PocketBase

pocketbase.iocontributed by Samuele Ongaro

YES

Replaceable in one session with an AI coding agent.

A backend in one file: SQLite, authentication, file storage, realtime subscriptions and an admin interface, in a single binary you drop on a server.

Promptfree, for everyone, and the only version there is
Build me the backend in the shape PocketBase has: SQLite, authentication, file storage, realtime and an admin interface, in one process on one machine.

Read this first: PocketBase is free and is a single binary — nothing is being saved in fees. Build this when you want the same shape in your own language and with your own decisions, and read the honest note at the end about where the one-process design stops.

STACK
- Node 20+ with Fastify
- SQLite through better-sqlite3, WAL mode. One file, and it will handle far more than you expect
- Local disk for files
- Server-rendered admin, no client-side framework
- Caddy in front

THE SHAPE
- One process, one database file, one command to run it. That simplicity is the entire proposition, and every design decision below defends it
- Migrations applied on boot, each once, in order, from files in the repository
- Everything configured by environment variables, with sensible defaults so it runs with none

COLLECTIONS
- collections: id, name, kind, schema_json, rules_json, indexes_json — a base collection, an auth collection, or a view
- Data lives in real SQL tables, created and altered by generated migration files. Not a generic key-value store: real columns mean real constraints, real indexes and fast queries
- Field types: text, number, boolean, email, url, date, select, relation, file, json, editor. Each with a parser, a validator, a formatter and a filter set
- A relation is a real foreign key; a multiple relation is a join table. Both created properly
- Schema changes through the admin write a migration file, so the production deploy applies the same change rather than a different one

API RULES, WHICH IS THE IDEA WORTH COPYING
- Each collection has five rules — list, view, create, update, delete — each an expression over the request's authenticated user and the record
- `@request.auth.id != "" && owner = @request.auth.id` is most of what an application needs, expressed in one line and enforced in the query
- Parsed into an AST and compiled into a WHERE clause. Never string-concatenated, never evaluated
- An empty rule means locked to admins only. Default deny, always
- The rule is applied inside the query, so a forbidden record is absent rather than filtered afterwards

AUTHENTICATION
- An auth collection is a normal collection with identity fields attached
- Passwords with argon2id and nothing else
- Email verification, password reset and email change, each by a single-use expiring token compared in constant time
- OAuth against the common providers, with the token exchange on the server
- Sessions as long random tokens stored hashed, in an httpOnly secure sameSite cookie, with a device list and central revocation
- Rate limits on every authentication route by address hash and by account, with identical responses and timing for an unknown address and a wrong password

FILES
- Uploads streamed to disk, never buffered whole
- Type from the file's own content, size capped per field, stored by hash outside the web root
- Served through a handler that applies the same access rules as the record, or through a signed expiring token
- Image transforms on demand — resize, crop, format — with the parameters signed so nobody uses your server as a free image farm, and the result cached
- Deletion is real, including derivatives, and refused while a record still references the file

REALTIME
- Server-sent events, one connection per client, subscribing to collections or records
- The subscription is authorised at connection time and re-checked against the rule for every event, so a rule change takes effect immediately
- Events emitted after the transaction commits, never before

THE ADMIN
- Collections, records, rules, files, logs and settings
- A rule tester: pick a user and a record and see whether the rule passes and why
- Server-rendered, fast, works on a phone
- Behind its own authentication, separate from application users, with the option to bind it to a private interface only

OPERATIONS
- .env: DATABASE_PATH, STORAGE_PATH, BASE_URL, SESSION_SECRET, SMTP_URL, HASH_SALT, OAUTH_*
- Nightly backup with VACUUM INTO, gzipped, uploaded off the machine, with a tested restore script
- Structured logs with tokens and secrets redacted
- Health endpoint touching the database, the disk and mail

THE HONEST LIMIT
- One process and one SQLite file means one machine. That is fine for a very large number of applications — SQLite on a modern disk handles thousands of writes a second — but it does not scale sideways, and a long-running query blocks writers
- Write down what you would do if it stopped being enough: read replicas, or a move to a client-server database with the same schema. Knowing the exit is what makes the simple choice safe
- Backups are the whole disaster-recovery story here, so test the restore rather than assuming it

WHAT MATTERS MOST
The rule engine and authentication. Compile rules into the query rather than filtering afterwards, and get sessions, hashing and rate limits right before anything else. Those two are where a mistake is somebody else's data.

Give me the repository, migrations, .env.example, an example application built on it, and a README with deploy steps behind Caddy and the scaling limit stated.

What you lose

  • Nothing in fees; it is free. What you take on is the server and the backup
  • Horizontal scaling, which SQLite in one process does not offer
  • A hosted option, since there is not one

If you would rather not build

  • Supabase, if you need Postgres
  • SQLite plus your own server, which is the same idea unbundled

What it costs

as published on their pricing page

PlanBilled monthlyBilled yearlyLast read
—$0/mo——

Their pricing page is where these came from. Seeing a different price? Tell us.

The escape hatch

open source · no votes, no paid placement

PocketBase

$0

The product itself: one binary with database, auth, files and realtime.

pocketbase/pocketbasefree · open source

Directus

$0

A similar admin-and-API layer over Postgres or MySQL instead.

directus/directusfree · open source

Why this verdict

our own opinion · changed only by a person

92/100

Verdict yes at 92, and it costs nothing. The one thing to understand is the single-writer model, and the one thing to get right is a consistent backup.

History

tracked since 10 Aug 2026 · nothing is ever overwritten

Interest · last 30 dayspeak 3/day
views012330 Aug4 Sept9 Sept14 Sept19 Sept24 Sept28 Sept
— views— prompt copies none yet— votes none yet

Questions about PocketBase

answered from the record above

Is PocketBase free?

No — the plan we track is $0 a month. Free and open source with no hosted tier; the cost is the server you run it on.

Can you replace PocketBase by building your own?

YES. Replaceable in one session with an AI coding agent. Replacement score 92 out of 100, build time one session. Read what you lose before you decide.

How much does PocketBase cost?

$0 a month on Free — $0 a year. Recorded 10 Aug 2026.

What do you lose by replacing PocketBase?

Nothing in fees; it is free. What you take on is the server and the backup; Horizontal scaling, which SQLite in one process does not offer; A hosted option, since there is not one. If any of those carry weight for you, keep paying.

Is there an open-source alternative to PocketBase?

Yes: PocketBase, Directus. The prompt on this page is for when you want it your way instead.

Related entries

same category first, most replaced first

All 21 in Hosting & databases

Not sending yet

Every week, something stops being worth paying for.

New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.

free forever · no tracking pixel · stored here, never passed to anyone

Esc