Skip to content
Human resources ⇄ Database

Hibob to Supabase integration — real-time, two-way sync

Keep Hibob and Supabase in sync without custom scripts. Cut weeks of integration work, eliminate silent data drift, and give your team a single, reliable source of truth.

  • SOC 2 and 6 other compliance frameworks
  • POC with real engineers in minutes

Adopted by fast-scaling companies moving mission-critical data in real time

Case study
Migrated from MuleSoft
Case study
Migrated from Celigo
Migrated from Heroku Connect
Migrated from Matillion
Case study
Migrated from Fivetran
Case study
Migrated from Celigo
Why teams connect Hibob and Supabase

Put your workforce data where your apps can reach it: Supabase and Hibob share the same people, positions, and org structure in real time.

Hibob is the system of record for the people side of the business — employees, candidates, roles, and the org structure around them. Supabase is where internal tools, dashboards, provisioning jobs, and analytics actually read and store records. The overlap is the workforce itself: Employment, Work, Salaries, Time off in Hibob need to exist as queryable Schemas, auth.users, Row Level Security Policies, JSONB Columns in Supabase before an app can act on them. When that bridge is a nightly export or a hand-run CSV, every downstream system spends the day working from a roster that has already moved on.

Stacksync syncs Schemas, auth.users, Row Level Security Policies, JSONB Columns in Supabase with Employment, Work, Salaries, Time off in Hibob field by field, in real time. You decide which system owns which fields — Hibob typically owns identity and org attributes, while operational or computed values can flow back the other way — and Stacksync keeps every copy consistent, matching records on a stable key and resolving conflicts by rules you set.

The result is one live picture of the workforce on both sides: HR keeps its source of truth, and the database keeps a current mirror that internal apps, reports, and access controls can trust without a batch window in between.

Common use cases

  • 01 Push product events captured in Supabase Postgres to marketing tools for lifecycle campaigns
  • 02 Consolidate Supabase project data into a warehouse for analytics while keeping the app database as the system of record
  • 03 Auto-provision or deprovision accounts in an IdP, ticketing tool, or app database when Bob Lifecycle events fire employee joined or terminated.
  • 04 Push Salaries and Variable Pay from Bob into a payroll provider or warehouse each pay cycle, using the Payroll-permitted service user.

Common sync patterns

One directory of record

When a person record is added, changed, or deactivated in either system, the matching row in the other stays current, ending dual maintenance.

Reporting and analytics on current data

Employment, Work, Salaries, Time off replicate into Supabase where they join operational tables, so headcount, roles, and status reports run on the live state without manual pulls.

Org and structure stay aligned

Groups, departments, managers, and reporting lines from Hibob stay consistent in Supabase, so hierarchy-driven logic and permissions don't drift.

What you can sync between Hibob and Supabase

Representative objects on each side — any object or custom field can map to any target. Schemas are auto-detected; types are converted between the two systems.

Hibob objects Supabase objects How this pairing syncs
Time off Absence requests and who's-out data via /timeoff/employees/{id}/requests and /timeoff/whosout; submit new requests and read balances. Database Functions Postgres functions that can transform or validate synced rows. Time off is specific to Hibob and Database Functions to Supabase — each maps to any object or custom field on the other side.
Lifecycle Hire, termination, and leave status changes at /people/{id}/lifecycle; read-only and the source of lifecycle webhook events. Storage Object Metadata File metadata rows that can be joined to synced application data. Lifecycle is specific to Hibob and Storage Object Metadata to Supabase — each maps to any object or custom field on the other side.
Documents Employee documents accessed under the Docs API; gated behind the Documents permission granted per service user. Tables Standard Postgres tables; the primary two-way sync target. Documents is specific to Hibob and Tables to Supabase — each maps to any object or custom field on the other side.
Named lists Dropdown option lists such as departments and sites used to resolve field values when mapping People records during sync. Views Read-side projections exposed to outbound syncs. Named lists is specific to Hibob and Views to Supabase — each maps to any object or custom field on the other side.
People (Employees) Core employee records with out-of-the-box and custom fields; read via POST /people/search, created and updated through the /people endpoints. Schemas Namespaces (public and custom) that scope sync access. People (Employees) is specific to Hibob and Schemas to Supabase — each maps to any object or custom field on the other side.
Employment Historical table of job terms, contract, and working pattern under /people/{id}/employment; full CRUD, entries keyed by effectiveDate. auth.users Managed authentication users, often mirrored into CRM or support systems. Employment is specific to Hibob and auth.users to Supabase — each maps to any object or custom field on the other side.

How changes propagate between Hibob and Supabase

Each direction of the sync is driven by what the source system can signal and what the destination accepts — detection, delivery, and expected latency below.

Hibob Supabase Sub-second propagation

DetectionHibob notifies Stacksync of record changes through webhook events. Webhooks fire for employee created/updated/deleted, table-entry created/updated, time off, and lifecycle events.

DeliveryEach detected change is applied to Supabase as a row-level write, with types converted between the two schemas.

Supabase Hibob Sub-second propagation

DetectionSupabase pushes changes as they happen — webhook events backed by change data capture. Log-based CDC via Postgres logical replication, the same WAL feed that powers Supabase Realtime.

DeliveryEach detected change is written to Hibob through its API, with automatic retries and rate-limit backoff.

Rate-limit considerations

  • Hibob: Rate limits are enforced per service user; violations return HTTP 429 with X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset response headers. The docs list POST /people/search at 50 requests per minute, and bulk /people/search is preferred over per-record reads.
  • Supabase: SQL access is bounded by connection limits (pooled connections are provided); the REST layer is subject to the platform's limits.
What ships with Hibob ⇄ Supabase

Connect Hibob and Supabase for flexible, real-time data sync.

Real-time sync, workflow automation, event queues, EDI, and monitoring, for every Hibob–Supabase connection.

Real-time

Two-way sync

Changes in Hibob or Supabase instantly reflect in both systems. No stale data, no manual imports.

No-code + pro-code

Workflow automation

Trigger automated workflows whenever Hibob or Supabase data changes, update records, fire webhooks, or kick off sequences without brittle API scripts.

At scale

Event queues

Handle millions of events per minute without losing a single Hibob or Supabase record.

Observability

Monitoring

Track your Hibob ⇄ Supabase sync health, view errors, and replay failed events in one click.

Trading partners

EDI

Transform legacy EDI complexity into simple database interactions between Hibob and Supabase.

How the Hibob and Supabase connectors work

Hibob

Integration surface
REST API (the Bob API)
Authentication
Service User credentials over HTTP Basic auth (Base64-encoded serviceUserId:serviceUserToken); permissions granted per data category (People, Payroll, Documents) in Bob admin
Change detection
Webhooks fire for employee created/updated/deleted, table-entry created/updated, time off, and lifecycle events; the employee.updated payload flags which fields changed and Bob recommends an API call for the full record. There is no CDC stream, and deleting a table entry fires no webhook (Bob has no table-entry deletion event).
Capabilities
read · write · webhooks
Rate limits
Rate limits are enforced per service user; violations return HTTP 429 with X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset response headers. The docs list POST /people/search at 50 requests per minute, and bulk /people/search is preferred over per-record reads.
Hibob setup guide

Supabase

Integration surface
Direct PostgreSQL wire protocol connection, plus an auto-generated REST API (PostgREST)
Authentication
Database credentials (connection string) for SQL access; API keys (anon / service role) for the REST layer
Change detection
Log-based CDC via Postgres logical replication, the same WAL feed that powers Supabase Realtime; database webhooks can also fire on row changes
Capabilities
read · write · CDC · webhooks
Rate limits
SQL access is bounded by connection limits (pooled connections are provided); the REST layer is subject to the platform's limits
How it works

How to connect Hibob to Supabase — three steps, no code

Configure and sync within minutes, no code. Whether you sync 50k or 100M+ records, Stacksync handles the queues, infra, and plumbing. Integrations are non-invasive and need zero setup on your systems.

  1. 01

    Connect your apps

    Authenticate Hibob and Supabase with each platform's native method — OAuth, API keys, or service accounts — plus secure options like SSH tunneling, IP whitelisting, and VPC peering.

    • OAuth 2.0
    • SSH tunnel
    • VPC peering
    Hibob connected
    Supabase connected
    OAuth 2.0
    SSH tunnel
    SSL certificate
    VPC peering
  2. 02

    Choose tables

    Pick the Hibob and Supabase objects to sync — Stacksync auto-detects both schemas, including custom fields where the platform exposes them. Sync to existing tables, or let Stacksync create new ones with ideal data types.

    • Standard objects
    • Custom objects
    • Auto-schema
    objects · Hibob ⇄ Supabase
    Customers 12,480
    Sales Orders 8,213
    Invoices 5,902
    Items 1,344
  3. 03

    Map fields

    Fields map automatically even when names and types differ. Stacksync handles transformation and type casting for you, zero configuration required.

    • Auto-map
    • Type casting
    • Transforms
    Hibob Supabase
    Company company_name text
    Email email text
    Amount amount numeric
    Created created_at timestamp
FAQ

Hibob and Supabase integration FAQ

SECURITY

Security teams trust Stacksync

As a data company, we understand the importance of keeping your data secure. Stacksync is built with security best practices to keep your data safe at every layer, and is DPF-certified for US, EU, UK and CH data transfers.

SOC 2 Type II
ISO 27001
HIPAA BAA
GDPR
CCPA
DPF US-EU-UK-CH
→ SECURITY WITH BENEFITS

SSO & SCIM

Let your users access Stacksync from your centralized user management systems. Works with Okta, Azure, Google SSO and more.

Alerts

Immediately get alerted about record syncing issues over email, Slack, PagerDuty and WhatsApp. Resolve issues from a centralized dashboard with retry and revert options.

Secure connection options

Securely connects to your systems with:

Related integrations

Every pair below is a real-time, two-way sync. Search all 540 integrations available for Hibob and Supabase.

Popular · 8 of 540
Coworkers laughing in front of a laptop in a casual office setting

Your last integration took months.
Your next one takes a prompt.