Home Stack Docs About

About Modback

An open-source Backend-as-a-Service written in Rust — the backend you'd build yourself if you had the time, and the ability to read all of it.

Why Modback

Most backend platforms are fast to start with and expensive to leave. Modback takes the opposite position: the whole thing is MIT licensed, it runs on your hardware, and every layer is a Rust crate you can read, fork and replace.

That means no per-seat pricing, no bandwidth bill, no vendor that can change your terms. The trade is that you run it yourself — which is the point.

Principles

Readable, not magic

The source is the documentation. Nothing is hidden behind a control plane you can't inspect.

Fast by construction

Rust throughout: sub-10ms API responses, sub-50ms edge cold starts.

Secure by default

Row-level security in Postgres, complete auth in the core, a zero-vulnerability dependency audit.

No lock-in

Standard Postgres and Redis underneath. Take your data and leave whenever you like.

Status

Modback is at v0.1.0 and under active development. 16 of 25 crates are production-ready; the core platform is supported by 145+ integration tests and 85%+ coverage.

Production-ready

Foundation
commons · core · types · error
Data
postgres · redis · query
API
api · rest · graphql · realtime
Features
auth · webhook · storage · zones · metrics

In development

Edge functions
Planned
CRDT sync gateway
Planned
AI orchestration
Planned
Multi-tenancy
Planned

Roadmap

PostgreSQL with RLS
Shipped
Authentication
Shipped
Storage — 6 providers
Shipped
GraphQL auto-generation
Shipped
Realtime WebSocket
Shipped
Admin dashboard
In progress
Client libraries
In progress
Managed cloud
Planned
CLI tool
Planned
VS Code extension
Planned

Community

Questions, bug reports and pull requests are all welcome. The project follows a standard contributor code of conduct.

  • Issues and feature requests on the tracker
  • Pull requests against the dev branch
  • Chat in the community Discord

Security

Please report vulnerabilities privately rather than opening a public issue, so a fix can be prepared before disclosure.

Modback keeps a zero-vulnerability dependency audit as part of its build. One transitive advisory is knowingly accepted: a timing side-channel in the rsa crate, reachable only through MySQL support that Modback does not use, since the platform targets PostgreSQL exclusively.

Modback is released under the MIT License. You may use, modify and redistribute it, including commercially, provided the licence notice is preserved. The software is provided as-is, without warranty.

The Modback server collects no telemetry and contacts no external service on your behalf — verify that in the source if it matters to you.