Two-way sync
Changes in Box or Supabase instantly reflect in both systems. No stale data, no manual imports.
Keep Box and Supabase in sync without custom scripts. Cut weeks of integration work, eliminate silent data drift, and give your team a single, reliable source of truth.
A database holds structured records; a storage system holds the files those records depend on, such as contracts, images, exports, uploads, and documents. The two describe the same things from opposite sides: a row in Supabase says a file exists and carries its name, location, and status, while Box holds the bytes. Linked only by a hand-kept path or a one-off script, the two drift the moment a file is renamed, moved, or deleted and the record still points at where it used to be.
Stacksync syncs Storage Object Metadata, Tables, Views, Schemas in Supabase with Folders, Metadata, Collaborations, Users in Box bi-directionally and in real time. File attributes, including name, path or object key, size, type, modified time, owner, and tags or custom properties, map field by field to columns on the matching row, and a change on either side shows up on the other within seconds. New files appear as rows, metadata edits travel in the direction you choose, and deletes stay consistent, with conflict rules you set in place of nightly reconciliation scripts.
Tags, custom properties, owner, or status columns edited on a row in Supabase write back to the matching file's metadata in Box, and metadata changed in Box updates the row, so the two never disagree about a file.
Where a record in Supabase references a file in Box, such as a contract, an image, an export, or an upload, the reference, path, and status stay consistent as files are renamed, moved, or replaced, so stored links keep resolving.
Files that arrive in a folder or bucket in Box become rows in Supabase as they land, so a database-driven process can pick them up without polling the storage system's API.
Representative objects on each side — any object or custom field can map to any target. Schemas are auto-detected; types are converted between the two systems.
| Box objects | Supabase objects | How this pairing syncs | |
|---|---|---|---|
| Metadata Structured key-value instances attached to files and folders via metadata templates; synced two-way with database columns for classification and search. | Views Read-side projections exposed to outbound syncs. | Metadata is specific to Box and Views to Supabase — each maps to any object or custom field on the other side. | |
| Collaborations Access grants linking a user or group to a file or folder with a role such as viewer, editor, or co-owner; written to manage sharing programmatically. | Schemas Namespaces (public and custom) that scope sync access. | Collaborations is specific to Box and Schemas to Supabase — each maps to any object or custom field on the other side. | |
| Users Managed and app users in the enterprise; provisioned, updated, and deprovisioned to keep Box access aligned with an HR or identity source. | auth.users Managed authentication users, often mirrored into CRM or support systems. | Users is specific to Box and auth.users to Supabase — each maps to any object or custom field on the other side. | |
| Groups Named user collections used for bulk collaboration; membership synced from a directory or IdP. | Row Level Security Policies Row-level access rules that govern what the REST layer exposes. | Groups is specific to Box and Row Level Security Policies to Supabase — each maps to any object or custom field on the other side. | |
| Tasks Review or approval assignments on a file with due dates and states; read for workflow reporting or written to start approvals. | JSONB Columns Semi-structured payloads such as event properties or nested objects. | Tasks is specific to Box and JSONB Columns to Supabase — each maps to any object or custom field on the other side. | |
| Events Enterprise admin event stream, an audit log of uploads, deletes, logins, and shares across the account; read-only, consumed for reporting or change feeds. | Database Functions Postgres functions that can transform or validate synced rows. | Events is specific to Box and Database Functions to Supabase — each maps to any object or custom field on the other side. |
Each direction of the sync is driven by what the source system can signal and what the destination accepts — detection, delivery, and expected latency below.
DetectionBox notifies Stacksync of record changes through webhook events. V2 webhooks fire on triggers such as FILE.UPLOADED, FILE.TRASHED, and METADATA_INSTANCE.UPDATED.
DeliveryEach detected change is applied to Supabase as a row-level write, with types converted between the two schemas.
DetectionSupabase pushes changes as they happen — webhook events backed by change data capture. Log-based CDC via Postgres logical replication, the same WAL feed that powers Supabase Realtime.
DeliveryEach detected change is written to Box through its API, with automatic retries and rate-limit backoff.
Real-time sync, workflow automation, event queues, EDI, and monitoring, for every Box–Supabase connection.
Changes in Box or Supabase instantly reflect in both systems. No stale data, no manual imports.
Trigger automated workflows whenever Box or Supabase data changes, update records, fire webhooks, or kick off sequences without brittle API scripts.
Handle millions of events per minute without losing a single Box or Supabase record.
Track your Box ⇄ Supabase sync health, view errors, and replay failed events in one click.
Transform legacy EDI complexity into simple database interactions between Box and Supabase.
Configure and sync within minutes, no code. Whether you sync 50k or 100M+ records, Stacksync handles the queues, infra, and plumbing. Integrations are non-invasive and need zero setup on your systems.
Authenticate Box and Supabase with each platform's native method — OAuth, API keys, or service accounts — plus secure options like SSH tunneling, IP whitelisting, and VPC peering.
Pick the Box and Supabase objects to sync — Stacksync auto-detects both schemas, including custom fields where the platform exposes them. Sync to existing tables, or let Stacksync create new ones with ideal data types.
Fields map automatically even when names and types differ. Stacksync handles transformation and type casting for you, zero configuration required.
Yes. Stacksync provides a managed, real-time two-way integration between Box and Supabase: authenticate both systems, choose the objects to sync (such as Box's Metadata and Collaborations), map fields visually, and changes propagate both ways in milliseconds — no code required.
On the Supabase side: Storage Object Metadata, Tables, Views, Schemas, plus custom fields where Supabase exposes them. On the Box side: Folders, Metadata, Collaborations, Users. Stacksync auto-detects both schemas and converts types between the two systems.
Yes. Each object mapping can be bidirectional or restricted to a single direction (both systems accept writes). Read-only mirrors, one-way pushes, and full two-way sync can be mixed in the same integration.
Common patterns for Box and Supabase: File metadata kept in step; Records that point at documents; A landing zone for incoming files. Tags, custom properties, owner, or status columns edited on a row in Supabase write back to the matching file's metadata in Box, and metadata changed in Box updates the row, so the two never disagree about a file.
Box: REST API (api.box.com/2.0), plus the Events API and V2 Webhooks. Authentication: OAuth 2.0 for user-delegated access, or server-to-server auth via JWT (RSA keypair) or Client Credentials Grant (CCG) using a Box app; short-lived developer tokens for testing. Supabase: Direct PostgreSQL wire protocol connection, plus an auto-generated REST API (PostgREST). Authentication: Database credentials (connection string) for SQL access; API keys (anon / service role) for the REST layer. Stacksync manages authentication, retries, and rate limits on both sides.
Supabase: Every Supabase project is a full PostgreSQL database, so standard Postgres drivers, SQL tooling, and log-based CDC apply directly. Box: Webhooks are capped per application and per file/folder target, must be verified with Box's signature keys, and their payloads carry the object reference rather than the full changed content. Stacksync's field mapping accounts for these differences between Box and Supabase without custom code.
As a data company, we understand the importance of keeping your data secure. Stacksync is built with security best practices to keep your data safe at every layer, and is DPF-certified for US, EU, UK and CH data transfers.
Let your users access Stacksync from your centralized user management systems. Works with Okta, Azure, Google SSO and more.
Immediately get alerted about record syncing issues over email, Slack, PagerDuty and WhatsApp. Resolve issues from a centralized dashboard with retry and revert options.
Securely connects to your systems with:
Every pair below is a real-time, two-way sync. Search all 531 integrations available for Box and Supabase.