Softr

softr.iocontributed by Samuele Ongaro

ALMOST

A weekend of work, and real gaps remain.

Builds client portals and internal apps over a table: user accounts, permissions per row, and pages assembled from blocks without code.

Promptfree, for everyone, and the only version there is
Build me a client portal that replaces Softr — and know what makes this ALMOST.

The feature that earns the price is **per-row permissions without code**: this client sees their own rows and nobody else's, configured rather than programmed. That is not hard to build — it is a predicate joined into every query — but it is easy to build wrongly, and building it wrongly means one customer seeing another's data. That is the whole verdict.

STACK
- Node 20+ with Fastify, server-rendered HTML with a little vanilla JS
- SQLite through better-sqlite3, WAL mode, as the mirror of your source data
- No client-side framework
- Caddy in front

THE DATA MODEL
- sources: id, kind, config_encrypted, sync_interval_seconds, last_synced_at, last_error — a spreadsheet, a table product, a database, a CSV
- collections: id, source_id, name, slug, table_ref, sync_cursor
- fields: id, collection_id, key, label, kind, is_visible, is_filter, is_searchable, position
- Records in real SQL tables per collection, keyed on a stable identifier you nominate — never row position, or a re-sort renumbers everything on the site
- users: id, email, external_ref, role, attributes_json, is_active, last_login_at
- access_rules: id, collection_id, role, action, predicate_json — the heart of it: which rows, which fields, which actions
- pages: id, slug, kind, collection_id, config_json, required_role — list, detail, form, dashboard
- audit: id, actor_id, action, collection, record_id, at — append-only

THE PERMISSION RULE, WHICH IS THE PRODUCT
- A predicate over the row and the signed-in user: `row.client_email = user.email`, or `row.account_id in user.account_ids`
- **Compiled into the WHERE clause of every query.** Never fetch and filter afterwards — a filtered result set still travelled, and one mistake in a template exposes it
- A forbidden field is absent from the response, not hidden in the page
- Default deny: a collection is invisible until a rule grants it
- A rule tester: pick a user, pick a record, and see whether access is granted and which rule decided. Without it, permission questions become guesswork
- A page listing every rule in plain language, generated from the table. That page is what you show somebody who asks whether their data is safe
- Test the negative case explicitly: sign in as one client and try to reach another's record by identifier in the URL. That test is the acceptance criterion for the whole build

SYNCING FROM THE SOURCE
- Mirror locally and serve from the mirror. Serving directly from a spreadsheet API is slow, rate-limited, and goes down when the source does
- Incremental with a cursor where the source supports it, full otherwise, on a schedule and on demand
- A record that disappears is marked missing rather than deleted, so a page returns a clear gone state rather than a broken link
- Writes from a form go back to the source, idempotently, with the local mirror updated on success. Never write to the mirror alone, or the two will drift

THE PAGES
- List with search, filters and pagination, respecting the row rules
- Detail, at a permanent URL, respecting them again
- Form, writing back to the source with server-side validation
- A simple dashboard of counts and totals, computed at query time from what this user may see
- Everything works at 320px and on a poor connection

AUTHENTICATION
- Magic links, because a client portal with a password is a portal with a password reset queue
- Sessions as long random tokens stored hashed, revocable, with a device list
- Users provisioned from the source data itself — the client list is already a table — or invited by email
- Rate limits on every authentication route

OPERATIONS
- .env: DATABASE_PATH, BASE_URL, SESSION_SECRET, ENCRYPTION_KEY, HASH_SALT, SMTP_URL, source credentials
- Migrations on boot, each once; nightly backup off the machine
- Health endpoint reporting the age of the last successful sync — a stale portal that looks fine is the quiet failure here

WHAT MATTERS MOST
The predicate in the query, and the negative test. Build access rules before any page exists, then spend an afternoon trying to see somebody else's row. Everything else here is a list view.

What you lose

  • Row-level permissions configured rather than coded, which is the part people underestimate
  • User accounts, sign-in and password resets already built
  • Blocks and templates a non-developer can assemble

If you would rather not build

  • Astro with a Node adapter, which is what the prompt builds
  • Retool, for internal rather than client-facing tools

What it costs

as published on their pricing page

PlanBilled monthlyBilled yearlyLast read
—$19/mo——

Their pricing page is where these came from. Seeing a different price? Tell us.

The escape hatch

open source · no votes, no paid placement

Budibase

$0

Self-hosted portals with users and row-level permissions.

Budibase/budibasefree · open source

Directus

$0

Generates an API with role and row permissions over your own database.

directus/directusfree · open source

Why this verdict

our own opinion · changed only by a person

60/100

Verdict kinda at 60. The portal is a weekend; the discipline that every query is scoped in SQL is what separates it from a leak.

History

tracked since 10 Aug 2026 · nothing is ever overwritten

Interest · last 30 dayspeak 2/day
views01230 Aug4 Sept9 Sept14 Sept19 Sept24 Sept28 Sept
— views— prompt copies none yet— votes none yet

Questions about Softr

answered from the record above

Is Softr free?

No — the plan we track is $19 a month. Basic at $19/month; Pro is $99 and Business $329. App users beyond the included ones are billed separately.

Can you replace Softr by building your own?

ALMOST. A weekend of work, and real gaps remain. Replacement score 60 out of 100, build time a weekend. Read what you lose before you decide.

How much does Softr cost?

$19 a month on Basic — $228 a year. Recorded 14 Aug 2026.

What do you lose by replacing Softr?

Row-level permissions configured rather than coded, which is the part people underestimate; User accounts, sign-in and password resets already built; Blocks and templates a non-developer can assemble. If any of those carry weight for you, keep paying.

Is there an open-source alternative to Softr?

Yes: Budibase, Directus. The prompt on this page is for when you want it your way instead.

Related entries

same category first, most replaced first

All 16 in No-code apps & databases

Not sending yet

Every week, something stops being worth paying for.

New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.

free forever · no tracking pixel · stored here, never passed to anyone

Esc