tuqo
DB + Auth + Storage

Tuqo + Supabase

Supabase gives you Postgres, authentication, file storage and realtime through a ready-made browser SDK. Tuqo serves your static front end over HTTPS, and the front end talks to Supabase directly with the public anon key. A full app without a backend of your own.

Static front end on Tuqo + Supabase straight from the browser · free SSL

What Tuqo + Supabase gives you

  • A PostgreSQL database with an auto-generated API (REST/GraphQL)
  • Auth: email, magic link, OAuth (Google, GitHub and more)
  • File storage and realtime subscriptions
  • All from the browser, no backend needed
1

Create a Supabase project

In the Supabase dashboard, create a new project and copy the Project URL and the public anon key.

2

Turn on RLS and policies

Enable Row-Level Security on your tables and define who can read and write what. That is what protects the data.

3

Add the SDK to the site

Add @supabase/supabase-js (CDN or npm) and initialize it with the URL and the anon key.

4

Deploy to Tuqo

deploy_files, the CLI or the panel: the site on name.tuqo.ru calls Supabase directly over HTTPS.

import { createClient } from '@supabase/supabase-js'

// the anon key is public by design, so it can live in client-side JS
const sb = createClient('https://xxxx.supabase.co', 'ANON_KEY')

const { data, error } = await sb.from('posts').select('*')

Security

The anon key is public BY DESIGN, so nobody hides it. The data is protected by Row-Level Security: turn on RLS and write policies for your tables. That part is yours (as with any static host), and it is standard practice.

Tuqo serves the front end over HTTPS and never touches your data or the service's secrets.

Tuqo + Supabase — frequently asked questions

Is it safe to keep the anon key in the browser? +

Yes, it is public by design. Access to the data is limited by Row-Level Security in the database itself. Without RLS a table is open, so be sure to set up policies.

Do I need a backend of my own? +

Not for most tasks: the SDK works from the browser. For admin operations with the service-role key, use Supabase Edge Functions (not the static site).

Does auth work on a static site? +

Yes. Supabase Auth (email, OAuth, magic link) runs entirely in the browser, and the SDK keeps the session.

Why Tuqo and not Supabase's own hosting? +

Tuqo is fast static hosting with servers in Russia (sites open there without a VPN), custom domains from the Start plan and deploys from an AI agent over MCP. Supabase stays your backend.

Other integrations