// the find
PostgREST/postgrest
REST API for any Postgres database
PostgREST turns a Postgres schema straight into a REST API, with no middleware layer in between — tables, views, and functions become endpoints automatically. It's for teams who are comfortable putting constraints, grants, and row-level security directly in Postgres and want the database to be the whole backend, not just storage behind an API server they'd otherwise have to write.
Authorization is enforced by actual Postgres roles and grants rather than application code re-implementing permission checks, so there's one place security logic can break instead of two out-of-sync ones. It's genuinely fast — Haskell plus Warp plus a pooled Hasql connection, stateless by design, so it scales horizontally without session affinity. OpenAPI docs and versioning both fall out of the schema for free: version via schema namespaces, document via introspection, neither needs separate upkeep.
It's Haskell — if something breaks in a way the docs don't cover, debugging or patching the server itself is off the table for most teams. Any logic that doesn't fit cleanly into a view or an SQL function has to become a stored procedure exposed as an RPC endpoint, which means business logic creeps into the database layer whether you planned for that or not. There's no real-time or webhook story built in (that's the gap Supabase fills on top of it), so most production setups end up running a companion service anyway. Getting the role/grant model wrong isn't just a bug, it's a security hole, and the learning curve for teams new to Postgres RLS is real.