Tessera docs

Launch Tessera

Launch

Auth

Row-level rules

Decide who can read and write each row, enforced inside the database.

Writing a rule

Rules are attached to tables in the schema. They compile to Postgres row-level security policies, so they apply to every client and every API call.

schema.ts
export const tasks = table("tasks", { /* … */ })  .rule("read", ({ user, row }) => row.ownerId.eq(user.id))  .rule("write", ({ user, row }) => row.ownerId.eq(user.id))

Team access

schema.ts
.rule("read", ({ user, row }) =>  exists(memberships.where({ userId: user.id, projectId: row.projectId })))

Testing rules

Use tessera rules test to run a query as a given user and see which rows it returns.

Deny by default

Tables with no rules are readable only by server keys. Add rules before exposing a table to the browser.

Was this helpful?

© 2026 Tessera, Inc.

Support

Status

Create a free website with Framer, the website builder loved by startups, designers and agencies.