TL;DR
PocketBase is an open-source backend in a single Go binary: SQLite database, auth, file storage, realtime and an admin dashboard, ready in minutes on a small server. It is free under the MIT license, and you run, scale, back up and update it yourself on one server. pylo is a hosted backend platform where data model, permissions, flows, admin UI, forms, events and AI access are one system, for developers and the rest of the team. If you want a lean backend for a side project or a small app and like running it yourself, PocketBase is hard to beat. If your app runs a business, your team needs to work with the data and you'd rather not operate the server, pylo gives you all of that out of the box.
What is pylo?
pylo is a Backend-as-a-Service platform from Germany that you can use to build the operating system for your company. You model entities, fields and relations in the admin panel or through the API, and pylo generates a typed GraphQL API instantly. The same permission model governs that API, the admin UI, forms, flows and the MCP server. pylo flows run business processes and automations on top of your own data model and connect to the tools you already use. With pylo you build apps, automations and products on one coherent data base across your whole team.
What is PocketBase?
PocketBase is an open-source project under the MIT license, built mainly by one developer on a volunteer basis and without a company behind it. It ships as one executable with an embedded SQLite database. Collections can be base, auth or view collections, with 13 field types including relations, files and JSON. You get a REST-style API with realtime subscriptions, JS and Dart SDKs, file storage on disk or S3 and a dashboard for superusers. You extend it with Go or JavaScript hooks and cron jobs.
At a glance
PocketBase | pylo | |
|---|---|---|
What you get | An app backend in one binary that you host: SQLite, auth, files, realtime, dashboard | A finished, hosted backend: data model, API, permissions, flows, admin UI, forms, analytics |
Data model | Base, auth and view collections with 13 field types and relations | Entities, fields and relations, visual or through the API, live in the admin panel |
API | REST-style API with realtime over server-sent events, JS and Dart SDKs | Typed GraphQL with subscriptions for real-time usecases, schema generated per user, webhooks, NextJS SDK |
Permissions | Five API rules per collection as filter expressions, no roles or field-level rules | Tenant isolation plus configurable ARO/ACO with hierarchy and field-level access |
Auth | Email/password, OTP, MFA, around 30 OAuth2 providers | Email/password, Microsoft and Google SSO, API keys |
Business logic | Go or JavaScript hooks and cron jobs that you write and deploy with the binary | Visual flow engine with cron, webhook and event triggers, pre-defined integrations plus TypeScript custom actions |
Admin UI for non-devs | Dashboard for superusers, who bypass all rules | Configurable list/detail views with state-based field visibility and different components for different datatypes, bound to the same permission system |
Forms | Build your own | Built in, powerful editor, public or authenticated, directly mapped to entities |
Analytics | Build your own | Every change emitted as an event with before/after values, you can bring your own events and build dashboards on everything with deeply integrated permissions |
AI access | No official MCP server, community servers only | MCP with the user's permissions; writes become proposals you approve |
Scaling | One server, vertical scaling only | Managed by the pylo team, ready to work with millions of records and ten thousands of flow runs |
Open source / self-host | Yes, MIT, self-hosted only | No |
Hosting | Your own server or third-party hosts | Hetzner, Germany |
A hosted backend instead of a binary to run
PocketBase's simplicity is real: download one file, start it and you have a database, an API and a dashboard. The PocketBase project offers no managed hosting, so production means your own server. You handle updates, which can break things until version 1.0, backups, monitoring and security. PocketBase scales on a single server only, so a more complex app needs a bigger machine and there is no failover if that server goes down.
In pylo you add an entity, a field or a relation in the admin panel and the typed GraphQL API updates at once, without any kind of migration or redeployment. Field types include relations, enums, JSON, public or private files, rich text, dates, booleans and number/text formatters, with validation built in. You filter across relations and group aggregations by any field, even across deeply nested data structures. Hosting, scaling, updates and backups are our job.
Permissions that follow the data everywhere
PocketBase secures each collection with five API rules, for list, view, create, update and delete. A rule is locked, public or a filter expression on the request and the record, which covers many app scenarios. There are no roles or groups as such, so you model them yourself inside the rules and there are no field-level rules beyond hiding a field from the API entirely. Superusers bypass all rules, so anyone who works in the dashboard sees and can change everything.
pylo separates tenants at the row level. Inside a tenant, any entity can act as the requester (ARO) and any entity as the requested object (ACO), with hierarchies and field-level rules. Every path into the data is GraphQL, so the same rules apply to the API, the admin panel, forms, flows and MCP, including the people who work in the admin panel.
pylo flows instead of hooks in your binary
In PocketBase, logic lives in hooks: you either use PocketBase as a Go framework and compile your own binary or write JavaScript hooks that run in an embedded engine without Node APIs or async code. Cron jobs are registered in code. Retries, rate limits, logging and connections to other systems are code you write, deploy and maintain.
In pylo you build the same logic in a visual workflow engine called pylo flows, where any event in pylo can start a flow, additionally you can use cron schedules and incoming webhooks. pylo flows include retries, custom rate limiting, error handling and full event logs and everything is statically typed. pylo ships integrations for email sending and a growing selection of third-party systems, but you can easily code your own flow actions in TypeScript.
An admin dashboard your operations team will actually use
The PocketBase dashboard is clean and fast, and it is made for superusers: the people who configure collections, rules and settings. Everyone who logs in there has full access, so it isn't a place for your sales or support team. There are no role-specific views, state-dependent fields or forms, so teams build their own back office.
pylo's admin UI is built for your whole team, no matter if they are developers or not: you compose list and detail views from predefined components, decide who sees what and show or hide fields depending on a record's state. The pylo form builder maps forms directly to your entities, including relations, with public or authenticated access, hidden fields, conditional rendering and submission limits per form or per user.
Events and dashboards built in with pylo analytics
PocketBase has no event stream or dashboards for your business data. Reporting means writing queries, adding hooks that log changes or exporting the SQLite file.
In pylo, every create, update and delete emits an event with the full before and after state, which you can enrich with your own event data through our API. On top of your events and regular pylo data you can build customized dashboards directly next to your data and workflows.
AI and MCP with guardrails
PocketBase has no official MCP server; community projects exist and how they handle writes depends on the project. The PocketBase FAQ is openly sceptical of AI-driven development.
pylo's MCP server is made for both, developers who want to use agentic coding and team members who want to analyze their data. The AI gets exactly the connected user's read permissions, nothing else. pylo never applies an AI's writes directly, instead they arrive as proposals that a human accepts or declines, so you can benefit from the speed of AI without kicking the human out of the loop.
File handling
PocketBase stores files on the local disk or on any S3-compatible storage, creates thumbnails on the fly and can protect files with short-lived tokens. pylo stores files in EU-hosted object storage with public or private links, no file size limit and for any file type, as fields on your entities with the same permissions as the rest of the record.
Agencies and multi-tenant work
With pylo, agencies can run many client workspaces from one user account; each workspace is its own tenant separated by RLS and one login switches between them. With PocketBase, agencies usually run one instance per client, which means one more server to update, back up and monitor for every client, and tenant separation inside an instance is something you build into the API rules yourself.
Pricing
PocketBase | pylo | |
|---|---|---|
Software | Free under MIT | 0€ plan with 5,000 records, 500 flow actions, 1 GB files, unlimited users and API requests |
Small production setup | Your own VPS from a few euros a month or a third-party host | Starter 49€ per workspace/month, including 100k records, 5k flow actions with additional overages |
Larger | A bigger server, no horizontal scaling | Business 999€/month, including 2M records, 250k flow actions, with additional overages |
Operations | Updates, backups, monitoring and security on you | Included, with a 99.5% SLA on paid plans |
Support | Community, no paid support | Personal support from the team that builds the product |
In pure server costs, PocketBase is the cheapest backend you can get: a small VPS handles a surprising amount of traffic. The real cost is time: setting up the server, updating across breaking releases, testing backups, and building permissions, automation and a back office in your own code.
pylo's price already includes hosting, flows, the admin UI, forms, analytics and personal onboarding. Every pylo plan has every feature and unlimited users, plans differ only in included usage.
Hosting, compliance and reliability
All pylo content data, data models and databases live in data centres in Germany, our subprocessor list is public and names every non-EU parent company openly. A GDPR data processing agreement is part of the terms and we never use customer data to train AI models. Paid plans come with a 99.5% availability SLA, hourly encrypted backups kept for 30 days at a separate German location and support from the team that builds the product.
With PocketBase, all of this is in your hands: you pick the data centre, set up backups and decide on uptime. That gives you full control, including hosting in Germany if you choose a German provider. There is no company behind PocketBase to sign a DPA, offer an SLA or hold certifications.
Where PocketBase is the better choice
We would rather tell you than have you find out later:
It is free and open source under MIT, with no lock-in at all
One binary with no dependencies, very fast and very cheap to run on a small server.
More auth options: OTP, MFA and around 30 OAuth2 providers, including Apple and GitHub.
JS and Dart SDKs, so it fits web and Flutter apps out of the box.
You can use it as a Go framework and extend it in any way you like.
A very large and active community.
If you build a side project, a prototype or a small app and enjoy running your own server, PocketBase is excellent. pylo is for teams whose app runs a business and who want the backend, the back office and the operations handled for them.
Where pylo is a great PocketBase alternative
We think these are the main reasons to pick pylo over PocketBase:
Nothing to operate. No server, updates, backups or monitoring to run yourself, and no single machine as a single point of failure.
Schema changes without a deploy. Add an entity or field and the typed GraphQL API is live immediately, without any migration or redeployment.
Permissions down to the field. API, admin panel, forms, flows and MCP all go through the same permission layer, with hierarchies and field-level rules, including for the people in the admin panel.
Business logic without deployments. The flow builder covers event, cron and webhook triggers, with retries, rate limiting, typed actions and full logs. Custom actions are plain TypeScript.
Non-developers can work without you. Configurable admin views, state-dependent fields and a full form builder let operations teams handle their own changes. Not every change has to become a developer ticket.
Analytics you don't have to instrument. pylo records every change as an event with before and after state, and dashboards sit right next to the data.
AI access that's safe for production. MCP runs with the connected user's exact read permissions, and every write goes through human approval as a proposal.
A company behind it. A DPA, a 99.5% SLA from the first paid plan, hourly backups with 30-day retention and personal support from the people who build the product.
Built for agencies. You can run many client workspaces with separate tenants and permissions, and switch between them with one login, without a server per client.
German hosting from a German company. pylo hosts user data in Germany and the DPA is part of the terms.
FAQs - Questions and answers about pylo
Is pylo open source like PocketBase? No, but you can export all data at any time as CSV or JSON or through the API. The data models, flow definitions and generated SDK code are yours to keep, even after you leave.
Can I self-host pylo? No, but if you need specific hosting options, we can discuss them as part of the Enterprise plan.
Does pylo support realtime? Yes, pylo's GraphQL API supports subscriptions and webhooks notify other systems when data changes.
Does pylo scale? Yes, production workspaces of our customers already run with millions of records today.
Where exactly is my data? Content data is in data centres in Germany and backups are kept at a different German location.
Can I get access now? pylo is currently in private beta. Request access and we will set up your first entities with you on a call and onboard you personally for your first project.
The short answer
Pick the one that fits the team you have.
Pick PocketBase if…
Choose PocketBase if you want a free, open-source backend in one binary for a side project, prototype or small app, like running your own server and are happy to write your business logic in hooks.
Pick pylo if…
Choose pylo if your app runs a business and you don't want to operate the backend yourself: you get a hosted, live data model, permissions down to the field, flows, admin views and forms your non-developers can use, built-in event analytics and AI access with approval. It is also the better fit if you need an SLA, a DPA and hosting in Germany by a German company.
Moving over
Bring your schema, keep your data.
PocketBase collections map onto pylo fairly directly: each collection becomes an entity, fields become fields and relation fields become relations. Model the entities in pylo first, then export your records through the PocketBase API or read them from the SQLite file and load them as CSV or JSON with pylo's import profiles. Import profiles let you map columns to fields, use any field as the matching key and apply regex transformations during import. We handle large datasets of multiple gigabytes and you can re-run your import in dry-run mode until the mapping is right.
API rules become pylo permissions, realtime subscriptions become GraphQL subscriptions and Go or JavaScript hooks and cron jobs become pylo flows. You can migrate users, but you need to reinvite them and have them choose a password again. Talk to us at any point of your migration and we will go through your collections with you and plan the migration together.
Keep comparing