# InsForge: an open source backend that agents drive over MCP

> InsForge bundles Postgres, auth, storage, edge functions and an LLM gateway behind an MCP server and a CLI, so a coding agent can configure the backend itself. Here is what the repository actually documents, and where the gaps are.

**InsForge/InsForge** — The all-in-one, open-source backend platform for agentic coding. InsForge gives your coding agent database, auth, storage, compute, hosting, and AI gateway to ship full-stack apps end-to-end.

- Repository: https://github.com/InsForge/InsForge
- Website: https://insforge.dev
- Stars: 13,022 · Forks: 1,197
- Language: TypeScript
- License: Apache-2.0
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/insforge-insforge

## The problem InsForge solves for agent-written applications

A coding agent can write a Next.js page in seconds and then stall completely on the database. Creating a table, wiring an auth provider, or provisioning a storage bucket usually means leaving the editor, opening a dashboard, and translating the agent's intent into clicks. InsForge's answer is to expose the backend as tools the agent can call. The README describes two interfaces: an MCP Server, available self-hosted and in the cloud, which exposes InsForge's operations as tools any MCP-compatible agent can invoke, and a CLI plus Skills, cloud only, that agents call from the terminal. The stated goal is that agents operate the backend like backend engineers, reading schemas, metadata and runtime logs, then configuring primitives such as edge functions, migrations, buckets and auth providers. The audience is narrow and specific: teams whose primary author of application code is already an agent. If a human writes the SQL and clicks the dashboard, most of the value here evaporates.

## What the stack is made of

The core products listed in the README are Authentication, a Postgres relational database, S3-compatible storage, a Model Gateway described as an OpenAI-compatible API across multiple LLM providers, Edge Functions, Compute marked as a private preview, and site build and deployment. The compose file shows how the data layer is assembled. A Postgres image is published at ghcr.io/insforge/postgres:v15.13.4, and PostgREST runs beside it at postgrest/postgrest:v12.2.12, configured with PGRST_DB_SCHEMA set to public and PGRST_DB_ANON_ROLE set to anon. PostgREST is what turns tables into an HTTP API, which is why the repository topics include realtime and websockets. The backend itself is TypeScript, with a Deno runtime pinned in the Dockerfile at denoland/deno:alpine-2.0.6. The repository is a monorepo: package.json declares workspaces for backend, frontend and packages/*, and turbo.json drives the dev, build, test and lint scripts. The topic list also names pgvector and embeddings, so vector search is part of the intended feature set rather than an add-on.

## Installing InsForge with Docker Compose

The README's self-hosted path requires Docker with Compose v2. The setup script fetches the files the stack reads and generates secrets, but starts nothing:

```bash
curl -fsSL https://raw.githubusercontent.com/InsForge/InsForge/main/deploy/setup.sh | sh -s ~/insforge
```

According to the README, that writes JWT_SECRET, ENCRYPTION_KEY, POSTGRES_PASSWORD, ROOT_ADMIN_PASSWORD and two access keys into ~/insforge/.env with mode 600. Re-running it refreshes the files and keeps values you have already set. Two variables in that file need your attention before anything is reachable from a browser:

```bash
cd ~/insforge
$EDITOR .env          # API_BASE_URL, VITE_API_BASE_URL — the URL browsers will use
docker compose up -d
```

Because .env sets COMPOSE_FILE, plain docker compose commands work from that directory without -f flags. The .env.example explains why COMPOSE_FILE matters: a self-hosted install points it at the image-only compose file under deploy/docker-compose, and a storage overlay is appended with a colon, for example deploy/docker-compose/docker-compose.yml:docker-compose.minio.yml. The same file warns that COMPOSE_PROJECT_NAME prefixes every container, volume and network, so a second instance on one host needs its own value or docker compose up will adopt the first instance's containers. The default port in .env.example is 7130. Contributing to the project itself is different: npm run install:all installs root, backend and frontend dependencies, and npm run dev runs both through turbo.

## Where the documentation goes quiet

Several things a production operator needs are simply not documented. There is no rollback procedure for a failed migration, and no documented upgrade path between releases beyond re-running the setup script, which the README says only refreshes files. The Compute product is labelled a private preview, so anything long-running should be assumed unavailable. The compose file ships development defaults: POSTGRES_PASSWORD falls back to postgres, and JWT_SECRET falls back to dev-secret-please-change-in-production when ENCRYPTION_KEY and JWT_SECRET are both unset. The setup script generates real values, but anyone copying docker-compose.yml by hand inherits those fallbacks. PostgREST's PGRST_DB_POOL defaults to 50 and the compose comment says to keep it in sync with the backend's POSTGREST_MAX_SOCKETS. That is a coupling you have to remember manually. The README also does not document backup, restore or secret rotation, despite .env.example advising rotation. None of this is unusual for a project at v2.3.2, but it is the difference between a demo and something you hand to a client.

## InsForge vs Supabase, and what the comparison actually turns on

Supabase is the obvious reference point, and the search data shows people asking for the differences. The architectural overlap is real: both put Postgres at the centre and expose it over HTTP. The divergence is the interface. Supabase is organised around a dashboard and client libraries that a person operates; InsForge is organised around an MCP server and a CLI that an agent operates, with the README explicitly listing the ability to pull schemas, metadata and runtime logs as a first-class feature. That matters because an agent debugging its own work needs to read state, not just write it. The second difference is packaging. InsForge ships a Docker Compose stack with an image-only variant and a storage overlay you select through COMPOSE_FILE, and it also offers a cloud at insforge.dev. Supabase's self-hosting story is a larger set of services. If your team wants a managed platform with a long track record, InsForge is the wrong side of that trade today. If you want the backend to be a tool your agent calls, the MCP-first design is the reason to look at it at all.

## Maintenance, licensing and what an upgrade costs

The repository is not archived, and the last push was on 2026-09-09, eight days before this writing, with v2.3.2 released on 2026-09-08. That is a live project by any reasonable reading. The licence is Apache-2.0, which permits commercial use and modification and includes a patent grant; it also means you carry the obligation to keep the licence and notice files with any redistribution. That is a description of the licence text, not legal advice, and if you embed InsForge in a product you should have counsel read it. Upgrade cost is where the design helps and hurts. The Dockerfile goes out of its way to keep image layers cached across releases: a package-prep stage strips the version field from the root package.json so that the dependency layer does not rebuild on a version bump. That is a deliberate choice to make frequent releases cheap to deploy. The counterweight is the manual coupling: COMPOSE_PROJECT_NAME must stay stable, COMPOSE_FILE must point at the right compose file, and PGRST_DB_POOL must track POSTGREST_MAX_SOCKETS. Those are three places where an upgrade can silently diverge from the intended configuration.

## Conclusion

Adopt InsForge if you already let an agent write most of your application code and you want that agent to create tables, buckets and auth providers without you relaying instructions. Skip it if you need a mature managed platform with published pricing, or if you want the compute tier, which the README still labels a private preview. Before committing, run the setup script into a scratch directory, confirm the generated .env holds JWT_SECRET, ENCRYPTION_KEY, POSTGRES_PASSWORD and ROOT_ADMIN_PASSWORD, and read deploy/docker-compose/docker-compose.yml to see exactly which containers the image-only stack starts.

## FAQ

### What is InsForge?

It is an open source backend platform for agentic coding, giving a coding agent database, auth, storage, compute, hosting and an AI gateway. Agents reach it through an MCP server, or through a CLI plus Skills on the cloud offering.

### What are the key differences between Supabase and InsForge?

Both put Postgres at the centre, but InsForge is designed around agents: the README describes an MCP server and a CLI that let an agent read schemas, metadata and runtime logs, then configure primitives itself. Supabase is organised around a dashboard and client libraries that a person operates.

### Is InsForge open source?

Yes. The repository is licensed Apache-2.0, and the README links to the opensource.org licence page. The self-hosted path is a Docker Compose stack rather than a closed hosted service.

### How much does InsForge cost?

The README does not state pricing. It documents a cloud-hosted option at insforge.dev and a self-hosted Docker Compose install, and the Apache-2.0 licence covers the source.

### What does InsForge do?

It provides database, auth, storage, edge functions, a model gateway and site deployment, and exposes them to coding agents through an MCP server or a CLI with Skills. The README frames the goal as letting agents ship full-stack apps end to end.

## Sources

- [InsForge/InsForge on GitHub](https://github.com/InsForge/InsForge)
- [License: Apache-2.0](https://github.com/InsForge/InsForge/blob/main/LICENSE)
- [Project website](https://insforge.dev)
- [README](https://github.com/InsForge/InsForge/blob/main/README.md)
- [Releases](https://github.com/InsForge/InsForge/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/insforge-insforge
