Cerbos vs Supabase
Supabase scores higher on the AgentReady, 74/100 against 46/100. They differ on 10 of the 41 signals. Which ones decides whether an agent can adopt them without a person watching.
What each one is
Cerbos. Authorization management platform for applications, APIs, AI agents, MCP servers, services, and workloads.
Supabase. Supabase is an open-source Firebase alternative that provides a complete backend platform built on top of Postgres, offering database, authentication, storage, realtime, edge functions, and vector capabilities.
Where Cerbos is ahead
Cerbos passes search discoverable and public docs discoverable, and Supabase does not. That is discover, whether an agent can find the product at all without being told it exists.
It also holds adopt: copyable quickstart, official typescript sdk and official python sdk. Supabase misses those.
And on operate, canonical workflow succeeds and observable execution. Supabase misses those.
Where Supabase is ahead
Supabase passes structured api reference and authentication documented, and Cerbos does not. That is understand, whether an agent can read the docs and work out how the API behaves before calling it.
It also holds adopt: cli available. Cerbos misses it.
What neither does
Both fail clear canonical domain, openapi / spec quality, pricing understandable, request examples provided, response examples provided, errors and status codes documented, limits / constraints documented, self-service signup, no mandatory sales call, programmatic credential creation, free trial or free allowance, fast time to first request, structured, predictable output, machine-readable errors, retry behavior documented, idempotency support, rate-limit behavior predictable, agent compatibility verified. If your agent needs any of those, you will be building it yourself either way.
Score, pillar by pillar
The AgentReady splits into four pillars, scored separately, because a product can be easy to find and still impossible to adopt.
Discover. Supabase leads 100 to 93. Cerbos misses clear canonical domain; Supabase misses search discoverable, clear canonical domain, public docs discoverable.
Understand is whether an agent can read the docs and work out how the API behaves before calling it. Supabase leads 67 to 15. Cerbos misses structured api reference, openapi / spec quality, authentication documented, pricing understandable, request examples provided, response examples provided, errors and status codes documented, limits / constraints documented; Supabase misses openapi / spec quality, pricing understandable, request examples provided, response examples provided, errors and status codes documented, limits / constraints documented.
Adopt. Supabase leads 63 to 40. Cerbos misses self-service signup, no mandatory sales call, agent-compatible signup flow, programmatic credential creation, free trial or free allowance, fast time to first request, cli available; Supabase misses self-service signup, no mandatory sales call, programmatic credential creation, free trial or free allowance, fast time to first request, copyable quickstart, official typescript sdk, official python sdk.
Operate. Supabase leads 67 to 35. Cerbos misses structured, predictable output, machine-readable errors, retry behavior documented, idempotency support, rate-limit behavior predictable, agent compatibility verified; Supabase misses canonical workflow succeeds, structured, predictable output, machine-readable errors, retry behavior documented, idempotency support, rate-limit behavior predictable, observable execution, agent compatibility verified.
Pricing
Cerbos does not publish a machine-readable starting price. Supabase does not publish one.
Signal by signal
| Signal | Cerbos | Supabase |
|---|---|---|
| AgentReady | 46 | 74 |
| Discovery | 93 | 100 |
| Understanding | 15 | 67 |
| Adoption | 40 | 63 |
| Operability | 35 | 67 |
| Public API | Yes | Yes |
| MCP server | Yes | Yes |
| OpenAPI spec | Unknown | Yes |
| CLI | Unknown | Yes |
| llms.txt | Yes | Yes |
| Self-serve signup | Unknown | Unknown |
| Free tier | Unknown | Unknown |
Which to pick
Cerbos clears more of the signals an agent needs, so it is the safer default for unattended use. Full profiles: Cerbos and Supabase. Alternatives to each: Cerbos, Supabase.
An agent can fetch this as data: POST /v1/compare {"slugs": ["cerbos", "supabase"]}