Appwrite

appwrite.iocontributed by Samuele Ongaro

YES

Replaceable in one session with an AI coding agent.

An open-source backend platform: database, authentication, storage, functions and realtime behind one API, hosted by them or on your own server.

Promptfree, for everyone, and the only version there is
Build me the backend I actually need instead of a hosted Appwrite: authentication, a database, file storage and scheduled jobs, in one Node service on one machine.

Read this first: the product you are replacing is open source, and self-hosting it is a real answer. What you pay for is a managed instance and SDKs for a dozen platforms. Build this instead when your application is one product with one team — a backend platform is a very general answer to a specific question, and the specific answer fits in a few thousand lines.

STACK
- Node 20+ with Fastify
- SQLite through better-sqlite3, WAL mode. One file, backed up nightly, and it will handle far more than you expect
- Local disk for files, with an S3-compatible target for backups
- Caddy in front

AUTHENTICATION, THE PART WORTH GETTING RIGHT
- users: id, email, email_verified_at, password_hash, name, avatar_path, status, created_at, last_login_at
- sessions: id, user_id, token_hash, ip_hash, user_agent_bucket, created_at, last_used_at, expires_at, revoked_at
- Passwords with argon2id at sensible parameters, never anything else, and never a hand-rolled scheme
- Session tokens are long random strings stored hashed; the cookie is httpOnly, secure, sameSite lax, with a short life and a rotating refresh
- Email verification and password reset by single-use tokens that expire, are invalidated on use, and are compared in constant time
- Magic links as an option, and OAuth against one or two providers if the product needs it
- Two-factor with TOTP: a secret per user, a window of one step either side, and single-use recovery codes stored hashed
- Rate limits on every authentication route by address hash and by account, with a lockout that fails closed and an unlock path
- Never say whether an email exists — the same response for a wrong password and an unknown address, and the same timing

THE DATABASE LAYER
- Real tables with real migrations, applied once in order and never edited after they have run
- Every query parameterised. No string building, anywhere, ever
- A small repository module per entity rather than a generic query API — a generic API over your own database is a lot of work to reinvent SQL badly
- Row-level authorisation checked in the repository, so a missing check is a compile-time-obvious omission rather than a forgotten middleware

FILE STORAGE
- Uploads streamed to disk, never buffered whole in memory
- Type determined from the content, not the filename or the client's claim
- A size cap, a per-user quota, and a per-minute rate limit
- Files stored by hash outside the web root and served through a signed URL with an expiry, or through an endpoint that checks permission
- Images transformed on demand with sharp — resize, crop, format — with the parameters signed so nobody can use your server as a free image farm, and the result cached
- Deletion is real, including the cached derivatives

FUNCTIONS AND SCHEDULES
- Instead of a function runtime, plain modules invoked by a queue table with leases and retries
- Cron with a time zone, computed from the schedule and stored as a next-run instant
- Every run recorded with its input, output, duration and error
- Idempotency keys so a retry never repeats a side effect

REALTIME
- Server-sent events for pushing changes to a browser: one connection, no protocol to implement, and it reconnects by itself
- A channel per user and per resource, with authorisation checked at subscription time
- WebSockets only if the product genuinely needs the client to speak too

THE API
- REST with a clear shape, versioned in the path
- Every write endpoint checks that the request came from your own origin, and every state-changing form carries a token
- Errors in one shape with a code, a message and a field where relevant
- Rate limits per route class, per key and per address hash

OPERATIONS
- .env: DATABASE_PATH, STORAGE_PATH, BASE_URL, SESSION_SECRET, HASH_SALT, SMTP_URL, S3_*
- Migrations on boot, each once
- Nightly backup with VACUUM INTO, gzipped, uploaded off the machine, with a tested restore script
- Structured logs with secrets and tokens redacted by key and by pattern
- Health endpoint that touches the database, the disk and the mail connection

WHAT MATTERS MOST
Authentication. Build sessions, password hashing, the reset flow and the rate limits first, and try to break each one — a reset token that survives use, a login route with no limit, a session that does not rotate. Everything else here is ordinary work; this is the part where a mistake is somebody else's account.

Give me the repository, migrations, .env.example, and a README with deploy steps behind Caddy and the security decisions listed.

What you lose

  • A managed instance where authentication, storage and functions are already connected
  • SDKs for a dozen platforms kept current
  • Scaling and backups you do not operate

If you would rather not build

  • Supabase, if Postgres suits you better

What it costs

read from their page 15 Aug 2026

PlanBilled monthlyBilled yearlyLast read
—$15/mo—15 Aug 2026

Their pricing page is where these came from. Seeing a different price? Tell us.

The escape hatch

open source · no votes, no paid placement

Appwrite

$0

The product itself, free to self-host with Docker Compose.

appwrite/appwritefree · open source

PocketBase

$0

One binary with SQLite, auth, files and realtime; far simpler to run.

pocketbase/pocketbasefree · open source

Why this verdict

our own opinion · changed only by a person

82/100

Verdict yes at 82. The software is free and complete; the permission model is the part to understand before writing any data.

History

tracked since 10 Aug 2026 · nothing is ever overwritten

Interest · last 30 dayspeak 2/day
views01230 Aug4 Sept9 Sept14 Sept19 Sept24 Sept28 Sept
— views— prompt copies none yet— votes none yet

Questions about Appwrite

answered from the record above

Is Appwrite free?

No — the plan we track is $15 a month. Pro at $15 per member per month billed monthly on the cloud; the software is free to self-host.

Can you replace Appwrite by building your own?

YES. Replaceable in one session with an AI coding agent. Replacement score 82 out of 100, build time one session. Read what you lose before you decide.

How much does Appwrite cost?

$15 a month on Pro — $180 a year. Recorded 10 Aug 2026.

What do you lose by replacing Appwrite?

A managed instance where authentication, storage and functions are already connected; SDKs for a dozen platforms kept current; Scaling and backups you do not operate. If any of those carry weight for you, keep paying.

Is there an open-source alternative to Appwrite?

Yes: Appwrite, PocketBase. The prompt on this page is for when you want it your way instead.

Related entries

same category first, most replaced first

All 21 in Hosting & databases

Not sending yet

Every week, something stops being worth paying for.

New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.

free forever · no tracking pixel · stored here, never passed to anyone

Esc