# Trade-offs and a Firebase Checklist — Firebase

Source: https://www.skillbyai.com/en/firebase/pr-check

> Firebase vs Supabase vs a custom backend.

## Choosing and reviewing

**Firebase** excels at fast delivery, realtime sync, offline-capable mobile apps and managed auth, at the cost of a NoSQL model without joins, per-operation pricing and platform lock-in. **Supabase** offers a Postgres database with SQL, joins and row-level security, which suits relational data and teams that know SQL. A **custom backend** gives full control and portability but you own servers, scaling and security. Many teams mix them, for example Firebase Auth and FCM with a separate database. Before launch, review: rules tested and deployed from the repo, App Check enabled, no secrets in clients, queries bounded and indexed, trusted logic in functions, costs alerted, and backups or exports planned.

## The checklist

Use it before launch and in reviews.

```text
[ ] separate projects for dev / staging / production
[ ] Security Rules: deny by default, owner and role checks, field validation
[ ] rules unit tests run against emulators in CI
[ ] App Check enabled; API key restricted where possible
[ ] no secrets in client code; functions use defineSecret
[ ] trusted operations (payments, roles, counters) in Cloud Functions
[ ] data modelled for queries; no unbounded arrays; composite indexes in repo
[ ] every query limited and paginated; listeners unsubscribed
[ ] transactions or batches for multi-document changes; idempotent triggers
[ ] budget alerts and usage dashboards reviewed
[ ] scheduled Firestore exports or backups (check current options)
[ ] Remote Config defaults; staged rollouts watched with Analytics / Crashlytics
[ ] exit plan: data export path if you outgrow the platform
```

## Decide by data shape

If your data is highly relational with complex reporting, weigh a SQL backend; if it is document-shaped and realtime, Firebase is a strong fit.

**Quiz:** Which is a common reason to choose Supabase or a SQL backend over Firestore?

- [ ] Wanting managed authentication
- [ ] Needing realtime listeners
- [x] Highly relational data that benefits from joins and SQL queries
- [ ] Deploying a static site

*Answer:* Highly relational data that benefits from joins and SQL queries. Firestore has no joins.
