Build (or fully build out) a small Supabase-backed app with RLS, auth and a real read/write
The capstone project for Supabase for Real Projects — a free Data & Tech course. Pass it and you earn a certificate anyone can verify.
- Free
- 6 steps
- Pass mark 65%
- Graded within minutes
- Beginner-friendly
The project unlocks once you complete the lessons. The workbook is free to download now so you can see exactly what is expected.
What you will submit
A live link to the working app (or the public GitHub repo of a coded project), plus a one-line note describing the app and how to try the read and write. The app must have at least one main table, working auth (a user can sign up and log in), RLS turned on with correct policies, and at least one working READ and one working WRITE from the frontend.
What to do, step by step
- Create a Supabase project and design AT LEAST one main table for a real idea (e.g. a 'services', 'listings', 'bookings' or 'products' table) with sensibly-typed columns — store phone numbers and IDs as text, money as int8/numeric — and add a few rows of realistic Nigerian test data (real naira prices, real-looking names).
- Turn on authentication (email and/or Google) and confirm a user can SIGN UP and LOG IN; capture the logged-in user's id so it can be tied to their data (e.g. a user_id column on a bookings or listings table).
- Turn RLS ON for every table holding real or personal data and write the right policies: a public-read policy where appropriate (using ( true )), and 'own rows only' policies tying rows to the user with auth.uid() = user_id for the relevant SELECT/INSERT/UPDATE actions — remember policies are per-action.
- Connect a frontend (coded with @supabase/supabase-js — plain HTML/JS, React or Next.js — OR a no-code tool like Bolt/Lovable/FlutterFlow) and make at least ONE working READ (e.g. list rows with .select()) AND at least ONE working WRITE (e.g. .insert() a new row) from the app, handling the 'error' value with a friendly message.
- Test your security like an attacker: log in as one user and confirm you canNOT see another user's private rows; confirm sign-up/login and your read AND write all work on the LIVE site, not just localhost (add your live domain to the auth redirect URLs if you used social login).
- Deploy the frontend to a live URL (Vercel/Netlify, or the no-code tool's published link) OR push a coded project to a public GitHub repo with your Supabase keys kept out of committed code, then submit the live link or repo with a one-line note saying what the app does and how to try the read/write.
Files to work with
Project workbook (fill in, then submit)The whole brief, an evidence checklist, the grading rubric as a self-check and the link-sharing steps in one file. Opens in Word, Google Docs or WPS.Word · 7 KBHow it is graded
| Criterion | Weight |
|---|---|
| Database design — at least one well-structured table with sensible column types (text for phone/IDs, int8/numeric for money) and realistic Nigerian test data | 20% |
| Authentication — a user can genuinely sign up and log in (email and/or Google), and logged-in identity is tied to their data via a user_id | 20% |
| Row-Level Security — RLS is ON for real-data tables with correct policies (public-read where intended, auth.uid() = user_id for own-rows), proven by not being able to see another user's private data | 30% |
| Working read AND write — at least one .select() read and one .insert()/.update() write work end-to-end from the frontend, with errors handled gracefully | 20% |
| Shipped & shareable — the app is live (or in a public repo with keys kept out of committed code) and the submitted link works, with a clear note on what it does and how to try it | 10% |
You need 65% overall to pass. A failed submission comes back with feedback and can be revised and resubmitted.
Before you submit: make your link public
If your work lives in Google Drive or Google Docs, open Share → General access and change “Restricted” to “Anyone with the link” (Viewer). Then paste the link into a private browser window: if it opens without sign-in, you are ready. A private link cannot be graded — it is the single most common reason a good project fails.
Frequently asked questions
Do I have to finish Supabase for Real Projects before submitting the project?
Yes. The submission screen opens once every lesson in Supabase for Real Projects is marked complete. The lessons are where the methods, the Nigerian context and the worked examples the project depends on are taught.
How is the project graded?
An examiner scores each rubric criterion from 0 to 100 and weights them as shown on this page; you need 65% overall to pass. Most submissions are graded within minutes and you get written feedback on what was strong and what to improve.
Can I resubmit if I fail?
Yes. A failed project comes back with feedback; revise the weak parts and resubmit. A passed project is final — the certificate is issued and cannot be re-rolled.
What do I actually submit?
A write-up of what you did (under 5,000 characters) plus a public link to your work — a Google Drive folder, Google Doc, spreadsheet, GitHub repository or video. The link must open without sign-in; a private link cannot be graded. The free project workbook on this page walks you through all 6 steps.
Is the certificate real?
Yes. Passing this project issues a certificate with a unique verification code. Anyone — an employer, a client, a school — can open the verification page and see that the certificate is genuine and which project earned it.
More Data & Tech projects
- Sales Dashboard for a Local Business
Data Analysis Foundations
- My Skillnaija Frontend Portfolio
Frontend Web Development
- My First Python Program: 'Kudi Tracker'
Coding Foundations
- Your Junior Technician Field Pack
Data Centre Technician: Racks, Power, Cooling, Cabling and Remote Hands
Ready to earn this certificate?
Supabase for Real Projects is free and self-paced. Finish the lessons, complete this project, and the certificate is yours to share.
Start learning free