Skip to content
Roadmap

What we shipped, what's next.

No promises on dates - but we ship in tagged releases and write each one up in the changelog. If you want to push something up the list, email contact@suparbase.com.

Recently shipped

12 items
  • Two-factor authentication (TOTP + recovery codes)

    Optional 2FA via any standards-compliant authenticator (Authy, 1Password, Bitwarden). 10 single-use recovery codes generated at enable time. Required for admin-panel access in deployments that have admins configured.

    v3.8.0
  • Forgot-password flow

    Self-service password reset via email link. SHA-256-hashed tokens, 1-hour expiry, enumeration-resistant, single-use.

    v3.6.0
  • Account deletion (GDPR Art. 17)

    Self-service delete from /settings/account with typed confirmation. Cascades through every linked row.

    v3.6.0
  • Invoice history

    Dodo-hosted PDF invoices accessible from /settings/billing - no more digging through receipt emails.

    v3.7.0
  • Admin: audit log search

    Forensic search at /admin/audit by user, connection, table, verb, and date range. Backed by the new compound index.

    v3.6.0
  • Database optimisation pass

    Index rework, query refactors, partial indexes for unapplied webhook events, batched audit-log retention.

    v3.4.3
  • Agent Sentry (one-click session undo)

    Every AI-agent write is fingerprinted and bucketed into a session. One-click undo replays the audit log in reverse inside a single transaction.

    Feature page
  • Public API + personal tokens

    Read-only tokens for /api/public/v1: list connections, pull the live schema or audit activity, read Sentry findings, run a SELECT. Revocable, expiring, rate-limited per token.

    API reference
  • Connection import / export

    Bulk-paste projects from JSON or CSV with a validated preview; export a secret-free manifest to move between accounts.

    v3.20.0
  • Production guard + scheduled Sentry

    Label a connection production / staging / development. Production adds typed confirmations to destructive actions. Sentry can re-scan on a cadence and notify in-app.

    v3.20.0
  • Schema snapshots, ERD, and types

    Automatic drift snapshots with a diff view, a live entity-relationship diagram, and TypeScript / Zod types generated from the real schema.

    v3.20.0
  • Performance advisor

    pg_stat-backed page: table sizes, scan patterns, bloat, unused indexes, slowest statements, and conservative suggestions with copy-paste SQL.

    v3.20.0

In progress

3 items
  • Annual billing

    Discount for paying yearly. UI scaffolded; live once the Dodo product is published.

  • End-to-end Playwright suite

    24 public and auth-adjacent browser checks now run in CI. Seeded signed-in dashboard workflows and sandbox payment flows are next.

  • Real-time error reporting (Sentry)

    Code paths instrumented via the reportError() shim. Operator-side wiring (instrumentation.ts + DSN) is in deployment guides.

Next

5 items
  • SSO via SAML / OIDC

    For Team-plan customers. Identity provider integration (Okta, Auth0, JumpCloud).

  • SOC 2 Type I

    Pursuing certification through Drata. Readiness assessment complete; remediation in progress.

  • Write scope for API tokens

    Opt-in write tokens (row upserts, snippet runs in write mode) with the same audit + agent-session attribution as the UI.

  • More AI-write archetypes

    Sentry now fingerprints 25 agent kinds, including Cursor, Claude Code, Codex, Copilot, Windsurf, Gemini CLI, Devin, Bolt, Zed, Amp, Kiro, OpenCode, Trae, and Junie. Keep expanding as new runtimes appear.

  • Column masking for viewers

    Per-column PII masks applied in the proxy for the viewer role, so support staff can browse without seeing raw emails or addresses.