About this role.
Supabase is hiring a senior Software Engineer to build and operate its Auth product, with primary development in Go and TypeScript. The role covers secure authentication features, protocol support for OAuth, OIDC, and SAML, Postgres migrations, and reliable operation of a large-scale service. The engineer will work across server-side systems and client libraries, improve observability, and contribute technical RFCs. This is a globally remote, asynchronous position requiring substantial ownership, collaboration, and engagement with the developer community.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
5/5Pace & Pressure
4/5Autonomy Level
5/5Communication Load
4/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I would use standards-compliant authorization-code flow with PKCE, validate issuer and audience claims, verify signatures using provider JWKS with key rotation support, and enforce state and nonce validation. I would also define a provider abstraction, secure token storage strategy, audit logging, and thorough integration tests for error and account-linking cases.
I would use an expand-and-contract migration plan: first introduce backward-compatible schema changes, deploy application code that supports both versions, backfill in controlled batches, validate progress with metrics, and only then remove deprecated structures. I would make the migration resumable, rate-limited, observable, and paired with a rollback or mitigation plan.
I focus on context propagation, bounded concurrency, timeout and cancellation handling, connection-pool tuning, race detection, memory profiling, and graceful shutdown. I also instrument critical paths with latency, error, saturation, and dependency metrics so that capacity and reliability issues can be identified before they affect users.
I would first compare deployment timing with latency and error metrics, then use distributed traces to isolate whether the delay is in application logic, database queries, external identity providers, or network calls. After identifying the regression, I would mitigate through rollback, feature flags, or traffic controls, document the incident, and add tests or alerts to prevent recurrence.
I would clearly state the problem, threat model, goals and non-goals, proposed design, alternatives, migration and rollback strategy, operational impact, and testing plan. I would request review from security, platform, and product stakeholders, incorporate feedback transparently, and ensure the final decision records the rationale and residual risks.
About Supabase
Supabase is the Postgres development platform, built by developers for developers. We provide a complete backend solution including Database, Auth, Storage, Edge Functions, Realtime, and Vector Search. All services are deeply integrated and designed for growth.
About the role
Auth, written in Go (server) and with client libraries for TypeScript, SSR and for other frameworks and technologies, is one of the most popular products in the Supabase stack. We are seeking someone to help us build new and maintain existing Auth features.
What you’ll be responsible for
Designing and implementing secure, scalable authentication features in Go and TypeScript.
Working across the stack: from server-side protocols to client-side libraries for frameworks like Next.js.
Owning the performance, reliability, and scalability of the Auth server across Supabase’s infrastructure.
Contributing to the evolution of our Auth architecture, including support for OAuth, OIDC, SAML, and other protocols.
Planning and executing safe database migrations across a large fleet of Postgres instances.
Building and improving observability: metrics, tracing, alerting, and dashboards to keep the system healthy at scale.
Writing and reviewing RFCs as part of our product development process.
Collaborating with engineers across Supabase to ensure a seamless experience for developers using our tools.
Supporting the community and responding to developer feedback on GitHub, Discord, and other channels.
You might be a good fit if you
(Required) Have 4+ years of professional experience writing and shipping Go in production.
(Required) Have 2+ years of professional experience working on an authentication system (implementing protocol support, maintenance at scale).
(Required) Have strong relational database experience (Postgres or MySQL); Postgres experience is a bonus.
Have strong knowledge of TypeScript in addition to Go (languages used daily).
Have strong knowledge of web technology fundamentals (cookies, sessions, JWT, HTTP, browser APIs).
Have good knowledge of and deep interest in authentication security (passwords, protocols such as OAuth, OIDC or SAML, cryptography fundamentals such as hash functions, signatures and ciphers).
Have experience working with multiple web frameworks like Next.js (or other SSR alternative in the JavaScript space) and traditional web frameworks like Ruby on Rails, Django, Laravel or equivalent (in any language).
Have good technical writing skills (RFC process is an important part of making changes to the Auth product).
Have hands-on experience building and operating services at significant scale.
Have deep understanding of systems-level concerns: memory management, concurrency patterns, and compute resource optimization in Go.
Have experience with Kubernetes and AWS (or comparable cloud platform) in a production setting.
Have solid grasp of observability practices — metrics, distributed tracing, structured logging, and alerting (e.g., Prometheus, Grafana, OpenTelemetry).
Have experience managing database schema migrations safely at scale.
What We Offer
Fully Remote
We hire globally. We believe you can do your best work from anywhere. There are no Supabase offices, but we provide a WeWork membership or co-working allowance you can use anywhere in the world.
ESOP
Every team member receives ESOP (equity ownership) in the company. We want everyone to share in the upside of what we’re building together.
Tech Allowance
Use this budget to set up your ideal work environment—laptop, monitor, headphones, or whatever helps you do your best work.
Health Benefits
Supabase covers 100% of health insurance for employees and 80% for dependents, wherever you are. Your wellbeing and your family’s health are important to us.
Annual Off-Sites
Once a year, the entire company gathers in a new city for a week of connection, collaboration, and fun. It’s a highlight of our year.
Flexible Work
We operate asynchronously and trust you to manage your own time. You know what needs to be done and when.
Professional Development
Every team member receives an annual education allowance to spend on learning—courses, books, conferences, or anything that supports your growth.
About the Team
Supabase was born-remote and open-source-first. We believe our globally distributed team is our secret weapon in building tools developers love.
~400 team members
60+ countries
20+ languages spoken
Over $1B raised (including our $500M Series F)
540,000+ community members
We move fast, build in public, and use what we ship. If it’s in your project, we probably use it in ours too. We believe deeply in the open-source ecosystem and strive to support—not replace—existing tools and communities.
Annual salary information is not provided for this position. Explore salary ranges for similar roles in our Salary Directory ›
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.







