \todos\ table with row-level security policies restricting access to the record owner, along with storage policies that allow authenticated users to create buckets and upload or list objects.

Examples/supabase/migrations · high confidence

Initial Supabase local development configuration for Swift examples

The Examples/supabase directory now includes a standard Supabase local development setup, providing a config.toml that initializes the local API, database (PostgreSQL 15), Studio, and email testing services on specific ports. The configuration enables anonymous sign-ins, manual account linking, and WebAuthn/passkey authentication, while also defining external OAuth providers for GitHub and Apple. A .gitignore file is added to exclude local state files, and an empty seed.sql is provided for database initialization.

Examples/supabase · high confidence

Initial Supabase local development environment and example schema

This change introduces the foundational configuration and database schema for the Supabase local development environment. It adds a \.gitignore\ to exclude local artifacts, a \config.toml\ defining the local service ports and enabled features (API, Database, Studio, Auth, Storage, Realtime), and SQL migrations that establish the \key\_value\_storage\, \todos\, \profiles\, and \messages\ tables with appropriate Row Level Security policies. Additionally, it includes a \seed.sql\ file with helper functions to populate sample data for the examples app, enabling immediate testing of CRUD operations, realtime subscriptions, and storage features locally.

supabase · high confidence

Introduce PostgrestMacrosPlugin for compile-time schema generation

This change adds the PostgrestMacrosPlugin, a Swift compiler plugin that introduces the @Table, @SelectionOf, and @Relationship macros to generate type-safe PostgREST client code. @Table generates a Columns namespace for type-safe filtering, a Draft shape for insertions, and conformance to PostgREST protocols, while @SelectionOf allows defining column subsets with automatic PostgREST select-string generation and embed support. The plugin also includes marker attributes (@Column, @PrimaryKey, @Default) and provides diagnostics for unannotated properties or invalid relationship key paths.

Sources/PostgrestMacrosPlugin · high confidence

Introduce compile-time safe PostgREST client generation via macros

The PostgrestMacros module now provides a set of Swift macros that generate type-safe PostgREST client code at compile time. The @Table macro synthesizes conformances to PostgREST protocols, automatically mapping Swift properties to database columns (camelCase to snake\_case) and generating a Columns namespace for type-checked filtering and ordering. New marker macros (@PrimaryKey, @Default, @Column) allow precise control over primary key handling, default values, and column naming. The @Relationship macro enables type-safe embedded relations by requiring a foreign key key path, preventing ambiguous PostgREST queries. Additionally, @SelectionOf allows defining named subsets of columns for efficient, type-checked selections.

Sources/PostgrestMacros · high confidence

Introduce typed relation and selection protocols for compile-time safety

The PostgREST client now uses a new type-safe system for defining database relations and selections. This introduces \PostgrestRelation\ and \PostgrestSelection\ protocols, allowing developers to define tables and views with explicit schema associations (e.g., \PublicSchema\ or custom schemas) and column namespaces. This enables compile-time checks to prevent querying relations from the wrong schema and provides a structured way to build filters and selections using column properties rather than raw strings. Additionally, \PostgrestWritableRelation\ defines a \Draft\ type for inserts/upserts, replacing the previous \Insert\ shape to better support upsert operations and nullable column handling.

Sources/PostgREST/Relations · high confidence

Introduces a fully typed query and mutation API for PostgREST

The library now provides a type-safe surface for building requests, replacing string-based column references with compile-time-checked key paths. Users can construct queries using \where\ and \order\ closures that operate on a generated \Columns\ namespace, ensuring column names are valid at compile time. The API supports schema-scoped clients via \client.schema(...).from(...)\, typed whole-row and column-subset selections, and batch inserts. Write operations are handled through \PostgrestTypedMutation\, which allows typed inserts, updates (including clearing nullable columns), and upserts with configurable conflict resolution (merge or ignore). The mutation surface also supports returning affected rows or row counts.

Sources/PostgREST/Query · high confidence

Introduces type-safe column expressions with aggregates, casts, and JSON paths

The SDK now supports a unified, type-safe column expression system that enables aggregate functions (sum, avg, min, max, count), type casts, and JSON path extraction directly within query builders. This change introduces strict position constraints to prevent invalid queries at compile time: aggregates and casts are restricted to the select list, while JSON paths and stored columns remain filterable and orderable. Additionally, embedded relations are now accessible as column expressions, allowing projections of related data in select and order operations, with to-many relations correctly restricted to select-only positions.

Sources/PostgREST/Columns · high confidence

New Admin API for user, MFA, and OAuth client management

The Auth module now exposes a dedicated \AuthAdmin\ client for server-side operations that require the secret key. This new API provides methods to create, update, delete, and list users (including an \AsyncSequence\ paginator for efficient bulk iteration), manage user multi-factor authentication factors (list and delete), and administer OAuth 2.1 client registrations (list, create, update, delete, and secret regeneration). These capabilities are accessed via the \admin\ namespace on the main \AuthClient\ or through a standalone \AuthAdmin\ initializer, enabling administrators to manage project users and OAuth configurations directly from secure backend environments.

Sources/Auth · high confidence

The Examples app now includes a dedicated view for demonstrating Supabase Edge Functions, allowing users to invoke a 'hello-world' function via a text field and see the response or errors directly in the UI. This view also provides educational context on Edge Functions and includes deployment instructions. To support this, a shared utility was added to generate GitHub source code links, enabling users to view the underlying implementation of the example directly on GitHub.

Examples/Examples/Functions, Examples/Examples/Shared · high confidence

New Examples project structure with integrated sample apps

The Examples project has been restructured to include dedicated sample applications for User Management and a Slack Clone, alongside a main Examples app. This change introduces new source files and framework dependencies, including Clerk for third-party authentication, GoogleSignIn, FacebookLogin, and metamask-ios-sdk, enabling users to explore these specific integration patterns directly within the project.

Examples/Examples.xcodeproj · high confidence

New Helpers module with HTTP transport types and API key validation

A new Sources/Helpers module has been added, introducing the HTTPTypes and HTTPTypesFoundation libraries to replace the previous internal HTTPRequest/HTTPResponse types, and providing a new APIKeyFormat utility that classifies Supabase API keys and prevents new-format keys (sb\publishable\/sb\secret\) from being incorrectly sent as Bearer tokens. The module also includes foundational helpers such as Base64URL encoding/decoding, JWT decoding, PostgREST filter value escaping, date formatting, and an EventEmitter for managing observations.

Sources/Helpers · high confidence

New OpenTelemetry trace propagation demo

Added a standalone SwiftPM executable in Examples/OpenTelemetryDemo that demonstrates how enabling the OpenTelemetry trait on the Supabase dependency automatically attaches a W3C traceparent header to outgoing requests. The demo uses a local URLProtocol stub to intercept requests and print the attached header alongside exported OpenTelemetry spans, allowing users to verify that the trace and span IDs match without requiring a live Supabase project.

Examples/OpenTelemetryDemo · high confidence

New Profile management example with identity and security features

Added a new Profile example section demonstrating user profile management, including viewing account details, updating email/phone/password with verification flows, managing linked social identities (OAuth), and configuring security settings like Multi-Factor Authentication and WebAuthn passkeys.

Examples/Examples/Profile · high confidence

New Realtime example app with v2 protocol support

The Realtime example section has been completely rewritten as a new SwiftUI app demonstrating Supabase Realtime v2 capabilities. It includes dedicated views for live database change tracking (Postgres INSERT/UPDATE/DELETE), presence tracking, and broadcast messaging. Notably, it adds support for binary broadcast frames using protocol 2.0.0 and includes a specific example for handling app lifecycle transitions (background/foreground) to verify automatic socket reconnection and channel re-subscription.

Examples/Examples/Realtime · high confidence

New Slack Clone example app for SwiftUI

Added a complete Slack Clone example application built with SwiftUI and the Supabase SDK. The app demonstrates real-time collaboration features including channel management, message history, and user presence tracking via Realtime V2 subscriptions. It implements authentication using magic links, manages local state with the new @Observable macro, and includes a full local Supabase development environment configuration (database schema, migrations, and server settings) to allow users to run and test the example locally.

Examples/SlackClone · high confidence

New comprehensive Storage example app with signed upload URLs and advanced file operations

The Examples app now includes a full suite of SwiftUI views demonstrating Supabase Storage capabilities. Users can explore bucket management (create, update, delete, empty), file uploads (including from photo library and documents with progress tracking), downloads with image/text previews, and file management (move, copy, delete). New features include generating signed download and upload URLs, image transformations (resize, quality, format), and advanced file search with sorting and metadata viewing. The examples also showcase the new \createSignedUploadURL\ and \createSignedURL\ methods, as well as bucket options like public access and file size limits.

Examples/Examples/Storage · high confidence

New comprehensive authentication examples in the iOS app

The Examples app now includes a dedicated Auth section demonstrating Supabase authentication methods. This includes email/password with magic links, phone OTP, anonymous sign-in, and social providers like Apple, Facebook, and Google (via the official SDK). It also introduces generic OAuth flows, WebAuthn passkey support (first-factor sign-in and management), and a Web3 example for signing in with MetaMask using SIWE.

Examples/Examples/Auth · high confidence

New database example views for aggregations, filtering, RPC, and relationships

Added new SwiftUI example views in the Database section that demonstrate advanced Supabase query capabilities. These include AggregationsView for counting and summing data, FilteringView for sorting and filtering results with inline code previews, RPCExamplesView for calling stored procedures, and RelationshipsView for querying joined data across tables. The DatabaseExamplesView now serves as a navigation hub for these new advanced query examples.

Examples/Examples/Database · high confidence

New test utilities for serialization, mocking, and HTTP inspection

The TestHelpers module now includes new utilities to stabilize and improve testing: \MockerSerializedTrait\ and \MainSerialExecutorSerializedTrait\ provide process-wide serialization to prevent cross-target race conditions in Mocker and concurrency tests; \ClosureTransport\ and \RecordingTransport\ allow tests to intercept, record, and stub HTTP requests using \HTTPTypes\; \waitUntil\ offers async polling for background conditions; and deferred snapshot comparison logic ensures \Mock.snapshotRequest\ assertions correctly fail when mismatches occur.

Sources/TestHelpers · high confidence

New typed PostgREST filter API with comprehensive operator support

The PostgREST client now provides a strongly-typed filter API that replaces the previous string-based approach, allowing users to build queries using compiler-checked methods like \eq\, \gt\, \like\, and \in\. This update introduces support for a wide range of Postgres-specific operations, including array containment (\contains\, \overlaps\), range comparisons (\rangeLt\, \rangeGt\), JSONB checks (\containsJSON\), and full-text search (\textSearch\). It also enables filtering with \Decimal\, \Float\, and sized integers (\Int16\ through \Int64\), and provides explicit methods for boolean (\isTrue\, \isFalse\) and null (\isNull\) checks to handle SQL semantics correctly. Filters can be composed using standard Swift operators (\&&\, \\|\|\, \!\), and a \raw\ escape hatch is available for unsupported operators.

Sources/PostgREST/Filters · high confidence

Storage client rewritten with new architecture and experimental vector support

The Storage module has been completely rewritten to use a stateless, Sendable struct-based architecture (StorageApi) that delegates to a unified HTTP client, replacing the previous implementation. This change introduces a new, structured StorageError type with specific kinds (server, transport, decoding, etc.) and server payloads for better error handling. It also adds experimental support for Supabase's vector buckets feature (create, list, delete buckets, manage indexes, and read/write vector data) behind an @\_spi(Experimental) flag. Additionally, the client now supports CDN cache purging, allows setting custom HTTP headers via a fluent API, and automatically rewrites legacy Supabase hostnames to the new storage-specific domain to enable large file uploads.

Sources/Storage · high confidence

Removals

PostgREST Legacy API is deprecated and behaviorally frozen

The files in Sources/PostgREST/Legacy, which contain the previous value-typed API implementation (including PostgrestClient, PostgrestRequestBuilder, and related types), are now officially deprecated. This directory is behaviorally frozen to prevent regressions during the deprecation period; no bug fixes or reimplementations should be applied here. The legacy code remains in place only because the new typed API in Query/ still depends on these symbols, and it will be removed in the next major version.

Sources/PostgREST/Legacy · high confidence

Behavioural changes

Auth module refactored with new internal architecture and concurrent PKCE support

The internal Auth module has been restructured to support concurrent PKCE flows by introducing a ring-buffer-based CodeVerifierStorage that manages multiple flow slots, preventing verifier collisions during simultaneous OAuth or password-reset requests. Session management is now handled by a dedicated SessionManager actor that enforces commit guards to discard token refreshes that outlive their originating session, ensuring that concurrent sign-ins do not overwrite each other's state. The HTTP layer has been standardized to use HTTPTypes, and the API client now applies a retry policy that includes POST, PUT, and DELETE methods while explicitly excluding 429 status codes to avoid burning rate-limit quotas. Additionally, the module now supports local verification of ES256 JWTs and includes storage migrations to handle legacy session formats and key names.

Sources/Auth/Internal · high confidence

Functions client restructured with new error handling and invocation options

The Functions module has been rewritten to use a stateless \FunctionsClient\ struct and a new \FunctionsError\ type that exposes a \Kind\ enum (relay, http, transport, decoding) along with raw response data for debugging. Invocation is now controlled via \FunctionInvokeOptions\, which supports custom HTTP methods, query parameters, headers, and per-call timeout overrides, while the default request idle timeout is set to 150 seconds. The client also supports custom JSON decoders and access token injection, and re-exports the \Helpers\ module for internal use.

Sources/Functions · high confidence

HTTP layer refactored to streaming bodies and configurable retry/timeout policies

The HTTP helper layer has been rebuilt to use streaming request and response bodies instead of buffering entire payloads in memory, which improves performance for large uploads and downloads. The new architecture introduces a pluggable transport protocol and middleware chain, allowing users to inject custom networking stacks or intercept requests. It also adds configurable per-client and per-request idle timeouts, and a shared jittered retry policy with exponential backoff for transient network errors and specific server status codes (including Cloudflare errors).

Sources/Helpers/HTTP · high confidence

Introduce JSONValue as a unified JSON type representation

The library now provides a \JSONValue\ enum (alongside \JSONObject\ and \JSONArray\ typealiases) to represent JSON-compatible values, replacing the previous \AnyJSON\ type. This new type supports literal initializers for strings, integers, floats, booleans, arrays, and dictionaries, as well as \Codable\ conformance. It includes helper properties to extract underlying Swift values (e.g., \stringValue\, \intValue\) and extensions to decode into \Decodable\ types using configurable \JSONEncoder\ and \JSONDecoder\ instances.

Sources/Helpers/JSONValue · high confidence

Introduces unified SupabaseError protocol and structured error models

The SDK now provides a common \SupabaseError\ protocol that all module-specific errors (Auth, PostgREST, Storage, Functions, Realtime) conform to, allowing users to catch failures from any module in a single \catch\ block. This change introduces \HTTPErrorResponse\ to expose raw HTTP details (status code, headers, body, and Supabase request ID) for debugging, and restructures \PostgrestError\ to include a detailed \ServerError\ payload with code, message, details, and hint fields, replacing the previous generic error handling approach.

Sources/Helpers/SharedModels · high confidence

Logging infrastructure replaced with swift-log

The internal logging implementation in the Helpers module has been migrated from the previous SupabaseLogger to the standard swift-log library. This change introduces a new default logger behavior: debug builds now automatically log at the warning level for visibility, while release builds use a zero-overhead no-op handler to eliminate performance costs. Additionally, an internal OSLogHandler is provided to support testing and parity with previous console output formats, and a new trace helper function is available for async operation logging.

Sources/Helpers/Logger · high confidence

The Auth module now uses a new \KeychainLocalStorage\ implementation for Apple platforms, replacing the previous storage mechanism. This change fixes the macOS Keychain consent prompt by defaulting to the data-protection Keychain (which requires app signing entitlements) and ensures session data is stored under a fixed service name (\supabase.gotrue.swift\) to maintain compatibility across SDK versions and share sessions across app targets with the same access group. The implementation also includes automatic migration logic to move sessions from legacy Keychain locations to the new data-protection store on first read.

Sources/Auth/Storage · high confidence

Realtime client refactored to RealtimeV2 with new concurrency and lifecycle management

The Realtime module has been refactored into a new V2 implementation that replaces the previous architecture with a structured, actor-based state machine. This change introduces dedicated managers for connection and channel lifecycle, significantly improving reliability by resolving race conditions during subscribe/unsubscribe operations and preventing duplicate connection handling. Users gain access to modern Swift concurrency patterns, including async/await APIs for Postgres changes, broadcasts, and presence events, as well as new capabilities like binary broadcast support, system event callbacks, and heartbeat status tracking.

Sources/Realtime · high confidence

Replace Makefile with dedicated shell scripts for build, test, and CI tasks

The project has removed the Makefile and introduced a suite of standalone shell scripts in the \scripts/\ directory to handle development and CI workflows. These scripts provide explicit entry points for building the library for evolution (\build-for-library-evolution.sh\), checking for breaking API changes (\check-for-breaking-api-changes.sh\), formatting Swift code (\format.sh\), generating code coverage (\generate-coverage.sh\), and running tests on various platforms including Linux (\run-on-linux.sh\) and via Xcode (\xcodebuild.sh\). Additional scripts manage environment variables (\load\_env.sh\), spell-checking (\spell-check.sh\), documentation validation (\test-docs.sh\), and integration testing (\test-integration.sh\), centralizing these operations into version-controlled, executable files.

scripts · high confidence

Supabase client rewritten for v2 with unified configuration and OpenTelemetry support

The Supabase client has been completely rewritten for version 2, replacing the previous \Supabase.swift\ implementation with a new \SupabaseClient\ that uses a structured \SupabaseClientOptions\ configuration object. This change introduces a unified HTTP transport and middleware chain shared across all sub-clients (Auth, PostgREST, Storage, Realtime, Functions), allowing for consistent header injection (including a new \X-Client-Info\ header) and access token management. A key new capability is automatic W3C trace context propagation via OpenTelemetry, enabled by adding the \OpenTelemetry\ trait to the package dependency, which injects \traceparent\ headers into all outgoing requests. The rewrite also exposes explicit clock injection for deterministic testing of time-based behaviors like token refresh and retries, and consolidates sub-client options (database schema, storage hostname, function region) into the main client configuration.

Sources/Supabase · high confidence

Swift SDK v3 preparation: Swift 6.2 requirement, v3 migration guide, and configuration scaffolding

The repository is now prepared for the upcoming v3 release. The minimum supported toolchain has been raised to Swift 6.2 (Xcode 26.0+), and the supported platforms have been updated to iOS 16+, macOS 13+, tvOS 16+, watchOS 9+, and visionOS 1+. A comprehensive V3\_MIGRATION.md has been added to document breaking changes, including the removal of all previously deprecated APIs, the conversion of several public types from \Codable\ to \Decodable\ or \Encodable\-only, and the removal of the \emitLocalSessionAsInitialSession\ configuration option. Additionally, the project now includes configuration files for automated releases via release-please, linting via SwiftLint and swift-format, and spell-checking via cSpell.

(repo-wide) · high confidence

Fixes

New URLSession-based WebSocket implementation with improved header handling

The Realtime module now includes a new \URLSessionWebSocket\ implementation that uses \URLRequest\ headers instead of \httpAdditionalHeaders\ to prevent interference with the WebSocket upgrade handshake. This implementation creates a dedicated internal \URLSession\ for each connection to ensure thread safety and proper resource cleanup, while forwarding delegate callbacks for authentication challenges.

Sources/Realtime/WebSocket · high confidence

Re-exports Helpers module in PostgREST

The PostgREST module now re-exports the Helpers module, allowing consumers of PostgREST to access Helpers' public API directly without needing to import Helpers separately.

Sources/PostgREST · high confidence

Test coverage

Added PostgREST integration tests; Added Swift Testing suite for Functions client invocation and error handling; Added comprehensive Swift Testing suite for PostgREST client; Added comprehensive test coverage for Auth module; Added comprehensive test coverage for Helpers module; Added comprehensive test coverage for Realtime V2 components; Added integration test database schema and API access grants; Added mock session fixtures for Auth testing; Added tests for PostgrestMacros diagnostics, expansion, and integration; Added tests for WebAuthn error handling and challenge type decoding; Comprehensive test coverage for Storage module; Migrate SupabaseTests to Swift Testing; New integration test suite for Auth, Realtime, Storage, and PostgREST; Swift-format lint configuration and Linux test runner cleanup; Updated Supabase CLI version for integration tests.

Dependencies

SDK v3 dependency overhaul and new OpenTelemetry example

The SDK has been upgraded to Swift 6.4 with stricter platform requirements (iOS 16, macOS 13, etc.) and a complete restructuring of its dependency graph. The legacy \gotrue-swift\ dependency was removed in favor of local modules (Auth, Functions, PostgREST, Realtime, Storage) and new dependencies including \swift-crypto\ (up to 5.0.0), \swift-http-types\, \swift-log\, and \swift-issue-reporting\. An OpenTelemetry demo example was added to showcase W3C trace context propagation, and a new \cspell\ tooling dependency was introduced for spell checking.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 54 → 63 (+8.6)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 95 → 95 (-0.1)
  • Architecture 94 → 89 (-5.8)
  • Maturity 50 → 50 (+0.0)
  • Readiness 43 → 65 (+21.3)
  • Security 61 → 75 (+13.8)

Resolved (50)

  • AuthClient.getClaims (cognitive 19) (Sources/Auth/AuthClient.swift)
  • Change coupling: PushV2.swift ↔ RealtimeClientV2.swift (Sources/RealtimeV2/PushV2.swift)
  • ClassTooLong: RealtimeChannelV2 (Sources/RealtimeV2/RealtimeChannelV2.swift)
  • ClassTooLong: RealtimeClientV2 (Sources/RealtimeV2/RealtimeClientV2.swift)
  • Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (12 lines × 2) (Sources/RealtimeV2/RealtimeChannelV2.swift)
  • Duplicated block (12–13 lines × 2) (Sources/Auth/AuthAdmin.swift)
  • Duplicated block (13 lines × 2) (Examples/Examples/Storage/FileUploadView.swift)
  • Duplicated block (13 lines × 2) (Sources/RealtimeV2/RealtimeChannelV2.swift)
  • Duplicated block (14 lines × 2) (Sources/RealtimeV2/RealtimeChannel+Status.swift)
  • Duplicated block (16–17 lines × 2) (Sources/PostgREST/Legacy/PostgrestQueryBuilder.swift)
  • Duplicated block (24 lines × 2) (Sources/Auth/AuthAdmin.swift)
  • Duplicated block (33 lines × 2) (Sources/RealtimeV2/RealtimeClientV2.swift)
  • Duplicated block (9 lines × 2) (Sources/RealtimeV2/Types.swift)
  • Duplicated block (9 lines × 4) (Sources/PostgREST/Legacy/PostgrestQueryBuilder.swift)
  • FileTooLong: RealtimeV2/RealtimeChannelV2.swift (Sources/RealtimeV2/RealtimeChannelV2.swift)
  • FileTooLong: RealtimeV2/RealtimeClientV2.swift (Sources/RealtimeV2/RealtimeClientV2.swift)
  • …and 30 more

New (98)

  • APIClient.error (cognitive 17) (Sources/Auth/Internal/APIClient.swift)
  • AuthClient.claims (cognitive 18) (Sources/Auth/AuthClient.swift)
  • Change coupling: PushV2.swift ↔ RealtimeClientV2.swift (Sources/Realtime/PushV2.swift)
  • ClassTooLong: AuthClient (Sources/Auth/AuthClient.swift)
  • ClassTooLong: RealtimeChannelV2 (Sources/Realtime/RealtimeChannelV2.swift)
  • ClassTooLong: RealtimeClientV2 (Sources/Realtime/RealtimeClientV2.swift)
  • Coverage not measured — Swift suite
  • Documentation: no project overview (README.md)
  • Duplicate intent for listing users. AuthAdmin exposes both 'listUsers' (returning a paginated response object) and 'users' (returning a sequence). This forces the user to choose between two different APIs for the same logical operation, with different return types and parameter structures.
  • Duplicated block (10 lines × 4) (Examples/Examples/Auth/AuthWithMagicLink.swift)
  • Duplicated block (10 lines × 6) (Examples/Examples/Auth/AuthWithEmailAndPassword.swift)
  • Duplicated block (11 lines × 2) (Examples/Examples/Auth/AuthWithMagicLink.swift)
  • Duplicated block (12 lines × 2) (Examples/Examples/Profile/ProfileView.swift)
  • Duplicated block (12 lines × 2) (Sources/PostgREST/Legacy/PostgrestQueryBuilder.swift)
  • Duplicated block (12 lines × 2) (Sources/Realtime/RealtimeChannelV2.swift)
  • Duplicated block (12 lines × 3) (Examples/Examples/Auth/AuthWithEmailAndPassword.swift)
  • Duplicated block (12 lines × 3) (Examples/Examples/Auth/AuthWithMagicLink.swift)
  • Duplicated block (12 lines × 3) (Examples/Examples/Profile/UpdateProfileView.swift)
  • Duplicated block (13 lines × 2) (Examples/Examples/Auth/SignInWithPhone.swift)
  • Duplicated block (13 lines × 2) (Examples/Examples/Storage/FileUploadView.swift)
  • …and 78 more

Changes since last survey

  • 49 commits — 37 feature/other, 12 fixes

By area

  • (root) — 15 commits
  • Sources/Auth — 12 commits
  • Sources/PostgREST — 4 commits
  • Sources/Helpers — 3 commits
  • Sources/RealtimeV2 — 3 commits
  • Sources/Storage — 3 commits
  • .github/workflows — 2 commits
  • Tests/AuthTests — 2 commits
  • Tests/IntegrationTests — 2 commits
  • Tests/RealtimeTests — 2 commits
  • Tests/PostgRESTTests — 1 commit

Notable commits

  • fix: fix(auth)!: decode OAuth clients that omit redirect URIs, grant types or response types (#1349)
  • fix: fix(auth)!: decode OAuth server responses that omit optional fields (#1347)
  • fix: fix(auth): discard a token refresh that outlived its session (#1374)
  • fix: fix(auth): encode confirmsEmail and confirmsPhone as email_confirm and phone_confirm (#1388)
  • fix: fix(auth): fall back to the JWT header alg when the JWK omits one (#1348)
  • fix: fix(auth): keep a fixed Keychain service for every KeychainLocalStorage (#1394)
  • fix: fix(auth): listen on the callback scheme the provider redirects to (#1363)
  • fix: fix(auth): parse the admin pagination Link header without trapping (#1379)
  • fix: fix(auth): preserve status context for non-JSON 5xx errors (#1392)
  • fix: fix(postgrest): quote array elements in rpc GET/HEAD params (#1383)
  • fix: fix(postgrest): strip nulls through the Accept media type, not Prefer (#1382)
  • fix: fix: split Package.swift by tools-version for the swift-issue-reporting migration (#1393)
  • change: chore(ci): swift-format lint gate, pinned Linux Swift, visionOS platform (#1340)
  • change: chore(deps): bump github.com/apple/swift-crypto from 4.5.2 to 5.0.0 (#1376)
  • change: chore(deps): bump github.com/pointfreeco/swift-snapshot-testing (#1387)
  • change: chore(deps): bump github.com/swiftlang/swift-syntax (#1377)
  • change: chore(deps): bump supabase/setup-cli from 3.0.0 to 3.0.1 (#1386)
  • change: chore: add SwiftLint 0.65.0 with pinned CI version (#1043)
  • change: chore: add a privacy manifest (#1354)
  • change: chore: declare Clocks where it is used and drop XCTestDynamicOverlay (#1353)
  • …and 29 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

supabase/supabase-swift was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d7fd461ca83ff8e90e617dcfd465909c038574fe — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.