Docs
Database
A paid app can have its own managed Postgres — a Supabase project Tofu creates, connects and pays for — created in the same action as the deploy, so the app goes live with its tables.
Agent tools
databaseCreatedatabaseStatusdatabaseReconciledatabaseDeletedatabaseRestore
One action with the deploy
A paid app can have one managed Supabase project, created from Database in the dashboard or by an agent's databaseCreate — any framework, Next.js, Vite or Astro included. The app does not have to be deployed first: choose the database on the deploy confirm step — the checkbox, or database: true / deploy --database for an agent — and one action does the rest, in this order:
Create
Tofu creates the database and waits for it.
Connect
It saves the connection settings on the app's hosting project.
Build
Only then is the build submitted, so the app goes live with its own migration already applied.
A database created earlier is connected the same way by the next deploy, before that deploy builds.
What your app receives
The connection variables reach the app from that project's sensitive environment: DATABASE_URL, SUPABASE_URL and the public URL and key. Next.js, Vite and Astro also get the same values under their own browser-facing prefix; every other preset, a Python, Go or JavaScript server app included, gets the server-side names only, because Tofu does not guess a prefix.
| Preset | Variables |
|---|---|
| Every app | DATABASE_URL, SUPABASE_URL, SUPABASE_ANON_KEY |
| Next.js | The same, plus NEXT_PUBLIC_SUPABASE_URL, NEXT_PUBLIC_SUPABASE_ANON_KEY and NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY |
| Vite | The same three under VITE_ |
| Astro | The same three under PUBLIC_ |
They are managed variables, read-only in the dashboard's Environment. The control database keeps names and flags only, and Tofu writes no connection string to a log.
Your schema, your migrations
The database is empty until your migration runs inside the build:
prisma migrate deploy
drizzle-kit migrate
supabase db push --db-url "$DATABASE_URL"A failed migration fails the build and blocks publication — the previous version keeps serving — but statements already accepted stay applied. That is the whole of the local-to-cloud promise, and its boundary: structure travels, data does not — the migration files in your repository reach this database, rows that live only on your own machine do not.
Tofu never runs migrations and has no SQL console. Its read is read-only — recorded migrations and the base-table count in public — reported as empty, populated, unavailable or unknown: a failed read is never an empty schema.
Seeing your data
The Database page carries a table editor: the base tables of the public schema, their rows 25 at a time, and — only while you have switched writing on for that app — one inserted, changed or deleted row per confirmed request. Writing is off by default.
- No schema changes, no raw SQL and no export: rows leave the editor one page at a time, on screen.
- The editor connects as the database's own admin role, so the row-level security policies your app adds for its users do not limit what it shows — the panel says so.
- Every write attempt leaves one audit line that names the table, never a value.
Yours to take or delete
The connection string. The dashboard action Show the connection string is the one owner-only exception: it rebuilds the value from the recorded attempt and writes one audit line per call. No agent can reach it, and rotation is not implemented.
Moving it. A managed database is kept for you when you leave, and its transfer to your own Supabase organization is arranged on request.
Deleting it. databaseDelete, or the Database page, removes the database — the data, the schema and the Supabase project behind it — permanently, with no copy kept by Tofu. It asks for the app's own name, typed back.
An archived database. databaseRestore puts it back into a new database Tofu runs and pays for, and databaseArchiveDownload hands you short-lived links to its stored copy.
An app with a managed database cannot be deleted until the database is deleted or transferred: projectDelete refuses it and names the step.
Limits
What Tofu does not do to your database
Run your migrations. The build runs them; Tofu has no SQL console and no migration runner.
Move your rows. Structure travels through your migration files; local data stays on your machine.
Rotate the password. Credential rotation is not built.
More than one per app. Each app has one managed database at most; the paid plan includes one for your apps.
The ship-it layer for vibe-coded apps. Your agent wrote it — Tofu ships it.
Works in all coding agents
© 2026 Tofu
trytofu.ai